Mechanism: Authority-Credentialed Hostility Attribution

The mechanism separates hostility attributes from competence attributes rather than combining them into an aggregate risk score, then credentials each hostility attribute through the authority competent to assert it. A hostility profile is composed of governance-credentialed attributes such as an aggression-history attribute summarizing prior credentialed incidents of aggressive behavior, an active-pursuit attribute characterizing persistent-following or stalking behavior, a target-specific-animosity attribute characterizing hostility directed at an identified target, a restraining-order or legal-constraint attribute indicating judicial or regulatory restrictions, and an escalation-trajectory attribute characterizing whether observed hostility is stable, escalating, or de-escalating. A compound hostility attribute is computed by governance-credentialed aggregation of the constituent attributes.

Each attribute carries the authority credential of the source that credentialed it, and the consuming agent evaluates each attribute against that source's authority and track record. Hostility profile credentialing sources admit a plurality of source classes: law-enforcement authorities for incident-history, conviction-history, and active-investigation attributes; judicial authorities for restraining-order, protective-order, and legal-constraint attributes; regulatory authorities for license-suspension and disciplinary-action attributes; insurance carriers for claim-history attributes subject to insured consent; employers and fleet operators for workplace-incident attributes within scope of employment; security authorities for protected-class attributes; intelligence and defense authorities for coalition-adversary attributes; and operator self-declaration for voluntary disclosure of restricted operating contexts. This is what distinguishes the mechanism from single-vendor algorithmic classification: authority-credentialed multi-source provenance with due-process credentialing.

Hostility profile signals are subject to privacy governance and to governance-policy-defined due-process constraints producing stricter privacy tiers than the operator risk profile. The disclosure tiers admit a minimal-disclosure tier revealing only an aggregated hostility class (none, elevated, acute); a proximity-gated tier revealing specific attributes only to consuming agents within a governance-policy-defined spatial proximity; a target-proximity tier revealing target-specific-animosity attributes only to the identified target's personal agent and to credentialed infrastructure agents in the target's vicinity; and a law-enforcement tier revealing the full profile only to credentialed authorities acting under investigative, protective, or emergency authority.

Consumption is lineage-bound rather than passive logging. Consuming agents adjust coordination margins, evasive-readiness thresholds, route selection, and response-mode defaults upon admission of hostility profile signals, and each adjustment is lineage-recorded so that downstream audit can reconstruct each coordination decision. The lineage records are held in tamper-evident, governance-chain-preserving storage. Because the architecture preserves retraction and correction, a superseding observation can correct a prior attribution while the lineage of the prior state remains for audit.

Operating Parameters: Privacy Tiers, Source Authority, and Inference Attribution

The disclosure level of a hostility attribute is governed by a parameterized privacy tier rather than by a single global setting. The minimal-disclosure tier reveals only an aggregated hostility class, none, elevated, or acute. The proximity-gated tier reveals specific attributes only to consuming agents within a governance-policy-defined spatial proximity. The target-proximity tier reveals target-specific-animosity attributes only to the identified target's personal agent and to credentialed infrastructure agents in the target's vicinity. The law-enforcement tier reveals the full profile only to credentialed authorities acting under investigative, protective, or emergency authority. These tiers are governance-policy-defined and can be extended.

Source authority is a parameter of each attribute, not of the profile as a whole. Each attribute carries the authority credential of its credentialing source, and the consuming agent weighs that attribute against the source's authority and track record. A target-specific-animosity attribute credentialed by a judicial protective order is weighed differently from a workplace-incident attribute credentialed by an employer. Where an attribute is inferred rather than credentialed by an asserting authority, it carries the inferring agent's authority credential and inference-function identifier, and is weighed by the inferring agent's authority and track record.

Cross-domain weighting parameters govern portability. Hostility inferred or credentialed in one domain can inform coordination in another domain subject to governance-policy-defined cross-domain weighting, spanning road vehicles, vessels, aircraft, unmanned systems, industrial equipment, and personal-agent-carried operators. The weighting is a governance-policy parameter, so a domain operator can constrain how strongly an out-of-domain attribution affects in-domain coordination.

Adversarial-intent inference adds further attribution parameters. An adversarial-intent classifier maps detected entities to a hostile-intent taxonomy, a cross-domain adversary classifier assigns them to domain-appropriate adversary classes, and an inferring-authority credential evaluator weights each inference by the inferring agent's authority and track record. A hostility-profile-integration evaluator combines inferred adversarial intent with admitted hostility profile signals to produce composite hostility estimates, and a composite admissibility evaluator applies cross-domain coherence before the estimate is admitted. Each inference, classification, counter-action selection, and downstream consequence is lineage-recorded.

Alternative Embodiments

The mechanism admits embodiments that vary by credentialing source. In one embodiment a target-specific-animosity attribute is credentialed by a judicial authority through a restraining-order or protective-order attribute; in another the same kind of attribute is credentialed by a law-enforcement authority through an active-investigation attribute; in a third it is credentialed by a security authority asserting a protected-class attribute. In each embodiment the consuming agent evaluates the attribute against the asserting source's authority and track record before acting on it.

Attribution admits embodiments ranging from authority-asserted to mesh-inferred. In the authority-asserted embodiment an attribute is credentialed by a competent source and carries that source's authority credential. In the inferred embodiment the adversarial-intent inference mechanism produces a governance-credentialed observation of an entity exhibiting adversarial signatures, maps it to a hostile-intent taxonomy, and emits it carrying the inferring agent's authority credential and inference-function identifier. A verification feedback loop compares inferred intent against observed outcome and refines the inference function, and the inference function's reputation is updated based on verification outcomes.

Disclosure admits embodiments at each privacy tier. Where only situational awareness is needed, a minimal-disclosure embodiment reveals an aggregated hostility class of none, elevated, or acute. Where a specific target is implicated, a target-proximity embodiment reveals target-specific-animosity attributes only to that target's personal agent and to credentialed infrastructure agents in the target's vicinity. Where credentialed authorities act under investigative, protective, or emergency authority, a law-enforcement embodiment reveals the full profile to those authorities.

Counter-action admits embodiments across a graduated response range. Lower-intensity embodiments adjust coordination margins, evasive-readiness thresholds, and route selection in response to an admitted hostility profile. Higher-intensity embodiments include governance-credentialed evasive-routing coordinated with infrastructure agents, authority-notification broadcasting credentialed observations to law-enforcement or coalition authorities, collective-warning emission to nearby agents, and target-protective routing toward credentialed safe-harbor locations. Each counter-action is admissibility-evaluated against governance-policy-defined authority, jurisdictional, civilian-safety, due-process, and use-of-force parameters, and each counter-action is lineage-recorded supporting after-action and legal review.

The architecture also admits the risk-versus-hostility bifurcation as a structural embodiment, in which hostility attributes are kept separate from competence and risk attributes rather than combined into a single aggregate score. This separation, together with the stricter privacy-tier governance, lets a deployment surface a hostility class to coordination logic without exposing the underlying credentialed attributes beyond the parties entitled to see them.

Composition With the Wider Operator-Intent Architecture

Due-process credentialing composes structurally with the operator-intent sharing primitive. The hostility profile mechanism sits alongside the operator risk profile mechanism, the adversarial-intent inference mechanism, the multi-source intent fusion engine, and the intent-verification feedback loop, all recorded by the intent-lineage recorder. Hostility attribution is one of several governance-credentialed intent signals carried through the same lineage field, distinguished from the operator risk profile by its stricter due-process-constrained privacy governance.

Composition with the governed mesh protocol is direct. Hostility profile signals and adversarial-intent observations are emitted as governed observations carrying authority credentials, and they are admitted through the cross-tier composite admissibility evaluator that applies tier-weighted evidential factors and cross-domain coherence. An attribution whose credentialing source has insufficient authority or track record is weighed accordingly by the consuming agent, so attributions of unknown or undocumented authority do not drive coordination on equal footing with credentialed ones.

Composition with the confidence-governed execution primitive mediates response. Counter-actions selected in response to admitted hostility or adversarial-intent signals are governed by intent-confidence and admissibility-evaluated against authority, jurisdictional, civilian-safety, due-process, and use-of-force parameters before they actuate. Each selection and each resulting consequence is recorded into the lineage, so a chain runs from observation through attribution through counter-action.

Composition with the training governance primitive governs inferred attribution. Where hostility or adversarial intent is inferred rather than asserted by a credentialing authority, the inference function carries an identifier and an authority attribution, the verification feedback loop compares the inference against observed outcome, and the inference function's reputation is updated based on verification outcomes. Inferred attributions therefore carry their provenance and are subject to correction rather than standing as opaque outputs.

Prior-Art Landscape

The hostility profile mechanism is structurally distinguished from prior usage-based telematics, driver-monitoring systems, and behavioral-analytics systems. Those systems combine hostility-relevant behavior into aggregate risk scores rather than separating hostility attributes from competence attributes, rely on single-vendor algorithmic classification rather than authority-credentialed multi-source provenance, and treat their outputs as passive logging rather than as signals consumed by neighboring units' governance chains for coordination adjustment. The mechanism here adds explicit separation of hostility from competence, due-process credentialing, stricter privacy-tier governance reflecting the sensitive nature of hostility attribution, cross-domain portability subject to governance-policy-defined weighting, and lineage-bound consumption supporting reconstruction of each coordination adjustment.

The wider operator-intent primitive is distinguished from prior coordination architectures. Prior vehicle-to-everything systems such as DSRC/IEEE 802.11p and C-V2X/3GPP define cross-vehicle message formats but lack governance-credentialed authority evaluation, fidelity-tier structure, and cross-source admissibility weighting. Prior advanced driver assistance systems infer other-unit behavior from onboard sensors without governance-chain integration. Prior driver-intent-prediction research produces probabilistic estimates without authority credentialing or attestation, whereas the present primitive produces governance-credentialed inferences with inference-function authority attribution.

The judicial and regulatory sources the architecture draws on, restraining orders, protective orders, license suspensions, disciplinary actions, are credentialing sources for hostility attributes rather than systems the architecture replaces. An attribute asserted by such an authority carries that authority's credential and is weighed by the consuming agent against the source's authority and track record. The architecture provides the governance substrate on which authority-asserted and mesh-inferred attributions are admitted, weighted, disclosed under privacy tiers, and lineage-recorded.

Disclosure Scope

This article describes subject matter from U.S. Provisional Application No. 64/049,409. The disclosure scope covers the hostility profile mechanism within the operator-intent sharing primitive: governance-credentialed hostility attributes separated from competence attributes; authority-credentialed multi-source provenance with due-process credentialing drawn from law-enforcement, judicial, regulatory, insurance, employer, security, and intelligence sources and operator self-declaration; stricter due-process-constrained privacy tiers spanning minimal-disclosure, proximity-gated, target-proximity, and law-enforcement tiers; cross-domain portability subject to governance-policy-defined weighting; the adversarial-intent inference mechanism with its hostile-intent taxonomy, cross-domain adversary classification, and inferring-authority credential evaluation; graduated counter-action selection admissibility-evaluated against authority, jurisdictional, civilian-safety, due-process, and use-of-force parameters; and lineage-recorded consumption supporting reconstruction of each coordination adjustment.

Operators of platforms whose coordination depends on hostility-relevant context, road vehicles, vessels, aircraft, unmanned systems, industrial equipment, and personal-agent-carried operators, gain a structural alternative to single-vendor aggregate risk scoring. The architecture provides authority-credentialed multi-source provenance, separation of hostility from competence, privacy-tier governance, and lineage-bound consumption, so that hostility attribution informs coordination while remaining auditable and subject to retraction and correction.