paper

System Identification under Noise and Attack Regimes: Agnostic and Composite Robustness

arXiv:2602.07288

Abstract

Dynamical systems often confront persistent zero-mean independent noise and/or sparse nonzero-mean adversarial attacks. While mean-based estimators like least-squares handle the former, the median-based -norm estimator is effective for the latter. In this paper, we develop robust system identification frameworks to identify a linearly-parametrized nonlinear system from a single trajectory of length . We tackle two types of robustness: (1) under either pure noise or pure attacks without knowing which regime is active; and (2) under concurrent noise and attacks. We first show that the Huber estimator attains agnostic robustness by achieving an error rate for the noise regime and a bounded error for the attack regime, serving as a one-stage estimator interpolating between mean- and median-based methods. We then prove that no convex one-stage estimator is consistent under both noise and attacks, which motivates a two-stage estimation that sequentially applies median- and mean-based estimators for composite robustness. These dual notions of robustness require a corresponding duality in estimator design, providing a solid foundation for robust control in safety-critical systems.

16 pages, 3 figures

System Identification under Noise and Attack Regimes: Agnostic and Composite Robustness · wovepaper