Anti-cheating detection method and system based on AI

By using AI prediction model and historical data comparison methods in the game, an anti-cheating treatment solution for cheating behavior is generated, which solves the problems of misjudgment and misjudgment in the existing technology, and improves the accuracy and effectiveness of detection.

CN120204732AActive Publication Date: 2025-06-27HANGZHOU KAIKAI NETWORK TECH CO LTD

Patent Information

Application Number
CN202510532521.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-25
Publication Date
2025-06-27
Estimated Expiration
2045-04-25

AI Technical Summary

Technical Problem

The existing AI-based anti-cheating detection methods have problems of misjudgment and misjudgment, and cheaters can bypass detection by studying the rules and loopholes, resulting in the detection method gradually failing.

Method used

By entering the player behavior characteristics of the current game game into the cheat prediction model, predicting the cheating results, and comparing the historical game game data, an anti-cheating treatment plan is generated, including overlapping part plan sets and different part plan sets, and integrating them to generate the final anti-cheating treatment plan.

Benefits of technology

It improves the accuracy of cheating behavior detection, reduces misjudgment and misjudgment, can quickly respond to known cheating patterns, and identify new cheating behaviors through multi-dimensional analysis to ensure the effectiveness of cheating measures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120204732A_ABST
    Figure CN120204732A_ABST
Patent Text Reader

Abstract

The invention discloses an AI-based anti-cheating detection method and system, and relates to the technical field of anti-cheating detection, and the method comprises the following steps: inputting the behavior characteristics of a current game player into a cheating prediction model, and predicting to obtain a cheating prediction result; if the player behavior characteristics of the current game match are consistent with the player behavior characteristics of the cheating prediction result in the historical game match, generating and obtaining a first anti-cheating processing scheme; if the player behavior characteristics of the current game match are inconsistent with the player behavior characteristics of the cheating prediction result in the historical game match, comparing the player behavior characteristics of the current game match with the player behavior characteristics of the historical game match to obtain a distribution condition of similar behavior characteristics and differential behavior characteristics; processing and analyzing the distribution conditions of the similar behavior characteristics and the differential behavior characteristics to obtain first behavior distribution characteristics and second behavior distribution characteristics; the effect is that cheating behaviors can be identified more comprehensively and accurately.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of anti-cheating detection technology, and more specifically, to an AI-based anti-cheating detection method and system. Background Art

[0002] Against the backdrop of the booming digital entertainment industry, online games have become an important part of people's daily entertainment. From multiplayer online tactical competitive games to immersive massively multiplayer online role-playing games, various types of online games have attracted a large number of players to participate. However, with the prosperity of the game industry, the problem of game cheating has become increasingly prominent, becoming a key obstacle to the healthy development of the game ecosystem.

[0003] With the development of gaming technology, cheating in games has become diverse and constantly evolving. Some cheaters exploit game loopholes to modify game client data or server interaction data in order to illegally obtain resources and quickly increase levels. Players may exploit loopholes to obtain large amounts of game currency or rare items to disrupt the economic balance within the game, or achieve instant level increases through data tampering, disrupting the normal growth system of the game and seriously affecting the fair competition environment of the game and the gaming experience of other players.

[0004] At present, the gaming industry mainly uses a variety of anti-cheating technologies to deal with the problem of cheating. Common AI-based anti-cheating detection methods use pre-set rules to determine whether the player's behavior is illegal, such as setting the upper limit of the player's aiming speed, the lower limit of the skill release interval, and other rules. If the player's behavior exceeds the scope of these rules, it is judged as cheating. However, this method has limitations. On the one hand, it is difficult to formulate rules to cover all possible cheating behaviors and special situations in normal games, so it is easy to cause misjudgment. On the other hand, cheaters can bypass detection by studying rule loopholes and using more covert cheating methods, making rule-based detection methods gradually ineffective. Summary of the invention

[0005] In view of the deficiencies in the prior art, the purpose of the present invention is to provide an anti-cheating detection method and system based on AI.

[0006] To achieve the above object, the present invention provides the following technical solutions: The AI-based anti-cheating detection method comprises the following steps: Step S1: inputting the player behavior characteristics of the current game into the cheating prediction model to obtain a cheating prediction result; Step S2: If the player behavior characteristics of the current game match are consistent with the player behavior characteristics of the cheating prediction results in the historical game match, a first anti-cheating processing solution is generated; Step S3: If the player behavior characteristics of the current game session are inconsistent with those of the players with cheating prediction results in historical game sessions, compare the player behavior characteristics of the current game session and the historical game sessions to obtain the distribution of similar behavior characteristics and different behavior characteristics, and process and analyze the distribution of similar behavior characteristics and different behavior characteristics to obtain the first behavior distribution characteristics and the second behavior distribution characteristics; Step S4: Compare the anti-cheating solution sets corresponding to the cheating prediction results according to the first behavior distribution characteristics and the second behavior distribution characteristics to extract the overlapping part solution set and the different part solution set; Step S5: Analyze the change characteristics between the different part solution sets to screen and obtain the different part solution screening result set, and integrate the different part solution screening result set with the overlapping part solution set to obtain the second anti-cheating processing solution.

[0007] Preferably, step S1 specifically includes the following steps: Obtain the game mode information and time period information of the current game session, and count the historical cheating record information of all historical game sessions under the same conditions according to the game mode information and time period information; Obtain the distribution of the player behavior characteristics in the current game session, and screen out the historical game sessions with the same current behavior characteristic distribution from all historical game sessions; Statistically mark the characteristic information of each player behavior and its adjacent behavior in the historical game session as the first characteristic information set, and establish a cheating prediction model according to the first characteristic information set; Obtain the characteristic information of each player behavior and its adjacent behavior in the current game session and mark it as the second characteristic information set; Obtain the behavior characteristic information of the target player in the current game session, and input the second characteristic information set and the behavior characteristic information of the target player into the cheating prediction model to obtain the cheating prediction result.

[0008] Preferably, step S2 specifically includes the following steps: If the player behavior characteristics of the current game session are consistent with those of the players with cheating prediction results in historical game sessions, extract the anti-cheating processing solutions for the historical game sessions to deal with the cheating prediction results; Use the anti-cheating processing solution as the anti-cheating solution for the current game session for the cheating prediction result and mark it as the first anti-cheating processing solution.

[0009] Preferably, step S3 specifically includes the following steps: If the player behavior characteristics in the current game session are inconsistent with those of the players with cheating prediction results in historical game sessions, then the distribution of similar behavior characteristics and different behavior characteristics between the historical game sessions and the current game session is counted; If the similar behavior characteristics are adjacent and concentrated, and the different behavior characteristics are adjacent and concentrated, then the first behavior distribution feature is output; If the similar behavior characteristics and the different behavior characteristics are cross-adjacent to each other, then the second behavior distribution feature is output.

[0010] Preferably, step S4 specifically includes the following steps: Extract the behavior positions of the cheating suspect behaviors in the cheating prediction results in the historical game sessions and mark them as the first type of behavior position information set; Extract the behavior positions of the cheating suspect behaviors in the cheating prediction results in the first behavior distribution feature and mark them as the second type of behavior position information set; Extract the behavior positions of the cheating suspect behaviors in the cheating prediction results in the second behavior distribution feature and mark them as the third type of behavior position information set; Extract and process the corresponding first type of anti-cheating solution set, second type of anti-cheating solution set, and third type of anti-cheating solution set for the cheating prediction results according to the first type of behavior position information set, second type of behavior position information set, and third type of behavior position information set; Compare the first type of anti-cheating solution set, second type of anti-cheating solution set, and third type of anti-cheating solution set to extract the overlapping anti-cheating solutions and the different anti-cheating solutions. Combine all the overlapping anti-cheating solutions to form an overlapping solution set, and combine all the different anti-cheating solutions to form a different solution set.

[0011] Preferably, step S5 specifically includes the following steps: Statistically obtain the different main decision factor set according to the main influencing factors of the anti-cheating solution decision for the cheating prediction results in the different solution set; Process the distribution and development and change directions of each main decision factor in the different main decision factor set to obtain a different solution decision influence set; Obtain the historical anti-cheating solutions of the current game platform in the most recent period; Process the historical anti-cheating solutions and the historical different solution set corresponding to the corresponding behaviors of the different solution set to obtain a second proportion change amplitude data set; According to the second proportion change amplitude data set and the different solution decision influence set, screen out various different solution sets from the different solution set to obtain a different solution screening result set; Integrate the different solution screening result set and the overlapping solution set to obtain a second anti-cheating processing solution.

[0012] Preferably, the distributions and development and change directions of the main decision factors in the differential main decision factor set are processed to obtain a differential scheme decision influence set, which specifically includes the following steps: Calculate the change range of the distribution ratio of each main decision factor in the differential main decision factor set to obtain a first ratio change range data set; Evaluate the development and change directions of each main decision factor in the differential partial scheme set to obtain a differential scheme development and change information set; Evaluate the decision influence coefficient between the first ratio change range data set and the differential scheme development and change information set to obtain a differential scheme decision influence set.

[0013] Preferably, the historical anti-cheating scheme and the historical differential partial scheme set of the corresponding behavior where the differential partial scheme set is located are processed to obtain a second ratio change range data set, which specifically includes the following steps: Extract the historical differential partial scheme set of the corresponding behavior where the differential partial scheme set is located from the historical anti-cheating scheme; Extract the corresponding second ratio change range data set of each differential partial scheme in the historical differential partial scheme set.

[0014] An AI-based anti-cheating detection system includes: Prediction module: Input the player behavior characteristics of the current game session into the cheating prediction model to predict the cheating prediction result; Generation module: If the player behavior characteristics of the current game session are consistent with the player behavior characteristics of the game sessions with cheating prediction results in the historical game sessions, generate a first anti-cheating treatment scheme; Processing module: If the player behavior characteristics of the current game session are inconsistent with the player behavior characteristics of the game sessions with cheating prediction results in the historical game sessions, compare the player behavior characteristics of the current game session and the historical game sessions to obtain the distribution of similar behavior characteristics and differential behavior characteristics, and process and analyze the distribution of similar behavior characteristics and differential behavior characteristics to obtain a first behavior distribution characteristic and a second behavior distribution characteristic; Comparison module: Compare the anti-cheating scheme set corresponding to the cheating prediction result according to the first behavior distribution characteristic and the second behavior distribution characteristic to extract the overlapping partial scheme set and the differential partial scheme set; Integration module: Analyze the change characteristics between the differential partial schemes in the differential partial scheme set to screen and obtain a differential partial scheme screening result set, and integrate the differential partial scheme screening result set and the overlapping partial scheme set to obtain a second anti-cheating treatment scheme.

[0015] Compared with the prior art, the present invention has the following beneficial effects: This application predicts cheating results by inputting the behavioral characteristics of players in the current game match into a cheating prediction model. The model is built based on a large amount of historical game match data and can learn the subtle and complex feature differences between normal player behavior and cheating player behavior, greatly improving the accuracy of cheating behavior detection and reducing misjudgments and missed judgments. At the same time, it processes the distribution of similar and different behavioral characteristics between current and historical game matches, considers player behavior from multiple dimensions, and also considers factors such as game stage and resource acquisition, to avoid the one-sidedness of single-dimensional analysis and identify cheating behavior more comprehensively and accurately.

[0016] When the current game player behavior characteristics are consistent with the historical cheating behavior characteristics, the historical anti-cheating solution is directly extracted to generate the first anti-cheating solution. This can quickly take effective measures against known cheating patterns without having to re-explore response plans. For situations that are inconsistent with the historical cheating behavior characteristics, suitable solutions are screened from the difference part of the solution set and integrated with the overlapping part of the solution set to generate the second anti-cheating solution. Taking the newly emerging cheating behavior of players exploiting game loopholes to gain special advantages as an example, by analyzing its unique behavioral feature distribution, screening out blocking measures for the loophole and monitoring strategies for player behavior, etc., a solution specifically for the player's suspected cheating behavior is customized to ensure that anti-cheating measures are accurately adapted to different types of cheating situations.

[0017] This technical solution can promptly detect changes in the game environment and emerging cheating trends by continuously analyzing historical game data and historical anti-cheating solutions. The system can adjust the cheating prediction model and anti-cheating strategy based on the newly accumulated historical data and solutions, adapt to game changes, and always maintain the effectiveness of anti-cheating. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] Figure 1 A schematic diagram of the steps of the AI-based anti-cheating detection method proposed by the present invention; Figure 2 The present invention provides a module schematic diagram of an AI-based anti-cheating detection system. DETAILED DESCRIPTION

[0019] Reference Figures 1 to 2 .

[0020] Embodiment 1 further illustrates the AI-based anti-cheating detection method and system proposed in the present invention.

[0021] The AI-based anti-cheating detection method comprises the following steps: Step S1: inputting the player behavior characteristics of the current game into the cheating prediction model to obtain a cheating prediction result; Step S2: If the player behavior characteristics of the current game session are the same as those of the players with cheating prediction results in historical game sessions, then generate a first anti-cheat processing plan; Step S3: If the player behavior characteristics of the current game session are different from those of the players with cheating prediction results in historical game sessions, then compare the player behavior characteristics of the current game session and historical game sessions to obtain the distribution of similar behavior characteristics and different behavior characteristics, and process and analyze the distribution of similar behavior characteristics and different behavior characteristics to obtain a first behavior distribution characteristic and a second behavior distribution characteristic; Step S4: Compare the anti-cheat plan sets corresponding to the cheating prediction results according to the first behavior distribution characteristic and the second behavior distribution characteristic to extract the overlapping part plan set and the different part plan set; Step S5: Analyze the change characteristics between the different part plan sets to screen and obtain a screening result set of the different part plans, and integrate the screening result set of the different part plans with the overlapping part plan set to obtain a second anti-cheat processing plan.

[0022] Suppose there is a current multiplayer online competitive game with a 5v5 team battle mode and a time period from 8 pm to 10 pm. First, obtain the game mode information (5v5 team battle) and time period information (8 pm to 10 pm) of the current game session, and then count the historical cheating record information of all historical game sessions under the same game mode and time period conditions in the database. For example, it is found that in the past, in this time period and game mode, there were 100 games with cheating behavior records, and some players obtained unfair advantages through the use of external programs, such as automatic aiming, perspective, etc. Then, input the player behavior characteristics of the current game session into the cheating prediction model to obtain the cheating prediction result.

[0023] If it is found that the behavior characteristics of player A in the current game session are the same as those of the players with cheating prediction results in historical game sessions. For example, in the past, there were players who showed similar attack frequencies and skill release characteristics as player A through the use of automatic aiming cheats. Then, extract the anti-cheat processing plan for this cheating prediction result from the database. For example, previously, for players using automatic aiming cheats, the anti-cheat processing plan was to directly ban the account for 7 days and announce their cheating behavior in the game.

[0024] Take the extracted anti-cheat processing plan as the anti-cheat solution for the cheating prediction result of player A in the current game session, marked as the first anti-cheat processing plan, that is, also take measures to ban player A's account for 7 days and announce their cheating behavior in the game.

[0025] Assume that the behavioral characteristics of player B in the current game match are inconsistent with those of players with cheating prediction results in historical game matches. The behavioral characteristics of player B are manifested as cautious movement in the early stage of the game and high resource acquisition efficiency, but suddenly some radical operations that do not conform to their early style appear in the late stage of the game. The distribution of similar behavioral characteristics and different behavioral characteristics between historical game matches and the current game match is statistically analyzed. For example, it is found that there are also players in historical games with high resource acquisition efficiency in the early stage, but fewer radical operations in the late stage. In these historical games, the similar behavioral characteristic is resource acquisition in the early stage, and the different behavioral characteristic is radical operations in the late stage.

[0026] After determining the first behavioral distribution characteristics and the second behavioral distribution characteristics of player B, extract the anti-cheating solutions for the overlapping part and the anti-cheating solutions for the different part. Combine all the anti-cheating solutions for the overlapping part to form the overlapping part solution set, and combine all the anti-cheating solutions for the different part to form the different part solution set. Integrate the solution screening result set of the different part with the overlapping part solution set to obtain the second anti-cheating processing solution. For example, it is finally determined to give player B a warning in the game first, and at the same time restrict some of their game functions (such as restricting the purchase of certain powerful items), and continuously monitor their subsequent behaviors.

[0027] Step S1 specifically includes the following steps: Obtain the game mode information and time period information of the current game match, and statistically analyze the historical cheating record information of all historical game matches under the same conditions according to the game mode information and time period information; Obtain the distribution status of the behavioral characteristics of players in the current game match, and screen out the historical game matches with the same behavioral characteristic distribution status as the current one from all historical game matches; Statistically mark the characteristic information of each player's behavior and adjacent behavior in the historical game match as the first characteristic information set, and establish a cheating prediction model based on the first characteristic information set; Obtain the characteristic information of each player's behavior and adjacent behavior in the current game match and mark it as the second characteristic information set; Obtain the behavioral characteristic information of the target player in the current game match, and input the second characteristic information set and the behavioral characteristic information of the target player into the cheating prediction model to obtain the cheating prediction result.

[0028] First, obtain the game mode information (5v5 team battle) and time period information (8 pm - 10 pm) of the current game session. Then, count the historical cheating record information of all historical game sessions under the same game mode and time period conditions in the database. For example, it is found that in the past, in this time period and game mode, there were 100 game sessions with cheating behavior records, and some players obtained unfair advantages through the use of cheating programs, such as auto-aiming, wallhacking, etc.

[0029] Obtain the distribution of players' behavior characteristics in the current game session, such as the distribution of data such as players' movement speed, attack frequency, and skill release timing. Assume that in the current game session, player A's attack frequency is abnormally higher than the average level, and the skill release timing is also extremely precise. According to the distribution of these players' behavior characteristics, screen out historical game sessions from all historical game sessions that have the same distribution of behavior characteristics as the current one. For example, 10 historical game sessions are screened out, and in these sessions, there are also cases where players have a high attack frequency and precise skill releases.

[0030] Statistically mark the characteristic information of each player's behavior and adjacent behavior in the screened historical game sessions as the first characteristic information set. For example, record information such as the movement direction before the player attacks and the skill connection after the attack. Based on the first characteristic information set, establish a cheating prediction model, which can be a neural network model based on deep learning. Through learning a large amount of historical data, master the characteristic differences between the behaviors of normal players and cheating players.

[0031] Obtain the characteristic information of each player's behavior and adjacent behavior in the current game session and mark it as the second characteristic information set. Then, obtain the behavior characteristic information of the target player (such as player A) in the current game session, and input the second characteristic information set and the behavior characteristic information of the target player into the cheating prediction model. After the analysis and calculation of the model, obtain the cheating prediction result, and judge that player A has a high suspicion of cheating.

[0032] Step S2 specifically includes the following steps: If the behavior characteristics of the players in the current game session are consistent with the behavior characteristics of the players in the historical game session with cheating prediction results, then extract the anti-cheating treatment plan for the historical game session to deal with the cheating prediction result; Take the anti-cheating treatment plan as the anti-cheating solution for the current game session for the cheating prediction result and mark it as the first anti-cheating treatment plan.

[0033] Taking a game as an example, the game process monitoring system continuously collects its behavior data, such as skill release frequency, movement accuracy, resource acquisition efficiency, etc., to form the behavior characteristics of the players in the current game session.

[0034] During the operation of the game, a large amount of historical game match data has been accumulated, and the matches determined to have cheating behaviors have been detailedly recorded, including the behavioral characteristics of the cheating players and the anti-cheating treatment plans adopted for such cheating behaviors.

[0035] When the current game ends, the system compares the behavioral characteristics of the game match with the behavioral characteristics of the players with cheating prediction results in the historical database. Suppose in the historical database, player C was determined to have cheated by using an auto-aiming external cheat. His behavioral characteristics were extremely high skill hit rates, being able to accurately hit key enemy heroes in complex team battles, and his movement positions could always skillfully avoid enemy skills. And in this game, player D also showed extremely high skill hit rates. In team battles, his skill releases on the enemy's core heroes were almost always accurate, and his movement positions were also extremely precise, hardly ever being hit by enemy skills. After the system's determination, the behavioral characteristics of player D in the current game match are consistent with the behavioral characteristics of player C with cheating prediction results in the historical game matches.

[0036] At this time, the system extracts the anti-cheating treatment plan for player C's cheating behavior from the historical records. At that time, the measure taken by the game official against player D was to ban the account for 14 days and announce his cheating behavior throughout the server in the game. The system extracts this anti-cheating treatment plan as the anti-cheating solution for the cheating prediction result of player C in the current game match and marks it as the first anti-cheating treatment plan.

[0037] Step S3 specifically includes the following steps: If the behavioral characteristics of the current game match are inconsistent with the behavioral characteristics of the players with cheating prediction results in the historical game matches, then count the distribution of similar behavioral characteristics and different behavioral characteristics between the historical game matches and the current game match; If the similar behavioral characteristics are adjacent and concentrated and the different behavioral characteristics are adjacent and concentrated, then output the first behavioral distribution characteristic; If the similar behavioral characteristics and the different behavioral characteristics are cross-adjacent to each other, then output the second behavioral distribution characteristic.

[0038] Player B participated in a game battle competition. During the game process, continuously collect player B's behavioral data, including shooting frequency, aiming speed, movement trajectory, material pickup preferences and other behavioral characteristics.

[0039] The database stores a large amount of historical game match data. Among them, some players in the historical game matches were determined to have cheating behaviors, and there are corresponding records of relevant cheating behavioral characteristics. The system compares the behavioral characteristics of player B in the current game match with the behavioral characteristics of the players with cheating prediction results in the historical game matches and finds that the behavioral characteristics of player B are not consistent with these historical cheating behavioral characteristics.

[0040] Next, the system begins to count the distribution of similar behavioral characteristics and different behavioral characteristics between historical game matches and the current game match (this match participated by Player B). For example, in historical game matches, normal players usually move cautiously in the early stage of the game and prioritize searching for basic supplies to ensure their survival ability. Player B also moves cautiously in the early stage of the game and focuses on collecting basic supplies such as weapons and ammunition. This is a similar behavioral characteristic.

[0041] In historical game matches, when normal players enter the final circle, they will choose the right time to transfer and ambush according to the location of the safe zone and the distribution of the remaining enemies. After Player B enters the final circle, his movement route and decision-making method are very unique. He does not follow common strategies and always takes risks to directly attack possible hiding places of the enemies. This unique behavior is a different behavioral characteristic.

[0042] The first line distribution characteristic: If the similar behavioral characteristics of Player B (such as cautiously collecting supplies in the early stage) appear concentrated within a period of time in the early stage of the game, and adjacent behaviors are all centered around collecting supplies; the different behavioral characteristics (such as unique movement decisions in the final circle) also appear concentrated in this specific stage of the final circle, and adjacent behaviors are all related unique decisions. That is, similar behavioral characteristics are adjacent and concentrated, and different behavioral characteristics are adjacent and concentrated. At this time, the system outputs the first line distribution characteristic.

[0043] The second line distribution characteristic: If during the game process of Player B, similar behavioral characteristics (such as collecting supplies) and different behavioral characteristics (such as unique movement decisions) are cross-adjacent. For example, during the process of collecting supplies, several unique adventurous movements are suddenly interspersed to test the enemy's position, and then continue to collect supplies, and so on. In this case where similar behavioral characteristics and different behavioral characteristics are cross-adjacent together, the system outputs the second line distribution characteristic.

[0044] Step S4 specifically includes the following steps: Extract the behavioral positions of cheating-suspected behaviors in the historical game matches in the cheating prediction results and mark them as the first type of behavioral position information set; Extract the behavioral positions of cheating-suspected behaviors in the first line distribution characteristic in the cheating prediction results and mark them as the second type of behavioral position information set; Extract the behavioral positions of cheating-suspected behaviors in the second line distribution characteristic in the cheating prediction results and mark them as the third type of behavioral position information set; Extract and process the corresponding first type of anti-cheating solution set, second type of anti-cheating solution set, and third type of anti-cheating solution set for the cheating prediction results according to the first type of behavioral position information set, the second type of behavioral position information set, and the third type of behavioral position information set; Compare the first type of anti-cheating solution set, the second type of anti-cheating solution set, and the third type of anti-cheating solution set to extract the overlapping anti-cheating solutions and the different anti-cheating solutions. Combine all the overlapping anti-cheating solutions to form an overlapping solution set, and combine all the different anti-cheating solutions to form a different solution set.

[0045] The system searches for the positions of behaviors similar to Player B's suspected cheating behavior in the historical game match data. For example, when the game reaches 20 minutes, Player B suddenly shows an extremely high hit rate of shooting through walls, presumably using a wallhack cheating function. The system searches for similar wallhack shooting cheating behaviors in the historical cheating game match data and finds that such cheating behaviors mostly occur in the 15 - 25 minute time period of the historical matches and are concentrated in certain specific map areas, such as "Abandoned Factory" and "Old City". Mark this behavior position information as the first type of behavior position information set.

[0046] Based on the first behavior distribution feature of Player B, the system extracts the behavior positions of his suspected cheating behavior in this feature. Assume that in the first behavior distribution feature of Player B, the suspected cheating behavior is mainly concentrated in the resource competition stage in the middle of the game, and there are frequently abnormal accurate shootings near specific resource points. The system marks this behavior position information, such as the specific resource point name, the time range of this stage, etc., as the second type of behavior position information set.

[0047] For the second behavior distribution feature of Player B, the system finds the behavior positions of the suspected cheating behavior. For example, in the second behavior distribution feature of Player B, his suspected cheating behavior is characterized by being interspersed in the normal process of collecting supplies and moving, and there are abnormal aiming and shooting behaviors randomly appearing in different map areas. The system records information such as the map coordinates where these behaviors occur and the approximate time points, and marks it as the third type of behavior position information set.

[0048] Based on the first type of behavior position information set, that is, the position information of similar cheating behaviors in the historical game matches, the system extracts the anti-cheating solutions for this type of cheating behavior and position in history. For example, in history, for the wallhack shooting cheating behavior that occurs in "Abandoned Factory" and "Old City" at a specific time period, the solutions taken include real-time monitoring of the behavior of players in this area and temporary restriction operations on suspected cheating players (such as reducing the movement speed, restricting weapon use, etc.). These solutions form the first type of anti-cheating solution set.

[0049] According to the second type of behavior position information set, extract the anti-cheating solutions for the positions of Player B's suspected cheating behavior in the first behavior distribution feature. For example, for the abnormal accurate shooting behavior near specific resource points in the middle of the game, the anti-cheating solutions include increasing the vision monitoring in this area and warning prompts for players who frequently show abnormal behaviors in this area. These solutions constitute the second type of anti-cheating solution set.

[0050] According to the third type of behavior location information set, extract the anti-cheating solutions for the cheating-suspected behavior locations of the corresponding player B in the second behavior distribution characteristics. For example, for the abnormal aiming and shooting behaviors that randomly occur during the process of material collection and transfer, the solutions adopted are to dynamically adjust the monitoring parameters, conduct behavioral trajectory tracking and analysis on suspicious players, etc. These solutions form the third type of anti-cheating solution set.

[0051] It is found that some solutions appear in all three types of solution sets. For example, analyzing the behavioral data records of suspected cheating players. These overlapping anti-cheating solutions are combined together to form the overlapping part solution set.

[0052] At the same time, there are also solutions that appear in one or two types of solution sets (such as the temporary restriction of operations on specific areas unique to the first type of solution set). These anti-cheating solutions in the different parts are combined into the different part solution set.

[0053] Step S5 specifically includes the following steps: Statistically obtain the different main decision factor set based on the main influencing factors of the anti-cheating solution decision for the cheating prediction result according to the different part solution set; Process the distribution and development trend of each main decision factor in the different main decision factor set to obtain the different solution decision influence set; Obtain the historical anti-cheating solutions of the current game platform in the most recent period; Process the historical anti-cheating solutions and the historical different part solution set of the corresponding behavior where the different part solution set is located to obtain the second proportion change range data set; According to the second proportion change range data set and the different solution decision influence set, screen out various different part solutions from the different part solution set to obtain the different part solution screening result set; Integrate the different part solution screening result set with the overlapping part solution set to obtain the second anti-cheating solution.

[0054] Statistically analyze the main influencing factors of the anti-cheating solution decision for the cheating prediction result according to the different part solution set. For example, in the different part solution set of player B, the main influencing factors include the economic situation in the game (such as having a large amount of in-game currency to purchase special items), the game character level (too high a level may unlock special abilities), and the game time (cheating behaviors are more frequent at certain specific time points), etc. Organize these main influencing factors to obtain the different main decision factor set.

[0055] Calculate the change range of the distribution ratio of each main decision factor in the different main decision factor set to obtain the first proportion change range data set. For example, it is found that the change range of the proportion of the amount of in-game currency obtained by player B in the early stage of the game to the total amount obtained is relatively large, that is, there is an obvious difference from the data of normal players.

[0056] Evaluate the development and change directions of each main decision factor in the difference part of the solution set to obtain the difference solution development and change information set. For example, it is observed that the level-up speed of player B's in-game character suddenly accelerates in the mid-game, and the frequency and types of using in-game currency to purchase items also change abnormally.

[0057] Evaluate the decision influence coefficient between the first ratio change amplitude data set and the difference solution development and change information set to obtain the difference solution decision influence set. By comprehensively analyzing these data, determine which factors have a greater impact on player B's suspected cheating behavior and how these factors interact to affect the anti-cheat solution decision.

[0058] Obtain the historical anti-cheat solutions of the current game platform in the recent period. For example, in the past month, the game platform has taken measures such as temporarily banning accounts and restricting in-game transactions for similar suspected cheating behaviors.

[0059] Extract the historical difference part solution set corresponding to the corresponding behavior of the difference part solution set from the historical anti-cheat solutions. For example, search for anti-cheat solutions for dealing with abnormal behaviors of similar players in the game economic system and character level in the past. Then, extract the corresponding second ratio change amplitude data set for each difference part solution in the historical difference part solution set. For example, the change amplitude of relevant data (such as the proportion of in-game currency held by players, the proportion of character level-up speed, etc.) before and after the implementation of different anti-cheat measures when dealing with similar situations in history.

[0060] According to the second ratio change amplitude data set and the difference solution decision influence set, screen out various difference part solutions from the difference part solution set. For example, if it is found that the measure of restricting in-game transactions was effective in dealing with similar player economic anomalies in history, and it is also judged from the difference solution decision influence set that the game economic factor has a greater impact on player B's suspected cheating behavior, then the solution of restricting in-game transactions will be screened out to obtain the difference part solution screening result set.

[0061] Integrate the difference part solution screening result set with the overlapping part solution set. Suppose there is a measure of real-time monitoring of player behavior in the overlapping part solution set, and there is a measure of restricting in-game transactions for player B in the difference part solution screening result set. Integrate these two measures to form the second anti-cheat solution for player B, that is, conduct real-time behavior monitoring on player B and at the same time restrict his in-game trading behavior.

[0062] Process the distribution and development and change directions of each main decision factor in the difference main decision factor set to obtain the difference solution decision influence set, which specifically includes the following steps: Calculate the change range of the distribution ratio of each main decision factor in the main decision factor set of differences to obtain the first ratio change range data set; Evaluate the development and change directions of each main decision factor in the difference part of the solution set to obtain the difference solution development and change information set; Evaluate the decision influence coefficient between the first ratio change range data set and the difference solution development and change information set to obtain the difference solution decision influence set.

[0063] In this game, normal players are in the resource collection and cautious development stage in the first 20 minutes of the game, and the game time accounts for about 30%-40% of the total game time. However, player B actively participates in battles within the first 20 minutes, and the battle frequency is much higher than that of normal players. The proportion of his game time spent on battles reaches 60%. In the later stage of the game, the proportion of the battle time of normal players will increase to 60%-70%, while the proportion of the battle time of player B drops to 40% at this time. Through calculation, it can be obtained that the change range of the proportion of player B's game time spent on battles relative to the normal range is 20%-30% in the early stage and -20%--30% in the later stage. These data constitute part of the game time factor in the first ratio change range data set.

[0064] Under normal circumstances, the resource acquisition volume of normal players accounts for 50%-60% of the total acquisition volume in the mid-early stage of the game. The proportion of the resource acquisition volume of player B in the mid-early stage is as high as 80%, and the proportion in the later stage drops significantly to 20%. From this calculation, the change range of the proportion of player B's resource acquisition volume relative to the normal range is 20%-30% in the mid-early stage and -30%--40% in the later stage, becoming the relevant data of the resource acquisition volume factor in the first ratio change range data set.

[0065] The kill efficiency of normal players is relatively low in the early stage of the game, and the number of kills accounts for about 10%-20% of the total number of kills. The proportion of the number of kills of player B in the early stage of the game reaches 40%, 40% in the mid-stage, and 20% in the later stage. After calculation, the change range of the proportion of player B's kill efficiency in the early stage relative to the normal range is 20%-30%, the change range in the mid-stage is relatively stable, and the change range in the later stage is -10%--20%. Summarize the change range data of these kill efficiency factors to obtain the complete first ratio change range data set.

[0066] Player B's use of game time decreases from aggressive combat in the early stage to less combat in the later stage. This change reflects that their game strategy may not be the gradual development of a normal player. Instead, they take advantage of some unknown advantages in the early stage to quickly establish an advantage and then adjust their strategy in the later stage. The system records this changing trend of game time allocation from aggressive to conservative and its impact on their game behavior at different stages, such as accumulating a large amount of advantageous resources due to frequent combat in the early stage, etc., forming the content about the game time factor in the development change information set of different scenarios.

[0067] Player B's resource acquisition in the early stage is significantly higher than the normal level and drops sharply in the later stage. This changing process may imply that they obtain resources through improper means in the early stage, and the resource acquisition channels are blocked or they no longer need a large amount of resources in the later stage. The impact of this high-low resource acquisition change on Player B's subsequent game behavior, such as using the large amount of resources obtained in the early stage to gain a combat advantage in the middle stage, etc., obtains the relevant information about the resource acquisition volume factor in the development change information set of different scenarios.

[0068] Player B's kill efficiency is extremely high in the early stage, maintains a certain level in the middle stage, and decreases in the later stage. This may indicate that they used some cheating means to improve their killing ability in the early stage, adjusted their strategy due to changes in the game situation in the middle stage but still had a certain advantage, and the advantage gradually weakened in the later stage. The system evaluates this phased change in kill efficiency and the possible reasons behind it and its impact on the game process, which constitutes part of the kill efficiency factor in the development change information set of different scenarios. Combining the evaluation results of various factors forms a complete development change information set of different scenarios.

[0069] Perform a correlation analysis between the first proportion change dataset and the development change information set of different scenarios. It is found that Player B's extensive use of game time for combat in the early stage is strongly correlated with a high resource acquisition volume and high kill efficiency, probably by using cheating means to quickly obtain resources in the early stage and using the advantage to fight. After evaluation, the influence coefficient of the game time factor on the decision-making of their cheating suspicion behavior is 0.4, the influence coefficient of the resource acquisition volume factor is 0.3, and the influence coefficient of the kill efficiency factor is 0.3. Integrate these factors and their influence coefficients to obtain the decision-making influence set of different scenarios.

[0070] Process the historical anti-cheating plan and the historical difference part plan set corresponding to the corresponding behavior of the difference part plan set to obtain the second proportion change dataset, which specifically includes the following steps: Extract from the historical anti-cheating plan the historical difference part plan set corresponding to the corresponding behavior of the difference part plan set; Extract the corresponding second proportion change dataset for each difference part plan in the historical difference part plan set.

[0071] The game operator has saved a large number of historical anti-cheat solutions. First, extract the historical differential part solution sets corresponding to the corresponding behaviors of the differential part solution sets different from Player B from these historical anti-cheat solutions. Suppose the differential part solution set of Player B involves behaviors such as unusually rapid character level improvement, a large amount of unusual in-game currency acquisition, and frequently completing high-difficulty tasks in a short period of time. Then, the system will search for records related to these behaviors in the historical anti-cheat solutions. For example, it is found that in a certain period in the past, other players have also shown similar situations of unusually rapid character level improvement. The anti-cheat solutions taken at that time included restricting the experience acquisition rate of the player and closely monitoring their leveling behavior; for the behavior of obtaining a large amount of unusual in-game currency, measures such as freezing the in-game currency assets and investigating the transaction records have been implemented; for the situation of frequently completing high-difficulty tasks in a short period of time, means such as suspending the access permission to the task system and verifying the task completion path have been taken. Organize these historical anti-cheat solutions for similar behaviors to form the historical differential part solution set corresponding to the differential part solution set of Player B.

[0072] After obtaining the historical differential part solution set, further extract the corresponding second proportion change amplitude data sets for each differential part solution. For the solution of restricting the experience acquisition rate, statistically analyze the change in the proportion of the character level improvement amount of the involved player in the total level improvement amount before and after the implementation of this solution. Suppose that before the implementation of the restriction, the proportion of the character level improvement amount of this player in the total level improvement amount within a week was 80%. After the implementation of the restriction, this proportion dropped to 20%. Calculate the change amplitude of the proportion of the level improvement amount as -60%. Record this change amplitude data for different time periods (such as daily, weekly) to form a part of the second proportion change amplitude data set for the solution of restricting the experience acquisition rate.

[0073] For the solution of freezing in-game currency assets and investigating transaction records, analyze the change in the proportion of the player's in-game currency holdings in the total in-game currency amount before and after the implementation. For example, before the implementation, the proportion of the player's in-game currency holdings was 10%. After the implementation of the freezing and investigation measures, the proportion dropped to 1%. Calculate the change amplitude of the proportion of the in-game currency holdings as -9%. Similarly, record the change amplitudes at different time nodes to construct the content of the second proportion change amplitude data set corresponding to this solution.

[0074] Regarding the solution of suspending the access permission to the task system and verifying the task completion path, statistically analyze the change in the proportion of the number of high-difficulty tasks completed by the player in the total number of tasks completed before and after the implementation. If the proportion of the number of high-difficulty tasks completed by this player before the implementation was 50%, and it dropped to 10% after the implementation, the change amplitude of the task completion proportion is obtained as -40%. And so on, extract and organize the proportion change amplitude data of the relevant data before and after the implementation of each historical differential part solution, and finally obtain the complete second proportion change amplitude data set.

[0075] Embodiment 2. An anti-cheating detection system based on AI includes: Prediction module: Input the player behavior characteristics of the current game session into the cheating prediction model to obtain the cheating prediction result; Generation module: If the player behavior characteristics of the current game session are consistent with the player behavior characteristics of the players with cheating prediction results in the historical game sessions, generate the first anti-cheating treatment plan; Processing module: If the player behavior characteristics of the current game session are inconsistent with the player behavior characteristics of the players with cheating prediction results in the historical game sessions, compare the player behavior characteristics of the current game session and the historical game sessions to obtain the distribution of similar behavior characteristics and different behavior characteristics, and process and analyze the distribution of similar behavior characteristics and different behavior characteristics to obtain the first behavior distribution characteristic and the second behavior distribution characteristic; Comparison module: Compare the anti-cheating plan set corresponding to the cheating prediction result according to the first behavior distribution characteristic and the second behavior distribution characteristic to extract the overlapping part plan set and the different part plan set; Integration module: Analyze the change characteristics between the different part plans in the different part plan set to screen and obtain the different part plan screening result set, and integrate the different part plan screening result set with the overlapping part plan set to obtain the second anti-cheating treatment plan.

[0076] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0077] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. The AI-based anti-cheating detection method is characterized by: The method comprises the following steps: Step S1: inputting the player behavior characteristics of the current game into the cheating prediction model to obtain a cheating prediction result; Step S2: If the player behavior characteristics of the current game match are consistent with the player behavior characteristics of the cheating prediction results in the historical game match, a first anti-cheating processing solution is generated; Step S3: if the player behavior characteristics of the current game match are inconsistent with the player behavior characteristics of the cheating prediction results in the historical game match, the player behavior characteristics of the current game match are compared with the player behavior characteristics of the historical game match to obtain the distribution of similar behavior characteristics and different behavior characteristics, and the distribution of the similar behavior characteristics and the different behavior characteristics is processed and analyzed to obtain a first behavior distribution characteristic and a second behavior distribution characteristic; Step S4: comparing the anti-cheating solution sets corresponding to the cheating prediction results according to the first behavior distribution feature and the second behavior distribution feature to extract overlapping solution sets and different solution sets; Step S5: Analyze the variation characteristics between the different partial solutions on the difference partial solution set to obtain the difference partial solution screening result set, and integrate the difference partial solution screening result set with the overlap partial solution set to obtain the second anti-cheating processing solution.

2. The AI-based anti-cheating detection method according to claim 1, characterized in that: Step S1 specifically includes the following steps: Statistically marking feature information of each player's behavior and adjacent behaviors in historical game matches as a first feature information set, and establishing a cheating prediction model based on the first feature information set; Obtain feature information of each player's behavior and adjacent behaviors in the current game and mark them as a second feature information set; Behavior feature information of a target player in a current game match is obtained, and the second feature information set and the behavior feature information of the target player are input into a cheating prediction model to obtain a cheating prediction result.

3. The AI-based anti-cheating detection method according to claim 1, characterized in that: Step S2 specifically includes the following steps: If the player behavior characteristics of the current game match are consistent with the player behavior characteristics of the cheating prediction results in the historical game match, then the anti-cheating processing solution for the cheating prediction results of the historical game match is extracted; The anti-cheating solution is used as the anti-cheating solution for the cheating prediction results in the current game and is marked as the first anti-cheating solution.

4. The AI-based anti-cheating detection method according to claim 1, characterized in that: Step S3 specifically includes the following steps: If the player behavior characteristics of the current game match are inconsistent with the player behavior characteristics of the cheating prediction results in the historical game match, the distribution of similar behavior characteristics and different behavior characteristics between the historical game match and the current game match is counted; If similar behavior features are adjacent and concentrated, and if different behavior features are adjacent and concentrated, then the first behavior distribution feature is output; If the similar behavior features and the different behavior features are intersected and adjacent to each other, the second behavior distribution feature is output.

5. The AI-based anti-cheating detection method according to claim 1, characterized in that: Step S4 specifically includes the following steps: Extract the behavior positions of suspected cheating behaviors in the cheating prediction results in the historical game matches and mark them as the first type of behavior position information set; Extract the suspected cheating behavior in the cheating prediction result at the behavior position of the first behavior distribution feature and mark it as the second type of behavior position information set; Extract the suspected cheating behavior in the cheating prediction result at the behavior position of the second behavior distribution feature and mark it as the third type of behavior position information set; Extracting, according to the first type of behavior location information set, the second type of behavior location information set, and the third type of behavior location information set, the first type of anti-cheating solution set, the second type of anti-cheating solution set, and the third type of anti-cheating solution set corresponding to the cheating prediction results; The first anti-cheating solution set, the second anti-cheating solution set and the third anti-cheating solution set are compared to extract the anti-cheating solutions of the overlapping part and the anti-cheating solutions of the different part, and all the anti-cheating solutions of the overlapping part are combined to form an overlapping part solution set, and all the anti-cheating solutions of the different parts are combined to form a different part solution set.

6. The AI-based anti-cheating detection method according to claim 5, characterized in that: Step S5 specifically includes the following steps: According to the difference partial solution set, the main influencing factors of the anti-cheating solution decision of the cheating prediction result are statistically analyzed to obtain the difference main decision factor set; The distribution and development change direction of each main decision factor in the difference main decision factor set are processed to obtain the difference plan decision influence set; Get the most recent historical anti-cheating solution for the current game platform; The historical anti-cheating schemes and the historical difference partial scheme sets of the corresponding behaviors where the difference partial scheme sets are located are processed to obtain a second percentage variation data set; According to the second proportion variation data set and the difference scheme decision influence set, various types of difference partial schemes are screened out from the difference partial scheme set to obtain a difference partial scheme screening result set; The second anti-cheating processing solution is obtained by integrating the screening result set of the difference part solutions with the overlapping part solution set.

7. The AI-based anti-cheating detection method according to claim 6, characterized in that: The distribution and development change direction of each main decision factor in the difference main decision factor set are processed to obtain the difference plan decision influence set, which specifically includes the following steps: Calculate the variation range of the distribution proportion of each main decision factor in the difference main decision factor set to obtain a first proportion variation data set; Evaluate the development and change direction of each main decision factor in the difference partial solution set to obtain the difference solution development and change information set; The decision influence coefficient between the first proportion value variation data set and the difference scheme development change information set is evaluated to obtain the difference scheme decision influence set.

8. The AI-based anti-cheating detection method according to claim 6, characterized in that: The historical anti-cheating schemes and the historical difference partial scheme sets of the corresponding behaviors where the difference partial scheme sets are located are processed to obtain a second percentage variation data set, specifically including the following steps: Extracting the historical difference partial solution set corresponding to the behavior where the difference partial solution set is located from the historical anti-cheating solutions; The second proportion variation data set corresponding to each difference partial scheme in the historical difference partial scheme set is extracted.

9. An AI-based anti-cheating detection system, applied to the AI-based anti-cheating detection method according to any one of claims 1 to 8, characterized in that: include: Prediction module: inputs the player behavior characteristics of the current game into the cheating prediction model to obtain the cheating prediction result; Generation module: if the player behavior characteristics of the current game match are consistent with the player behavior characteristics of the cheating prediction results in the historical game match, a first anti-cheating solution is generated; Processing module: if the player behavior characteristics of the current game match are inconsistent with the player behavior characteristics of the cheating prediction results in the historical game match, the player behavior characteristics of the current game match and the historical game match are compared to obtain the distribution of similar behavior characteristics and different behavior characteristics, and the distribution of the similar behavior characteristics and the different behavior characteristics is processed and analyzed to obtain a first behavior distribution characteristic and a second behavior distribution characteristic; Comparison module: compares the anti-cheating solution set corresponding to the cheating prediction result according to the first behavior distribution feature and the second behavior distribution feature to extract the overlapping solution set and the different solution set; Integration module: Analyze the change characteristics between the different partial solutions in the difference partial solution set to obtain the difference partial solution screening result set, and integrate the difference partial solution screening result set with the overlapping partial solution set to obtain the second anti-cheating processing solution.

Citation Information

Patent Citations

  • Abnormal operation behavior detection method, device and equipment and storage medium

    CN111558226A

  • Machine-learned trust scoring for player matchmaking

    CN112805076A

  • Safety monitoring method and system based on virtual game

    CN118079403A

  • Cheating detection method and device based on H5 game

    CN119499667A

  • Methods, Devices, and Systems for Countering Cheats in Games

    US20230256346A1

Cited By

  • Game vulnerability automatic detection method and system based on AI

    CN121902158A