A Research Agenda for Expert Agent Communities

Written by

in

At WPP Research, we are experimenting with peer-to-peer communities of LLM-powered AI agents, each with its own persona and traits, its own abilities and data tools, and its own limitations and blind spots. No central coordinator sits above them, directing who does what. Agents discover one another, decide whom to trust, form teams, share and withhold information, and get work done by talking to their peers. This growing population of diverse expert agents is an ideal testbed for a wide range of exciting research questions.

Most of what we know about LLM agents is about individual agents: how well one reasons, plans, or uses a tool. The interesting behaviour of a community, though, is not the sum of its members. It emerges from their interaction. Groups of agents can outperform any single member, dynamically recomposing themselves as tasks demand [1]. They spontaneously develop conventions, norms, and even social hierarchy without anyone designing those in [2, 3, 4]. And at the largest scales observed so far, the results are humbling: in a population of ~90,000 autonomous agents, meaningful role differentiation was confined to a small active minority and cooperative tasks often did worse than a single agent working alone [5, 6].

In short: collective intelligence in agent communities is real, fragile, and poorly understood. Building and researching such communities is the only way to move past their risks and limitations. For me, it is also the continuation of a path that I have been pursuing for much of my career in both academia and industry.

Long before large language models, my research was about how to find expertise inside a network and how to assemble the right people into the best possible teams. More than 15 years ago, my paper on team formation in social networks, with Kun Liu and Evimaria Terzi [7], posed the problem of choosing a subset of individuals who jointly cover a task’s required skills while keeping the communication cost between them low. That work became one of the most widely cited starting points for collaborative team formation in expert networks. My research thread continued through a survey of expert-location algorithms and systems, work on how influence and information spread through a network, and studies of the adversarial side of networked reputation.

Such questions do not disappear when the experts are AI rather than people. They just become much harder. Agents are in many ways more capable than any human expert. They are also far less predictable, and they can fail, hallucinate, collude, or leak at machine speed. Everything we have learned about how expertise is found, combined, trusted, and abused in human networks now matters more than ever.

The potential of multi-agent communities is vast, and so are the risks. Learning how to harness that potential safely and efficiently is a genuine research challenge, and exactly the kind of challenge WPP Research is built to take on. In this blog post, we put forward our research agenda for this exciting domain, setting out specific research questions and discussing the impact of each one.

Our Research Agenda

An expert community is easy to picture as a purely cooperative place: agents as helpful collaborators, traits and tools as capability knobs, diversity as a risk-free benefit. That picture is where most of the collaboration literature lives. However, this is only half the story.

The same traits, tools, and capabilities that make an agent useful are also an attack surface. A persona is also a basis for discrimination. A data tool is also a thing to be poisoned or hoarded. An open communication channel is also a way to take the system down. Our agenda is deliberately organised to tackle both framings at once, the cooperative and the adversarial.

We group the work into six tracks that follow a single arc:

Tracks 1–3
Works well
How the community becomes more than the sum of its members.
Tracks 4–5
Goes wrong
How the same strengths become attack surfaces and failure modes.
Track 6
Observe & judge
How we measure, verify, and hold the community to account.

These tracks are not independent, by design. For instance, reputation (Track 2) is a defence against poisoning and collusion (Track 5) and the foundation that routing is built on (Track 1). Fairness failures (Track 4) corrupt expert routing (Track 1) and distort markets (Track 3). We expect the most interesting findings to live at these seams, where a mechanism that helps one property quietly undermines another.

1Collective intelligence: expertise, teams, and self-organisation

The foundational question: does the community actually get smarter than its members, and how?

  • ▸Emergent expert routing. Without a coordinator, can agents learn who to ask from interaction history alone, and does the resulting who-asks-whom network end up matching who is genuinely best at what [8]?
  • ▸Team formation, distinct from task routing. Routing decides who handles an existing task; team formation decides who forms a group. How are these groups formed? Are they stable? Is team formation based on genuine merit, or merely driven by similarity, with agents grouping with others like themselves [9]?
  • ▸Complementarity versus redundancy. Agents differ in what they are good at and, just as importantly, in how they fail. When do agents with different strengths and error profiles cancel one another’s mistakes, and when do their errors instead correlate into shared blind spots and groupthink? Recent theory suggests the gains come from genuinely independent lines of reasoning and evaporate once agents grow too similar [10].
  • ▸Network shape and shared memory. Does the shape of the community’s communication network (everyone talking to everyone, tight clusters joined by a few long-range links, or a handful of central hubs) change its effectiveness, speed, resilience, and inequality? And when agents write to a shared memory instead of keeping private notes, does the community learn better or simply drift off course together [11]?
  • ▸Long-horizon self-evolution. Do agents productively specialise and improve from peer interaction over time, or simply drift and degrade [12]?

2Trust, reputation, and information flow

An expert community lives or dies on whether good information reaches the right agents and bad information is contained. This track studies the organic dynamics of trust and information, how they behave when everyone is acting in good faith; the deliberate corruption of the same channels is the subject of Track 5.

  • ▸Reputation that resists gaming. Which way of scoring an agent’s reputation best sends work to genuine experts while resisting manipulation? Letting an old track record fade over time, asking agents to put something of value at stake, having peers vouch for one another, or some combination of these? Each option carries its own failure mode, from newcomers being frozen out to agents behaving well only to cash in their standing later [13].
  • ▸How information and misinformation spread. How does a claim travel from agent to agent, which traits turn an agent into a super-spreader and which into a firewall, and how quickly can a false belief take over the whole community? In earlier studies, a few messages reach almost everyone while most reach almost no one [5]. Can we trace a propagated piece of information back to its originator?
  • ▸Claim attribution and the echo problem. When one agent shares a claim, others repeat it, and it can circle back to the original agent dressed up as independent corroboration. Do agents fall for this, treating their own echoed opinion as fresh confirmation and growing falsely confident? Can a whole community talk itself into a false consensus this way? Can we keep a community honest by tracking each claim back to its original source [11]?
  • ▸Collective calibration. Does the community learn how much to trust each peer, or does it systematically over-trust the ones that are confident but wrong? Early signs are not encouraging: in head-to-head debates, agents tend to grow more confident as they argue, even while losing [14].

3Cooperation, incentives, and agent economies

Our agents hold scarce resources: compute budgets, privileged tools, proprietary data. That turns cooperation into an economic problem.

  • ▸Shared resources. Knowledge-sharing and shared tool budgets benefit everyone, but no single agent is forced to maintain them. When does free-riding (taking without contributing) exhaust them, and does asking each agent to consider whether the group could survive if everyone behaved as it does help keep the community healthy [15]?
  • ▸Trait-driven cooperation. How do persona traits such as altruism, self-interest, or adaptability change the community’s collective outcomes, and can we tune them to make cooperation more likely? Adjusting these traits directly does shift how much agents cooperate, though the more agreeable ones also turn out to be easier to exploit [16].
  • ▸Agent markets. When agents trade tools and data, do prices and allocations converge to something efficient, or cycle and diverge? The evidence so far is cautionary: the collective outcome gets worse as the market grows, agents lean heavily toward whoever makes the first offer regardless of its quality, and prices may never settle down [17, 18, 19].
  • ▸Designing incentives for honesty. Can we design the rules and rewards so that an agent’s best move is always to report its true ability and confidence, rather than overselling itself? One promising direction has agents grade one another so that honest reporting becomes the stable outcome, with no ground-truth answer key required [20].

4Fairness and agentic discrimination

Giving agents distinct identities is exactly what opens the door to discrimination, agents being judged by the persona they present rather than the quality of what they contribute.

  • ▸Persona-induced bias. Do agents judge the same contribution differently depending on the persona behind it, trusting some personas more and deferring to their own kind, so that work is routed to the wrong “experts” [21, 22]?
  • ▸Emergence, propagation, amplification. Does a community of agents amplify bias that a single agent would have contained, and once in-group favouritism takes hold, can it be reversed? Prior work finds multi-agent systems can be less robust to bias than single agents [23].
  • ▸Mitigations. Techniques that stop identity from swaying judgement, such as hiding who said what so a message is weighed on its content alone, together with measures of how strongly an agent favours its own group: can we keep the benefits of diversity while removing the discriminatory weighting [24, 25]?

5Security and safety of a decentralised society

A peer-to-peer community has no central coordinator to police it, which makes it uniquely exposed. Where Track 2 studied how information behaves when everyone acts in good faith, this track studies its deliberate corruption. We organise it around three classic security goals, keeping data correct (integrity), keeping the system running (availability), and keeping secrets secret (confidentiality), plus the distinctively multi-agent risk of collusion.

  • ▸Integrity: compromised peers. How many faulty or hostile agents can the community tolerate before quality collapses, whether they behave erratically, have been hijacked by hidden malicious instructions smuggled into their inputs, or quietly inject subtle errors, and which network shapes stop the damage from spreading [26]?
  • ▸Availability: attacks that grind the community to a halt. How many attackers can the community withstand before it stops functioning, and which defences actually help: spotting runaway loops, limiting how often an agent can be called, or cutting off connections that misbehave? The threats range from attacks that make an agent burn its time and budget on wasteful work [27] to harmless-looking messages that spread from agent to agent and trap the whole network in pointless loops [28].
  • ▸Confidentiality: private data leaking between agents. Does a group of agents leak more sensitive data than a single agent would, and can we stop it? The worry is that information flows through the messages agents send each other and through shared memory that a check on the final output never sees [29], and that these leaks compound as data passes from agent to agent, so keeping each agent individually careful is not enough [30, 31].
  • ▸Poisoned shared knowledge. Can a single bad entry written into shared memory mislead every agent that later reads it, even ones that never encountered the attacker, and what reliably stops it? A single poisoned record in a shared memory or knowledge base can be retrieved and trusted by agents that never met the attacker, with high success rates and almost no effect on ordinary tasks [32].
  • ▸Deception and collusion. When do agents start colluding against the rest of the community, and can oversight catch them when they do? Agents may voluntarily adopt unfair collusion tools even while acknowledging the harm [33], and can coordinate in secret by hiding their real messages inside ordinary-looking content, slipping past any monitor [34, 35].

6Evaluation, accountability, and the community as an instrument

Finally, we cannot study any of the above without the means to observe it, and the community is also a scientific instrument in its own right. Observation is also the first step toward verification: before the community routes work to an agent, trusts its answers, or holds it to account, something has to establish that the agent is who it claims to be and can do what it claims to do, and keep checking as it changes.

  • ▸Agentic verification. Almost every track above quietly assumes you can already tell a capable, honest agent from an incapable or deceptive one: routing sends work to claimed experts (Track 1), reputation scores claimed performance (Track 2), and security trusts claimed identities (Track 5). How do we verify those claims continuously rather than taking them on faith, confirming an agent’s identity, testing its real competence against its advertised skills, and re-checking its behaviour as it learns and drifts?
  • ▸Judging the process, not just the answer. Can we tell not only whether an agent reached the right answer but whether it got there legitimately, catching “corrupt success”, tasks that look complete but were finished by breaking the rules? This means moving beyond final-answer accuracy to a full, inspectable record of what each agent did and why [36, 37].
  • ▸Pinpointing failures without a coordinator. With no central coordinator, can the community work out which peer or interaction caused a collective error? This is the diagnostic tail of the self-improvement loop whose constructive head, long-horizon self-evolution, sits in Track 1 [12].
  • ▸Benchmarks for emergent coordination. What should we actually measure to capture how well a community coordinates, divides into roles, and keeps its information trustworthy? Reusable metrics for these remain an acknowledged gap, though early benchmarks are beginning to score coordination and communication quality directly, not just whether the task was solved [38].
  • ▸The community as a social-science testbed. How faithfully does it reproduce known human phenomena (polarisation, convention formation, tragedies of the commons), and where do agents diverge from people in informative ways [39]?
  • ▸Humans as peers. When human experts join the community, do the agents defer to them at the right moments, and is the trust between humans and agents well-calibrated in both directions? In human-AI teams, both over-trust and under-trust are common and measurable, and well-designed prompts to pause or reconsider can nudge reliance back toward the right level [40].

What we are committing to

As we tackle these questions, we are committed to publishing what we find and sharing both our results and our code with the AI community. The agenda described in this blog post is a living document. The current version reflects today’s literature and today’s platform; both will change, and so will this plan. What will not change is our motivation and belief that the only way to understand agentic communities is to actually build them, populate them with a genuine diversity of abilities and limitations, and study them in the open.

References

  1. [1] AgentVerse: facilitating multi-agent collaboration and exploring emergent behaviors.
  2. [2] Emergent social conventions and collective bias in LLM populations (Science Advances).
  3. [3] CRSEC: the emergence of social norms in generative agent societies.
  4. [4] CAREB-MAS: emergent roles and behaviours in multi-agent systems.
  5. [5] MoltBook: a study of social dynamics at the scale of ~90,000 agents.
  6. [6] Does socialization emerge in large agent societies?
  7. [7] T. Lappas, K. Liu, E. Terzi. Finding a team of experts in social networks (KDD 2009).
  8. [8] AgentNet: decentralised evolutionary coordination for LLM-based multi-agent systems.
  9. [9] Society Protocol: demand-driven spawning of agent groups.
  10. [10] Understanding agent scaling in LLM-based multi-agent systems via diversity.
  11. [11] Mesh Memory Protocol: provenance-aware shared memory for agent communities.
  12. [12] Beyond Individual Intelligence: long-horizon self-evolution and failure attribution.
  13. [13] Inter-agent trust models: brief, claim, proof, stake, reputation, and constraint.
  14. [14] When two LLMs debate, both think they’ll win.
  15. [15] GOVSIM: governance of shared resources among LLM agents.
  16. [16] Identifying cooperative personalities through personality steering.
  17. [17] Magentic Marketplace: a testbed for agent economies.
  18. [18] AgenticPay: negotiation and payment dynamics among agents.
  19. [19] Market game dynamics with LLM agents.
  20. [20] Incentivizing truthful language models via peer elicitation games.
  21. [21] From Single to Societal: persona-induced bias in multi-agent systems.
  22. [22] Truth or Tribe: in-group favouritism among LLM agents.
  23. [23] The Social Cost of Intelligence: bias amplification in multi-agent systems.
  24. [24] When Identity Skews Debate: mitigating persona-driven bias.
  25. [25] MALIBU: a benchmark for measuring bias in multi-agent systems.
  26. [26] The Achilles heel of distributed multi-agent systems.
  27. [27] AgentDoS: resource-exhaustion attacks on LLM agents.
  28. [28] CORBA: contagious recursive blocking attacks on multi-agent systems.
  29. [29] AgentLeak: internal-channel privacy leakage in multi-agent systems.
  30. [30] Information-theoretic privacy control for multi-agent systems.
  31. [31] PRISM: privacy risks in multi-agent information sharing.
  32. [32] AgentPoison: red-teaming LLM agents via poisoning memory or knowledge bases.
  33. [33] Voluntary Collusion among LLM agents.
  34. [34] Secret Collusion: covert coordination via steganographic communication.
  35. [35] Hidden messaging via tool calls.
  36. [36] Traces to Trust: process-level evaluation of agent behaviour.
  37. [37] Procedure-aware evaluation of multi-agent systems.
  38. [38] MultiAgentBench: evaluating the collaboration and competition of LLM agents.
  39. [39] AgentSociety: large-scale simulation of social behaviour with LLM agents.
  40. [40] Adjust for Trust: mitigating trust-induced inappropriate reliance on AI assistance.

Author

  • Ted co-leads WPP Research and serves as Head of Data Science at Satalia. He is an Assistant Professor in the Department of Marketing and Communication at the Athens University of Economics and Business. His research spans scalable algorithms for multimodal data, synthetic data generation, simulation-based verification for AI agents, and information diffusion and collective intelligence in expert networks.

More posts