# Counterterrorism Predictive Graph
**Entity class:** Conceptual counterterrorism analytic model
## Definition
A **counterterrorism predictive graph** is a temporal heterogeneous graph used to maintain conditional estimates about a focal person, cohort, or network. Nodes may represent lawfully obtained people, accounts, devices, organizations, locations, transactions, identifiers, or events; edges represent observed or hypothesized relationships with time, type, provenance, and confidence.
It is closer to a continuously updated **network state estimator** than a static dossier. Each new observation may update the focal node, neighboring nodes, identity resolution, hidden relationships, and competing network configurations.
## Evidence architecture
The graph separates three propositions that are often collapsed: **origin**, **capability**, and **application**. A method can originate in one domain, demonstrate technical capability across several domains, and remain publicly undocumented in a particular operational program. Failure to prove the last proposition does not count against the first two.
The governing ladder is **documented capability → documented cross-domain method transfer → documented sponsor mission relevance → strongly indicated foreseeable dual use → specific operational application not publicly established**. The final phrase means undetermined. It is not evidence that the use did not occur, was not intended, or was technically excluded.
In the Oden case, Bui-Thanh's public radiation and epidemic projects establish method transfer across physical and biological propagation. DTRA's public research record separately establishes institutional interest in social and physical networks, adversarial intent, threat-network illumination, advanced analytics, forecasting, and counter-threat-network work. Counterterrorism scholarship independently establishes network diffusion, complex contagion, temporal graphs, and conditional inference as relevant analytic models. Together these sources document capability, portability, sponsor relevance, and foreseeable dual use while leaving any specific undisclosed operational application unresolved.
The person-scale graph can also represent an assembled mass-casualty system. A dangerous individual is not reduced to an ideology label: the graph distinguishes motivational or ideological payload, expressed intent, behavioral mobilization, access, expertise, relationships, platform, target vulnerability, timing, and observed steps toward capability. The resulting object is a [[wiki/Person as Threat System|person-as-threat-system]] hypothesis. In a September 11-type configuration, the person supplies cognitive guidance while an ordinary civilian platform supplies mobility and energy. Mass destruction emerges from the coupled configuration.
This systems model must remain separate from statutory biological terminology. A [[wiki/Vector (Biological Weapons Law)|biological vector]] carries an actual biological agent or toxin to a host. A [[wiki/Memetic Vector|memetic vector]] carries narratives or behavioral scripts through a social network. The first is a legal/biological category; the second is an analytic metaphor grounded in contagion and diffusion research.
## Predictive Questions
Prediction means conditional inference: which network configurations remain plausible; where reinforcement may be occurring; which transitions are becoming more or less probable; which missing observation would discriminate between hypotheses; and how new evidence changes those probabilities. It does not mean deterministic accusation or prediction of guilt.
## Relationships
- **data model:** [[wiki/Temporal Heterogeneous Graph|Temporal Heterogeneous Graph]] and [[wiki/Predictive Graph|Predictive Graph]].
- **updates:** [[wiki/Data Assimilation|Data Assimilation]], [[wiki/State Estimation|State Estimation]], and [[wiki/Contact Tracing|Contact Tracing]].
- **inference:** [[wiki/Inverse Problems in Counterterrorism Networks|Inverse Problems in Counterterrorism Networks]].
- **transmission model:** [[wiki/Ideological Transmission as Complex Contagion|Ideological Transmission as Complex Contagion]].
- **operational router:** [[wiki/Counterterrorism|Counterterrorism]].
- **evidence discipline:** [[wiki/Counterterrorism Predictive Graph Evidence Ladder|Counterterrorism Predictive Graph Evidence Ladder]], [[wiki/Documented Cross-Domain Method Transfer|Documented Cross-Domain Method Transfer]], and [[wiki/Specific Operational Application Not Publicly Established|Specific Operational Application Not Publicly Established]].
- **institutional bridge:** [[wiki/Defense Threat Reduction Agency|Defense Threat Reduction Agency]], [[wiki/Cognitive and Information Science|Cognitive and Information Science]], and [[wiki/Foreseeable Dual Use|Foreseeable Dual Use]].
## Sources / Provenance
- [NIJ — Role of Social Networks in Domestic Radicalization, April 2024](https://nij.ojp.gov/library/publications/role-social-networks-facilitating-and-preventing-domestic-radicalization-what)
- [ODNI — Data Mining Report CY2021–2023](https://www.odni.gov/files/documents/CLPO/CY2021-2023_Data_Mining_Report_FINAL.pdf)
- [2019 DTRA Strategic Plan for Research, Development, Test and Evaluation](https://www.dtra.mil/Portals/61/Documents/Missions/190424_2019_DTRA_Strategic_Plan_for_RDTE.pdf)
- [Basic Research for Countering Weapons of Mass Destruction — DTRA](https://www.govinfo.gov/content/pkg/GOVPUB-D15-PURL-gpo18268/pdf/GOVPUB-D15-PURL-gpo18268.pdf)