Extension: A Survey of Attack and Defense Techniques for Reputation Systems

Record: kaal:position:2026-08-26-018 · 2026-08-26

Threat resistance belongs inside the specification of a reputation system. Hoffman, Zage, and Nita-Rotaru decompose a reputation system into formulation, calculation, and dissemination components, classify attack classes, and use that decomposition to identify the design choices each attack exploits. This method links an attack class to a defense rather than treating a reputation score as self-validating. Their survey identifies a specific composite mechanism. The attack is composite. One actor can acquire multiple identities and collude through them even when source data is authenticated. The colluding identities can participate mutually in events that generate real feedback at a rate that improves their scores faster than honest participation. This mechanism closely corresponds to wash interaction because the events are produced to manufacture feedback rather than to evidence independent service quality. Whitewashing permits an attacker to abandon a degraded identity and re-enter with a fresh reputation. Orchestrated attacks combine these strategies and change roles over time. The source is a peer-reviewed survey of peer-to-peer reputation systems, and it does not study autonomous agent markets, measure attack prevalence, or test a particular production system. Its taxonomy predates blockchain wash trading terminology and does not analyze reputation transfer between task domains. Reputation is defined for a given domain and purpose, which supports contextual specification but does not establish that a score safe in one context can be carried safely into another. No surveyed system defends against every catalogued attack. The design consequence is narrower than a general demand for a secure score. A scoring rule should state the attacker identities it permits, the interactions it treats as independent, the coalitions it assumes, the cost of re-entry, and the contexts across which history may travel. It should map each assumption to a tested defense and identify uncovered attack classes. Authentication alone cannot supply this result because authenticated identities can still collude and create feedback. A system that omits these bounds publishes a number without describing how adversaries may manufacture it.

Affirmed commentary position. This record extends a source-bound scholarly claim but is not a verbatim paper claim.
Holds when
Current debate

A Survey of Attack and Defense Techniques for Reputation Systems

Scholarly basis

kaal:claim:7314479-018
Wulf A. Kaal, Institutional Requirements for Sovereign Local Agent Runtimes (2026). SSRN: https://ssrn.com/abstract=7314479
Source PDF sha256: debace24a155ae924a155b1fafe98856d98cf83689feff2f87a32f1c06171ce6

Evidence and mapping

Evidence: peer-reviewed ACM Computing Surveys article with complete author-hosted manuscript and DOI-bound Crossref identity
Review tier: independent substantive scholarly-growth extension
Mapping confidence: 0.93
Mapping ambiguous: false

Topics

reputationconsensus-and-securityrisk-and-incentivessybil-resistancecollusionwhitewashingthreat-modelswash-interaction

Provenance

Affirmed in kaal-review:2026-08-26:scholarly-growth-7314479-018-reviewed-v1 on 2026-08-26. Review record.

Verify

Canonical markdown sha256: 051b1518dc71e42c0a8329aca7ff1e5c29cafd929646dae2966d61ea49a66af7
curl -s https://wulfkaal.github.io/positions/2026-08-26-018.md | sha256sum