Pith. sign in

REVIEW 2 major objections 5 minor 253 references

Large language models turn misinformation from a content problem into an ecosystem security challenge by enabling attacks on social context, evidence, and verification systems themselves.

Reviewed by Pith at T0; open to challenge. T0 means a machine referee read the full paper against a public rubric. the ladder, T0–T4 →

T0 review · grok-4.5

2026-07-14 12:00 UTC pith:VER7NEP2

load-bearing objection Solid unifying survey: role×layer taxonomy plus attack–defense matrices that actually organize the LLM-misinformation literature and name three usable open challenges. the 2 major comments →

arxiv 2607.10402 v1 pith:VER7NEP2 submitted 2026-07-11 cs.CR cs.AIcs.SI

Large Language Models in Misinformation Ecosystems: Misuse, Defense, and Vulnerability

classification cs.CR cs.AIcs.SI
keywords misinformationlarge language modelsecosystem securityretrieval-augmented generationadversarial attacksfact-checkingagentic verificationrole-layer framework
verification ladder T0 review T1 audit T2 compute T3 formal T4 reserved

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

This paper argues that large language models have expanded misinformation beyond generating false text. They can be misused as attackers, used as defenders, and become the weak points inside detection systems. The authors introduce a role-layer framework that places LLMs as attackers, defenders, or victims across content, social contexts, evidence environments, and verification workflows. Using that map they organize attacks, LLM-based defenses, pipeline vulnerabilities, and countermeasures, then name three open challenges: budgeted ecosystem-level risk evaluation, hardening LLM-centered pipelines, and auditable human-in-the-loop deployment. A reader should care because defenses that only catch fake articles miss how LLMs can poison the social signals, evidence corpora, and agentic workflows that modern fact-checking depends on.

Core claim

LLMs have transformed misinformation from a primarily content-centric problem into a broader ecosystem-level security challenge. Misuse enables attacks not only on false content generation but on social contexts, evidence sources, retrieval corpora, and verification workflows. A role-layer framework—LLMs as attackers, defenders, and vulnerable components, crossed with content, social, evidence, and verification layers—unifies these risks and defenses and surfaces three open challenges: moving from static detection accuracy to budgeted ecosystem-level risk evaluation, hardening LLM-centered verification pipelines against adversarial manipulation, and deploying auditable human-in-the-loop syst

What carries the argument

The role-layer framework: roles (LLM as attacker, defender, or vulnerable component of a verification system) crossed with layers (content, social contexts, evidence environments, and verification workflows). It is the organizing structure that sorts attacks, defenses, vulnerabilities, and countermeasures into one map.

Load-bearing premise

The three-role by four-layer partition is treated as an adequate map of the field, and the survey’s coverage of attacks and defenses is assumed complete enough to justify the gap conclusions without a formal search protocol.

What would settle it

A systematic review of LLM-misinformation work from 2022–2026 that shows most high-impact papers fall outside the role-layer cells, or that the many empty defense cells are already filled by substantial misinformation-specific defenses the survey missed, would overturn the claimed unification and gap analysis.

Watch this falsifier — get emailed when new claim-graph text bears on it.

If this is right

  • Evaluation must shift from static detection accuracy to budgeted ecosystem-level risk under realistic attacker access and cost limits.
  • LLM-as-judge and agentic fact-checking pipelines must be hardened against prompt injection, corpus poisoning, tool misuse, and multi-agent prompt infection.
  • Real-world defense requires auditable human-in-the-loop systems with risk-adaptive resource allocation and post-deployment monitoring.
  • Content-only robustness leaves social-context and evidence-layer attacks largely open, matching the empty cells in the paper’s attack-defense matrices.
  • Future defenses should be designed and scored against the same attack surfaces the framework defines.

Where Pith is reading between the lines

These are editorial extensions of the paper, not claims the author makes directly.

  • The framework implies that platform integrity metrics—retrieval corpus health and engagement-graph authenticity—may matter as much as model accuracy for procurement and regulation.
  • Empty social and evidence defense cells point to long-horizon campaign simulation and provenance-aware RAG as high-leverage next empirical programs.
  • Treating LLMs as victims reframes fact-checking safety as a systems security problem, tying misinformation work more tightly to RAG poisoning and multi-agent prompt-infection research than the paper states.
  • Budgeted risk evaluation, if adopted, would push benchmarks to report cost-normalized attack success rather than peak success under white-box assumptions.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, simulated authors' rebuttal, and a circularity audit.

Referee Report

2 major / 5 minor

Summary. This survey argues that LLMs transform misinformation from a content-centric problem into an ecosystem-level security challenge. It introduces a role-layer framework (LLMs as attackers, defenders, and victims/vulnerable components of verification systems × content, social-context, evidence, and verification-workflow layers) to organize LLM-enabled attacks (Sec. 2), vulnerabilities of LLM-as-judge and agentic detectors (Sec. 3), LLM-based defenses (Sec. 4), and countermeasures with attack–defense correspondence matrices (Sec. 5, Tables 3–5). It further surveys datasets and metrics (Sec. 6) and identifies three open challenges: budgeted ecosystem-level risk evaluation, hardening LLM-centered pipelines, and auditable human-in-the-loop deployment (Sec. 7).

Significance. If the synthesis holds, the paper provides a useful organizing map for a rapidly growing and fragmented literature at the intersection of LLMs, misinformation, and security. Strengths include the explicit tri-role comparison against prior surveys (Table 1), coherent taxonomies (Figs. 4, 6, 8), attack–defense matrices that surface uneven coverage (Tables 3–5, including explicit “×” cells), and a clear shift from accuracy-only evaluation toward evidence quality, attack effectiveness, and deployment metrics (Table 7). The three challenges in Sec. 7 are actionable for follow-on work. As a survey, value rests on faithful organization and gap framing rather than new experiments; that is appropriate for the venue class if the coverage is transparent.

major comments (2)
  1. Sec. 1 and Tables 3–5: The gap conclusions (many “×” cells and the claim of a growing mismatch between attacks and defenses) are load-bearing for the paper’s contribution, yet the manuscript does not state a search protocol, inclusion/exclusion criteria, time window beyond Fig. 2’s reference counts, or how “misinformation-specific” was operationalized when marking defenses absent. Without that, Tables 3–5 read as expert synthesis rather than defensible gap maps. A short methods subsection (databases, keywords, cutoff date, and criteria for “×”) would make the central gap narrative reproducible and proportionate.
  2. Table 2 and Sec. 3 vs. Sec. 4: The victim role is defined as failure of LLM-centric verification pipelines, while the defender role covers design of those same pipelines. Several agentic and RAG systems appear in both taxonomies (e.g., multi-agent fact-checking, retrieval-centric verification). The manuscript should state more clearly when a work is classified as defense design versus vulnerability analysis (or both), and how double-counting is avoided in Fig. 2’s temporal counts, so the role partition remains non-arbitrary for readers using the framework.
minor comments (5)
  1. Fig. 2: State the counting rule (unique papers vs. multi-role assignment) and the June 2026 cutoff so the temporal claim is interpretable.
  2. Table 6: Several rows list evidence sources as empty or “–” while the text discusses evidence-grounded use; align table cells with the prose for PHEMEPlus, FELM, and related sets.
  3. Sec. 5 tables: The footnote that “×” means no identified misinformation-specific defense is helpful; consider also noting when general RAG/security defenses exist but were excluded, to avoid over-reading absence.
  4. Presentation: Occasional spacing/typos (e.g., “Defensing” in a cited title context, inconsistent hyphenation of “fact-checking”) and dense multi-citation runs could be lightly edited for readability.
  5. Sec. 6.2: Briefly distinguish metrics that are standard in the cited works from those proposed as desiderata for future LLM-era evaluation.

Circularity Check

0 steps flagged

No significant circularity: role-layer framework is organizational taxonomy, not a derivation that reduces predictions to fitted inputs or self-definitional claims.

full rationale

This is a survey/synthesis paper. Its central contribution is a role (attacker/defender/victim) × layer (content/social/evidence/verification) taxonomy that organizes existing literature on LLM-enabled misinformation, plus three open challenges derived from that synthesis. There are no equations, fitted parameters, uniqueness theorems, or quantitative predictions that could reduce by construction to their inputs. Table 1's self-positioning against prior surveys is standard survey practice and does not force the gap conclusions. Tables 3–5 mark many defense cells with "×" and explicitly caveat that the authors "did not identify directly targeted defenses in the misinformation-specific literature"; those are literature-coverage claims, not circular derivations. Self-citations to the authors' own prior work appear only as ordinary references among many external works and are not load-bearing for any uniqueness or forced-choice argument. The three open challenges (budgeted ecosystem-level risk evaluation, hardening LLM-centered pipelines, auditable human-in-the-loop systems) are forward-looking recommendations, not results claimed to follow from a closed formal chain. Honest finding: score 0; steps empty.

Axiom & Free-Parameter Ledger

0 free parameters · 4 axioms · 1 invented entities

This is a conceptual survey. Load-bearing structure is definitional (roles and layers), domain assumptions about what counts as misinformation and verification, and the unstated completeness of literature coverage used to assert defense gaps. No free parameters or physical constants. The main invented entity is the role-layer framework itself, used as an organizing device rather than a falsifiable physical object.

axioms (4)
  • ad hoc to paper Misinformation risks with LLMs are usefully partitioned into content, social-context, evidence-environment, and verification-workflow layers.
    Introduced as the layer dimension of the role-layer framework (Table 2, §1); not derived from a uniqueness theorem or external standard ontology.
  • ad hoc to paper LLMs in the misinformation ecosystem are adequately characterized by three roles: attacker, defender, and victim (vulnerable component of verification systems).
    Core organizing claim of §1 and Table 2; used to structure §§2–4 and to differentiate from prior surveys in Table 1.
  • domain assumption Misinformation is false or misleading information regardless of intent.
    Stated in §1 with citations [4, 28, 63, 241]; standard definitional stance that scopes the survey.
  • domain assumption Absence of identified misinformation-specific defenses in the surveyed literature implies a real defense gap for the corresponding attack type (Tables 3–5 “×” cells).
    Underpins §5 gap discussions; depends on unstated search completeness rather than a proof of nonexistence.
invented entities (1)
  • Role-layer framework (attacker/defender/victim × content/social/evidence/workflow) no independent evidence
    purpose: Unify LLM-enabled attacks, LLM-based defenses, and vulnerabilities of LLM-centric verification into one map and motivate three open challenges.
    Primary conceptual contribution of the paper (Table 2, Fig. 1); organizes the survey rather than predicting a measurable quantity outside the taxonomy.

pith-pipeline@v1.1.0-grok45 · 40530 in / 3141 out tokens · 40431 ms · 2026-07-14T12:00:26.206328+00:00 · methodology

0 comments
read the original abstract

Large language models (LLMs) have transformed misinformation from a primarily content-centric problem into a broader ecosystem-level security challenge. When misused, LLMs create risks beyond false content generation, enabling attacks on the social contexts, evidence sources, retrieval corpora, and verification workflows that misinformation defense depends on. In this paper, we introduce a role-layer framework to unify these risks and defenses. The role dimension characterizes LLMs as attackers, defenders, and vulnerable components of verification systems, while the layer dimension covers content, social contexts, evidence environments, and verification workflows. Guided by this framework, we organize LLM-enabled attacks, investigate LLM-based detection and verification methods, analyze vulnerabilities in LLM-centric detection paradigms, and discuss existing countermeasures against LLM-enabled attacks. Building on this synthesis, we identify three key open challenges: moving from static detection accuracy to budgeted ecosystem-level risk evaluation, hardening LLM-centered verification pipelines against adversarial manipulation, and deploying auditable human-in-the-loop verification systems for trustworthy real-world misinformation defense.

Figures

Figures reproduced from arXiv: 2607.10402 by Dou Hu, Lingwei Wei, Philip S. Yu, Songlin Hu, Wei Zhou.

Figure 1
Figure 1. Figure 1: Overview of LLM roles in the misinformation ecosystem. [PITH_FULL_IMAGE:figures/full_fig_p002_1.png] view at source ↗
Figure 2
Figure 2. Figure 2: Temporal distribution of references across the three LLM roles from 2022 to June 2026 in this work. [PITH_FULL_IMAGE:figures/full_fig_p004_2.png] view at source ↗
Figure 3
Figure 3. Figure 3: Overview of LLM-empowered attack for misinformation detection. [PITH_FULL_IMAGE:figures/full_fig_p005_3.png] view at source ↗
Figure 4
Figure 4. Figure 4: The taxonomy of LLM-enabled misinformation attacks. [PITH_FULL_IMAGE:figures/full_fig_p006_4.png] view at source ↗
Figure 5
Figure 5. Figure 5: Overview of vulnerabilities of LLM-based misinformation detection paradigms. [PITH_FULL_IMAGE:figures/full_fig_p009_5.png] view at source ↗
Figure 6
Figure 6. Figure 6: The taxonomy of vulnerabilities of LLM-based misinformation detection paradigms. [PITH_FULL_IMAGE:figures/full_fig_p010_6.png] view at source ↗
Figure 7
Figure 7. Figure 7: Overview of LLM-based defense methods for misinformation detection. [PITH_FULL_IMAGE:figures/full_fig_p012_7.png] view at source ↗
Figure 8
Figure 8. Figure 8: The taxonomy of LLM-based defense methods. [PITH_FULL_IMAGE:figures/full_fig_p013_8.png] view at source ↗

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.

Reference graph

Works this paper leans on

253 extracted references · 1 canonical work pages

  1. [1]

    Sahar Abdelnabi and Mario Fritz. 2023. {Fact-Saboteurs}: A taxonomy of evidence manipulation attacks against {Fact-Verification}systems. InUSENIX Security. 6719–6736

  2. [2]

    Sarfraz Ahmad, Hasan Iqbal, Momina Ahsan, Numaan Naeem, Muhammad Ahsan Riaz Khan, Arham Riaz, Muham- mad Arslan Manzoor, Yuxia Wang, and Preslav Nakov. 2025. UrduFactCheck: An Agentic Fact-Checking Framework for Urdu with Evidence Boosting and Benchmarking. InEMNLP. 22788–22802

  3. [3]

    Md Shoaib Ahmed and Francesca Spezzano. 2026. A New Attack Surface: XAI-guided Adversarial Comment Generation with LLMs to Attack Fake News Detectors. InWSDM. 1058–1062

  4. [4]

    Esma Aïmeur, Sabrine Amri, and Gilles Brassard. 2023. Fake news, disinformation and misinformation in social media: a review.Social Network Analysis and Mining13, 1 (2023), 30

  5. [5]

    Nouar Aldahoul and Yasir Zaki. 2025. Toward a safer web: multilingual multi-agent LLMs for mitigating adversarial misinformation attacks.arXiv preprint arXiv:2510.08605(2025)

  6. [6]

    Rami Aly, Zhijiang Guo, Michael Schlichtkrull, James Thorne, Andreas Vlachos, Christos Christodoulopoulos, Oana Cocarascu, and Arpit Mittal. 2021. The fact extraction and VERification over unstructured and structured information (FEVEROUS) shared task. InProceedings of the Fourth Workshop on Fact Extraction and VERification (FEVER). 1–13

  7. [7]

    Pepa Atanasova, Jakob Grue Simonsen, Christina Lioma, and Isabelle Augenstein. 2022. Fact checking with insufficient evidence.TACL10 (2022), 746–763

  8. [8]

    Alexandru-Andrei Avram, Alexandru Lecu, and Adrian Groza. 2025. MCP-Orchestrated Multi-Agent System for Automated Disinformation Detection. InSYNASC. 333–341

  9. [9]

    Yangxiao Bai and Kaiqun Fu. 2024. A Large Language Model-based Fake News Detection Framework with RAG Fact-Checking. InIEEE Big Data. IEEE, 8617–8619

  10. [10]

    Chathura Bandara. 2024. Hallucination as disinformation: The role of LLMs in amplifying conspiracy theories and fake news.Journal of Applied Cybersecurity Analytics, Intelligence, and Decision-Making Systems14, 12 (2024), 65–76

  11. [11]

    Alimohammad Beigi, Zhen Tan, Nivedh Mudiam, Canyu Chen, Kai Shu, and Huan Liu. 2024. Model attribution in llm-generated disinformation: A domain generalization approach with supervised contrastive learning. In2024 IEEE , Vol. 1, No. 1, Article . Publication date: July 2026. 26 Lingwei Wei, Dou Hu, Wei Zhou, Songlin Hu, and Philip S. Yu 11th International ...

  12. [12]

    Mazal Bethany, Nishant Vishwamitra, Cho-Yu Jason Chiang, and Peyman Najafirad. 2025. CAMOUFLAGE: Exploit- ing Misinformation Detection Systems Through LLM-driven Adversarial Claim Transformation.arXiv preprint arXiv:2505.01900(2025)

  13. [13]

    Chong Jun Rong Brian, Yixuan Tang, and Anthony Kum Hoe Tung. 2025. MPCG: Multi-Round Persona-Conditioned Generation for Modeling the Evolution of Misinformation with LLMs. InEMNLP. 34018–34052

  14. [14]

    Roopa Bukke, Soumya Pandey, Suraj Kumar, Soumi Chattopadhyay, and Chandranath Adak. 2025. Agentic Multi- Persona Framework for Evidence-Aware Fake News Detection.arXiv preprint arXiv:2512.21039(2025)

  15. [15]

    Han Cao, Lingwei Wei, Wei Zhou, and Songlin Hu. 2025. Enhancing Multi-Hop Fact Verification with Structured Knowledge-Augmented Large Language Models. InAAAI. AAAI Press, 23514–23522

  16. [16]

    Hongyan Chang, Ergute Bao, Xinjian Luo, and Ting Yu. 2026. Overcoming the Retrieval Barrier: Indirect Prompt Injection in the Wild for LLM Systems.arXiv preprint arXiv:2601.07072(2026)

  17. [17]

    Zhiyuan Chang, Mingyang Li, Xiaojun Jia, Junjie Wang, Yuekai Huang, Ziyou Jiang, Yang Liu, and Qing Wang. 2025. One Shot Dominance: Knowledge Poisoning Attack on Retrieval-Augmented Generation Systems. InFindings of the Association for Computational Linguistics: EMNLP 2025. 18811–18825

  18. [18]

    Canyu Chen and Kai Shu. 2024. Can LLM-generated misinformation be detected?. InICLR, Vol. 2024. 34687–34726

  19. [19]

    Canyu Chen and Kai Shu. 2024. Combating misinformation in the age of llms: Opportunities and challenges.AI magazine45, 3 (2024), 354–368

  20. [20]

    Kuan-Chun Chen, Chih-Yao Chen, and Cheng-Te Li. 2023. Anti-disinformation: an adversarial attack and defense network towards improved robustness for disinformation detection on social media. InIEEE BigData. 5476–5484

  21. [21]

    Lei Chen and Zhongyu Wei. 2024. Resolving Unseen Rumors with Retrieval-Augmented Large Language Models. In NLPCC, Vol. 15362. 319–332

  22. [22]

    Liuji Chen, Xiaofang Yang, Yuanzhuo Lu, Jinghao Zhang, Xin Sun, Qiang Liu, Shu Wu, Jing Dong, and Liang Wang

  23. [23]

    PoisonArena: Uncovering Competing Poisoning Attacks in Retrieval-Augmented Generation.arXiv preprint arXiv:2505.12574(2025)

  24. [24]

    Mengyang Chen, Lingwei Wei, Han Cao, Wei Zhou, and Songlin Hu. 2025. Explore the Potential of LLMs in Misinfor- mation Detection: An Empirical Study. InAAAI 2025 Workshop on Preventing and Detecting LLM Misinformation

  25. [25]

    Mengyang Chen, Lingwei Wei, Wei Zhou, and Songlin Hu. 2025. Structure-aware Propagation Generation with Large Language Models for Fake News Detection. InFindings of the Association for Computational Linguistics: EMNLP 2025. 13258–13272

  26. [26]

    Mengyang Chen, Lingwei Wei, Wei Zhou, and Songlin Hu. 2026. An Information-theoretic Propagation Denoising and Fusion Framework for Fake News Detection. InIJCAI

  27. [27]

    Qiuyi Chen. 2026. Networked manipulation: multi-actor coordinated communities and formation mechanisms in disinformation campaigns.Online Information Review(2026), 1–20

  28. [28]

    Qizhi Chen, Chao Qi, Yihong Huang, Muquan Li, Rongzheng Wang, Dongyang Zhang, Ke Qin, and Shuang Liang

  29. [29]

    Kepo: Knowledge evolution poison on graph-based retrieval-augmented generation. InWWW. 2308–2319

  30. [30]

    Sijing Chen, Lu Xiao, and Akit Kumar. 2023. Spread of misinformation on social media: What contributes to it and how to combat it.Computers in Human Behavior141 (2023), 107643

  31. [31]

    Tailun Chen, Yu He, Yan Wang, Shuo Shao, Haolun Zheng, Zhihao Liu, Jinfeng Li, Zhizhen Qin, Yuefeng Chen, Zhixuan Chu, Zhan Qin, and Kui Ren. 2026. MIRAGE: Misleading Retrieval-Augmented Generation via Black-box and Query-agnostic Poisoning Attacks. InCCS

  32. [32]

    Zhuo Chen, Yuyang Gong, Jiawei Liu, Miaokun Chen, Haotan Liu, Qikai Cheng, Fan Zhang, Wei Lu, and Xiaozhong Liu. 2025. Flippedrag: Black-box opinion manipulation adversarial attacks to retrieval-augmented generation models. InSIGSAC. 4109–4123

  33. [33]

    Pengzhou Cheng, Yidong Ding, Tianjie Ju, Zongru Wu, Wei Du, Ping Yi, Zhuosheng Zhang, and Gongshen Liu

  34. [34]

    Trojanrag: Retrieval-augmented generation can be backdoor driver in large language models.arXiv preprint arXiv:2405.13401(2024)

  35. [35]

    Ethan Chern, Steffi Chern, Shiqi Chen, Weizhe Yuan, Kehua Feng, Chunting Zhou, Junxian He, Graham Neubig, and Pengfei Liu. 2025. FacTool: Factuality Detection in Generative AI–A Tool Augmented Framework for Multi-Task and Multi-Domain Scenarios. InSecond Conference on Language Modeling. https://openreview.net/forum?id=hJkQL9VtWT

  36. [36]

    Anshuman Chhabra, Shrestha Datta, Shahriar Kabir Nahin, and Prasant Mohapatra. 2026. Agentic AI security: Threats, defenses, evaluation, and open challenges.IEEE Access(2026)

  37. [37]

    Sukmin Cho, Soyeong Jeong, Jeongyeon Seo, Taeho Hwang, and Jong C Park. 2024. Typos that broke the rag’s back: Genetic attack on rag pipeline by simulating documents in the wild via low-level perturbations. InFindings of the Association for Computational Linguistics: EMNLP 2024. 2826–2844

  38. [38]

    Christopher Clark, Kenton Lee, Ming-Wei Chang, Tom Kwiatkowski, Michael Collins, and Kristina Toutanova. 2019. Boolq: Exploring the surprising difficulty of natural yes/no questions. InNAACL-HLT. 2924–2936. , Vol. 1, No. 1, Article . Publication date: July 2026. Large Language Models in Misinformation Ecosystems: Misuse, Defense, and Vulnerability 27

  39. [39]

    Limeng Cui and Dongwon Lee. 2020. CoAID: COVID-19 Healthcare Misinformation Dataset.CoRRabs/2006.00885 (2020)

  40. [40]

    Zikun Cui, Tianyi Huang, Chia-En Chiang, and Cuiqianhe Du. 2025. Toward verifiable misinformation detection: A multi-tool LLM agent framework. InProceedings of the 2025 International Conference on Generative Artificial Intelligence for Business. 179–185

  41. [41]

    Enyan Dai, Yiwei Sun, and Suhang Wang. 2020. Ginger cannot cure cancer: Battling fake health news with a comprehensive data repository. InProceedings of the International AAAI Conference on Web and Social Media, Vol. 14. 853–862

  42. [42]

    Valdemar Danry, Pat Pataranutaporn, Matthew Groh, and Ziv Epstein. 2025. Deceptive explanations by large language models lead people to change their beliefs about misinformation more often than honest explanations. InCHI. 1–31

  43. [43]

    Dao, Yasuhiro Hashimoto, and Truong Cong Thang

    Hong N. Dao, Yasuhiro Hashimoto, and Truong Cong Thang. 2025. An LLM-Enabled Multi-Agent System for Evidence-Grounded Fact Checking. InMCSoC. IEEE, 125–130

  44. [44]

    Rupak Kumar Das and Jonathan Dodge. 2025. Fake news detection after llm laundering: Measurement and explanation. arXiv preprint arXiv:2501.18649(2025)

  45. [45]

    Zehang Deng, Yongjian Guo, Changzhou Han, Wanlun Ma, Junwu Xiong, Sheng Wen, and Yang Xiang. 2025. Ai agents under threat: A survey of key security challenges and future pathways.Comput. Surveys57, 7 (2025), 1–36

  46. [46]

    Matthew R DeVerna, Harry Yaojun Yan, Kai-Cheng Yang, and Filippo Menczer. 2024. Fact-checking information from large language models can decrease headline discernment.Proceedings of the National Academy of Sciences121, 50 (2024), e2322823121

  47. [47]

    Jay DeYoung, Sarthak Jain, Nazneen Fatema Rajani, Eric Lehman, Caiming Xiong, Richard Socher, and Byron C Wallace. 2020. ERASER: A benchmark to evaluate rationalized NLP models. InACL. 4443–4458

  48. [48]

    Yuze Ding and Shibin Zhang. 2025. Dynamic Semantic-Constrained Adversarial Training and Defensing: A Re- inforcement Learning Framework for LLM-Generated Fake Information Detection. InProceedings of the 2025 2nd International Conference on Generative Artificial Intelligence and Information Security. 237–241

  49. [49]

    Liwei Dong, Yanli Chen, Wei Ke, Hanzhou Wu, Lunzhi Deng, and Guixiang Liao. 2026. Multimodal Fake News Detection via Evidence Retrieval and Visual Forensics with Large Vision-Language Models.Inf.17, 4 (2026), 317

  50. [50]

    Yunyun Dong, Jinfeng Luo, Tingchao Fu, Fanxiao Li, Dayang Li, Viradeth Sixanonh, and Wei Zhou. 2026. DPSA: Deception Pattern Learning and Sentiment-Aware Enhancement for Unseen Misinformation Detection. InDASFAA. 613–628

  51. [51]

    John Dougrez-Lewis, Elena Kochkina, Miguel Arana-Catania, Maria Liakata, and Yulan He. 2022. PHEMEPlus: enriching social media rumour verification with external evidence. InProceedings of the fifth fact extraction and verification workshop (FEVER). 49–58

  52. [52]

    Yibing Du, Antoine Bosselut, and Christopher D Manning. 2022. Synthetic disinformation attacks on automated fact verification systems. InAAAI, Vol. 36. 10581–10589

  53. [53]

    David Farr, Lynnette Hui Xian Ng, Stephen Prochaska, Iain J Cruickshank, and Jevin West. 2025. Simulating Misinformation Vulnerabilities with Agent Personas. In2025 Winter Simulation Conference (WSC). IEEE, 1907–1918

  54. [54]

    Zetao Fei, Yu-Ming Shang, Rouxi Wang, Gang Wang, Yong Liu, and Yong Ma. 2026. Enhancing text representation with frequency-domain features for robust fake news detection.Knowledge-Based Systems(2026), 116009

  55. [55]

    Shangbin Feng, Herun Wan, Ningnan Wang, Zhaoxuan Tan, Minnan Luo, and Yulia Tsvetkov. 2024. What does the bot say? opportunities and risks of large language models in social media bot detection. InACL. 3580–3601

  56. [56]

    Runpeng Geng, Yanting Wang, Ying Chen, and Jinyuan Jia. 2025. UniC-RAG: Universal Knowledge Corruption Attacks to Retrieval-Augmented Generation.arXiv preprint arXiv:2508.18652(2025)

  57. [57]

    Yuyang Gong, Zhuo Chen, Jiawei Liu, Miaokun Chen, Fengchang Yu, Wei Lu, XiaoFeng Wang, and Xiaozhong Liu. 2025. Topic-FlipRAG: Topic-Orientated Adversarial Opinion Manipulation Attacks to Retrieval-Augmented Generation Models. InUSENIX Security. 3807–3826

  58. [58]

    Yuxia Gong, Shuguo Hu, and Huaiwen Zhang. 2025. Cross-domain Rumor Detection via Test-Time Adaptation and Large Language Models. InEMNLP. 8062–8077

  59. [59]

    Lukas Gosch, Mahalakshmi Sabanayagam, Debarghya Ghoshdastidar, and Stephan Günnemann. 2025. Provable Robustness of (Graph) Neural Networks Against Data Poisoning and Backdoor Attacks.TMLR(2025)

  60. [60]

    Hyeonjeong Ha, Qiusi Zhan, Jeonghwan Kim, Dimitrios Bralios, Saikrishna Sanniboina, Nanyun Peng, Kai-Wei Chang, Daniel Kang, and Heng Ji. 2025. MM-PoisonRAG: Disrupting Multimodal RAG with Local and Global Poisoning Attacks.arXiv preprint arXiv:2502.17832(2025)

  61. [61]

    Md Ahsan Habib, Md Anwar Hussen Wadud, MF Mridha, and Md Jakir Hossen. 2026. LLM-powered multimodal reasoning for fake news detection.Computers, Materials, & Continua87, 1 (2026)

  62. [62]

    Chen Han, Yijia Ma, Jin Tan, Wenzhen Zheng, and Xijin Tang. 2026. Beyond Detection: Exploring Evidence-based Multi-Agent Debate for Misinformation Intervention and Persuasion. InAAAI, Vol. 40. 38542–38550. , Vol. 1, No. 1, Article . Publication date: July 2026. 28 Lingwei Wei, Dou Hu, Wei Zhou, Songlin Hu, and Philip S. Yu

  63. [63]

    Chen Han, Wenzhen Zheng, and Xijin Tang. 2025. Debate-to-detect: Reformulating misinformation detection as a real-world debate with large language models. InEMNLP. 15125–15140

  64. [64]

    Kyubeen Han, Junseo Jang, Hongjin Kim, Geunyeong Jeong, and Harksoo Kim. 2025. Exploring the impact of instruction-tuning on llm’s susceptibility to misinformation. InACL. 26711–26731

  65. [65]

    Linfeng Han, Xiaoming Zhang, Tianbo Wang, Yun Liu, and Zhiqiang Dong. 2026. Enhancing large language model for fake news video detection via cross-modal retrieval.Inf. Process. Manag.63, 2 (2026), 104471

  66. [66]

    Katrin Hartwig, Frederic Doell, and Christian Reuter. 2024. The landscape of user-centered misinformation interventions-a systematic literature review.Comput. Surveys56, 11 (2024), 1–36

  67. [67]

    Haorui He, Yupeng Li, Dacheng Wen, Yang Chen, Reynold Cheng, Donglong Chen, and Francis CM Lau. 2026. Debating truth: Debate-driven claim verification with multiple large language model agents. InWWW. 8851–8861

  68. [68]

    Haorui He, Yupeng Li, Bin Benjamin Zhu, Dacheng Wen, Reynold Cheng, and Francis CM Lau. 2026. Fact2Fiction: Targeted poisoning attack to agentic fact-checking system. InAAAI, Vol. 40. 30943–30950

  69. [69]

    Jing He, Han Zhang, Yuanhui Xiao, Wei Guo, Shaowen Yao, and Renyang Liu. 2026. Factguard: Event-centric and commonsense-guided fake news detection. InAAAI, Vol. 40. 363–371

  70. [70]

    Spencer Hong, Meng Luo, and Xinyi Wan. 2025. Emulate: A multi-agent framework for determining the veracity of atomic claims by emulating human actions. InProceedings of the Eighth Fact Extraction and VERification Workshop (FEVER). 179–183

  71. [71]

    Beizhe Hu, Qiang Sheng, Juan Cao, Yang Li, and Danding Wang. 2025. Llm-generated fake news induces truth decay in news ecosystem: A case study on neural news recommendation. InProceedings of the 48th International ACM SIGIR Conference on Research and Development in Information Retrieval. 435–445

  72. [72]

    Beizhe Hu, Qiang Sheng, Juan Cao, Yuhui Shi, Yang Li, Danding Wang, and Peng Qi. 2024. Bad actor, good advisor: Exploring the role of large language models in fake news detection. InAAAI, Vol. 38. 22105–22113

  73. [73]

    Hui Huang, Muyun Yang, and Yuki Arase. 2026. DiVA: Fine-grained Factuality Verification with Agentic-Discriminative Verifier.arXiv preprint arXiv:2601.03605(2026)

  74. [74]

    Larry Huynh, Andrew Gansemer, Hyoungshick Kim, and Jin B Hong. 2024. Improving the Robustness of Rumor Detection Models with Metadata-Augmented Evasive Rumor Datasets. InInternational Conference on Web Information Systems Engineering. Springer, 336–351

  75. [75]

    Md Athikul Islam, Noel Ellison, Bishal Lakha, and Edoardo Serra. 2025. Inconsistent Reasoning Attacks to Identify Weaknesses in Automatic Scientific Claim Verification Tools. InJoint European Conference on Machine Learning and Knowledge Discovery in Databases. Springer, 56–73

  76. [76]

    Bhavuk Jain, Sercan O Arik, and HARDEO KUMAR THAKUR. 2026. Adversarial Attacks on Multimodal Large Language Models: A Comprehensive Survey.TMLR(2026). https://openreview.net/pdf?id=zwzodDJkzZ

  77. [77]

    Iveri Jajanidze and Ioseb Kartvelishvili. 2025. Large Language Models and Their Abuse in High-Level Social Engineer- ing Campaigns.Editorial Board(2025), 34

  78. [78]

    Wei Jiang, Tong Chen, Xinyi Gao, Wentao Zhang, Lizhen Cui, and Hongzhi Yin. 2025. Epidemiology-informed network for robust rumor detection. InWWW. 3618–3627

  79. [79]

    Xiaochong Jiang, Shiqi Yang, Wenting Yang, Yichen Liu, and Cheng Ji. 2026. Agentic ai as a cybersecurity attack surface: Threats, exploits, and defenses in runtime supply chains. InCAI. 2142–2149

  80. [80]

    Di Jin, Jun Yang, Xiaobao Wang, Junwei Zhang, Shuqi Li, and Dongxiao He. 2025. A Dynamic Knowledge Update- Driven Model with Large Language Models for Fake News Detection. InIJCAI. ijcai.org, 3000–3008

Showing first 80 references.