Study: Generative AI succumbs to conversational misinformed pressure and argument

By Mikayla Mace Kelley, University Communications
Today
Image
A man looking at his phone with a confused look on this face.

The results are in: Which AI model is the most fallible? Persuadable? Correctible?

University of Arizona research assessed seven different generative AI language learning models, or LLMs, for these three qualities during lengthy conversation. Their work, published in Nature's Scientific Reports, reveals intrinsic limitations that might go undetected during one-off interactions.

Among the seven LLMs tested – ChatGPT (GPT-3.5, GPT-4o, GPT-4o-mini), Claude 3.5, Sonnet, Gemini 1.5 Pro, Llama-3-70B, and DeepSeek-R1 – they found that:

  • ChatGPT 3.5 was most vulnerable to reaffirming misinformation during a conversation containing repeated false statements; Claude 3.5 Sonnet was the least. 
  • All seven were more susceptible to misinformation on obscure topics, implying that more training data on a given topic leads to more robust resistance to misinformation. 
  • DeepSeek was the most persuadable, as measured by responses to increasingly argumentative prompts, mostly because of its tendency toward sarcastic answers, which could not be reliably interpreted.
  • Four models – ChatGPT 4o, ChatGPT 4o-mini, Gemini 1.5 Pro, and DeepSeek – corrected errors 100% of the time when given a second opportunity.

"This underscores the need for careful human engagement and the danger of blind reliance," said senior study author Dr. Marvin Slepian, Regents Professor of medicine and biomedical engineering. "When generative AI came out in November 2022, there was a lot of regulation potential, but that has since fell by the wayside. People are recognizing the onus is now left to the users."

Many people are familiar with AI's limitations, such as a tendency toward sycophancy, or the tendency to agree with users, and hallucination, or confidently wrong answers, but there has been very little work on evaluating AI's limitations during what is called multi-turn conversations, in which answers are predicated on previous context. Such usage more closely mirrors the real-world, according to the research team.

"These limitations raise important safety concerns, particularly as generative AI systems are increasingly deployed in high-stakes settings," Slepian said.

The team also identified four different ways the models failed to affirm factual information. For example, some models oscillated between accepting and rejecting the same false statement during the conversation.

"If one were relying on the model for critical decision-making, one might – depending upon the phase of the oscillation – 'fire the missile' or 'cut off the leg,' or not, based simply on chance," Slepian said.

As a medical doctor, specifically a cardiologist member of the Sarver Heart Center, he characterizes such failures as "pathologies." This specific pathology was dubbed "reverberation." 

"This is dangerous," said Slepian, who led the artificial intelligence subcommittee of the United States Patent and Trademark Office until last year. He is also a member of the James E. Rogers College of Law faculty. "How can we use fickle systems that are not reproducible? These need to be fixed, but this study has spanned three years, and there's still the same unfixed characteristics."

But, closed models, such as Chat and Claude, make it impossible to "peek under the hood" to diagnose and solve the problem.

However, as the founder and director of the Arizona Center for Accelerated Biomedical Innovation, or ACABI, Slepian and his team are beginning to develop diagnostic tools for open AI models as part of their AI Pathology Lab.

"I use AI and so does my team, but as scientist and physician, I have to understand the anatomy and physiology, then understand pathologies – what can go wrong – to diagnose and prevent them. The same goes for AI."

Co-authors on the study include the U of A's Jordan Rodgriguez, Zachary Hansen, Luis De Anda, Katelyn Rohrer and Camila Grubb – all computer science students and researchers in ACABI; as well as Mihai Surdeanu and Enrique Noriega of the Department of Computer Science.