Mechanism
The mechanism extends the cooperative intent primitive and the hostility profile to operating environments in which one or more entities within the spatial region are adversarial. It is operable across civilian, commercial, industrial, emergency-response, and defense domains rather than being scoped to any single domain. The same primitive operates in each; only the parameters, the adversary classes, and the credential chain differ.
The mechanism comprises a set of cooperating components. An adversarial-entity detector produces governance-credentialed observations of entities exhibiting adversarial signatures. An adversarial-intent classifier maps detected entities to a hostile-intent taxonomy. A cross-domain adversary classifier assigns detected adversaries to domain-appropriate adversary classes. An inferring-authority credential evaluator weights adversarial-intent inferences by the inferring agent's authority and track record per the reputation discipline. A hostility-profile-integration evaluator combines inferred adversarial intent with admitted hostility profile signals to produce composite hostility estimates. A composite admissibility evaluator applies the cross-domain coherence of the coherence chapter to the adversarial-intent inferences. A counter-action selector produces governance-policy-defined graduated counter-action. A lineage recorder records each inference, classification, counter-action selection, and downstream consequence.
The classification of an entity as adversarial is itself a governed observation. It is produced under a credential, carries references to the contributing observations, and is admissibility-evaluated before it can drive any action, rather than acting directly on a single raw detection.
Adversarial Signatures
Adversarial-entity detection signatures admit a plurality of categories spanning civilian and defense domains. Civilian-vehicular adversarial signatures include erratic or targeting-consistent trajectory patterns such as weaving, sudden cut-in, targeting maneuvers, and ramming approaches, along with road-rage behavioral patterns and persistent-following or stalking trajectories across governance-policy-defined distance and duration thresholds. Unmanned-aerial-system signatures include harassment-following behavior, surveillance-hovering directed at specific targets, weaponized-payload signatures, and unauthorized-airspace intrusion. Maritime signatures include piracy-approach, ramming-approach, and unauthorized-boarding trajectories. Robotic and industrial-equipment signatures include compromised-robot targeting, deliberate-safety-override patterns, and malicious-takeover indicators. Cyber-physical signatures include signal-injection patterns, spoofed-credential patterns, and coordinated denial patterns directed at the consuming unit.
Defense-domain adversarial signatures include passive radio-frequency emissions characteristic of weapon guidance or targeting such as radar-lock signatures and fire-control emissions, visible, infrared, and electro-optical signatures of weapon deployment, formation and movement signatures characteristic of hostile force structure, acoustic signatures of hostile vehicles or weapons, electromagnetic-spectrum signatures of jamming or spoofing directed at the consuming unit or coalition, and deceptive masquerading signals purporting to be cooperative signals. Composite multi-domain signatures combine two or more categories, and any governance-policy-defined adversarial signature is admissible.
Hostile-Intent Taxonomy
The hostile-intent taxonomy admits a plurality of categories operable across civilian and defense domains. An offensive category indicates preparation or execution of attack. A defensive category indicates protection of an adversarial asset. A pursuit category indicates persistent targeting-following such as road-rage pursuit, stalking, or intercept shadowing. A reconnaissance or surveillance category indicates observation or shadowing without immediate offensive action. A deceptive category indicates masquerading signals to mislead consuming units, including fake-identity broadcast and credential spoofing. A coordination category indicates adversarial-entity coordination with other adversarial entities. A harassment category indicates non-lethal persistent aggressive behavior without immediate terminal offensive intent. An opportunistic-predation category indicates exploitation of detected target vulnerability. Any governance-policy-defined hostile-intent category is admissible.
The classification is weighted by the inferring agent's authority and track record, and it is combined with admitted hostility profile signals to produce a composite hostility estimate, so that an inference carries no more weight than the credential and reputation of the agent that produced it.
Counter-Action Selection
Counter-action response admits graduated response per the graduated response modes of the system, across civilian and defense contexts. Admissible counter-actions include, without limitation: evasive-maneuver actuation including civilian evasive driving, flight-path deviation, vessel course-change, or robotic workspace-clearance; governance-credentialed evasive-routing coordinated with infrastructure agents to produce route-plan changes that avoid the adversarial entity; authority-notification broadcasting governance-credentialed observations to law-enforcement, regulatory, public-safety, or coalition authorities; collective-warning emission broadcasting credentialed adversarial-presence observations to nearby agents through the governed mesh; target-protective routing for units that are the identified target, including rerouting to governance-credentialed safe-harbor locations; de-escalation-coordinated response adjusting coordination margins, speed, and engagement distance per the de-escalation-responsiveness attribute of the adversarial operator's hostility profile; counter-deception emission broadcasting credentialed observations contradicting adversarial deceptive signals; and escalation-to-authority handoff transferring coordination to governance-credentialed emergency-response or law-enforcement authorities with the intercepted adversarial observation lineage.
Each counter-action is admissibility-evaluated against the composite framework of the coherence chapter, with governance-policy-defined authority, jurisdictional, laws-of-armed-conflict, civilian-safety, due-process, and use-of-force parameters constraining the admissible counter-actions per domain. Each counter-action is lineage-recorded, supporting command audit, after-action review, legal review, and regulatory-compliance review.
Cross-Domain Operation
The mechanism is operable across domains without being rebuilt for each. The cross-domain adversary classifier assigns detected adversaries to domain-appropriate adversary classes, and the hostility profile carries a cross-domain portability mechanism producing per-domain hostility weightings from portable cross-domain attributes, whereby hostility inferred or credentialed in one domain informs coordination in another domain subject to governance-policy-defined cross-domain weighting.
In civilian operation the admissible counter-actions, the adversary classes, and the credential chain are tuned to the civilian context, where due-process constraints and use-of-force parameters are stringent and the privacy tiers governing hostility attribution are stricter than those governing the operator risk profile. In defense operation the adversary classes extend to hostile force structure and weapon-guidance emissions, and counter-actions extend to those admissible under appropriate governance-credentialed authority and applicable laws of armed conflict. In each domain the same primitive operates, and the invariance is what lets an organization operating across multiple domains deploy a single implementation and configure it per deployment rather than building a separate adversarial-inference stack per domain.
Risk Versus Hostility
The hostility profile that the mechanism consumes is distinct from the operator risk profile. The risk profile characterizes competence-relevant and capability-relevant attributes of the operator, such as skill level, experience, medical impairment, and violation history as indicia of competence. The hostility profile characterizes hostility-relevant attributes, such as aggression history, active pursuit or stalking behavior, target-specific animosity, and legal-constraint status. This separation keeps a confused or unskilled operator from being treated as hostile, and keeps a competent operator's hostility from being masked by a clean competence record.
Hostility profile attributes are credentialed by domain-appropriate sources: law-enforcement authorities for incident and conviction history, judicial authorities for restraining-order and protective-order constraints, regulatory authorities for license-suspension and disciplinary attributes, and intelligence and defense authorities for coalition-adversary attributes. Each attribute carries the credentialing source's authority credential, and the consuming agent evaluates each attribute against the source's authority and track record. The hostility profile is subject to governance-policy-defined due-process constraints producing stricter privacy tiers than the operator risk profile, with disclosure tiers ranging from a minimal-disclosure tier revealing only an aggregated hostility class through a target-proximity tier revealing target-specific animosity only to the identified target's agent, to a law-enforcement tier revealing the full profile only to credentialed authorities acting under investigative, protective, or emergency authority.
Prior-Art Distinction
The hostility profile signal mechanism is structurally distinguished from prior usage-based telematics, driver-monitoring systems, and behavioral-analytics systems in a plurality of respects. It explicitly separates hostility attributes from competence attributes rather than combining them into a single aggregate risk score. It carries authority-credentialed multi-source provenance with due-process credentialing rather than single-vendor algorithmic classification. It applies stricter privacy-tier governance reflecting the sensitive nature of hostility attribution. Its signals are consumed by neighboring units' governance chains for coordination adjustment, including evasive-readiness elevation, rather than being passively logged. It carries cross-domain portability whereby hostility inferred or credentialed in one domain informs coordination in another subject to governance-policy-defined cross-domain weighting. And every consumption is lineage-bound, supporting reconstruction of each coordination adjustment.
Disclosure Scope
This article describes subject matter disclosed in U.S. Provisional Application No. 64/049,409. The disclosure covers the adversarial-intent inference mechanism and its components: the adversarial-entity detector, the adversarial-intent classifier and hostile-intent taxonomy, the cross-domain adversary classifier, the inferring-authority credential evaluator, the hostility-profile-integration evaluator, the composite admissibility evaluator applying cross-domain coherence, the graduated counter-action selector, and the lineage recorder. It covers operation across civilian, commercial, industrial, emergency-response, and defense domains and the cross-domain portability of hostility attribution. The specific numerical thresholds, the specific adversary classes, and the specific authorities are deployment-dependent and are not themselves the subject of the disclosure; the disclosure is to the structure that admits any of them under appropriate credential. Particular embodiments are illustrative rather than limiting.