Beyond Global EigenTrust: Enhancing Fairness and Security in Maze P2P Social Networks
Bring Reputation System to Social Network in the Maze P2P File-Sharing System 1
This paper presents an enhanced EigenTrust-based reputation system deployed within "Maze," a large-scale P2P file-sharing network in China. By introducing a location-aware pre-trusted peer selection algorithm and integrating social friend networks, the authors significantly improve fairness for "satellite clusters" and increase robustness against colluding nodes.
TL;DR
Calculating trust in a massive P2P network like Maze isn't just about counting bytes; it's about understanding where those bytes go. This paper identifies critical flaws in the classic EigenTrust algorithm—specifically its tendency to penalize isolated subnets and its susceptibility to collusion—and introduces a location-aware selection strategy and social network integration to fix them.
Background: The Maze Ecosystem
Maze is a large-scale P2P file-sharing system (developed by Peking University) that uniquely blends traditional Napster-like sharing with social network features. With over 2.3 million users and 1PB of data, it provides a massive real-world testbed for reputation systems. However, even with EigenTrust, "free-riders" and "malicious colluders" remain persistent threats.
The Problem: The "Satellite Cluster" Trap
When mapping EigenTrust to Maze, the authors discovered a disturbing pattern: peers with identical upload volumes were being split into two distinct trust bands (High and Low regions).
Why? Most "Region-Low" peers were part of university subnets. While they shared massive amounts of data internally, their external upload volume was low. In the eyes of the global EigenTrust algorithm, these clusters acted as "trust sinks" where reputation would run out and disappear, unfairly penalizing high-contributing local distributors.
Methodology: Location-Awareness and Social Trust
To bridge the gap between global reputation and local reality, the authors introduced two key innovations:
1. Location-aware Pre-trusted Peer Selection
Instead of picking pre-trusted peers randomly or by top global activity, the authors used WHOIS data to partition the network into Zones.
- The Logic: Ensure every zone has a representative pre-trusted peer.
- The Result: Trust is "injected" back into satellite clusters, preventing they from being characterized as malicious sinks.
Figure: The core power iteration of EigenTrust, which the authors modified via the distribution of vector p.
2. Social Network Integration
Colluders often gain high scores by tricking reputable peers (or pre-trusted peers) into downloading a small piece of a file, which "leaks" reputation to the malicious node.
- The Insight: Use the Maze Friend Network. Pre-trusted peers should only pass their massive "trust weight" to nodes they have explicitly added as friends, rather than anyone who happens to download from them.
Experiments & Results
The improvements were validated using a month of Maze traffic logs (495TB of data).
- Fairness Boost: In the location-aware model, the "Region-Low" population was slashed by over 50%. Local distributors saw their global rank jump by an average of 600%.
- Collusion Defense: By limiting trust to friend-based links, the system successfully isolated and demoted almost all known colluding groups that had previously "gamed" the high-trust band.
Figure: Impact of Location-aware selection—note the significant migration of nodes from the low-trust band to their deserved trust levels.
Critical Insight: The "Lucky Colluder"
Even with these fixes, a few "lucky colluders" remained. These were malicious nodes that managed to become "friends" with pre-trusted peers. This discovery highlights a fundamental limit: reputation systems are only as honest as the social relationships they are built upon. If a pre-trusted peer is socially engineered, the algorithm will still propagate that error.
Summary
The transition from theoretical P2P models to real-world deployment reveals that network topology (locality) and human behavior (friend networks) are just as important as the underlying math. This work serves as a foundational blueprint for deploying robust, fair reputation systems in modern decentralized applications.
