Properties of Reputation Lag Attack Strategies

S. Sirur (University of Oxford), Tim Muller (University of Nottingham)

Abstract

The trustors in a reputation system share trust-relevant information about trustees; their reputation. The presence of lag in the sharing mechanism can be exploited by malicious trustees to perform otherwise impermissible additional bad actions. This is the reputation lag attack. In this paper, we use simulations to explore properties of the reputation lag attack and strategies which improve the attacker's success. We demonstrate the following key findings: Attackers in lagged systems clearly outperform attackers in lag-free systems. The attacker's success is proportional to the rate at which they can interact with victims, plateauing at a maximum. Attackers who wait for their good reputation to disseminate outperform those who do not. Attackers who perform only good actions, wait for dissemination and then perform only bad actions outperform attackers who do not follow this ordering. This implies reputation-lag attacks are effective exit strategies. In typical social networks, smart attackers may cheat users with a low centrality, but in a homogeneous network, this strategy is ineffectual. Our findings help allow developers of reputation systems defend against a class of attacks that has not yet received a great deal of attention.