A data processing method and related apparatus
By processing game feature data through spatial and temporal anomaly recognition models, the problem of low accuracy in cheat detection is solved, and more efficient cheat detection is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SHENZHEN TENCENT INFORMATION TECH CO LTD
- Filing Date
- 2022-09-21
- Publication Date
- 2026-05-19
AI Technical Summary
Existing cheat detection methods are difficult to use and lack accuracy when dealing with professional, customized, and covert cheats.
The game feature data is processed using spatial anomaly identification models and temporal anomaly identification models. By combining the anomaly factors in the spatial and temporal domains, the cheat detection results are determined.
By employing a two-dimensional anomaly detection method, the accuracy of cheat detection has been improved.
Smart Images

Figure CN117018628B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and in particular to a data processing method and related apparatus. Background Technology
[0002] Cheating software refers to programs that modify the game to gain an advantage for players. Its main principle is to change the abilities of game characters by modifying the normal game code or data. The existence of cheating software will seriously undermine the fairness of the game.
[0003] Currently, cheat detection in games typically employs countermeasures based on cheat samples, which includes steps such as cheat collection, procurement, analysis, detection, and feature-based countermeasures. However, as anti-cheat efforts deepen, cheat programs are becoming increasingly professional, customized, and stealthy, significantly increasing the difficulty of countermeasures based on cheat samples, leading to greater difficulty and lower accuracy in cheat detection. Therefore, improving the accuracy of cheat detection is essential. Summary of the Invention
[0004] This application provides a data processing method and related apparatus, which helps to improve the accuracy of cheat detection.
[0005] In a first aspect, embodiments of this application provide a data processing method, the method comprising:
[0006] Obtain game characteristic data of the target object in the target game;
[0007] The game feature data of the target object is processed by calling the spatial anomaly identification model to obtain the spatial anomaly factor of the target object; wherein, the spatial anomaly identification model is constructed based on the statistical feature data of multiple sample objects in game matches within a preset time period;
[0008] The game feature data of the target object is processed by calling the temporal anomaly identification model to obtain the temporal anomaly factor of the target object; wherein, the temporal anomaly identification model is obtained by training an encoding and decoding neural network based on the temporal feature data of any sample object in the game within a preset time period;
[0009] Based on the spatial anomaly factor and the temporal anomaly factor, the detection result of the external plug-in for the target object is determined.
[0010] Secondly, embodiments of this application provide a data processing apparatus, the apparatus comprising:
[0011] The acquisition unit is used to acquire game feature data of the target object in the target game match.
[0012] The processing unit is used to call the spatial anomaly identification model to process the game feature data of the target object and obtain the spatial anomaly factor of the target object; wherein, the spatial anomaly identification model is constructed based on the statistical feature data of multiple sample objects in game matches within a preset time period;
[0013] The processing unit is further configured to call a temporal anomaly identification model to process the game feature data of the target object and obtain the temporal anomaly factor of the target object; wherein, the temporal anomaly identification model is obtained by training an encoding and decoding neural network based on the temporal feature data of any sample object in a game within a preset time period.
[0014] The processing unit is further configured to determine the external detection result of the target object based on the spatial anomaly factor and the temporal anomaly factor.
[0015] Thirdly, embodiments of this application provide a computer device including a processor, a communication interface, and a memory, which are interconnected. The memory stores a computer program, and the processor is used to call the computer program to execute the data processing method of any of the above possible implementations.
[0016] Fourthly, embodiments of this application provide a computer-readable storage medium storing a computer program that, when executed by a processor, implements the data processing method of any possible implementation.
[0017] Fifthly, embodiments of this application also provide a computer program product, which includes a computer program or computer instructions, and the computer program or computer instructions are executed by a processor to implement the steps of the data processing method provided in embodiments of this application.
[0018] Sixthly, embodiments of this application also provide a computer program, the computer program including computer instructions, the computer instructions being stored in a computer-readable storage medium, a processor of a computer device reading the computer instructions from the computer-readable storage medium, and the processor executing the computer instructions, causing the computer device to perform the data processing method provided in embodiments of this application.
[0019] In this embodiment of the application, when performing cheat detection on a target object in a target game, the game feature data of the target object in the target game can be processed by a spatial anomaly identification model to obtain a spatial anomaly factor, and the game feature data of the target object can be processed by a temporal anomaly identification model to obtain a temporal anomaly factor. This enables dual-dimensional anomaly detection of the target object in both the temporal and spatial domains, which helps to improve the accuracy of cheat detection. Attached Figure Description
[0020] To more clearly illustrate the technical methods of the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0021] Figure 1a An application scenario diagram of a data processing method provided in an embodiment of this application;
[0022] Figure 1b A schematic diagram of a game interface when using a wallhack, provided as an embodiment of this application;
[0023] Figure 1c A flowchart illustrating an external plugin detection method provided in an embodiment of this application;
[0024] Figure 2 A flowchart illustrating a data processing method provided in an embodiment of this application;
[0025] Figure 3 A flowchart illustrating another data processing method provided in an embodiment of this application;
[0026] Figure 4 This is a schematic diagram of the structure of an encoding / decoding neural network provided in an embodiment of this application;
[0027] Figure 5 This is a schematic diagram of the encoding and decoding neural network processing involved in the embodiments of this application;
[0028] Figure 6 A flowchart illustrating another data processing method provided in an embodiment of this application;
[0029] Figure 7 A schematic diagram of an isolated forest model tree provided in an embodiment of this application;
[0030] Figure 8 A flowchart illustrating another data processing method provided in an embodiment of this application;
[0031] Figure 9 This is a schematic diagram of the structure of a data processing device provided in an embodiment of this application;
[0032] Figure 10 This is a schematic diagram of the structure of a computer device provided in an embodiment of this application. Detailed Implementation
[0033] The technical methods in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.
[0034] This application proposes a data processing method applicable to various fields and scenarios such as cloud technology, artificial intelligence, blockchain, vehicle networking, smart transportation, and smart homes. In one embodiment, the data processing method provided in this application can be implemented based on machine learning technology within artificial intelligence. Artificial intelligence is a comprehensive discipline involving a wide range of fields, encompassing both hardware and software technologies. Fundamental artificial intelligence technologies generally include sensors, dedicated AI chips, cloud computing, distributed storage, large-scale video processing, operating / interactive systems, and mechatronics. Artificial intelligence software technologies mainly include computer vision, speech processing, natural language processing, and several major directions such as machine learning / deep learning, autonomous driving, and smart transportation. Machine learning technology is a multidisciplinary field involving probability theory, statistics, approximation theory, convex analysis, and algorithm complexity theory. It specifically studies how computers can simulate or implement human learning behavior to acquire new knowledge or skills and reorganize existing knowledge structures to continuously improve their performance. Machine learning is the core of artificial intelligence and the fundamental way to enable computers to possess intelligence; its applications span all areas of artificial intelligence. Machine learning and deep learning typically include techniques such as artificial neural networks, belief networks, reinforcement learning, transfer learning, inductive learning, and formulaic learning. For example, in the embodiments of this application, machine learning techniques are used to train an encoder-decoder neural network to obtain a temporal anomaly recognition model, and to construct a spatial anomaly recognition model.
[0035] See Figure 1a , Figure 1a This is a schematic diagram illustrating an application scenario of a data processing method provided in an embodiment of this application. For example... Figure 1a As shown, this application scenario includes a terminal device 11, a server 12, and a database 13, which can communicate with each other via a network.
[0036] Terminal device 11 runs a game client for the target game. The target game can be any of the following: FPS (First Person Shooting), TPS (Third Person Shooting), multiplayer online tactical battle royale, sports, racing, etc. Players can participate in the target game through the game client running on terminal device 11. Server 12 is the backend server for the game client. The backend server can be equipped with an airspace anomaly detection model and a temporal anomaly detection model to execute the data processing method provided in this application embodiment, thereby detecting cheats used by players using the game client, such as wallhacks and aimbots in shooting games. Figure 1b This is a schematic diagram of the game interface when using a wallhack; database 13 is the database used by server 12, which can be used to store game data generated by the game client, such as game feature data.
[0037] See Figure 1c , Figure 1c This is a flowchart illustrating a cheat detection method provided in an embodiment of this application. In this cheat detection method, the server 12 integrates player data to obtain player spatial feature data and player temporal feature data. Player spatial feature data refers to data that reflects the characteristics of the player in the spatial domain (e.g., data to be detected that subsequently includes behavioral feature values and first mapping feature values). Player temporal feature data refers to data that reflects the characteristics of the player in the temporal domain (e.g., subsequent time-series feature data). By processing the player's spatial feature data using a spatial anomaly recognition model, anomaly detection of the player in the spatial domain can be achieved. By processing the player's temporal feature data using a temporal anomaly recognition model, anomaly detection of the player in the temporal domain can be achieved. Finally, by combining the degree of anomaly of the player in the temporal and spatial domains, it is determined whether the player is using cheats.
[0038] In one embodiment, players can participate in game matches through a game client running on terminal device 11. After the game match ends, server 12 can determine whether the player who participated in the game match used cheats. Specifically, server 12 can obtain the player's game feature data from database 13, process the player's game feature data using an onboard spatial anomaly detection model to obtain spatial anomaly factors, and process the target object's game feature data using an onboard temporal anomaly detection model to obtain temporal anomaly factors. This achieves anomaly detection of the target object's game feature data in both the temporal and spatial domains. Based on the spatial and temporal anomaly factors, the cheat detection result for the player is determined. Server 12 can construct the onboard spatial anomaly detection model based on statistical feature data of multiple sample objects in game matches within a preset time period; server 12 can train an onboard temporal anomaly detection model by training an encoding / decoding neural network based on temporal feature data of any sample object in game matches within a preset duration. This application helps improve the accuracy of cheat detection.
[0039] Optionally, the aforementioned terminal device 11 can be a smartphone, tablet computer, laptop computer, desktop computer, intelligent voice interaction device, smart home appliance, vehicle terminal, etc., but is not limited to these. The aforementioned server 12 can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery network (CDN), and big data and artificial intelligence platforms.
[0040] The specific implementation of the data processing method provided in this application is described in detail below. (See reference...) Figure 2 , Figure 2 This is a flowchart illustrating a data processing method provided in an embodiment of this application. This method can be applied to the above-described... Figure 1a Server 12 in the middle, the method includes:
[0041] S201. Obtain the game feature data of the target object in the target game.
[0042] The target object is the player or player account to be detected for cheating. In one embodiment, any game match in the target game in which the target object participates can be considered the target game match. The target game can be any of the following: FPS game, TPS game, multiplayer online tactical battle royale game, sports game, racing game, etc. Game feature data refers to data that reflects the behavioral characteristics of the object in the game match. For example, in shooting games, game feature data can include data such as the number of kills, deaths, shots fired, hit rate, and damage dealt in the match.
[0043] S202. The spatial anomaly identification model is called to process the game feature data of the target object to obtain the spatial anomaly factor of the target object; wherein, the spatial anomaly identification model is constructed based on the statistical feature data of multiple sample objects in the game within a preset time period.
[0044] In one embodiment, to obtain the airspace anomaly identification model, multiple sample objects can be identified. These sample objects can be highly active players selected from all players participating in the target game; highly active players refer to players who frequently participate in the target game. For each of the multiple sample objects, game feature data of each sample object in game matches within a preset time period is obtained. It is understood that each sample object can participate in multiple game matches within the preset time period, and game feature data for each game match within those multiple game matches needs to be obtained. Statistical feature data of each sample object in game matches within the preset time period can be obtained by statistically processing the obtained multiple game feature data. For example, if sample A participates in three game matches within a preset time period, we can obtain the number of kills, deaths, shots, hit rate, and damage in each game match. By calculating the average of the number of kills, deaths, shots, hit rate, and damage in each of the three game matches, we can obtain the statistical characteristic values of each sample A in the game matches within the preset time period. Thus, we can use the obtained multiple statistical characteristic values to construct the statistical characteristic data of each sample A in the game matches within the preset time period.
[0045] A spatial anomaly detection model is further constructed using statistical feature data from multiple sample objects in game matches within a preset time period. This model determines the degree of anomaly of a target object in a game match within that preset time period compared to players in other games within the same time period. Specifically, the spatial anomaly detection model processes the target object's game feature data to obtain its spatial anomaly factor. This factor reflects the degree of anomaly of the target object in the spatial dimension, i.e., its degree of anomaly compared to players in other games within the same time period.
[0046] S203. Call the temporal anomaly identification model to process the game feature data of the target object and obtain the temporal anomaly factor of the target object; wherein, the temporal anomaly identification model is obtained by training the encoding and decoding neural network based on the temporal feature data of any sample object in the game within a preset time period.
[0047] In one embodiment, to obtain a temporal anomaly model, any sample object can be identified, which may be a highly active player selected from all players participating in the target game. Then, game feature data of this sample object within a preset time period is used to construct temporal feature data of the sample object within that preset time period. Specifically, this sample object can participate in multiple game matches within a preset time period. Game feature data for each of these multiple game matches needs to be obtained. Interpolation processing is performed on the obtained game feature data to obtain the temporal feature data of the sample object within the preset time period. The game feature data included in the obtained temporal feature data has a temporal relationship, determined according to the chronological order of the game time information (e.g., game start time) of each game match within the multiple game matches. The server can train an encoding / decoding neural network to obtain a temporal anomaly recognition model based on the temporal feature data of the sample object within the preset time period. The trained temporal anomaly detection model can detect anomalies in the temporal dimension of target objects. For detailed training procedures of the encoder-decoder neural network, please refer to [link to relevant documentation]. Figure 3 The example implementation is as follows. In one embodiment, a temporal anomaly detection model can be invoked to process the game feature data of the target object to obtain a temporal anomaly factor of the target object, which can reflect the degree of anomaly of the target object in the temporal dimension.
[0048] S204. Based on spatial anomaly factors and temporal anomaly factors, determine the external detection results of the target object.
[0049] In one implementation, a larger spatial anomaly factor indicates a greater degree of anomaly in the spatial dimension of the target object. Therefore, when the spatial anomaly factor is greater than or equal to a first preset threshold (which can be manually set), the detection result of the target object is determined to be that an external cheat exists. Conversely, a smaller spatial anomaly factor indicates a smaller degree of anomaly in the spatial dimension of the target object. Therefore, when the spatial anomaly factor is less than the first preset threshold, the detection result of the target object is determined to be that no external cheat exists.
[0050] In another implementation, a larger temporal anomaly factor indicates a greater degree of anomaly in the temporal dimension of the target object. Therefore, when the temporal anomaly factor is greater than or equal to a second preset threshold (which can be manually set), the target object's cheat detection result is determined to be that a cheat exists. Conversely, a smaller temporal anomaly factor indicates a smaller degree of anomaly in the temporal dimension of the target object. Therefore, when the temporal anomaly factor is less than the second preset threshold, the target object's cheat detection result is determined to be that a cheat does not exist.
[0051] In a feasible embodiment, the sum of the spatial anomaly factor and the temporal anomaly factor can be calculated. When the sum is greater than or equal to a third preset threshold (which can be set manually), it indicates that the game feature data may have a high degree of anomaly in both the spatial and temporal dimensions, and the cheat detection result for the target object is determined to be the presence of cheats. When the sum is less than the third preset threshold, it indicates that the game feature data may have a low degree of anomaly in both the spatial and temporal dimensions, and the cheat detection result for the target object is determined to be the absence of cheats.
[0052] In this embodiment of the application, when performing cheat detection on a target object in a target game, the game feature data of the target object in the target game can be processed by a spatial anomaly identification model to obtain a spatial anomaly factor, and the game feature data of the target object can be processed by a temporal anomaly identification model to obtain a temporal anomaly factor. This enables dual-dimensional anomaly detection of the target object in both the temporal and spatial domains, which helps to improve the accuracy of cheat detection.
[0053] See Figure 3 , Figure 3 This is a flowchart illustrating a method for acquiring a time-domain anomaly recognition model, as provided in an embodiment of this application. This method can be applied to the above-mentioned... Figure 1a Server 12 in the middle, the method includes:
[0054] S301. Obtain game feature data of any sample object in multiple game matches within a preset time period.
[0055] The preset duration can be manually set. Since the acquisition of the time-domain anomaly identification model needs to consider the patterns presented by the player's game feature data in the time domain, the preset duration can be relatively long, such as one month or two months. Simultaneously, it must be ensured that any given sample object participates in multiple game matches within the preset duration to obtain multiple game feature data with a temporal relationship. This application will acquire the game feature data of each game match within the multiple game matches played by any given sample object within the preset duration. It should be noted that any given sample object did not use any cheats in any of the multiple game matches it participated in within the preset duration.
[0056] S302. Based on the preset duration and preset time interval, interpolate the game feature data of multiple game matches to obtain the temporal feature data of any sample object within the preset duration.
[0057] The preset duration corresponds to an actual time span. For example, a preset duration of one month corresponds to a time span from January 1st to January 30th. The preset time interval is the unit time interval used to divide this time span and can be manually set. In one embodiment, the server can divide the time span corresponding to the preset duration into multiple time periods based on the preset time interval. For example, if the preset time interval is 24 hours, for the time span of January 1st to January 30th, multiple time periods can be obtained: January 1st-January 2nd, January 2nd-January 3rd, ..., January 29th-January 30th.
[0058] Furthermore, the game time information for each game in multiple game matches is obtained, which can be the game start time. Then, the time period to which each game match's start time belongs is determined from multiple time periods. Based on the sequential position information of each game match's start time within these multiple time periods, the temporal position information for each game match is determined. For example, if game match 1 belongs to January 1st-January 2nd, since January 1st-January 2nd is the first time period arranged in chronological order (i.e., sequential position information), the temporal position information for game match 1 is 1; if game match 2 belongs to January 3rd-January 4th, since January 3rd-January 4th is the third time period arranged in chronological order (i.e., sequential position information), the temporal position information for game match 2 is 3.
[0059] Furthermore, based on the temporal position information of each game match, interpolation processing is performed on the game feature data from multiple game matches to obtain the temporal feature data of any sample object within a preset duration. Each game feature data in this temporal feature data is arranged according to its temporal position information, and the value at a position not corresponding to a game match is padded with 0. For example, the temporal feature data is [V battle_1 ,0,0,V battle_2 ,0,0,V battle_2 [,0,0], where V battle_1 For game feature data of game match 1, via V battle_1 Based on its location, the start time of game match 1 belongs to the first time period in a chronological order among multiple time periods; V battle_2 For game feature data of game match 2, via V battle_2Based on its location, the start time of game match 2 belongs to the fourth time period in chronological order among multiple time periods; V battle_3 For game feature data of game match 3, via V battle_3 The location indicates that the start time of game match 3 belongs to the seventh time period in chronological order among multiple time periods. The position of the padding data 0 indicates that there are no corresponding game matches in these time periods.
[0060] In a feasible embodiment, the game start time of a game match can be normalized using a linear normalization function to obtain the normalized game start time. The expression of the linear normalization function can be found in the following equation (1):
[0061]
[0062] Among them, X max X represents the maximum value of the time span corresponding to the preset duration. min X represents the minimum time span corresponding to the preset duration, and X represents the start time of the game. norm This indicates the start time of the game after normalization.
[0063] Furthermore, the normalized time span corresponding to each of the multiple time periods is determined. For example, for multiple time periods: January 1st-January 2nd, January 2nd-January 3rd, ..., January 29th-January 30th, the normalized time span corresponding to January 1st-January 2nd is 0-1 / 30, the normalized time span corresponding to January 2nd-January 3rd is 1 / 30-2 / 30, and so on. The temporal position information of a game can be determined by the normalized time span to which the game start time belongs after normalization.
[0064] S303. Call the encoding and decoding neural network to process the time series feature data to obtain the first predicted feature data.
[0065] See Figure 4 , Figure 4This is a schematic diagram of the network architecture of an encoder-decoder neural network proposed in this application. The encoder-decoder neural network includes a first encoder-decoder network and a second encoder-decoder network. The first and second encoder-decoder networks include a shared encoder. Additionally, the first encoder-decoder network includes a decoder 1, and the second encoder-decoder network includes a decoder 2. The encoder performs data compression, and the decoders (including decoder 1 and decoder 2) perform data decompression. This application does not impose specific limitations on the structure of the encoder and decoder. For example, the encoder can be implemented using a bidirectional RNN (Recurrent Neural Network), such as a bidirectional LSTM (Long Short-Term Memory), and the decoder can be implemented using a unidirectional RNN, such as a unidirectional LSTM. It should be noted that the input and output dimensions of the first and second encoder-decoder networks are the same; for example, the input dimension is m×n, and the output dimension is also m×n, where m and n are positive integers.
[0066] In one embodiment, the timing feature data X can be processed by calling the first and second codec networks respectively, to obtain the fourth transformed feature data D1(E(X)) output by the first codec network and the fifth transformed feature data D2(E(X)) output by the second codec network. Specifically, as shown... Figure 5 As shown, the temporal feature data X is input into the encoder to obtain the first coded feature data E(X). Then, the coded feature data E(X) is input into decoder 1 to obtain the fourth transformed feature data D1(E(X)) output by the first codec network. Simultaneously, the coded feature data E(X) is input into decoder 2 to obtain the fifth transformed feature data D2(E(X)) output by the second codec network. The second codec network is then used to process the fourth transformed feature data D1(E(X)) to obtain the sixth transformed feature data D2(E(D1(E(X)))). The purpose of designing the sixth transformed feature data is to increase the robustness of the temporal anomaly detection model.
[0067] Furthermore, the first predicted feature data Y1 can be determined according to the following formula (2) and based on the fifth transformation feature data D2(E(X)) and the sixth transformation feature data D2(E(D1(E(X)))).
[0068] Y1=αD2(E(X))+βD2(E(D1(E(X)))) (2)
[0069] Where α represents the weight coefficient of the fifth transformation feature data D2(E(X)), and its value can be set manually, for example, it can be 0.7; β represents the weight coefficient of the sixth transformation feature data D2(E(D1(E(X)))), and its value can be set manually, for example, it can be 0.3. The sum of α and β is 1.
[0070] S304. The encoding and decoding neural network is trained based on the difference data between the first predicted feature data and the time-series feature data to obtain the time-domain anomaly recognition model.
[0071] Since the sample object did not use any cheats in the multiple game matches it participated in within the preset time period, the encoding and decoding neural network can be trained based on the processing logic that the input (temporal feature data of the sample object) and the output (first predicted feature data) of the encoding and decoding neural network should be the same. In one embodiment, the difference data L(X) between the first predicted feature data and the temporal feature data of the sample object can be obtained, which can be achieved by the following formula (3):
[0072] L(X)=[αD2(E(X))+βD2(E(D1(E(X))))-X] 2 (3)
[0073] Furthermore, the encoding / decoding neural network is trained once using the difference data L(x). One training iteration refers to adjusting the network parameters of the encoding / decoding neural network once using the difference data L(x). Understandably, temporal feature data of multiple sample objects within a preset time period can be obtained. Then, the encoding / decoding neural network is trained multiple times using the multiple difference data obtained from the temporal feature data of multiple sample objects. When the difference data obtained in a certain training iteration is less than a fourth preset threshold (which can be manually set), or when the number of training iterations reaches a preset number, the trained encoding / decoding neural network is determined as a temporal anomaly detection model.
[0074] It should be explained that this application trains the encoder-decoder neural network along the direction where the difference in data decreases. During this training process, the encoder-decoder neural network makes the input temporal feature data increasingly similar to the output first predicted feature data. The trained temporal anomaly detection model, for target objects that do not use cheats, will make the input game feature data (which can also be temporal feature data) of the target object similar to the output second predicted feature data. However, for target objects that use cheats, it will make the input game feature data (which can also be temporal feature data) of the target object dissimilar to the output second predicted feature data.
[0075] In this embodiment, temporal feature data of the sample object can be constructed by using game feature data from multiple game matches of the sample object and the temporal relationship of multiple game matches. The temporal feature data is then used to train the encoding and decoding neural network, so that the trained temporal anomaly recognition model can detect anomalies of players in the temporal domain, which is beneficial to improving the accuracy of cheat detection.
[0076] See Figure 6 , Figure 6 This is a flowchart illustrating another data processing method provided in an embodiment of this application. This method can be applied to the above-described... Figure 1a Server 12 in the middle, the method includes:
[0077] S601. Obtain the game feature data of the target object in the target game.
[0078] The target object is the player or player account to be detected for cheating. In one embodiment, any game match in the target game in which the target object participates can be considered the target game match. The target game can be any of the following: FPS game, TPS game, multiplayer online tactical battle royale game, sports game, racing game, etc. Game feature data refers to data that reflects the behavioral characteristics of the object in the game match. For example, in shooting games, game feature data can include data such as the number of kills, deaths, shots fired, hit rate, and damage dealt in the match.
[0079] S602. Based on the game time information of the target game and the preset time period corresponding to each of the multiple airspace anomaly identification models, determine the airspace anomaly identification model that matches the target game from the multiple airspace anomaly identification models.
[0080] In one embodiment, multiple preset time periods can be manually set, such as 1:00-3:00, 4:00-8:00; or a reference duration can be set, and an airspace anomaly identification model is constructed at each reference duration interval to determine multiple preset time periods. For example, if the reference duration is 2 hours, then for a day, the multiple preset time periods include: 0:00-2:00, 2:00-4:00, ..., 22:00-24:00.
[0081] For any given preset time period among multiple preset time periods, statistical characteristic data for each sample object within that preset time period can be determined based on the game feature data of each sample object in its game matches within that preset time period. Specifically, one or more game matches that each sample object participated in within that preset time period are identified. Game feature data for each game match of each sample object in those one or more game matches is obtained. Statistical processing is then performed on the behavioral feature values under each feature dimension of the game feature data for each game match to obtain statistical feature values under multiple feature dimensions. These multiple statistical feature values are used to construct the statistical characteristic data for each sample object in its game matches within that preset time period. For example, if sample object A participated in three game matches within a preset time period, the kill count, death count, number of shots, hit rate, and damage in each game match can be obtained. By calculating the average of the kill count, death count, number of shots, hit rate, and damage in each of the three game matches, the statistical characteristic values included in the statistical characteristic data for each sample object in its game matches within the preset time period can be obtained.
[0082] Furthermore, based on the statistical feature data of each sample object in the multiple sample objects, including multiple statistical feature values, the sample data corresponding to each sample object is determined. This sample data includes multiple statistical feature values and multiple first mapping feature values, wherein each first mapping feature value is obtained by mapping two statistical feature values from the multiple statistical feature values. The specific process of the mapping process can be implemented using the following equation (4):
[0083] K(x, z) = (γx·z + r) d (4)
[0084] Equation (4) is the expression of the polynomial kernel function, x and z represent the inputs of the polynomial kernel function, which can be any two statistical characteristic values, r, γ, and d can be coefficients determined by humans, and K(x, z) represents the output of the polynomial kernel function.
[0085] Ultimately, an isolated forest model can be constructed based on multiple sample data corresponding to multiple sample objects and a preset isolated forest algorithm, and the constructed isolated forest model can be used as the spatial anomaly identification model for any preset time period.
[0086] The isolated forest model comprises multiple isolated trees, each a random binary tree. Each node in an isolated tree corresponds to a feature dimension and a node feature value. Each node is either a leaf node or has two child nodes: a left child node and a right child node. The left child node consists of data whose feature value (which can be a statistical feature value or a first-mapping feature value) is less than the node's feature value, while the right child node consists of data whose feature value (which can be a statistical feature value or a first-mapping feature value) is greater than the node's feature value. Each comprehensible preset time period corresponds to a spatial anomaly detection model.
[0087] In one embodiment, based on the game time information of the target game (which could be the game start time) and the preset time period corresponding to each of the multiple airspace anomaly identification models, an airspace anomaly identification model matching the target game can be determined from among the multiple preset time periods corresponding to the multiple airspace anomaly identification models. Specifically, the target preset time period to which the game time information of the target game belongs can be determined from the multiple preset time periods corresponding to the multiple airspace anomaly identification models. For example, if the game start time is 2:12 on [date], then the target preset time period could be 2:00-4:00 on [date]. The airspace anomaly identification model corresponding to the target preset time period can be determined as the airspace anomaly identification model matching the target game.
[0088] S603. Call the spatial anomaly identification model that matches the target game match to process the game feature data of the target object and obtain the spatial anomaly factor of the target object.
[0089] In one embodiment, the game feature data of the target object includes behavioral feature values under multiple feature dimensions. Each pair of behavioral feature values can be mapped using the above equation (4) to obtain multiple second mapped feature values. Further, the data to be detected is constructed based on these multiple second mapped feature values and the multiple behavioral feature values. Since the spatial anomaly identification model matching the target game is an isolated forest model, it will include multiple isolated trees. The path length of the data to be detected in each of these isolated trees can be obtained by traversing the data to be detected in each isolated tree.
[0090] Specifically, starting from the root node of each isolated tree, the data to be detected is traversed along the tree structure of each isolated tree according to the feature dimension and node feature value corresponding to each node, until the leaf node of each isolated tree is reached. During the traversal, feature values (which can be behavioral feature values or second mapping feature values) with the same feature dimension as the current node are obtained from the data to be detected, and these same feature values are compared with the node feature value of the current node. If the same feature value is greater than the node feature value of the current node, the right child node of the current node is selected as the node to be visited; if the same feature value is less than the node feature value of the current node, the left child node of the current node is selected as the node to be visited. This process is repeated sequentially, and the visited nodes are recorded. The traversal stops when the leaf node of each isolated tree is reached. The number of edges traversed by the data to be detected from the root node to the visited leaf node can be used as the path length of the data to be detected in each isolated tree.
[0091] Furthermore, based on the path length of the data to be detected in each isolated tree, the average path length of the data to be detected in all isolated trees is calculated, and this average is used as the average path length of the data to be detected in the isolated forest model (i.e., the spatial anomaly identification model matching the target game). The shorter the average path length, the easier it is for the target object to be distinguished from the game players, the greater the difference from other game players, and the more likely it is to use cheats; the longer the average path length, the less difficult it is for the target object to be distinguished from the game players, the smaller the difference from other game players, and the less likely it is to use cheats. The spatial anomaly factor of the target object can be determined based on this average path length, specifically using the following equations (5) and (6).
[0092]
[0093]
[0094] Where S(x, n) represents the spatial anomaly factor, c(n) represents the average path length of each isolated tree in the spatial anomaly identification model, n represents the number of sample data used when constructing the spatial anomaly identification model, h(x) represents the path length of the data to be detected x in the isolated tree, E(h(x)) represents the average path length of the data to be detected in the spatial anomaly identification model, and ξ represents Euler's constant, which is approximately 0.5772156649.
[0095] like Figure 7 As shown, when using statistical characteristic data of multiple sample objects (i.e. Figure 7When constructing a spatial anomaly detection model (i.e., an isolated forest model) using example data such as Player 1 data and Player 2 data, the average path length of each sample object in the constructed spatial anomaly detection model can be determined, thus obtaining the spatial anomaly factor of each sample object (e.g., ...) among the multiple sample objects. Figure 7 Examples include Player 1's spatial anomaly factor, Player 2's spatial anomaly factor, etc. Therefore, the spatial anomaly factors of each sample object corresponding to the spatial anomaly identification model can be stored. When it is necessary to determine the spatial anomaly factor of a target object, it can first be checked whether it is stored. If it is not stored, then the spatial anomaly identification model matching the target game match is used to determine the spatial anomaly factor of the target object.
[0096] S604. Call the temporal anomaly identification model to process the game feature data of the target object and obtain the temporal anomaly factor of the target object.
[0097] The temporal anomaly detection model includes a first encoder-decoder network and a second encoder-decoder network. The first and second encoder-decoder networks share a common encoder and each has its own dedicated decoder; specifically, the first encoder-decoder network includes decoder 1, and the second encoder-decoder network includes decoder 2. The first and second encoder-decoder networks in the temporal anomaly detection model are trained using the first and second encoder-decoder networks within the encoder-decoder neural network.
[0098] In one embodiment, the game feature data of the target object can be processed by calling the first encoding / decoding network and the second encoding / decoding network respectively to obtain the first transformed feature data output by the first encoding / decoding network and the second transformed feature data output by the second encoding / decoding network. Specifically, the game feature data of the target object in the target game is input into the encoder to obtain the output second encoded feature data, and then the second encoded feature data is input into the decoder 1 to obtain the first transformed feature data output by the first encoding / decoding network. At the same time, the second encoded feature data is input into the decoder 2 to obtain the second transformed feature data output by the second encoding / decoding network. The second encoding / decoding network is further called to process the first transformed feature data to obtain the third transformed feature data. Then, based on the second transformed feature data and the third transformed feature data, the second predicted feature data of the target object is determined. The processing logic is the same as the processing logic declared in the above equation (2). The difference data between the game feature data and the second predicted feature data is further determined. The processing logic is the same as the processing logic declared in the above equation (3). The difference data can be determined as the temporal anomaly factor of the target object.
[0099] While the above method can obtain the temporal anomaly factors of the target object in the target game, the temporal anomaly identification model fails to accurately grasp the temporal patterns exhibited by the target object. Therefore, in another embodiment, game feature data of each game in multiple game matches within a target duration (which can be manually set) can be obtained, including the target game match.
[0100] Furthermore, based on the game feature data of each game match acquired, temporal feature data of the target object in the game matches within the target duration is constructed, and the temporal anomaly identification model is called to process the temporal feature data of the target object to obtain the target predicted feature data. The processing logic is the same as the aforementioned processing logic for generating temporal feature data and generating the second predicted feature data, and will not be repeated in this embodiment.
[0101] Furthermore, the difference data between the temporal feature data and the target predicted feature data of the target object is determined. This difference data can be understood as a vector, where a value represents the temporal difference factor of the target object in the corresponding game (including the target game). For example, the temporal feature data is [V battle_1 ,0,0,V battle_2 ], the target prediction feature data is [a, b, c, d], then the difference data calculated according to equation (3) is [(V battle_1 -a) 2 ,(0-b) 2 (0-c) 2 , (V battle_2 -d) 2 ],(V battle_1 -a) 2 For the temporal difference factor corresponding to the target object in game match 1, (V) battle_2 -d) 2 This is the temporal difference factor corresponding to the target object in game match 2.
[0102] S605. Based on spatial anomaly factors and temporal anomaly factors, determine the external detection results of the target object.
[0103] In one embodiment, it can be based on spatial anomaly factors. Spatial weighting coefficient γ, temporal anomaly factor And the time-domain weighting coefficient μ, to determine the joint anomaly factor I. anomaly The specific implementation process is shown in equation (7) below:
[0104]
[0105] When combined abnormal factors When the preset judgment conditions are met, the target object's cheat detection result is determined to be that no cheat is found. When the combined anomaly factors do not meet the preset judgment conditions, the target object's cheat detection result is determined to be that cheat is found. Meeting the judgment conditions can refer to the combined anomaly factors. Less than the preset anomaly factor The failure to meet the judgment criteria may refer to the combined abnormal factors. Greater than or equal to the preset anomaly factor
[0106] In this embodiment, multiple isolated forest models corresponding to multiple preset time periods can be constructed to determine multiple spatial anomaly detection models. Then, the spatial anomaly identification model that matches the target game match among the multiple spatial anomaly detection models can be used to detect anomalies in the spatial dimension of the target object. At the same time, the temporal anomaly identification model can be used to detect anomalies in the temporal dimension of the target object. By realizing the detection of anomalies in both the temporal and spatial dimensions of the target object, it is beneficial to improve the accuracy of cheat detection.
[0107] See Figure 8 , Figure 8 This is a flowchart illustrating another data processing method provided in an embodiment of this application. This method can be applied to the above-described... Figure 1a Server 12 in the middle, the method includes:
[0108] S801. Obtain game feature data of multiple game matches of the target object within a target duration. The target duration can be set manually. Specifically, obtain game feature data of each game match of the target object within the target duration.
[0109] S802. Interpolate the game feature data from multiple game matches to obtain the temporal feature data of the target object within the target duration of the game matches. The detailed implementation process is the same as the processing logic for obtaining temporal feature data in step S302 above, and will not be repeated here.
[0110] S803: Call the time-domain anomaly identification model to process the time-series feature data and obtain the target prediction feature data.
[0111] S804. Based on the difference data between the target predicted feature data and the temporal feature data of the target object, determine the target game from multiple game matches. Understandably, the input and output dimensions of the temporal anomaly identification model are the same; therefore, the difference data is a vector, where each value is the temporal anomaly factor of the target object in the corresponding game match. Game matches with temporal anomaly factors greater than a fifth preset threshold (which can be manually set) can be considered as the target game matches.
[0112] S805. Based on the game feature data of the target object in the target game, determine multiple second mapping feature values, and based on the multiple second mapping feature values and multiple behavioral feature values in the game feature data, determine the data to be detected.
[0113] S806. Based on the data to be detected and the spatial anomaly identification model that matches the target game, determine the spatial anomaly factors of the target object in the target game.
[0114] S807. Determine the detection result of the target object based on the spatial anomaly factor and temporal anomaly factor of the target object in the target game.
[0115] In this embodiment, the target game can be identified from multiple game games by first identifying the temporal anomaly factor of the target object in multiple game games, and then the spatial anomaly factor and temporal anomaly factor of the target object in the target game game can be used to jointly determine whether the target object is using cheats, which can improve the accuracy of cheat detection.
[0116] It is understood that in the specific embodiments of this application, which involve behavioral feature values and other related data in game feature data, when the above embodiments of this application are applied to specific products or technologies, user permission or consent is required, and the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions.
[0117] The methods of the embodiments of this application have been described in detail above. To facilitate better implementation of the methods of the embodiments of this application, the apparatus of the embodiments of this application is provided below. Please refer to... Figure 9 , Figure 9 This is a schematic diagram of the structure of a data processing device provided in an embodiment of this application. The data processing device 90 may include:
[0118] Acquisition unit 901 is used to acquire game feature data of target objects in the target game;
[0119] Processing unit 902 is used to call the spatial anomaly identification model to process the game feature data of the target object to obtain the spatial anomaly factor of the target object; wherein, the spatial anomaly identification model is constructed based on the statistical feature data of multiple sample objects in game matches within a preset time period;
[0120] The processing unit 902 is further configured to call a temporal anomaly identification model to process the game feature data of the target object and obtain the temporal anomaly factor of the target object; wherein, the temporal anomaly identification model is obtained by training an encoding and decoding neural network based on the temporal feature data of any sample object in a game within a preset time period.
[0121] The processing unit 902 is further configured to determine the external detection result of the target object based on the spatial anomaly factor and the temporal anomaly factor.
[0122] In one embodiment, the acquisition unit 901 is specifically used to: acquire the game time information of the target game match;
[0123] The processing unit 902 is specifically used to: determine, based on the game time information and the preset time period corresponding to each of the multiple spatial anomaly identification models, a spatial anomaly identification model that matches the target game match from the multiple spatial anomaly identification models; wherein, each spatial anomaly identification model is constructed based on the statistical feature data of multiple sample objects in the game match within the corresponding preset time period; and call the spatial anomaly identification model that matches the target game match to process the game feature data of the target object to obtain the spatial anomaly factor of the target object.
[0124] In one embodiment, the acquisition unit 901 is specifically used to: acquire statistical feature data of multiple sample objects in game matches within any preset time period of any preset time period, wherein the statistical feature data includes statistical feature values under multiple feature dimensions.
[0125] The processing unit 902 is specifically used to: determine sample data corresponding to each sample object based on the multiple statistical feature values included in the statistical feature data of each sample object among the multiple sample objects, wherein the sample data includes the multiple statistical feature values and multiple first mapping feature values, and each first mapping feature value is obtained by mapping two statistical feature values among the multiple statistical feature values; and construct a spatial anomaly identification model corresponding to any preset time period based on the multiple sample data corresponding to the multiple sample objects and a preset isolated forest algorithm.
[0126] In one embodiment, the game feature data of the target object includes behavioral feature values under the multiple feature dimensions; the processing unit 902 is specifically used to: perform mapping processing on every two behavioral feature values among the multiple behavioral feature values to obtain multiple second mapping feature values, and construct the data to be detected based on the multiple second mapping feature values and the multiple behavioral feature values;
[0127] Based on the data to be detected, traverse each of the multiple isolated trees to obtain the path length of the data to be detected in each isolated tree;
[0128] Based on the path length of the data to be detected in each isolated tree, the spatial anomaly factor of the target object is determined.
[0129] In one embodiment, the processing unit 902 is specifically used to: determine the target preset time period to which the game time information belongs from the multiple preset time periods corresponding to the multiple spatial anomaly identification models; and determine the spatial anomaly identification model corresponding to the target preset time period as the spatial anomaly identification model that matches the target game match.
[0130] In one embodiment, the acquisition unit 901 is specifically used to: acquire game feature data of any sample object in multiple game matches within a preset time period;
[0131] The processing unit 902 is specifically used to: perform interpolation processing on the game feature data in the multiple game matches according to the preset duration and preset time interval to obtain the temporal feature data of any sample object within the preset duration; call the encoding and decoding neural network to process the temporal feature data to obtain first predicted feature data; and train the encoding and decoding neural network based on the difference data between the first predicted feature data and the temporal feature data to obtain a temporal anomaly recognition model.
[0132] In one embodiment, the temporal anomaly identification model includes a first encoding / decoding network and a second encoding / decoding network. The processing unit 902 is specifically configured to: call the first encoding / decoding network and the second encoding / decoding network respectively to process the game feature data of the target object, obtaining first transformed feature data output by the first encoding / decoding network and second transformed feature data output by the second encoding / decoding network; call the second encoding / decoding network to process the first transformed feature data, obtaining third transformed feature data; determine second predicted feature data of the target object based on the second transformed feature data and the third transformed feature data; and determine the difference data between the game feature data and the second predicted feature data as the temporal anomaly factor of the target object.
[0133] In one embodiment, the acquisition unit 901 is specifically used to: determine a joint anomaly factor based on the spatial anomaly factor, the spatial weight coefficient, the temporal anomaly factor, and the temporal weight coefficient; when the joint anomaly factor meets a preset judgment condition, determine that the target object's cheat detection result is that no cheat exists; when the joint anomaly factor does not meet the preset judgment condition, determine that the target object's cheat detection result is that cheat exists.
[0134] It is understood that the functions of each functional unit of the data processing device described in the embodiments of this application can be specifically implemented according to the methods in the above method embodiments, and the specific implementation process can be referred to the relevant descriptions in the above method embodiments, which will not be repeated here.
[0135] In this embodiment of the application, when performing cheat detection on a target object in a target game, the game feature data of the target object in the target game can be processed by a spatial anomaly identification model to obtain a spatial anomaly factor, and the game feature data of the target object can be processed by a temporal anomaly identification model to obtain a temporal anomaly factor. This enables dual-dimensional anomaly detection of the target object in both the temporal and spatial domains, which helps to improve the accuracy of cheat detection.
[0136] like Figure 10 As shown, Figure 10 This is a schematic diagram of the structure of a computer device provided in an embodiment of this application. The internal structure of the computer device 100 is as follows: Figure 10 As shown, it includes: one or more processors 1001, memory 1002, and communication interface 1003. The processors 1001, memory 1002, and communication interface 1003 can be connected via bus 1004 or other means. This embodiment of the application takes the connection via bus 1004 as an example.
[0137] The processor 1001 (or CPU, Central Processing Unit) is the computing and control core of the computer device 100. It can parse various instructions within the computer device 100 and process various data. For example, the CPU can parse power-on / off commands sent by the user to the computer device 100 and control the computer device 100 to perform power-on / off operations; it can also transmit various interactive data between internal structures of the computer device 100, and so on. The communication interface 1003 may optionally include standard wired interfaces or wireless interfaces (such as Wi-Fi, mobile communication interfaces, etc.), and is controlled by the processor 1001 for sending and receiving data. The memory 1002 is the storage device in the computer device 100, used to store computer programs and data. It is understood that the memory 1002 here can include both the computer device 100's built-in memory and extended memory supported by the computer device 100. The memory 1002 provides storage space for the operating system of the computer device 100, which may include, but is not limited to, Windows, Linux, Android, iOS, etc., and this application does not limit this to any particular system. The processor 1001 performs the following operations by running the computer program stored in the memory 1002:
[0138] Obtain game characteristic data of the target object in the target game;
[0139] The game feature data of the target object is processed by calling the spatial anomaly identification model to obtain the spatial anomaly factor of the target object; wherein, the spatial anomaly identification model is constructed based on the statistical feature data of multiple sample objects in game matches within a preset time period;
[0140] The game feature data of the target object is processed by calling the temporal anomaly identification model to obtain the temporal anomaly factor of the target object; wherein, the temporal anomaly identification model is obtained by training an encoding and decoding neural network based on the temporal feature data of any sample object in the game within a preset time period;
[0141] Based on the spatial anomaly factor and the temporal anomaly factor, the detection result of the external plug-in for the target object is determined.
[0142] In one embodiment, the processor 1001 is specifically configured to: acquire game time information of the target game match; based on the game time information and a preset time period corresponding to each of the multiple spatial anomaly identification models, determine a spatial anomaly identification model that matches the target game match from the multiple spatial anomaly identification models; wherein, each spatial anomaly identification model is constructed based on statistical feature data of multiple sample objects in game matches within the corresponding preset time period; and call the spatial anomaly identification model that matches the target game match to process the game feature data of the target object to obtain the spatial anomaly factor of the target object.
[0143] In one embodiment, the processor 1001 is specifically configured to: acquire statistical feature data of multiple sample objects in game matches within any preset time period of any of a plurality of preset time periods, wherein the statistical feature data includes statistical feature values under multiple feature dimensions; determine sample data corresponding to each sample object based on the multiple statistical feature values included in the statistical feature data of each of the plurality of sample objects, wherein the sample data includes the plurality of statistical feature values and multiple first mapping feature values, wherein each first mapping feature value is obtained by mapping two statistical feature values among the plurality of statistical feature values; and construct a spatial anomaly identification model corresponding to the any preset time period based on the multiple sample data corresponding to the plurality of sample objects and a preset isolated forest algorithm.
[0144] In one embodiment, the game feature data of the target object includes behavioral feature values under the multiple feature dimensions; the spatial anomaly identification model matching the target game match includes multiple isolated trees; the processor 1001 is specifically used to: perform mapping processing on every two behavioral feature values among the multiple behavioral feature values to obtain multiple second mapped feature values, and construct data to be detected based on the multiple second mapped feature values and the multiple behavioral feature values; traverse each of the multiple isolated trees based on the data to be detected to obtain the path length of the data to be detected in each isolated tree; and determine the spatial anomaly factor of the target object based on the path length of the data to be detected in each isolated tree.
[0145] In one embodiment, the processor 1001 is specifically configured to: determine the target preset time period to which the game time information belongs from the multiple preset time periods corresponding to the multiple spatial anomaly identification models; and determine the spatial anomaly identification model corresponding to the target preset time period as the spatial anomaly identification model that matches the target game match.
[0146] In one embodiment, the processor 1001 is specifically configured to: acquire game feature data of any sample object in multiple game matches within a preset duration; perform interpolation processing on the game feature data in the multiple game matches according to the preset duration and a preset time interval to obtain temporal feature data of the any sample object within the preset duration; call an encoding / decoding neural network to process the temporal feature data to obtain first predicted feature data; and train the encoding / decoding neural network based on the first predicted feature data and the difference data between the temporal feature data to obtain a temporal anomaly recognition model.
[0147] In one embodiment, the temporal anomaly identification model includes a first encoding / decoding network and a second encoding / decoding network. The processor 1001 is specifically configured to: call the first encoding / decoding network and the second encoding / decoding network respectively to process the game feature data of the target object, obtaining first transformed feature data output by the first encoding / decoding network and second transformed feature data output by the second encoding / decoding network; call the second encoding / decoding network to process the first transformed feature data, obtaining third transformed feature data; determine second predicted feature data of the target object based on the second transformed feature data and the third transformed feature data; and determine the difference data between the game feature data and the second predicted feature data as the temporal anomaly factor of the target object.
[0148] In one embodiment, the processor 1001 is specifically configured to: determine a joint anomaly factor based on the spatial anomaly factor, the spatial weight coefficient, the temporal anomaly factor, and the temporal weight coefficient; when the joint anomaly factor meets a preset judgment condition, determine that the target object's cheat detection result is that no cheat exists; when the joint anomaly factor does not meet the preset judgment condition, determine that the target object's cheat detection result is that cheat exists.
[0149] In specific implementations, the processor 1001, memory 1002, and communication interface 1003 described in the embodiments of this application can execute the implementation method described in the data processing method provided in the embodiments of this application, or they can execute the implementation method described in the data processing device provided in the embodiments of this application, which will not be repeated here.
[0150] In this embodiment of the application, when performing cheat detection on a target object in a target game, the game feature data of the target object in the target game can be processed by a spatial anomaly identification model to obtain a spatial anomaly factor, and the game feature data of the target object can be processed by a temporal anomaly identification model to obtain a temporal anomaly factor. This enables dual-dimensional anomaly detection of the target object in both the temporal and spatial domains, which helps to improve the accuracy of cheat detection.
[0151] This application also provides a computer-readable storage medium storing a computer program that, when run on a computer device, causes the computer device to perform the data processing method described in any of the possible implementations above. Specific implementations are described above and will not be repeated here.
[0152] This application also provides a computer program product, which includes a computer program or computer instructions. When executed by a processor, the computer program or computer instructions implement the steps of the data processing method provided in this application. The specific implementation method can be found in the foregoing description and will not be repeated here.
[0153] This application also provides a computer program comprising computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the data processing method provided in this application. Specific implementation details are provided above and will not be repeated here.
[0154] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, as some steps may be performed in other orders or simultaneously according to this application. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions and modules involved are not necessarily essential to this application.
[0155] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be implemented by a program instructing related hardware. The program can be stored in a computer-readable storage medium, which may include: a flash drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, etc.
[0156] The above-disclosed embodiments are only some of the embodiments of this application, and should not be construed as limiting the scope of this application. Therefore, any equivalent changes made in accordance with the claims of this application shall still fall within the scope of this application.
Claims
1. A data processing method, characterized in that, The method includes: Obtain game characteristic data of the target object in the target game; The game feature data of the target object is processed by calling the spatial anomaly identification model to obtain the spatial anomaly factor of the target object; wherein, the spatial anomaly identification model is constructed based on the statistical feature data of multiple sample objects in game matches within a preset time period; The game feature data of the target object is processed by calling the temporal anomaly identification model to obtain the temporal anomaly factor of the target object; wherein, the temporal anomaly identification model is obtained by training an encoding and decoding neural network based on the temporal feature data of any sample object in the game within a preset time period; Based on the spatial anomaly factor and the temporal anomaly factor, the detection result of the external plug-in for the target object is determined.
2. The method according to claim 1, characterized in that, The process of calling the spatial anomaly identification model to process the game feature data of the target object to obtain the spatial anomaly factor of the target object includes: Obtain the game time information of the target game match; Based on the game time information and the preset time period corresponding to each of the multiple spatial anomaly identification models, a spatial anomaly identification model that matches the target game match is determined from the multiple spatial anomaly identification models; wherein, each spatial anomaly identification model is constructed based on the statistical feature data of multiple sample objects in the game match within the corresponding preset time period; The spatial anomaly identification model that matches the target game match is invoked to process the game feature data of the target object, thereby obtaining the spatial anomaly factor of the target object.
3. The method according to claim 2, characterized in that, The method further includes: For any one of multiple preset time periods, obtain statistical feature data of multiple sample objects in the game within any one preset time period, the statistical feature data including statistical feature values under multiple feature dimensions; Based on the statistical feature data of each of the multiple sample objects, including multiple statistical feature values, the sample data corresponding to each sample object is determined. The sample data includes the multiple statistical feature values and multiple first mapping feature values. Each first mapping feature value is obtained by mapping two statistical feature values among the multiple statistical feature values. Based on multiple sample data corresponding to the multiple sample objects and a preset isolated forest algorithm, a spatial anomaly identification model corresponding to any preset time period is constructed.
4. The method according to claim 3, characterized in that, The game feature data of the target object includes behavioral feature values under the multiple feature dimensions; the spatial anomaly identification model matching the target game match includes multiple isolated trees; The step of calling the spatial anomaly identification model that matches the target game match to process the game feature data of the target object, and obtaining the spatial anomaly factor of the target object, includes: Mapping is performed on every two behavioral feature values among multiple behavioral feature values to obtain multiple second mapped feature values, and the detection data is constructed based on the multiple second mapped feature values and the multiple behavioral feature values; Based on the data to be detected, traverse each of the multiple isolated trees to obtain the path length of the data to be detected in each isolated tree; Based on the path length of the data to be detected in each isolated tree, the spatial anomaly factor of the target object is determined.
5. The method according to any one of claims 2-4, characterized in that, The step of determining the airspace anomaly identification model that matches the target game match from the multiple airspace anomaly identification models, based on the game time information and the preset time period corresponding to each airspace anomaly identification model, includes: The target preset time period to which the game time information belongs is determined from the multiple preset time periods corresponding to the multiple airspace anomaly identification models; The spatial anomaly identification model corresponding to the target preset time period is determined as the spatial anomaly identification model that matches the target game match.
6. The method according to claim 1, characterized in that, The method further includes: Obtain game feature data of any sample object in multiple game sessions within a preset time period; Based on the preset duration and preset time interval, interpolation processing is performed on the game feature data of the multiple game matches to obtain the temporal feature data of any sample object within the preset duration. The time-series feature data is processed by an encoding / decoding neural network to obtain the first predicted feature data; The encoding and decoding neural network is trained based on the difference data between the first predicted feature data and the time-series feature data to obtain a time-domain anomaly recognition model.
7. The method according to claim 1, characterized in that, The temporal anomaly detection model includes a first encoding / decoding network and a second encoding / decoding network. The process of calling the temporal anomaly detection model to process the game feature data of the target object to obtain the temporal anomaly factor of the target object includes: The game feature data of the target object are processed by calling the first codec network and the second codec network respectively, to obtain the first transformed feature data output by the first codec network and the second transformed feature data output by the second codec network; The second codec network is invoked to process the first conversion feature data to obtain the third conversion feature data; Based on the second transformation feature data and the third transformation feature data, the second prediction feature data of the target object is determined; The difference between the game feature data and the second predicted feature data is determined as the temporal anomaly factor of the target object.
8. The method according to claim 1, characterized in that, The determination of the cheat detection result of the target object based on the spatial anomaly factor and the temporal anomaly factor includes: Based on the spatial anomaly factor, the spatial weight coefficient, the temporal anomaly factor, and the temporal weight coefficient, a joint anomaly factor is determined; When the joint anomaly factor meets the preset judgment condition, the detection result of the target object is determined to be that there is no cheat. When the joint anomaly factor does not meet the preset judgment condition, the detection result of the target object is determined to be that there is a cheat.
9. A data processing apparatus, characterized in that, The device includes: The acquisition unit is used to acquire game feature data of the target object in the target game match. The processing unit is used to call the spatial anomaly identification model to process the game feature data of the target object and obtain the spatial anomaly factor of the target object; wherein, the spatial anomaly identification model is constructed based on the statistical feature data of multiple sample objects in game matches within a preset time period; The processing unit is further configured to call a temporal anomaly identification model to process the game feature data of the target object and obtain the temporal anomaly factor of the target object; wherein, the temporal anomaly identification model is obtained by training an encoding and decoding neural network based on the temporal feature data of any sample object in a game within a preset time period. The processing unit is further configured to determine the external detection result of the target object based on the spatial anomaly factor and the temporal anomaly factor.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the data processing method as described in any one of claims 1-8.
11. A computer device, characterized in that, The computer device includes a memory, a communication interface, and a processor, wherein the memory, the communication interface, and the processor are interconnected; the memory stores a computer program, and the processor calls the computer program stored in the memory to implement the data processing method as described in any one of claims 1-8.
12. A computer program product, characterized in that, The computer program product includes a computer program or computer instructions, which, when executed by a processor, implement the data processing method as described in any one of claims 1-8.