Actually, the confiuration of the ClientRegistration when using the private_key_jwt
do not allow to modify the aud (audience) field.
But according to OpenID:
REQUIRED. Audience. The aud (audience) Claim. Value that identifies the Authorization Server as an intended audience. The Authorization Server MUST verify that it is an intended audience for the token. The Audience SHOULD be the URL of the Authorization Server's Token Endpoint.
The audience should be configurable in the ClientRegistration and must have a default value set to the URL of the Authorization Server's Token Endpoint.