@inproceedings{huang-etal-2026-vulnerability,
title = "Vulnerability of {LLM}s' Stated Belief? {LLM}s Belief Resistance Check Through Strategic Persuasive Conversation Interventions",
author = "Huang, Fan and
Kwak, Haewoon and
An, Jisun",
editor = "Liakata, Maria and
Moreira, Viviane P. and
Zhang, Jiajun and
Jurgens, David",
booktitle = "Findings of the {A}ssociation for {C}omputational {L}inguistics: {ACL} 2026",
month = jul,
year = "2026",
address = "San Diego, California, United States",
publisher = "Association for Computational Linguistics",
url = "https://preview.aclanthology.org/ingest-acl/2026.findings-acl.2074/",
pages = "41759--41794",
ISBN = "979-8-89176-395-1",
abstract = "Large Language Models (LLMs) are increasingly employed in various question-answering tasks. However, recent studies showcase that LLMs are susceptible to persuasion and could adopt counterfactual beliefs.We present a systematic evaluation of LLM susceptibility to persuasion under the \textit{Source{--}Message{--}Channel{--}Receiver} (SMCR) communication framework. Across six mainstream Large Language Models (LLMs) and three domains (factual knowledge, medical QA, and social bias), we analyze how different persuasive strategies influence stated belief stability over multiple interaction turns.We further examine whether verbalized confidence prompting (i.e., eliciting self-reported confidence scores) affects resistance to persuasion.Results show that the smallest model (Llama 3.2-3B) exhibits extreme compliance, with 82.5{\%} of belief changes occurring at the first persuasive turn (average end turn of 1.1{--}1.4).Contrary to expectations, verbalized confidence prompting \textit{increases} vulnerability by accelerating belief erosion rather than enhancing robustness. Finally, an exploratory study of adversarial fine-tuning reveals highly model-dependent effectiveness: GPT-4o-mini achieves near-complete robustness (98.6{\%}) and Mistral{~}7B improves substantially (35.7{\%} $\rightarrow$ 79.3{\%}), but Llama models remain highly susceptible ($<$14{\%} RQ1) even when fine-tuned on their own failure cases. Together, these findings highlight substantial model-dependent limits of current robustness interventions and offer guidance for developing more trustworthy LLMs[{\ensuremath{<}}https://github.com/muyuhuatang/llm{\_}stated{\_}belief{\ensuremath{>}}]."
}Markdown (Informal)
[Vulnerability of LLMs’ Stated Belief? LLMs Belief Resistance Check Through Strategic Persuasive Conversation Interventions](https://preview.aclanthology.org/ingest-acl/2026.findings-acl.2074/) (Huang et al., Findings 2026)
ACL