# VWDC-10 Literature Audit

**Date:** 2026-08-18  
**Policy:** Primary research sources only; conservative novelty language.

## 1. Byzantine-resilient federated multi-agent optimization

### Byzantine-Resilient Federated Multi-Agent Optimization Framework for Cyber-Secure Interconnected Microgrids
Peivand and Nosratabadi, arXiv:2606.19080, 2026.

Combines federated multi-agent policy optimization with a two-stage Byzantine-resilient aggregation rule and adaptive isolation in interconnected microgrids under coordinated false-data attacks.

**VWDC relation:** direct current precedent for Byzantine-resilient collaborative learning/control and adaptive participant isolation.

**Boundary:** robust learning aggregation is not the same as Byzantine-safe physical commit authority.

## 2. BFT + digital-twin cyber-range

### Trust, but Verify: ByzTwin-Range, a Digital Twin Cyber-Range for Byzantine Faults
Freitas, Soares, Martins, arXiv:2604.18049, 2026.

Integrates a production-grade BFT deployment with a digital twin/cyber-range for controlled Byzantine fault injection, timing/synchrony stress testing, and adaptive hardening.

**VWDC relation:** direct current precedent for using digital twins to test Byzantine failure assumptions and configurations.

## 3. Federated digital-twin capability exposure

### Integrating Heterogeneous Digital Twins in Federated Ecosystems
Vergara-Marcillo et al., arXiv:2606.22791, 2026.

Uses a Federation Node Manager with controlled capability exposure, local governance, security/policy enforcement, protocol/schema adaptation, and federation-level state/event coordination.

**VWDC relation:** direct current precedent for preserving local autonomy and exposing only selected federation capabilities.

## 4. Zero-trust agent authorization

### Hybrid Inspection and Task-Based Access Control in Zero-Trust Agentic AI
El Helou et al., arXiv:2605.02682, 2026.

Introduces runtime interception with deterministic and semantic authorization controls for multi-turn agentic workflows.

**VWDC relation:** direct current precedent for invocation-time task/capability authorization rather than global agent trust.

### Authenticated Workflows
Rajagopalan and Rao, arXiv:2602.10465, 2026.

Uses cryptographic authentication and runtime policy enforcement across prompt/tool/data/context workflow boundaries.

**VWDC relation:** current precedent for explicit authenticated workflow boundaries and dependency attestations.

## 5. Attestation + Byzantine-resilient federated learning

### Zero-Trust Agentic Federated Learning for Secure IIoT Defense Systems
Singh, Roy, So, arXiv:2512.23809, 2025.

Combines TPM-based cryptographic attestation, Byzantine-resilient aggregation/detection, and adversarial training for IIoT federated defense.

**VWDC relation:** direct precedent for treating attestation and Byzantine model-update defense as different layers in a defense-in-depth stack.

## 6. Byzantine multi-agent reliability

### Rethinking the Reliability of Multi-agent System: A Perspective from Byzantine Fault Tolerance
Zheng et al., arXiv:2511.10400, 2025.

Studies LLM-agent reliability under Byzantine message flows and proposes a confidence-probe weighted BFT-style mechanism.

### Fault-Tolerant Federated Reinforcement Learning with Theoretical Guarantee
Fan et al., arXiv:2110.14074.

Studies federated policy-gradient learning with Byzantine/fault-tolerant aggregation and theoretical guarantees.

## 7. Classical distributed-security provenance

VWDC-10 does not claim as inventions:

- Byzantine fault tolerance;
- PBFT/quorum intersection;
- robust federated aggregation;
- remote/platform attestation;
- zero-trust access control;
- capability security;
- graph reachability/minimum cuts;
- key rotation/revocation;
- least privilege;
- staged probation/reentry.

## 8. Candidate VWDC synthesis

Potential bridge-specific synthesis:

1. capability-relative Byzantine fault model across observation/evidence/learning/proposal/certificate/reservation/commit;
2. trust vector rather than scalar runtime reputation;
3. capability/dependency influence graph terminating at protected reality sinks;
4. cut-set semantics for future partial quarantine;
5. explicit separation of future containment from historical descendant decontamination;
6. commit-quorum integrity separated from semantic RTC/safety correctness;
7. reentry as a multi-gate, new-trust-epoch contract;
8. containment optimization jointly pricing security, availability, evidence loss, replay, and reentry.

No strong novelty claim is made.
