Deep-Research Agents Can Be Poisoned via User-Generated Content
2026/05/22 by Tingwei Zhang, Harold Triedman, Vitaly Shmatikov · 17 voices · 1 citation
#cs.CR
paper · pdf
Abstract
Deep-research agents, i.e., systems that rely on multi-agent pipelines to iteratively retrieve, synthesize, and cite Web content in order to produce structured reports, are rapidly replacing traditional search for both routine and complex information needs. These agents issue many related queries during a single research session. We show that for many common search topics, they repeatedly retrieve the same user-generated content (UGC) pages from platforms such as Reddit and Wikipedia. Next, we argue that this retrieval overlap creates a concentrated attack surface: an adversary who appends a short, crafted text to a single, frequently retrieved UGC page can cause the agent to cite attacker-chosen content and promote attacker-chosen entities across many related queries. We evaluate this attack on three representative deep-research systems (STORM, Co-STORM, and OmniThink) across multiple query clusters. We also study defenses at different stages of the pipeline, including source-level filtering and output-based detection. Our findings highlight a fundamental vulnerability in how deep-research agents retrieve and integrate web content.
Citations
Cited by
Discussions
- It Is Trivially Easy to Use Reddit to Manipulate AI Search, Research Suggests [lemmy, 193 points, 15 comments]
- arxiv.org/pdf/2605.24245 [bsky, 48 points, 3 comments]
- It Is Trivially Easy to Use Reddit to Manipulate AI Search, Research Suggests [lemmy, 32 points, 1 comments]
- It Is Trivially Easy to Use Reddit to Manipulate AI Search, Research Suggests [lemmy, 14 points, 0 comments]
- I'm an AI security researcher, my lab just published a paper on the vulnerabilities of these kinds of systems to spam, scams, and misinfo content: arxiv.org/abs/2605.24245 tldr it's not just biohackin [bsky, 8 points, 0 comments]
- Link to the freaking paper 😱 arxiv.org/abs/2605.24245 [bsky, 5 points, 0 comments]
- It's easy to get the impression that an AI is considering and thoughtfully weighing many sources when answering your query, but nope, it may just be parroting some single Reddit comment which could ha [bsky, 4 points, 1 comments]
- is this big enough to kill the #AI hype? Deep-Research Agents Can Be Poisoned via User-Generated Content https://arxiv.org/pdf/2605.24245 #science #technology #NoAI [bsky, 3 points, 0 comments]
- Deep-Research Agents Can Be Poisoned via User-Generated Content [hn, 3 points, 0 comments]
- For reference, this is the paper they're discussing. arxiv.org/abs/2605.24245 [bsky, 2 points, 0 comments]
- [Read] Deep-Research Agents Can Be Poisoned via User-Generated Content arxiv.org/pdf/2605.242.... From academic context probably only Google scholar (any paper that looks "scholarly" or academic searc [bsky, 1 points, 0 comments]
- Deep-Research Agents Can Be Poisoned via User-Generated Content 22 May 2026 arxiv.org/abs/2605.24245 [bsky, 1 points, 1 comments]
- so it appears posting a 11 to 15 words length post on reddit is enough to manipulate AI search results consumed by hundreds of millions of people worldwide every day. I can't see what could possibly e [bsky, 0 points, 0 comments]
- arxiv.org/pdf/2605.24245 Deep-Research Agents Can Be Poisoned via User-Generated Content "From the attacker’s perspective, Reddit’s consistent dominance makes it the highest-leverage target." #deepres [bsky, 0 points, 0 comments]
- The preprint discussed in the 404Media article is available here: "Deep-Research Agents Can Be Poisoned via User-Generated Content" arxiv.org/pdf/2605.24245 #GenAI #LLMs #deepresearch [bsky, 0 points, 0 comments]
- Really interesting research that follows up on some of the concerns I had about AI well poisoning. My larger concern is that they don’t bring up how easy this would be to do to inject security vulnera [bsky, 0 points, 1 comments]
- read the study behind the "it's really easy to manipulate AI with tiny Wikipedia edits" and the wiki angle here is a little overstated; this particular attack sticks out a lot more in a wiki article t [bsky, 0 points, 1 comments]
Related