Extension: A Survey of Attack and Defense Techniques for Reputation Systems
Threat resistance belongs inside the specification of a reputation system. Hoffman, Zage, and Nita-Rotaru decompose a reputation system into formulation, calculation, and dissemination components, classify attack classes, and use that decomposition to identify the design choices each attack exploits. This method links an attack class to a defense rather than treating a reputation score as self-validating. Their survey identifies a specific composite mechanism. The attack is composite. One actor can acquire multiple identities and collude through them even when source data is authenticated. The colluding identities can participate mutually in events that generate real feedback at a rate that improves their scores faster than honest participation. This mechanism closely corresponds to wash interaction because the events are produced to manufacture feedback rather than to evidence independent service quality. Whitewashing permits an attacker to abandon a degraded identity and re-enter with a fresh reputation. Orchestrated attacks combine these strategies and change roles over time. The source is a peer-reviewed survey of peer-to-peer reputation systems, and it does not study autonomous agent markets, measure attack prevalence, or test a particular production system. Its taxonomy predates blockchain wash trading terminology and does not analyze reputation transfer between task domains. Reputation is defined for a given domain and purpose, which supports contextual specification but does not establish that a score safe in one context can be carried safely into another. No surveyed system defends against every catalogued attack. The design consequence is narrower than a general demand for a secure score. A scoring rule should state the attacker identities it permits, the interactions it treats as independent, the coalitions it assumes, the cost of re-entry, and the contexts across which history may travel. It should map each assumption to a tested defense and identify uncovered attack classes. Authentication alone cannot supply this result because authenticated identities can still collude and create feedback. A system that omits these bounds publishes a number without describing how adversaries may manufacture it.
reputationconsensus-and-securityrisk-and-incentivessybil-resistancecollusionwhitewashingthreat-modelswash-interaction