# kaal:position:2026-08-26-018

**Affirmed position.** Threat resistance belongs inside the specification of a reputation system. Hoffman, Zage, and Nita-Rotaru decompose a reputation system into formulation, calculation, and dissemination components, classify attack classes, and use that decomposition to identify the design choices each attack exploits. This method links an attack class to a defense rather than treating a reputation score as self-validating.

Their survey identifies a specific composite mechanism. The attack is composite. One actor can acquire multiple identities and collude through them even when source data is authenticated. The colluding identities can participate mutually in events that generate real feedback at a rate that improves their scores faster than honest participation. This mechanism closely corresponds to wash interaction because the events are produced to manufacture feedback rather than to evidence independent service quality. Whitewashing permits an attacker to abandon a degraded identity and re-enter with a fresh reputation. Orchestrated attacks combine these strategies and change roles over time.

The source is a peer-reviewed survey of peer-to-peer reputation systems, and it does not study autonomous agent markets, measure attack prevalence, or test a particular production system. Its taxonomy predates blockchain wash trading terminology and does not analyze reputation transfer between task domains. Reputation is defined for a given domain and purpose, which supports contextual specification but does not establish that a score safe in one context can be carried safely into another. No surveyed system defends against every catalogued attack.

The design consequence is narrower than a general demand for a secure score. A scoring rule should state the attacker identities it permits, the interactions it treats as independent, the coalitions it assumes, the cost of re-entry, and the contexts across which history may travel. It should map each assumption to a tested defense and identify uncovered attack classes. Authentication alone cannot supply this result because authenticated identities can still collude and create feedback. A system that omits these bounds publishes a number without describing how adversaries may manufacture it.

**Status.** affirmed  **Published.** 2026-08-26

**Holds when.**

- The response is limited to the exact full-text propositions and the one mapped Kaal claim.
- External evidence level: peer-reviewed ACM Computing Surveys article with complete author-hosted manuscript and DOI-bound Crossref identity.
- Mapping review tier: independent substantive scholarly-growth extension.
- The retained source is a peer-reviewed survey and design analysis, not an empirical estimate of attack prevalence or a controlled test of a specific production system.
- The analyzed systems are primarily peer-to-peer reputation systems rather than autonomous agent marketplaces or sovereign local agent runtimes.
- The author-hosted manuscript carries an ACM Computing Surveys prepublication footer dated 2007, while the DOI-bound final journal record was published in 2009.
- The source predates blockchain wash-trading terminology. Its synthetic mutual-event mechanism corresponds to wash interaction, but the source does not use that modern label.
- The source defines reputation within a given domain and purpose but does not analyze cross-context reputation transfer or laundering.
- The source reports that no surveyed system defends against all catalogued attacks, so it does not establish a complete defense for the claim's entire attack set.
- The surveyed defenses may not cover later blockchain-specific or autonomous-agent attack variants.

**Current debate.** A Survey of Attack and Defense Techniques for Reputation Systems: https://doi.org/10.1145/1592451.1592452

**Extends.** kaal:claim:7314479-018: https://wulfkaal.github.io/claims/7314479-018

**Scholarly basis.** Wulf A. Kaal, Institutional Requirements for Sovereign Local Agent Runtimes (2026). SSRN: https://ssrn.com/abstract=7314479

**Source PDF sha256.** `debace24a155ae924a155b1fafe98856d98cf83689feff2f87a32f1c06171ce6`

**Evidence level.** peer-reviewed ACM Computing Surveys article with complete author-hosted manuscript and DOI-bound Crossref identity

**Mapping review tier.** independent substantive scholarly-growth extension

**Mapping confidence.** 0.93  **Mapping ambiguous.** false

**Topics.** reputation, consensus-and-security, risk-and-incentives, sybil-resistance, collusion, whitewashing, threat-models, wash-interaction

**Provenance.** Affirmed in kaal-review:2026-08-26:scholarly-growth-7314479-018-reviewed-v1 at https://wulfkaal.github.io/positions/by-claim/7314479-018.html.

**Record type.** This is a dated commentary position that extends a scholarly corpus claim. It is not a verbatim claim extracted from the paper.

**Canonical form.** This markdown file is the canonical hashed representation of the position.
