English

On the Necessity of Two-Stage Estimation for Learning Dynamical Systems under Both Noise and Node-Wise Attacks

Optimization and Control 2026-02-23 v2

Abstract

The least-squares estimator has achieved considerable success in learning linear dynamical systems from a single trajectory of length TT. While it attains an optimal error of O(1/T)\mathcal{O}(1/\sqrt{T}) under independent zero-mean noise, it lacks robustness and is particularly susceptible to adversarial corruption. In this paper, we consider the identification of a networked system in which every node is subject to both noise and adversarial attacks. We assume that every node is independently corrupted with probability smaller than 0.50.5 at each time, placing the overall system under almost-persistent local attack. We first show that no convex one-stage estimator can achieve a consistent estimate as TT grows under both noise and attacks. This motivates the development of a two-stage estimation method applied across nodes. In Stage I, we leverage the 1\ell_1-norm estimator and derive an estimation error bound proportional to the noise level σw\sigma_w. This bound is subsequently used to detect and filter out attacks, producing a clean dataset for each node, to which we apply the least-squares estimator in Stage II. The resulting estimation error is on the order O(1/T)\mathcal{O}(1/\sqrt{T}) plus the product of σw\sigma_w and the number of misclassifications. In the event of perfect separability between attack and non-attack data, which occurs when injected attacks are sufficiently large relative to the noise scale, our two-stage estimator is consistent for the true system.

Keywords

Cite

@article{arxiv.2602.07288,
  title  = {On the Necessity of Two-Stage Estimation for Learning Dynamical Systems under Both Noise and Node-Wise Attacks},
  author = {Jihun Kim and Javad Lavaei},
  journal= {arXiv preprint arXiv:2602.07288},
  year   = {2026}
}

Comments

33 pages

R2 v1 2026-07-01T10:25:34.693Z