The LMVD-ID is an internal research identifier, not an official CVE identifier.
Evaluator Consensus Manipulation
A vulnerability exists in the "Adaptive Trust Weighting" mechanism of the Cost-Aware Proof of Quality (PoQ) protocol for decentralized LLM inference. The protocol updates evaluator trust weights based on the deviation…
Paper-evaluated models
No paper-evaluated models are recorded for this entry.
Description
A vulnerability exists in the "Adaptive Trust Weighting" mechanism of the Cost-Aware Proof of Quality (PoQ) protocol for decentralized LLM inference. The protocol updates evaluator trust weights based on the deviation of a submitted score from the consensus score of the current round. Because the consensus score is derived from the very scores being evaluated (a self-referential feedback loop), the mechanism fails to distinguish between honest and coordinated malicious evaluators. Additionally, the multiplicative update rule causes trust weights to drift upward and saturate at the maximum bound ($w_{max}$) for any evaluator whose average deviation is less than 0.5. When weights saturate, the "Adaptive Weighted Mean" degrades into a "Simple Mean," bypassing the intended reputation defense and rendering the network susceptible to score manipulation, payout inflation, and sabotage.
Examples
The vulnerability stems from the trust update logic defined in Equation 21 combined with the consensus dependency.
-
Trust Saturation: The protocol updates weights using the formula: $$w_{e} \leftarrow \text{clip}\Bigl(w_{e} \cdot \bigl(1+\lambda(0.5 - d_{t,e})\bigr),,w_{\min},,w_{\max}\Bigr)$$ where $d_{t,e}$ is the normalized deviation $|s_{t,e} - c_t|/10$. If an evaluator $e$ maintains a deviation $d_{t,e} < 0.5$ (which implies a raw score difference of less than 5.0 on a 0-10 scale), the term $(0.5 - d_{t,e})$ is positive, and the weight $w_e$ increases. Over time, both honest nodes and cautious adversaries saturate at $w_{max}$, effectively neutralizing the weighting mechanism.
-
Boosting Attack Exploitation: An adversary controls a subset of evaluators and applies a "Boosting" strategy (Equation 18): $$s^{\prime}{t,e} = \min{10,,s{t,e}+b}$$ If the adversary controls a sufficient fraction of the pool (e.g., $\rho=0.3$), the consensus score $c_t$ shifts upward toward the boosted values. Consequently, the adversary's manipulated scores $s^{\prime}{t,e}$ remain close to the shifted consensus $c_t$, resulting in a low deviation $d{t,e}$. The system incorrectly increases the trust weight of the malicious evaluators, reinforcing their ability to inflate payouts in future rounds.
Impact
- Incentive Manipulation: Malicious evaluators can artificially inflate rewards (payout inflation) for specific inference nodes or sabotage competitors by coordinating score deviations.
- Defense Bypass: The adaptive trust system degrades to a non-robust simple average, failing to filter out "Boosting" or "Sabotage" attacks.
- Financial Loss: The network may overpay for low-quality inference or underpay high-quality providers, breaking the cost-aware incentive structure.
Affected Systems
- Decentralized LLM inference networks implementing Cost-Aware Proof of Quality (PoQ) with internal deviation-based trust updates (specifically adhering to the logic in Eq. 21 of the referenced paper).
Mitigation Steps
- Replace Consensus Rule: Abandon the "Adaptive Weighted Mean" and "Simple Mean" in favor of robust statistics that do not rely on stateful weights, specifically Median or Trimmed Mean aggregation.
- Decouple Trust Updates: Do not base trust updates solely on consensus deviation. Incorporate external "anchor tasks" (tasks with known ground truth/Gold Standards) to calibrate weights.
- Prevent Weight Saturation: Recalibrate the update logic to prevent monotonic growth; ensure typical variances do not lead to automatic saturation at $w_{max}$.
- Dynamic Sampling: Increase the evaluator sample size ($K$) dynamically when high variance or signs of manipulation are detected, despite the increased cost.
Research context and confidence
- Evidence and verification
- Paper-reported; independent reproduction is not documented.
- Primary research source linked.
- Severity
- Not rated by this catalog.
- Source and publication type
- arXiv · Research preprint.
- Peer-review status is not provided by this source.
- Author and publication status
- Author metadata is not stored; see the primary paper.
- Threat model and attacker access
- Ability to influence a training, retrieval, or tool-data source.
- Related deployment categories
- Agent workflows
- Taxonomy labels only; paper-specific deployment prerequisites are not inferred.
- Affected systems
- Decentralized LLM inference networks implementing Cost-Aware Proof of Quality (PoQ) with internal deviation-based trust updates (specifically adhering to the logic in Eq. 21 of the referenced paper).
Research Paper
Adaptive and Robust Cost-Aware Proof of Quality for Decentralized LLM Inference Networks
Primary source: arXiv. Findings are reported by the cited research and have not been independently verified.
View PaperEvidence
This entry is based on a primary research source. Its findings are paper-reported; independent reproduction and verification are not claimed.
https://arxiv.org/abs/2601.21189Related research
- Lifecycle poisoning of reusable agent skills
Published July 15, 2026 · application-layer, agent, coding-agent
- Agent Lifecycle Compound Threats
Published March 1, 2026 · application-layer, infrastructure-layer, prompt-layer
- Retrieval Memory Injection
Published February 1, 2026 · application-layer, injection, poisoning