Mechanism
Markers are passive environmental devices installed in the navigable environment whose stored data ties them to a specific segment of a credentialed route. Each marker carries an authority credential identifying the authority that installed or maintains it, verified against the governance chain. A vehicle traversing the route reads markers through whatever sensing modality the marker class supports, passive photonic, passive radio-frequency, passive acoustic, magnetic-signature, or embedded-infrastructure, and constructs a candidate marker observation that includes the credential, the asserted segment, and the unit's mesh-derived position at the time of the read.
Adversarial rejection operates through a marker-read admissibility evaluator that composes a set of independent consistency checks against the candidate observation. A marker-integrity verifier checks the cryptographic integrity attestation of the read. A marker-authority evaluator verifies the marker's authority credential against the governance chain; failure here indicates a forged or revoked credential. A marker-sequence-consistency evaluator compares the current read against the preceding marker's next-expected-marker specification; failure here indicates a marker whose credential is valid in form but whose claim is inconsistent with the segment's structural identity: a marker placed out of order, replayed from another segment, or planted at a location the credential does not cover. A marker-position-consistency evaluator compares the marker's claimed position against the vehicle's mesh-derived position, and a marker-temporal-consistency evaluator compares the marker's temporal validity against mesh-derived time; failure here indicates a marker whose position or time assertion is inconsistent with the mesh's own estimate. Further evaluators verify cross-modality consistency where multi-modal markers are deployed, verify that the marker's revision version is the most recent admitted version, and weight reads by the marker's reputation track record.
A marker that fails any evaluator is excluded from the vehicle's solution set for the segment in question. Exclusion is not silent: a marker-rejection-lineage recorder records each rejection event, the applied evaluator, and the supporting evidence. The rejection is preserved in the governance chain, so that the rejection lineage is itself auditable. Rejections trigger a governance-chain-preserving graduated response and cascade propagation to adjacent units and infrastructure agents, which consume the rejection event as evidence of adversarial activity at the named segment.
Adversarial-Attack Coverage
The adversarial-marker rejection mechanism addresses a plurality of attack classes without limitation. Replay-attack rejection detects previously-observed marker reads replayed at new locations or times. Injection-attack rejection detects fabricated marker reads inserted through adversarial emission. Substitution-attack rejection detects unauthorized marker-payload substitution at the deployment location. Tampering-attack rejection detects physical-tampering evidence. Supply-chain-attack rejection detects markers with invalid manufacture provenance under the governance chain's continuity. Denial-attack rejection detects marker-coverage denial that forces the unit into a governed fallback. Composite-attack rejection detects coordinated multi-vector adversarial campaigns.
Each evaluator draws on governance-policy-defined parameters rather than fixed thresholds. The marker-authority evaluator verifies the credential against the governance chain, and a revoked credential is ineligible: a revocation governed observation issued by the credentialing authority invalidates previously-admitted reads under a governance-policy-defined retroactive-effect window. The marker-sequence-consistency and marker-position-consistency evaluators compare each read against the preceding marker's next-expected-marker specification and against the mesh-derived position, so that a marker inconsistent with the credentialed sequence or with the unit's own mesh position is rejected.
A rejection does not result in silent failure. It triggers a governance-chain-preserving graduated response proportional to the classified attack and its authority, and cascade propagation to adjacent units and infrastructure agents. An operator reviewing the segment's history can reconstruct each rejection, the applied evaluator, and the supporting evidence from the marker-rejection lineage.
Alternative Embodiments
The primitive admits embodiments across marker modality and verification topology. The markers disclosed are passive environmental markers that respond to interrogation without an internal battery, including passive photonic, passive acoustic, passive radio-frequency, passive chemical or spectroscopic, and magnetic-signature markers, as well as embedded-infrastructure markers integrated into road studs, raised pavement markers, guardrail reflectors, and similar components. Multi-modal markers combine two or more modalities to produce redundant authentication. The structural mechanism, integrity attestation, authority verification, sequence and position consistency, and recorded rejection, is identical across modalities; only the means of reading the marker and verifying its credential vary.
At each marker read, the unit validates the marker's authority credential through the governance chain, updates its route-progress state against the pre-departure authorized-route manifest, and verifies that the next-expected marker is consistent with the current marker's distance-to-next and topology data. The unit's sensor suite operates in parallel, producing observations consumed through the cross-domain coherence evaluator for obstacle detection and for conditions not represented in the track topology; when a sensor observation conflicts with the track topology, the unit applies multi-source conflict resolution and a graduated response to select an admissible response. A read weighted by the marker's reputation track record carries correspondingly more or less admission weight.
Composition with Adjacent Primitives
Adversarial marker rejection composes with the marker-track architecture's other primitives. Route-manifest construction reads admitted markers and excludes rejected markers from the segment's solution set, and the marker-rejection lineage is preserved alongside the manifest's route lineage. Cascade propagation carries rejection events to adjacent units and infrastructure agents as governed observations of adversarial activity. Marker-sequence-primary navigation treats the governance-credentialed sequence of marker reads as the unit's primary navigation reference, so a rejected marker is removed from that sequence and the unit falls back on parallel sensor observations and conflict resolution.
Validation, in the broader cognition pipeline that the marker-track architecture inherits or interfaces with, treats admitted markers as credentialed observations subject to the same admissibility checks applied to other credentialed evidence. A marker that passes adversarial rejection is not unconditionally trusted; it is admitted to validation, where it may still be rejected on grounds independent of the adversarial-rejection primitive: for example, on freshness grounds, or on conflict with an authoritative segment update. The primitive is a necessary, not sufficient, gate.
Audit composes naturally. A regulator with credentialed read-access reconstructs the segment's marker history by traversing admitted-read and rejection events recorded in the governance chain lineage field. The reconstruction yields an account of which markers were admitted, which were rejected, on what grounds, and by which units, supporting per-segment regulatory approval rather than per-unit sensor-stack approval.
Prior-Art Distinction
The marker-track transport primitive is structurally distinguished from prior architectures. Prior autonomous-vehicle architectures operate through sensor-primary navigation, producing path-by-inference routes without governance-credentialed attestation of an authorized route, whereas the present primitive operates through governance-credentialed marker sequences as the primary routing reference. Within that model, adversarial-marker rejection is a structural event of the architecture rather than a perception-stack heuristic: a marker read is admitted only after passing the marker-read admissibility evaluator, and every rejection is recorded by the marker-rejection-lineage recorder.
The distinction the rejection primitive draws is that an admissible marker must satisfy multiple independent evaluators at once: cryptographic integrity attestation, authority-credential verification against the governance chain, consistency with the preceding marker's next-expected-marker specification, and consistency with the unit's mesh-derived position and time. Because the credentialed marker sequence is the primary navigation reference, a successful attack must compromise several independent structural elements rather than the perception layer alone, and any rejection is preserved in the governance chain for regulatory and liability review.
Rejection Lineage
The rejection lineage is the persistent structural artifact of the primitive, and it is the principal output by which downstream consumers reason about adversarial activity on the route rather than only at the moment of observation. A marker-rejection-lineage recorder records each rejection event, the applied evaluator, and the supporting evidence in the governance chain lineage field. The marker-track lineage recorder more broadly records each marker read, navigation determination, admissibility evaluation, coordination event, topology update, and fail-safe transition, so admitted and rejected reads sit in a common governance-chain record.
Because the rejection is recorded in the governance chain, its integrity rests on the same governance-credentialed trust domain that issued the marker's authority credential in the first place. A revocation governed observation issued by the credentialing authority invalidates previously-admitted reads under a governance-policy-defined retroactive-effect window, so the same authority that admits a credential is the authority that can withdraw it. This keeps the audit chain coherent: the trust model does not depend on an arbitrary timestamp service or on the vehicle's local store.
Replay of the rejection lineage follows the same governance-chain-preserving pattern as the rest of marker-track operation. A credentialed reader reconstructs the segment's marker history, traversing admitted-read and rejection events recorded against the governance chain, and confirms that the governance-policy version applied was consistent with the operator's declared policy. The composite trail of admission and rejection events is the segment's adversarial-event record, supporting incident reconstruction and liability determination.
Disclosure Scope
This article describes subject matter disclosed in U.S. Provisional Application No. 64/049,409. The disclosure covers the marker-read admissibility evaluator and its component evaluators (integrity attestation, authority-credential verification, sequence consistency, position consistency, temporal consistency, cross-modality consistency, revision verification, and reputation-weighted admission), the adversarial-marker rejection mechanisms addressing replay, injection, substitution, tampering, supply-chain, denial, and composite attacks, the marker-rejection-lineage recorder, and the composition of the primitive with route-manifest construction, marker-sequence-primary navigation, cascade propagation, and governance-chain-preserving audit. The scope spans passive photonic, acoustic, radio-frequency, chemical or spectroscopic, magnetic-signature, embedded-infrastructure, and multi-modal markers. The scope does not depend on a particular marker modality, a particular cryptographic suite, or a particular sensor stack; it depends on the structural treatment of marker admission as a governance-credentialed event and rejection as a recorded lineage artifact.