Source-linked AI summary
Belief Cascades Drive Persuasion in LLM Agent Networks
Haoyi Qiu, Genglin Liu, Pranav Narayanan Venkit, Kung-Hsiang Huang, Saadia Gabriel, Chien-Sheng Wu, Nanyun Peng
TL;DR
Agent-to-agent persuasion in LLM networks is undermeasured despite its role in debate, research coordination, and social simulation. The paper builds a controlled testbed across graph topologies, policy statements, model backbones, and competing persuaders, then finds that belief movement depends on their interaction and can travel through direct and peer-mediated exposure. It concludes that evaluation should track trajectories, exposure provenance, and action logs rather than post text or final answers alone.
Problem
Agent-to-agent persuasion remains underexplored as a networked belief-dynamics problem, even though LLM agents increasingly influence one another in multi-agent systems.
Method
The paper simulates persuaders and persuadees in directed real-world ego-network topologies with bounded feeds, repeated belief probes, and exposure and action logging.
Results
Persuasion dynamics depend on topology, competition, topic, and model prior, while direct exposure predicts next-round stance change and peer relays carry smaller measurable influence.
Takeaways & Limitations
Evaluating multi-agent persuasion requires belief trajectories, exposure provenance, mediated amplification, and intermediate volatility, not only final answers or generated content.
Takeaways & Limitations
Initial beliefs are assigned from Personalized PageRank, entangling network location with priors; isolating this scheme is left to future work.
Abstract
from arXiv · showhide
Multi-agent LLM systems increasingly debate answers, coordinate research, simulate users, and mediate information flows, making agent-to-agent persuasion a basic but undermeasured capability. We introduce a controlled testbed for studying how goal-directed persuaders shift elicited stances in networks of LLM agents grounded in real-world ego-network topologies. Across four LLM backbones, five graphs, and 55 policy statements, we find that persuasion dynamics depend on the interaction between topology, competition, topic, and model prior. Additionally, we show that direct exposure reliably predicts next-round stance change in competing runs, and peer relays carry smaller but measurable influence, showing that agents not assigned to persuade can still transmit persuasive force. Finally, analyzing post text alone misses important movement: planned strategies are only partly realized in executed messages, action choices can diverge from message content, and persuadees rarely state the stance shifts detected by probes. These results argue for evaluating multi-agent persuasion as a trajectory- and exposure-level process, using belief probes, exposure provenance, and action logs to identify who influenced whom and whether visible language reflects underlying stance movement.
1 Introduction
The paper frames persuasion among networked LLM agents as an underexplored belief-dynamics problem and introduces a controlled testbed to measure how topology, competition, and model priors shape stance movement.
- Agent-to-agent persuasion supports coordination and correction but can also amplify manipulative narratives at scale.
- The study treats networks as determinants of claim visibility, relay paths, and whether stance shifts reflect direct persuasion, peer amplification, or competing narratives.
- The testbed assigns agents to directed graph nodes, uses bounded feeds and repeated fixed token-probability probes, and derives initial stances from Personalized PageRank.
- The paper analyzes belief outcomes, direct versus peer-mediated channels, and whether plans and actions explain belief change.
- The design varies topology, initial stance, topic, model, and competition across five graphs, 55 policy statements, and four LLM backbones.
- The findings emphasize elicited stance movement, threshold crossings, and influence paths rather than only whether influence spreads.
2 Related Work
Prior work studies LLM persuasion, opinion elicitation, social simulation, and agent interaction, while this paper focuses on belief change under cascaded persuasive exposure among LLM agents.
- Studies show that model-generated messages can influence human attitudes across political, health, advertising, policy, misinformation, and conspiracy-belief settings.
- Recent research examines strategic and deceptive persuasion alongside increasingly capable LLM agents that debate, simulate users, and influence one another.
- Work on LLM opinions probes latent beliefs, values, emotions, moral sentiments, political bias, ideological shifts, and related dispositions.
- LLM social simulators model users, social networks, large societies, and domains including epidemics, trust, negotiation, and social evolution.
- Related agent research studies social intelligence, opinion dynamics, polarization, and echo chambers, whereas this paper targets belief change under cascaded persuasive exposure.
3 Simulation Infrastructure
The simulator isolates belief updating in directed multi-agent networks by combining bounded exposure, fixed social actions, repeated probes, and detailed event logging.
- Each run places LLM agents in a directed graph and tracks every persuadee’s round-by-round belief trajectory.
- Persuaders advocate fixed target positions, while persuadees update after exposure using role-specific objectives, initial beliefs, persona framing, and within-round order.
- Personalized PageRank on the reversed follow graph deterministically maps network position to initial persuadee beliefs, coupling graph location and priors.
- Bounded feeds mix directly followed and algorithmically surfaced content so exposures can be attributed to their sources.
- Each round freezes the persuadee snapshot before actions, then measures beliefs and logs the round to prevent same-round cascades from confounding execution order.
- Seven-point token-probability probes produce scalar beliefs that preserve uncertainty and score integrated stance from the bounded feed rather than only the latest item.
- Exposure, rationale, action, belief-check, and summary events distinguish direct, peer-mediated, and secondary persuasion, while exposure effects remain controlled associations rather than randomized causal effects.
4 Experimental Setup
The experimental sweep varies real-world directed network structure, contestable policy statements, model backbones, and prior tendencies to study persuasion across controlled configurations.
- The factorial design spans graph instances, seed statements, evaluated models, and a run matrix for the large-scale experiment.
- The study uses five directed SNAP Twitter ego-network topologies selected to vary size and directed density, ranging from 18 to 42 nodes.
- The 55-statement seed set uses concise, policy-flavored, broadly understandable, and plausibly contestable claims across 11 domains and five subtopics each.
- Model-specific no-context belief probes establish baselines for separating social-exposure effects from default tendencies without selecting the seed statements.
- The sweep evaluates GPT-4o, GPT-4.1, Gemini-2.5-Flash, and Gemini-2.5-Pro across two persuader settings and two random seeds.
5 Results
The results show that topology, competition, and model- and topic-dependent trajectories shape elicited belief movement, while exposure pathways and behavioral traces reveal influence that post text alone misses.
- Outcome: Dense graphs reduce one-sided movement but increase PR1-directed movement under competing persuasion.G3 PEs moving toward the persuader fall to 22–52% under singlePR versus 69–83% in sparser graphs, but reach 49–68% toward PR1 under dualPR.
- Outcome: Under singlePR, topic means generally move away from model priors toward the affirmative persuader, whereas dualPR endpoints remain closer to those priors.Competition changes the attractor rather than simply suppressing movement.
- Outcome: Under dualPR, converted_con rises to 17.1%, the con end-band grows from 4.5% to 25.5%, and tug_of_war reaches 57.8%.The tug_of_war share is about three times its singlePR level, while jump_and_hold remains almost entirely PR1-directed.
- Mechanism: Influence analysis therefore requires belief trajectories, exposure provenance, and action logs rather than final text or broadcaster-only monitoring.These records identify mediated pathways and linguistically silent movement.
- Channel: Direct exposure predicts next-round stance change consistently in dualPR, while peer-mediated exposure has smaller but measurable associations.Cumulative direct-channel associations over roughly 50 exposures per side range from +0.16 to +0.26 for PR1 and −0.22 to −0.32 for PR2; Gemini-2.5-Pro peer-mediated PR2 exposure reaches −0.0053.
- Mechanism: Persuasion strategies and behavior diverge across planning, executed text, actions, and elicited stance probes.Only 72.7% of planned Cialdini labels appear in executed text, action mixes can remain similar despite textual differences, and measured belief shifts are rarely stated explicitly.
6 Conclusion
The paper treats persuasion as a core multi-agent capability whose effects propagate through networks and may remain invisible in generated language. It concludes that evaluation should follow belief movement and exposure pathways, not only final answers or messages.
- Influence in multi-agent systems depends on network regime, competition, peer-mediated exposure, and can be linguistically silent.
- Multi-agent evaluations should track belief trajectories, exposure provenance, mediated amplification, and intermediate volatility.
Limitations
The study’s conclusions are constrained by graph-derived priors, limited network and seed coverage, and a narrow model and interaction setting.
- Graph-derived priors correlate network location with initial stance, so the study does not isolate persuasion dynamics from its prior-assignment scheme.Randomized or uniform-prior ablations are left for future work.
- Five small ego-networks and two random seeds provide limited coverage of graph structure and stochastic variation.The reported trajectory and strategy percentages should therefore be read as descriptive estimates over this run set.
- The experiments use four English-language backbones, public policy statements, fixed actions, and no external tools, without validation against human persuasion data.Extension to other models, languages, action spaces, or human participants remains open.
Ethical Considerations
The authors frame the work as measurement and monitoring of influence channels while acknowledging potential dual-use implications. The simulation remains confined to language-model agents and a closed environment.
- Characterizing influence channels could inform more manipulative agents, but the stated contribution focuses on auditing through exposure provenance and belief trajectories.
- The study uses only language-model agents and public-discourse topics, with human input limited to annotation of classifier labels.The simulation is closed and was not deployed against real users or platforms.
A Simulator and Experimental Setup Details
The simulator models repeated persuasion in directed ego-network graphs, combining PPR-derived initial beliefs, fixed agent roles, bounded social exposure, and round-by-round belief measurement. Its experiments vary topology, competition, topic, model, and initial stance while recording trajectories, exposures, actions, and per-run artifacts.
- Simulator: Each run initializes a directed graph, PPR-derived beliefs, a seed statement, configuration, and a round-0 belief check before social exposure.The simulation then executes 10 communication rounds and writes per-run outputs.
- Experimental design: The experiments reuse five directed SNAP ego-network topologies spanning 18–42 nodes and sparse-to-dense connectivity, discarding original identities and content.The selected graphs provide variation in size and directed density for the network dimension.
- Simulator: Persuaders act first, while persuadees act from the same feed-building pipeline on a same-round snapshot before belief checks and sequential write-back.Both roles share the backend, action schema, and feed construction; role differences are limited to objectives, initial beliefs, persona framing, and ordering.
- Initial beliefs: SinglePR initializes persuadees from proximity to one persuader, min–max scaled to [0.1, 0.9], whereas dualPR uses two competing PPR sources and symmetric share-of-mass beliefs around 0.5.SinglePR has an asymmetric four-bin ladder; dualPR uses a symmetric seven-bin ladder with endpoints pinned to 1.0 and 0.0.
- Experimental design: Across five graphs, 55 policy statements, and four LLMs, the design varies topology, initial stance, topic, model, and competition under a fixed interaction protocol.The analysis tracks outcome, channel, and mechanism, including topic trajectories and graph-density effects that differ between singlePR and dualPR.
B.6 Per-Backbone Trajectory Crosstabs
Across backbones, singlePR concentrates persuadee trajectories around converted_pro outcomes, whereas dualPR redistributes them toward converted_con endpoints and neutral-start oscillations. Topic and seed-post content also shape trajectory direction, with cultural_social_norms consistently down-heavy and most topics showing sign flips when seed stance is negated.
- Topic effects: cultural_social_norms is the only topic consistently down-heavy across all four topic-by-model panels.The bars average across five graphs, random seeds, and seed-post variants.
- Cross-backbone replication: Across all four backbones, singlePR shows a converted_pro peak, while dualPR shifts mass toward converted_con and sharply increases neutral-start tug_of_war.Gemini-2.5-Pro reaches the highest dualPR tug_of_war share at 69.6%, while Gemini-2.5-Flash has the most balanced dualPR polarization.
- Content-versus-structure: Three of four topics show a clean belief-trajectory sign flip when the seed-post stance is negated.cultural_social_norms-005 reverses this pattern because its original seed text already leans disagree.
C.2 Robustness of the Per-Exposure Estimates
Robustness checks preserve the dualPR direct-exposure signs across backbones and increasingly saturated specifications, while singlePR estimates remain weak and sign-unstable. Topic-level refits support the dualPR pattern broadly but reveal backbone- and topic-specific variation under singlePR; the rhetorical audit also validates the classifier used for related analyses.
- DualPR robustness: Direct exposure to PR1 is positive and to PR2 negative at p < .001 across all four backbones and all four specifications.The fully saturated M3 specification adds receiver, round, graph, topic, and lagged-belief controls; magnitudes remain within roughly a factor of two of baseline.
- DualPR robustness: Peer-mediated coefficients are an order of magnitude smaller and more specification-sensitive than dualPR direct-channel coefficients.The lagged-belief control restores the con-side peer effect, consistent with mean reversion masking it when prior belief is uncontrolled.
- SinglePR robustness: Under singlePR, all |β| ≤0.0009 and coefficient signs are not stable across specifications, so their signs are not interpreted.The baseline model controls for neither receiver heterogeneity nor prior belief, and exposures are not randomly assigned.
- Topic-level refits: The dualPR direct-exposure sign holds in 11/11 topics on every backbone, the only effect surviving both topic and backbone variation.Under singlePR, direct effects vary by backbone: Gemini-2.5-Flash is significantly negative on 5/11 topics, Gemini-2.5-Pro on healthcare only, GPT-4o is null, and GPT-4.1 is positive-significant on prior-disagreeing topics.
- Measurement validation: The Cialdini classifier’s per-principle calls were judged correct 87.3% of the time across 600 blind human judgments.Accuracy exceeded 81% for every principle, with comparable correctness for PRESENT and ABSENT calls.
D.3 Strategy Composition Results
The strategy audit finds that executed persuasion varies with topic, backbone, and competition, while planned rhetoric is only partly realized in messages. Action choices can also diverge from textual strategy, and rhetorical associations with success can reverse across settings.
- Executed rhetoric: Executed PR rhetoric centers on commitment and social proof, while reciprocity and scarcity remain marginal on the GPT backbones.Under dualPR, GPT-4o raises commitment, both GPT backbones reduce liking, and PR2 emphasizes commitment more than PR1.
- Plan–text gap: 72.7% of planned Cialdini labels also appear in executed text, with the largest drops for social proof and commitment.An offload audit finds that likes, reposts, and follows do not carry the missing principles.
- Topic dependence: Topic prior shapes principle composition more than setting or model, with authority coverage spanning 11× across evidence-rich and identity-rich topics.The same topic varies only 5–25% across settings or backbones, so global strategy claims require conditioning on topic prior.
- Backbone and competition: Competitive rhetorical responses are backbone-specific: GPT-4o concentrates on commitment and authority, whereas GPT-4.1 distributes shares across four principles.PR2 compresses authority, social proof, and liking relative to PR1, compensating with commitment or scarcity depending on the backbone.
- Cross-family replication: The qualitative strategy structure replicates on Gemini, although authority levels and PR1-to-PR2 compression differ by backbone.Gemini backbones retain commitment and liking as the leading singlePR pair, while competition produces distinct Flash and Pro shifts.
- Strategy and success: Liking predicts success under singlePR but failure under dualPR, while authority marks failure in singlePR and disappears as a signal under dualPR.The associations therefore depend on the persuasion setting rather than defining a model-invariant rhetorical strategy.
E Extended Implications for MAS Communication
The paper treats multi-agent communication as an influence channel whose safety implications include direct diffusion, secondary relays, competitive volatility, and non-verbal persuasion. It therefore evaluates belief propagation through trajectories, provenance, action logs, and belief probes rather than message text alone.
- Extended Implications for MAS Communication: Communication becomes an influence channel when agents observe, quote, summarize, repost, endorse, rank, or reuse one another’s outputs.The relevant safety object is belief propagation, not merely message delivery.
- Extended Implications for MAS Communication: Secondary persuasion can arise through relaying, summarizing, reframing, quoting, or endorsing another agent’s message.Exposure provenance should record the original source, delivery mode, and downstream consumers.
- Extended Implications for MAS Communication: A single goal-directed persuader can shift a population’s belief distribution despite heterogeneous initial beliefs.The paper recommends tracking source-level influence centrality and flagging unusually high-impact agents.
- Extended Implications for MAS Communication: Adding an opposing persuader does not automatically neutralize persuasion and can increase polarization, oscillation, and tug-of-war dynamics.Debate-style systems should be evaluated for volatility, source dependence, mediated amplification, and propagated intermediate beliefs.
- Extended Implications for MAS Communication: Monitoring generated text alone misses persuasion through likes, reposts, quotes, rankings, source selection, summarization, memory writes, repeated citation, or silence.Action logs and latent belief probes are needed to capture non-verbal or interactional influence.
- Belief Measurement: Belief probes ask persuadees to select one of seven ordered stance options from strongly disagree to strongly agree about the seed statement.The probe is invoked once per round on every persuadee, while only logprobs for options A–G are retained.