Contamination Resistance in Multi-Agent LLM Systems: The Role of Decision Authority
Abstract
AI systems are increasingly used in tasks where wrong answers can pose real consequences. Multi-agent systems have been built on the idea that distributing a task across several agents makes it less likely that any single agent's error can become the team's final answer. While prior work has explored differences in performance among these systems, relatively less is known about how the systems differ in their resistance to a misinformed agent. We study this question by injecting a single piece of benign, question-specific misinformation into one agent in nine different systems, spanning a single-agent baseline and eight coordination structures common in deployed systems, and measuring how much of that misinformation reaches the team's final answer. Each architecture is run on 379 WinoGrande commonsense questions from the MINT dataset, comparing a clean control condition against a single contamination-seeded agent, across four models from different labs (Claude Opus 5, GPT-5.6 Sol, DeepSeek-V4-Pro, and Grok 4.20 Reasoning). For each run we measure the team's accuracy and the share of unseeded teammates that adopt the false claim. The results reveal meaningful variation across two categories of multi-agent system architectures, showing how the setup design can affect the systems' resistance to contamination. This work provides a detailed view of where and how contamination spreads across these multi-agent systems, and which may be best suited to resist it.