One hack could be to agree on a (totally unsafe) deterministic nsec key generation to represent any given URI. That solves the duplication issue: no matter the bridge, it will always generate the same npub for the same person in the Fediverse.
But it means anyone can fake messages from anyone in the Fediverse, with no way to know what to filter.
Perhaps this could be fixed by making the bridge add their private key to the deterministic key. This would require adding a meta-data field to the Nostr post ("orig-URI"). That way all clients can de-deduplicate by subtracting the URI from the npub. And then they can keep a list of which bridges they trust and ignore the spam.