{
 "@context": "https://schema.org",
 "@type": "Claim",
 "@id": "https://wulfkaal.github.io/positions/2026-08-26-018",
 "identifier": "kaal:position:2026-08-26-018",
 "additionalType": "https://wulfkaal.github.io/positions/schema.json#AffirmedPositionClaim",
 "name": "Attack Specific Reputation Design",
 "text": "Threat resistance belongs inside the specification of a reputation system. Hoffman, Zage, and Nita-Rotaru decompose a reputation system into formulation, calculation, and dissemination components, classify attack classes, and use that decomposition to identify the design choices each attack exploits. This method links an attack class to a defense rather than treating a reputation score as self-validating.\n\nTheir survey identifies a specific composite mechanism. The attack is composite. One actor can acquire multiple identities and collude through them even when source data is authenticated. The colluding identities can participate mutually in events that generate real feedback at a rate that improves their scores faster than honest participation. This mechanism closely corresponds to wash interaction because the events are produced to manufacture feedback rather than to evidence independent service quality. Whitewashing permits an attacker to abandon a degraded identity and re-enter with a fresh reputation. Orchestrated attacks combine these strategies and change roles over time.\n\nThe source is a peer-reviewed survey of peer-to-peer reputation systems, and it does not study autonomous agent markets, measure attack prevalence, or test a particular production system. Its taxonomy predates blockchain wash trading terminology and does not analyze reputation transfer between task domains. Reputation is defined for a given domain and purpose, which supports contextual specification but does not establish that a score safe in one context can be carried safely into another. No surveyed system defends against every catalogued attack.\n\nThe design consequence is narrower than a general demand for a secure score. A scoring rule should state the attacker identities it permits, the interactions it treats as independent, the coalitions it assumes, the cost of re-entry, and the contexts across which history may travel. It should map each assumption to a tested defense and identify uncovered attack classes. Authentication alone cannot supply this result because authenticated identities can still collude and create feedback. A system that omits these bounds publishes a number without describing how adversaries may manufacture it.",
 "author": {
  "@type": "Person",
  "name": "Wulf A. Kaal",
  "identifier": "https://orcid.org/0009-0008-7840-1847"
 },
 "datePublished": "2026-08-26",
 "dateModified": "2026-08-26",
 "creativeWorkStatus": "Affirmed",
 "responseType": "extension",
 "keywords": [
  "reputation",
  "consensus-and-security",
  "risk-and-incentives",
  "sybil-resistance",
  "collusion",
  "whitewashing",
  "threat-models",
  "wash-interaction"
 ],
 "scope_conditions": [
  "The response is limited to the exact full-text propositions and the one mapped Kaal claim.",
  "External evidence level: peer-reviewed ACM Computing Surveys article with complete author-hosted manuscript and DOI-bound Crossref identity.",
  "Mapping review tier: independent substantive scholarly-growth extension.",
  "The retained source is a peer-reviewed survey and design analysis, not an empirical estimate of attack prevalence or a controlled test of a specific production system.",
  "The analyzed systems are primarily peer-to-peer reputation systems rather than autonomous agent marketplaces or sovereign local agent runtimes.",
  "The author-hosted manuscript carries an ACM Computing Surveys prepublication footer dated 2007, while the DOI-bound final journal record was published in 2009.",
  "The source predates blockchain wash-trading terminology. Its synthetic mutual-event mechanism corresponds to wash interaction, but the source does not use that modern label.",
  "The source defines reputation within a given domain and purpose but does not analyze cross-context reputation transfer or laundering.",
  "The source reports that no surveyed system defends against all catalogued attacks, so it does not establish a complete defense for the claim's entire attack set.",
  "The surveyed defenses may not cover later blockchain-specific or autonomous-agent attack variants."
 ],
 "currentDebate": {
  "name": "A Survey of Attack and Defense Techniques for Reputation Systems",
  "url": "https://doi.org/10.1145/1592451.1592452"
 },
 "extends": {
  "identifier": "kaal:claim:7314479-018",
  "url": "https://wulfkaal.github.io/claims/7314479-018",
  "citation": "Wulf A. Kaal, Institutional Requirements for Sovereign Local Agent Runtimes (2026). SSRN: https://ssrn.com/abstract=7314479",
  "paper": "Wulf A. Kaal, Institutional Requirements for Sovereign Local Agent Runtimes",
  "authors": [
   "Wulf A. Kaal"
  ],
  "year": "2026",
  "ssrn": "https://ssrn.com/abstract=7314479",
  "source_pdf_sha256": "debace24a155ae924a155b1fafe98856d98cf83689feff2f87a32f1c06171ce6"
 },
 "isBasedOn": [
  {
   "@id": "https://wulfkaal.github.io/claims/7314479-018"
  },
  {
   "@type": "CreativeWork",
   "name": "A Survey of Attack and Defense Techniques for Reputation Systems",
   "url": "https://doi.org/10.1145/1592451.1592452"
  }
 ],
 "batch_id": "kaal-review:2026-08-26:scholarly-growth-7314479-018-reviewed-v1",
 "review_provenance": "https://wulfkaal.github.io/positions/by-claim/7314479-018.html",
 "publicationStatus": "public",
 "recordTypeNote": "Dated commentary position extending a scholarly corpus claim. Not a verbatim claim extracted from the paper.",
 "isPartOf": {
  "@id": "https://wulfkaal.github.io/positions/index.json"
 },
 "version": "1.0",
 "canonical_url": "https://wulfkaal.github.io/positions/2026-08-26-018",
 "canonicalForm": "https://wulfkaal.github.io/positions/2026-08-26-018.md",
 "candidateId": "kaal:response-candidate:2026-08-26:scholarly-growth-7314479-018-attack-specific-reputation-design-01",
 "evidenceLevel": "peer-reviewed ACM Computing Surveys article with complete author-hosted manuscript and DOI-bound Crossref identity",
 "reviewTier": "independent substantive scholarly-growth extension",
 "mappingConfidence": 0.93,
 "mappingAmbiguous": false,
 "mappingMethod": "independent substantive scholarly-growth one-to-one review",
 "mappingWhyRelevant": "The survey independently decomposes a reputation system into attack surfaces and defenses. It explains how Sybil identities and collusion can manufacture transaction-bound feedback even when inputs are authenticated, how whitewashing resets degraded history, and why identity, transaction-proof, computation, and collusion defenses must be stated separately. This directly extends Kaal's threat-model requirement. The mapping remains bounded because the survey does not analyze autonomous agents, modern wash-trading terminology, or cross-context reputation laundering.",
 "sourceProvenance": {
  "source": "peer-reviewed ACM Computing Surveys article with complete author-hosted manuscript and DOI-bound Crossref identity",
  "sourceRecordId": "doi:10.1145/1592451.1592452",
  "doi": "10.1145/1592451.1592452",
  "canonicalUrl": "https://doi.org/10.1145/1592451.1592452",
  "publicFullTextUrl": "https://homes.cerias.purdue.edu/~crisn/papers/p2p-reputation-survey.pdf",
  "retrievedAt": "2026-08-27T10:18:04.100Z",
  "fullTextPdfSha256": "cc91383d2b6952dab1e448052a0ac2e95fecbc50a770de8951b393edf6ecd52d",
  "extractedTextSha256": "caa024cfbaf443e22759fb8e926769fadd6cb1629d8dede314be12291563a074",
  "crossrefRecordSha256": "0008cc87b0cccb3560a9d2908af035792372275babb64dc75a2b5f3ebf0380ef",
  "primaryEvidenceReceiptSha256": "e00ea604a762a0c7b497e2ee6670cda523ada7b8cb828a6dfeecdebc7fa94676",
  "sourceProposition": "Hoffman, Zage, and Nita-Rotaru explain that authenticated reputation inputs remain vulnerable when Sybil identities collude to manufacture real feedback, while whitewashing permits re-entry with a fresh identity, and they map those attack mechanisms to identity, transaction-proof, computation, and collusion defenses.",
  "sourcePropositionSha256": "378799ff07217f29b328089b23fd872a128574b9d35a5516e0a923293067ed4f",
  "sourceEvidenceSetSha256": "28552110331de2194a377792b8d846a3e8c388218447f04604a70d5a08fe5603",
  "sourceEvidencePassages": [
   {
    "text": "Reputation allows parties to build trust, or the degree to which one party has confidence in another within the context of a given purpose or decision.",
    "locator": {
     "publication": "ACM Computing Surveys 42(1), Article 1",
     "page": 2,
     "section": "1 Introduction"
    },
    "sha256": "f848c8e5b02552296ff77d1a6ce6867573379d2127730d067db0e1c560f13c8a"
   },
   {
    "text": "However, even if source data is authenticated using cryptographic mechanisms, self-promotion attacks are possible if disparate identities or a single physical identity acquiring multiple identities through a Sybil attack [Douceur 2002] collude to promote each other. Systems that do not require participants to provide proof of interactions which result in positive reputations are particularly vulnerable to this attack. To perform the attack, colluding identities mutually participate in events that generate real feedback, resulting in high volumes of positive feedback for the colluding participants.",
    "locator": {
     "publication": "ACM Computing Surveys 42(1), Article 1",
     "page": 13,
     "section": "4.2.1 Self-promoting"
    },
    "sha256": "e799afd8633c9efc99fc53a63ce4618f5b0f0503055b618e022397ff83b5ffbb"
   },
   {
    "text": "Techniques to mitigate self-promoting attacks include requiring reputation systems to provide accountability, proof of successful transactions, and the ability to limit or prevent an attacker from obtaining multiple identities. The computation dimension should also include mechanisms to prevent colluding adversaries from subverting the computation and storage of the reputation values.",
    "locator": {
     "publication": "ACM Computing Surveys 42(1), Article 1",
     "page": 14,
     "section": "4.2.1 Self-promoting"
    },
    "sha256": "41ab41b0ad691a3d2227cb6e037c21f3b85fc6a54b30fe0fd66ee5254e046653"
   },
   {
    "text": "Whitewashing attacks occur when attackers abuse the system for short-term gains by letting their reputation degrade and then escape the consequences of abusing the system by using some system vulnerability to repair their reputation. Often attackers will attempt to re-enter the system with a new identity and a fresh reputation [Lai et al. 2003].",
    "locator": {
     "publication": "ACM Computing Surveys 42(1), Article 1",
     "page": 14,
     "section": "4.2.2 Whitewashing"
    },
    "sha256": "867d5e4de63df6278d86d185d163f0006f61d85de97b2f55a1561ce08b8c22cc"
   }
  ],
  "workId": "work:doi:10.1145/1592451.1592452",
  "workAuthors": [
   "Kevin J. Hoffman",
   "David Zage",
   "Cristina Nita-Rotaru"
  ],
  "workPublishedAt": "2009-12",
  "identityKeys": [
   "doi:10.1145/1592451.1592452",
   "pdf:cc91383d2b6952dab1e448052a0ac2e95fecbc50a770de8951b393edf6ecd52d",
   "proposition:378799ff07217f29b328089b23fd872a128574b9d35a5516e0a923293067ed4f"
  ],
  "claimMappings": [
   {
    "claimId": "kaal:claim:7314479-018",
    "claimUrl": "https://wulfkaal.github.io/claims/7314479-018",
    "rank": 1,
    "confidence": 0.93,
    "method": "independent substantive scholarly-growth one-to-one review",
    "whyRelevant": "The survey independently decomposes a reputation system into attack surfaces and defenses. It explains how Sybil identities and collusion can manufacture transaction-bound feedback even when inputs are authenticated, how whitewashing resets degraded history, and why identity, transaction-proof, computation, and collusion defenses must be stated separately. This directly extends Kaal's threat-model requirement. The mapping remains bounded because the survey does not analyze autonomous agents, modern wash-trading terminology, or cross-context reputation laundering.",
    "ambiguous": false
   }
  ],
  "substantiveReview": {
   "reviewedAt": "2026-08-27T10:18:04.100Z",
   "sourceIdentityVerified": true,
   "authorIndependenceVerified": true,
   "kaalReferenceFoundInSource": false,
   "temporalIndependence": "The final journal article was published in 2009, before Kaal's 2026 paper.",
   "canonicalPublicStatusVerified": true,
   "peerReviewedStatusVerified": true,
   "evidenceClassification": "peer-reviewed survey and design analysis",
   "retractionOrSupersessionFound": false,
   "propositionFidelityVerified": true,
   "mechanismCorrespondence": "Sybil identities and collusion manufacture positive feedback through mutually generated events, whitewashing resets degraded history, and attack resistance depends on separately specified identity, transaction-proof, computation, and collusion defenses",
   "compatibleScope": "general peer-to-peer reputation systems, limited because the source does not study autonomous agents, cross-context transfer, or later blockchain-specific variants",
   "responseWordingDefensible": true,
   "oneToOneExtendsMapping": true,
   "exactSupportingQuotesVerified": true,
   "nonOverlap": {
    "candidateIdMatches": false,
    "canonicalUrlMatches": false,
    "propositionHashMatches": false,
    "priorPositionForClaim": false
   },
   "limitations": [
    "The retained source is a peer-reviewed survey and design analysis, not an empirical estimate of attack prevalence or a controlled test of a specific production system.",
    "The analyzed systems are primarily peer-to-peer reputation systems rather than autonomous agent marketplaces or sovereign local agent runtimes.",
    "The author-hosted manuscript carries an ACM Computing Surveys prepublication footer dated 2007, while the DOI-bound final journal record was published in 2009.",
    "The source predates blockchain wash-trading terminology. Its synthetic mutual-event mechanism corresponds to wash interaction, but the source does not use that modern label.",
    "The source defines reputation within a given domain and purpose but does not analyze cross-context reputation transfer or laundering.",
    "The source reports that no surveyed system defends against all catalogued attacks, so it does not establish a complete defense for the claim's entire attack set.",
    "The surveyed defenses may not cover later blockchain-specific or autonomous-agent attack variants."
   ],
   "rejectionReasonsRecorded": true
  },
  "contentMap": {
   "proposition": "A reputation score is not threat-specified unless its attack surfaces and defenses are stated separately.",
   "evidenceLayer": "peer-reviewed ACM Computing Surveys article with complete author-hosted manuscript and DOI-bound Crossref identity",
   "strongestLimitation": "The source analyzes peer-to-peer systems and does not cover cross-context reputation laundering in autonomous agent markets.",
   "consequence": "Authentication does not prevent Sybil identities and colluders from manufacturing feedback, and identity reset can erase degraded history.",
   "requestedAction": "State permitted identities, independent interactions, coalition assumptions, re-entry costs, context-transfer rules, tested defenses, and uncovered attack classes."
  },
  "stylePack": {
   "profile": "M1 early sole-author baseline v1.2.0",
   "verifiedProfileWorks": [
    "1428387",
    "1998455",
    "2150377",
    "2267560"
   ],
   "passageCount": 4,
   "rhetoricalFunctions": [
    "classification before inference",
    "regulatory limitation",
    "design implication"
   ],
   "sameRegisterPassagePackAvailable": true,
   "limitation": "The short public position permits only bounded stylometric comparison."
  },
  "m1Validation": {
   "status": "M1-PASS-WITH-LIMITS",
   "deterministicGate": "pass",
   "hardFailures": 0,
   "warnings": 0,
   "words": 324,
   "reason": "The publication-bound position passed strict and public deterministic controls against a task-local multi-work style pack. Its short length limits stylometric comparison."
  }
 },
 "userAffirmation": "Authorized under public authority SHA-256 87aad20196a753015a36d970f742c885eb763efdbada4869949bfffe3298130c and event supersession SHA-256 7d47ef36085c4dce590f287c986e4106f3bf35a7da5a25322d6fc3d4abf456d4. Publication remains receipt-bound to successful workflows and exact live-byte verification.",
 "sha256": "051b1518dc71e42c0a8329aca7ff1e5c29cafd929646dae2966d61ea49a66af7"
}
