Jointly optimized physics- and aggregation-aware poisoning

Determine how much poisoning capability survives when an adversary simultaneously optimizes the poisoning objective subject to the physical invariants and against the server-side aggregation filters used in physics-attested federated learning.

Background

The physics-attested federated learning framework evaluates process-invariant compliance in data space before aggregation and uses server-side aggregation rules to filter model updates. The experiments evaluate adaptive adversaries that project poisoned telemetry onto the invariant-feasible subspace, but they do not study an adversary that jointly optimizes both the poisoned data and the resulting update to evade the downstream aggregation mechanism.

The paper identifies this stronger adversarial capability as unresolved because replayed, regime-spliced, and successfully projected batches can evade the physical gate, while update-space filters have their own blind spots. Establishing the surviving poisoning capability under simultaneous optimization would characterize the robustness of the combined defense more completely.

References

An adversary that directly optimises the poisoning objective within the feasible invariants and tailors updates to evade downstream aggregation rules, represents a stronger threat. It remains open how much poisoning capability survives when an adversary simultaneously optimises across both the physical invariants and the server's filters.

— Physics-Attested Federated Learning: Securing Collaborative Anomaly Detection in Critical Water Infrastructure  (2609.34804 - Nijsse et al., 28 Sep 2026) in Section 6, Limitations