Autonomous agents designed for deep research are failing their professional competency tests in open environments. While the market dreams of fully automated analytics, a study by the Beijing University of Posts and Telecommunications and the Shanghai AI Laboratory reveals a systemic vulnerability: Deep Research agents are critically defenseless against "plausible" disinformation. Using the MisKnow-Agent framework, researchers proved that even a minimal injection of convincing falsehoods poisons the entire workflow—from initial planning to the synthesis of the final report.
Distorted data does more than just enter the sample; it becomes the foundation upon which the agent builds subsequent steps, compresses information, and draws false conclusions that appear to be the result of rigorous analysis.
Key Research Findings
The vulnerability is fundamental: this is not a random hallucination, but a logical failure in processing multi-stage tasks. Verification models recognize fakes during direct fact-checking but ignore them when embedded in a complex data synthesis process. Experiments across 6,000 scenarios showed that neither advanced planning nor sophisticated text-processing skills protect against disinformation. Existing filtering methods only insignificantly reduce the level of unreliability in final reports.
Business Risks and Defense Strategy
In our view, the industry has hit a paradox. For businesses, this represents a direct threat: strategic decisions in R&D or fintech risk being made based on industrially synthesized fiction. Blindly trusting autonomous pipelines has become a significant management risk.
To prevent AI analytics from becoming a generator of convenient but false myths, companies must implement independent verification layers and cryptographic source control at the framework architecture level. Without rigorous control over the evidentiary base, any "autonomous expertise" remains nothing more than a costly and dangerous illusion.