How can one prevent the state power from simply eliminating the witnesses?
The network would very rapidly notice whenever a witness stops posting units. Since witnesses are publicly known, they can be contacted, and if no satisfactory explanation is given (or the problem is not solved) the community at large will decide to replace that particular witness address for someone else's.
So no matter what the state power does, or a hacker, or just a witness turned malicious by himself, Byteball is not vulnerable.
So in that sense I'd argue we don't even have to "trust" these witnesses.