惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

H
Help Net Security
T
ThreatConnect
SecWiki News
SecWiki News
F
Future of Privacy Forum
AWS News Blog
AWS News Blog
C
Cisco Blogs
A
Arctic Wolf
Vercel News
Vercel News
The GitHub Blog
The GitHub Blog
Scott Helme
Scott Helme
V
V2EX
博客园 - 叶小钗
阮一峰的网络日志
阮一峰的网络日志
K
Kaspersky official blog
G
Google Developers Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
P
Privacy International News Feed
C
Cyber Attacks, Cyber Crime and Cyber Security
N
News | PayPal Newsroom
Schneier on Security
Schneier on Security
NISL@THU
NISL@THU
Microsoft Azure Blog
Microsoft Azure Blog
量子位
The Hacker News
The Hacker News
Stack Overflow Blog
Stack Overflow Blog
Security Latest
Security Latest
M
Microsoft Research Blog - Microsoft Research
Google Online Security Blog
Google Online Security Blog
博客园_首页
C
CXSECURITY Database RSS Feed - CXSecurity.com
I
InfoQ
Google DeepMind News
Google DeepMind News
Y
Y Combinator Blog
The Cloudflare Blog
Microsoft Security Blog
Microsoft Security Blog
Martin Fowler
Martin Fowler
Cisco Talos Blog
Cisco Talos Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
T
Troy Hunt's Blog
F
Fox-IT International blog
S
Security @ Cisco Blogs
博客园 - 司徒正美
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
C
Comments on: Blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
L
LINUX DO - 最新话题
GbyAI
GbyAI
Project Zero
Project Zero
腾讯CDC
T
Tailwind CSS Blog

cs updates on arXiv.org

Rethinking Continual Anomaly Detection on the Edge: Benchmarking Under Realistic Industrial Conditions Toward Enactive Artificial Intelligence Analyzing the Effects of Two-Stage Peer Evaluation Fourier Feature Pyramids for Physics-Informed Neural Networks Safety-Oriented Routing Analysis of Mixtral MoE Under Benign and Harmful Prompts Attested Tool-Server Admission: A Security Extension to the Model Context Protocol Optimizing Digital Therapeutic Interventions: Online Learning under Endogenous Adherence How Well Do Models Follow Their Constitutions? ECo-MoE: Embodiment-Conditioned Mixture of Experts Increases the Evolvability of Robots PrivFusion: A Privacy-preserving Multi-Agent Framework for Harmonizing Distributed Datasets Unlocking Apple's Private Cloud Compute: An Analysis of Privacy-Preserving Artificial Intelligence A Comprehensive Evaluation of Vertex Elimination Algorithms for Algorithmic Differentiation Plume Segmentation from MethaneSAT with Cross-Sensor Transfer Learning and Physics-Informed Postprocessing MeVer at CheckThat! 2026: Cluster-Aware Hard-Negative Mining for Multilingual Scientific-Source Retrieval Identifying and Mitigating Systemic Measurement Bias in Production LLM Inference Benchmarks A lift for input-convex neural network training ContextEcho: A Benchmark for Persona Drift in Long Agentic-Coding Sessions Polar: Agentic RL on Any Harness at Scale Accuracy Analysis of the Proxy Point Method with Applications to Some Toeplitz Matrices Sketch Bug: Using Sketch-Based Input for Interactive Code Debugging Beyond Final Answers: Auditing Trajectory-Level Hallucinations in Multi-Agent Industrial Workflows DRInQ: Evaluating Conversational Implicature with Controlled Context Variation CRISP -- Clustering-Based Redundancy-Reduced Instance Sampling for Pathology Case Representation and Retrieval GIBLy: Improving 3D Semantic Segmentation through an Architecture-Agnostic Lightweight Geometric Inductive Bias Layer Ant Backpressure Routing for Dynamic Wireless Multi-hop Networks with Mixed Traffic Patterns Program Synthesis for Non-Linear Real Arithmetic: Going Beyond Realizability Learning regime-dependent governing equations: A symbolic decision tree approach Resident KV Claims: A Conformance Contract for Future Reuse under Active KV Pressure Bayesian Rational Search Engine User An Interactive Paradigm for Deep Research Improving Labeling Consistency with Detailed Constitutional Definitions and AI-Driven Evaluation QUEST: Training Frontier Deep Research Agents with Fully Synthetic Tasks A Survey of Text and Speech Resources for Hausa and Fongbe: Availability, Quality, and Gaps for NLP Development Query-Adaptive Semantic Chunking for Retrieval-Augmented Generation: A Dynamic Strategy with Contextual Window Expansion How Far Will They Go? Red-Teaming Online Influence with Large Language Models RAS: Reflection-Augmented Scaling with In-Context Learning for Executable Cypher Query Generation Graph Alignment Topology as an Inductive Bias for Grounding Detection Can AI Guess What You Know? Performance Comparison of Large Language Models for Human Domain Knowledge Estimation From Communication Logs A Reproducible Universal Dependencies-Style Pipeline for Katharevousa Greek Parliamentary Text Memorization Dynamics of Fill-in-the-Middle Pretraining A Proactive Multi-Agent Dialogue Framework for Assessing Social Language Disorder Traits in Autism Brain-LLM Alignment Tracks Training Data, Not Typology HawkesLLM: Semantic Uncertainty Propagation in Agentic Text Simulation DreamerNLplus: Interpretable Modeling of Mental Health Dynamics from Social Media Timelines using Hybrid Rule-Based and RAG Methods Model Collapse as Cultural Evolution BOHM: Zero-Cost Hierarchical Attribution for Compound AI Systems NeuroNL2LTL: A Neurosymbolic Framework for Natural Language Translation of Linear Temporal Logic RMA: an Agentic System for Research-Level Mathematical Problems DFKI-MLT at SemEval-2026 TASK 7: Steering Multilingual Models Towards Cultural Knowledge SciAtlas: A Large-Scale Knowledge Graph for Automated Scientific Research The Efficiency Frontier: A Unified Framework for Cost-Performance Optimization in LLM Context Management Energy per Successful Goal: Goal-Level Energy Accounting for Agentic AI Systems A Comparative Evaluation of Structural Topic Models and BERTopic for Short, Open-Ended Survey Responses ImProver 2: Iteratively Self-Improving LMs for Neurosymbolic Proof Optimization Fast-dDrive: Efficient Block-Diffusion VLM for Autonomous Driving PathCal: State-Aware Reflection-Marker Calibration for Efficient Reasoning Positional Failures in Long-Context LLMs: A Blind Spot in Reasoning Benchmarks Inductive Deductive Synthesis: Enabling AI to Generate Formally Verified Systems Self-Improving In-Context Learning Redrawing the AI Map: A Theory of Accountability Boundaries in Agentic Ecosystems Hidden Human-Like Nature of Machine-Generated Texts: Theory and Detection Enhancement AutoResearch AI: Towards AI-Powered Research Automation for Scientific Discovery Foundation Protocol: A Coordination Layer for Agentic Society Convergence Without Understanding: When Language Models Agree on Representations but Disagree on Reasoning GENSTRAT: Toward a Science of Strategic Reasoning in Large Language Models AraHopeCorpus: Annotation Guidelines and Dataset for Hope Speech in Arabic Social Media Crisis Discourse Design and Report Benchmarks for Knowledge Work ClimateChat-300K: A Multi-Modal Facebook Dataset for Understanding Diverse Perspectives in Climate Communication Parallel Context Compaction for Long-Horizon LLM Agent Serving Emotion Recognition in Sign Language Conversation Ontological Knowledge Blocks: Executable Compliance and Profile-Based Validation for Trustworthy AI Systems GEM-4D: Geometry-Enhanced Video World Models for Robot Manipulation Cultural Adaptation in Large Language Models for Political Discourse DART: Semantic Recoverability for Structured Tool Agents Seeing without Looking: Do Vision-Language Benchmarks Really Test Vision? From Correctness to Preference: A Framework for Personalized Agentic Reinforcement Learning Human-in-the-Loop Multi-Agent Ventilator Decision Support with Contextual Bandit Preference Learning Suicide Risk Assessment from AI-powered Video Surveillance: An Interpretable Framework for Prevention in Metro Stations CoMoGen: COntrollable MOtion Dynamics and Interactions with Mask-Guided Video GENeration ARES: Automated Rubric Synthesis for Scalable LLM Reinforcement Learning The TIME Machine: On The Power of Motion for Efficient Perception One Policy, Infinite NPCs: Persona-Traceable Shared RL Policies for Scalable Game Agents Asking For An Old Friend: Diagnosing and Mitigating Temporal Failure Modes in LLM-based Statutory Question Answering Millimeter-wave Imaging for Anthropometric Body Measurement MemAudit: Post-hoc Auditing of Poisoned Agent Memory via Causal Attribution and Structural Anomaly Detection Structure-Guided Entity Resolution: Fine-Tuning LLMs for Robust Name Matching in Complex Linguistic Contexts Dithering Defense: Adversarial Robustness of Vision Foundation Models via Multi-Level Floyd-Steinberg Dithering Agentic Proving for Program Verification Benchmarking Google Embeddings 2 against Open-Source Models for Multilingual Dense Retrieval and RAG Systems RoboSurg-VQA: A Multimodal Benchmark for Surgical Segmentation-Aware Visual Question Answering Beyond Binary Edits Robust Multimodal Knowledge Editing with Adversarial Subspace Alignment How Human-Like Are Large Language Models? A Register-Aware Linguistic Evaluation Framework Flow Mismatching: Unsupervised Anomaly Detection via Velocity Discrepancies in Flow Matching Models Inconsistency-aware Multimodal Schrödinger Bridge for Deepfake Localization OpenSkillEval: Automatically Auditing the Open Skill Ecosystem for LLM Agents OnePred: Next-Query Prediction via Recursive Intent Memory in Multi-Turn Conversations Exploiting Longitudinal Context in Clinician-Verified Interactive Lesion Tracking ChartFI: Benchmarking Faithfulness and Insightfulness of Chart Descriptions from Multimodal Large Language Models An AI-Driven Framework for Energy-Efficient Environmental Monitoring in Smart Cities Using Edge Intelligence VisAnalog: A Diagnostic Suite for Visual Concept Transfer on Natural Images
Deep-Research Agents Can Be Poisoned via User-Generated Content
Tingwei Zhan · 2026-05-26 · via cs updates on arXiv.org

View PDF HTML (experimental)

Abstract:Deep-research agents, i.e., systems that rely on multi-agent pipelines to iteratively retrieve, synthesize, and cite Web content in order to produce structured reports, are rapidly replacing traditional search for both routine and complex information needs. These agents issue many related queries during a single research session. We show that for many common search topics, they repeatedly retrieve the same user-generated content (UGC) pages from platforms such as Reddit and Wikipedia. Next, we argue that this retrieval overlap creates a concentrated attack surface: an adversary who appends a short, crafted text to a single, frequently retrieved UGC page can cause the agent to cite attacker-chosen content and promote attacker-chosen entities across many related queries.
We evaluate this attack on three representative deep-research systems (STORM, Co-STORM, and OmniThink) across multiple query clusters. We also study defenses at different stages of the pipeline, including source-level filtering and output-based detection. Our findings highlight a fundamental vulnerability in how deep-research agents retrieve and integrate web content.
Subjects: Cryptography and Security (cs.CR)
Cite as: arXiv:2605.24245 [cs.CR]
  (or arXiv:2605.24245v1 [cs.CR] for this version)
  https://doi.org/10.48550/arXiv.2605.24245

arXiv-issued DOI via DataCite (pending registration)

Submission history

From: Tingwei Zhang [view email]
[v1] Fri, 22 May 2026 21:46:32 UTC (1,527 KB)