Behavior monitoring and recognition method for preventing game cheating

By generating prediction ranges and combining player IP and operating habit analysis, the problem of inability to effectively judge plug-ins or proxy players in the existing technology is solved, the accuracy and fairness of game monitoring are improved, and the player's gaming experience is improved.

CN120361548AActive Publication Date: 2025-07-25BEIJING JINGXI INTERACTIVE ENTERTAINMENT TECHNOLOGY CO LTD

Patent Information

Application Number
CN202510508683.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-22
Publication Date
2025-07-25
Estimated Expiration
2045-04-22

AI Technical Summary

Technical Problem

The existing behavior monitoring and identification methods to prevent game cheating cannot effectively determine whether players have plug-ins or agents, resulting in damage to the fairness of the game and the inability to generate an estimated model based on player historical operations, resulting in inaccurate monitoring.

Method used

By obtaining the player's current and historical operation data, generating prediction ranges and combining player IP and operation habit analysis, we can determine whether the player has plug-ins or agents, including training models, IP analysis and operation habit similarity judgment.

Benefits of technology

It reduces monitoring inaccuracy during game monitoring, improves game fairness and the gaming experience of normal players.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120361548A_ABST
    Figure CN120361548A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of game monitoring and recognition, and discloses a behavior monitoring and recognition method for preventing game cheating, which comprises the following steps of: acquiring operation data of a user, and judging whether the user operation is abnormal or not, according to the behavior monitoring and recognition method for preventing game cheating, generating an estimated model according to the historical operation condition of a player, the method comprises the following steps of: judging an ability range which a player can approximately reach in each stage, so as to judge whether the player has the possibility of cheating such as plug-in or substitution according to the change condition of the game promotion speed of the player within a certain time; in combination with the condition of the account logged in the game by the current game IP of the player and the condition of the current game operation habit of the player, whether the player cheats such as plug-in or substitute playing is judged, so that the condition of inaccurate monitoring in the game monitoring process is reduced, the fairness of the game is prevented from being damaged, and the user experience is improved. And the game experience of players playing games normally is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of game monitoring and identification, and in particular to a behavior monitoring and identification method for preventing game cheating. Background Art

[0002] Behavior monitoring and identification methods to prevent cheating in games cover multiple fields such as computer science, network security, artificial intelligence, statistics, and game development, and can effectively deal with increasingly complex cheating behaviors. Although existing behavior monitoring and identification methods to prevent cheating in games have made certain progress, there are still many shortcomings in practical applications, such as the limitations of client-based detection, the challenges of server-based detection, detection of specific cheating types, the limitations of universality, and legal and ethical issues. The development of anti-cheating technology often lags behind cheating technology. When new cheating methods appear, the anti-cheating system needs time to analyze, learn, and develop corresponding countermeasures, which means that there will always be a "vacuum period" during which cheaters can use this time to cheat. Cheaters are also constantly learning the strategies of the anti-cheating system and taking corresponding countermeasures, such as using more covert cheating tools, modifying cheating behavior patterns, etc., which forms a continuous "cat and mouse game";

[0003] Existing behavior monitoring and identification methods for preventing game cheating cannot judge whether a player has the possibility of cheating by using plug-ins or proxy playing according to the changes in the player's game promotion speed within a certain period of time. It cannot generate an estimated model based on the player's historical operation of the game to judge the approximate ability range that the player can achieve at each stage with his or her own operation habits and operation data, and thus judge whether the player has the possibility of cheating by using plug-ins or proxy playing according to the player's current operation situation. When the player's game promotion speed within a certain period of time exceeds the maximum value estimated by the model to a certain extent, it is impossible to combine the player's current game IP with the account logged in in the game and whether the player's current game operation habits are similar to those of other players in the game to judge whether the player has cheated by using plug-ins or proxy playing. Inaccurate monitoring is likely to occur during the game monitoring process, thereby destroying the fairness of the game and causing psychological harm to normal players. Its practicality has certain limitations. Summary of the invention

[0004] The present invention provides a behavior monitoring and identification method for preventing game cheating, which is used to promote the solution of the problems mentioned in the background technology.

[0005] The present invention provides the following technical solution: a behavior monitoring and identification method for preventing game cheating, comprising:

[0006] Get the current operation data of the target user, recorded as E current ;

[0007] Obtain all historical operation data of the target user and generate a historical data set;

[0008] Extract the time difference between each element in the historical data set and its previous adjacent element, define it as the interval difference, denoted as a = {a1, a2,..., a n};

[0009] Calculate the average value of the interval differences, define it as the average difference, denoted as

[0010]

[0011] Obtain the time difference between the current operation data and the last element in the historical data set, define it as the analysis difference, denoted as b;

[0012] If then continuously obtain the operation data of the target user;

[0013] If then obtain the training model;

[0014] Through the training model, according to the average difference, make T predictions to obtain T predicted values, denoted as :

[0015]

[0016] where t = {1, 2,..., T};

[0017] Set a mean function to calculate the mean of the predicted values, denoted as μ:

[0018]

[0019] Set a variance function to calculate the variance of the predicted values, denoted as:

[0020]

[0021] Generate a prediction range for each prediction, denoted as [E min , E max :

[0022] E min = μ - k × σ;

[0023] E max = μ + k × σ;

[0024] where k is a coefficient determined according to the confidence level;

[0025] According to the analysis difference, extract the prediction range of the current operation data, denoted as [E min_c , Emax_c ;

[0026] If E current ≥ E max_c ·(1 + 15%), continuously obtain the operation data of the target user;

[0027] If E current <E max_c ·(1 + 15%), perform operation analysis on the user.

[0028] As an alternative solution of the method for behavior monitoring and recognition to prevent game cheating according to the present invention, wherein: the obtaining of the training model is specifically:

[0029] S1. Set an initial data model, designated as the initial model, denoted as M, and its parameters as θ;

[0030] Randomly initialize the model parameters, denoted as θ0;

[0031] S2. Obtain all feature vectors X in the historical dataset h ;

[0032] For each feature vector X h According to its chronological order in the historical dataset, successively use it as the analysis feature vector;

[0033] For each sample in the analysis feature vector, successively identify it as the analysis feature sample, denoted as xi i ;

[0034] S1. Calculate the predicted output of the model, denoted as :

[0035]

[0036] Wherein, θ nt Represents the model parameters of the nt-th iteration;

[0037] S3. Extract the true value of the analysis feature sample, denoted as p i ;

[0038] S4. Generate a loss function according to the predicted output and the true value, denoted as

[0039] S5. Calculate the gradient of the loss function with respect to the model parameters, denoted as

[0040] S6. Set an optimization function to update the model parameters:

[0041]

[0042] Among them, η is the learning rate, which controls the step size of each update;

[0043] S7. Set the iteration threshold, denoted as nt_t;

[0044] Repeat steps S1 - S6 until nt > nt_t, then stop.

[0045] As an alternative solution of the method for monitoring and identifying behaviors to prevent game cheating according to the present invention, wherein: the analysis of the user's operations includes the analysis of the user's address, specifically:

[0046] Obtain the current game IP of the user, denoted as IP current ;

[0047] Obtain all the historical game IPs of the user to form a historical IP set, denoted as IP history ;

[0048] Set an account threshold, denoted as IP threshold ;

[0049] Judge whether the user's current IP is normal through the matching function Match_IP(·):

[0050]

[0051] If Match_IP(IP current ) = True, it is determined that the user's current IP is normal;

[0052] If Match_IP(IP current ) = False, it is determined that the user's current IP is suspicious, and perform suspicious IP analysis.

[0053] As an alternative solution of the method for monitoring and identifying behaviors to prevent game cheating according to the present invention, wherein: the suspicious IP analysis is specifically:

[0054] Query the database of the target game;

[0055] Obtain all the accounts used by the current game IP IP current in the target game to form an account set, denoted as A IP ;

[0056] Calculate the size of the account set, denoted as |A IP |;

[0057] Set an account matching function Match_account(·) to judge whether the user's current IP is abnormal:

[0058]

[0059] If Match_account(|A IP |) = True, it is determined that the user's current IP is normal;

[0060] If Match_account(|A IP |) = False, it is determined that the user's current IP is abnormal.

[0061] As an alternative solution to the method for monitoring and identifying behaviors to prevent game cheating according to the present invention, wherein: the analysis of the user's operations further includes the analysis of the user's habits, specifically:

[0062] For each historical login time in the historical dataset, all operations at each historical login time are respectively obtained to form a historical operation sequence, denoted as O h ={o h1 , o h2 ,..., o hn};

[0063] wherein each o hi represents an operation of the player at the historical login time;

[0064] Obtain all operations of the target user at the current login time to form a current operation sequence, denoted as O c ={o c1 , o c2 ,..., o cn};

[0065] wherein each o ci represents an operation of the player at the current login time;

[0066] Set a similarity threshold, denoted as T consistent ;

[0067] For each operation o hi and o ci , respectively extract the feature vectors, denoted as ch h and ch c ;

[0068] Through the comprehensive similarity function, calculate the comprehensive similarity between the current operation sequence O c at the current login time and the historical operation sequence O h , denoted as P consistent :

[0069]

[0070] wherein g is the number of operations in the current operation sequence O c , c is the index of the c-th operation in the current operation sequence O c , mh axsimilarity(ch h ,ch c ) represents the similarity of the c-th operation ch for the current login time c in the historical operation sequence O h to the most similar operation ch h , where h is the operation index in the historical operation sequence O h , and the value range is from 1 to the number of historical operations;

[0071] In the comprehensive similarity function, similarity(ch h ,ch c ) is the similarity between each current operation and the historical operation, and the specific formula is:

[0072]

[0073] where ||ch h || represents the modulus length of the vector ch h , reflecting the size of the vector ch h , ||ch c || represents the modulus length of the vector ch c , reflecting the size of the vector ch c ;

[0074] Set a habit matching function to determine whether the user's current operation is normal:

[0075]

[0076] Obtain the number of times when Match_operate(P consistent ) = True, which is defined as the consistent number and denoted as N consistent ;

[0077] Obtain the number of historical login times in the historical dataset, which is defined as the collection number and denoted as N gather ;

[0078] If then it is determined that the user's current operation is normal;

[0079] If then it is determined that the user's current operation is suspicious, and the suspicious operation analysis is performed.

[0080] As an alternative solution to the behavior monitoring and recognition method for preventing game cheating described in the present invention, where: the suspicious operation analysis is specifically:

[0081] Obtain the current operation sequence O of the target user c ;

[0082] Query the database of the target game;

[0083] Obtain the operation sequences of all users in the target game to form a set of user operation sequences, denoted as U = {U1, U2,..., U k};

[0084] Set a similarity threshold, denoted as T common ;

[0085] Obtain the feature vector ch ci for each operation o c ;

[0086] For each operation u k in the user operation sequence U k,i , extract the feature vector, denoted as ch k,i ;

[0087] Set a sequence similarity function to calculate the similarity between the current operation sequence O c and each user operation sequence U k :

[0088] P common = similarity(O c , U k );

[0089]

[0090] where dtw(l Oc , l Uk ) is the DTW distance between O c and U k , used to measure the similarity of two time series, l Oc is the length of O c , and l Uk is the length of U k ;

[0091] Set an operation matching function to determine whether the user's current operation is abnormal:

[0092]

[0093] Set a user threshold, denoted as User threshold ;

[0094] Obtain the number of Match_user(P common ) = True, defined as the similarity count, denoted as User similar ;

[0095] If User similar < User threshold, it is determined that the user's game operation is normal;

[0096] If User similar ≥ User threshold , it is determined that the user's game operation is abnormal.

[0097] As an alternative solution of the method for monitoring and identifying behaviors to prevent game cheating according to the present invention, wherein: the analysis of the user's operations further includes comprehensive data analysis, specifically:

[0098] If it is determined that the user's game operation is abnormal and it is determined that the user's current IP is abnormal, it is determined that the data of the user's current game operation is abnormal, and the user's account is subject to a violation treatment;

[0099] If it is determined that the user's game operation is normal or it is determined that the user's current IP is normal, it is determined that the data of the user's current game operation is normal, and then the operation data of the target user can be continuously obtained.

[0100] As an alternative solution of the method for monitoring and identifying behaviors to prevent game cheating according to the present invention, wherein: the obtaining of all historical operation data of the target user to generate a historical data set is specifically:

[0101] Obtain all historical login times of the target user in the target game to form a historical time set, denoted as H = {H1, H2,..., H m};

[0102] wherein, m is the number of logins;

[0103] Obtain the historical operation data of the target user at each historical login time to form a historical operation set, denoted as H h_s = {h h1 , h h2 ,..., h hi};

[0104] wherein, hi is the number of samples;

[0105] Through the sample determination function Ab(·), for each sample h h_s in the historical operation set H hj at each historical login time, determine whether it is an outlier:

[0106]

[0107] wherein, Ab1 is abnormal, Ab0 is normal, and L and U are respectively the lower and upper limits of the set normal sample values;

[0108] For the historical operation set H h_s at each historical login time, remove the historical operation set H h_sFor all the outliers in it, the resulting set is defined as the net set, denoted as H clean_h ;

[0109] Through the error determination function, for each net set H of the historical login times clean_h and for each sample h hj in it, determine whether it is incorrect data:

[0110]

[0111] where Wr1 is incorrect data, Wr0 is correct data, Lo is too many missing values, and Fo is incorrect format;

[0112] For each net set H of the historical login times clean_h , remove all the incorrect data in this net set H clean_h , and the resulting set is defined as the cleaned set, denoted as H h_s ', where the number of samples is i';

[0113] For each cleaned set H of the historical login times h_s ', extract the key features from the cleaned set H h_s ' to obtain the feature vector, denoted as X h = {x1, x2,..., x hm};

[0114] where hm is the number of features;

[0115] Integrate the historical time set, each cleaned set H of the historical login times h_s ' and the corresponding feature vector X of each cleaned set H h_s ' to form the historical data set. h As an alternative solution of the method for monitoring and identifying behaviors to prevent game cheating described in the present invention, wherein: the obtaining of the current operation data of the target user is specifically:

[0116] Obtain the current login time of the target user in the target game, denoted as H

[0117] ; c ;

[0118] Obtain the current operation data of the target user at the current login time to form the current operation set, denoted as H c_s = {h c1 , h c2 ,..., h ci};

[0119] where ci is the number of samples;

[0120] Through the sample determination function Ab(·), for each sample h in the current operation set H at the current login time c_s judge whether it is an outlier: cj

[0121]

[0122] where Ab1 means abnormal, Ab0 means normal, and L and U are respectively the lower and upper limits of the set normal sample values;

[0123] For the current operation set H at the current login time c_s remove all outliers in the current operation set H c_s The resulting set is defined as the net set, denoted as H clean_c ;

[0124] Through the error determination function Wr(·), for each sample h in the net set H at the current login time clean_c judge whether it is error data: cj

[0125]

[0126] where Wr1 means error data, Wr0 means correct data, Lo means too many missing values, and Fo means incorrect format;

[0127] For the net set H at the current login time clean_c remove all error data in the net set H clean_c The resulting set is defined as the cleaned set, denoted as H c_s ', where the number of samples is i';

[0128] For the cleaned set H at the current login time c_s ', extract key features from the cleaned set H c_s ' to obtain a feature vector, denoted as X c ={x1, x2,..., x cm};

[0129] where cm is the number of features;

[0130] Integrate the current login time, the cleaned set H at the current login time c_s ' and the feature vector X corresponding to the cleaned set H c_s ' to form the current data set. c

[0131] The present invention has the following beneficial effects:

[0132] ​​​1. The method for monitoring and identifying behavior to prevent game cheating generates an estimated model by obtaining the historical operation situation of players in this game, and judges the approximate range of capabilities that players can reach at each stage according to their own operation habits and operation data. Thus, based on the current operation situation of players, it judges whether the current promotion speed and game operation situation of players exceed the maximum value of the estimated range to a certain extent, and further judges whether there is a possibility of cheating such as using external software or having a proxy play the game. If the current promotion speed and game operation situation of players are within a certain threshold of the maximum value of the estimated range, it indicates that the players are promoted and operate normally. Otherwise, it indicates that there are abnormalities in the promotion speed and operation of the players, reducing the inaccurate monitoring situation during the game monitoring process, avoiding damaging the fairness of the game, and enhancing the gaming experience of normal players.

[0133] 2. The method for monitoring and identifying behavior to prevent game cheating, when the game promotion speed of a player exceeds the maximum value estimated by the model to a certain extent within a certain period of time, obtains whether there is a coincidence between the player's current game IP and the player's historical IP. If there is a coincidence, it indicates that the player operates normally. If there is no coincidence, it traverses the game database to judge whether the current IP has logged in to a relatively large number of game accounts. If the number of accounts logged in by the current IP is within the threshold, it indicates that the current IP is normal. If the number of accounts logged in by the current IP exceeds the threshold, it indicates that the current IP is abnormal, reducing the inaccurate monitoring situation during the game monitoring process, avoiding damaging the fairness of the game, and enhancing the gaming experience of normal players.

[0134] 3. The method for monitoring and identifying behavior to prevent game cheating, when the game promotion speed of a player exceeds the maximum value estimated by the model to a certain extent within a certain period of time, obtains the similarity between the player's current game operation habits and the player's historical operation habits. If the similarity is high, it indicates that the player operates normally. If the similarity is low, it traverses the game database to judge whether there is a similar situation between the current operation habits and the operation habits of other players in the game. If there is no similar situation between the current operation habits and the operation habits of other players in the game, it indicates that the player's current operation is normal. If there is a similar situation between the current operation habits and the operation habits of other players in the game, it indicates that the player's current operation is abnormal. Combining with the player's current IP, if the player's current IP and the current operation do not both show abnormalities, it is considered that the player operates the game normally. If both the player's current IP and the current operation show abnormalities, it indicates whether there is a situation of cheating such as using external software or having a proxy play the game, reducing the inaccurate monitoring situation during the game monitoring process, avoiding damaging the fairness of the game, and enhancing the gaming experience of normal players. Description of the Drawings

[0135] Figure 1Flowchart of the method for monitoring and identifying behaviors to prevent game cheating in the present invention. Specific implementation mode

[0136] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0137] Embodiment 1, a method for monitoring and identifying behaviors to prevent game cheating, refer to Figure 1 , including:

[0138] Obtain the current operation data of the target user, denoted as E current ;

[0139] Obtain all the historical operation data of the target user and generate a historical data set;

[0140] Extract the time difference between each element in the historical data set and its previous adjacent element, defined as the interval difference, denoted as a = {a1, a2,..., a n};

[0141] Calculate the average value of the interval differences, defined as the average difference, denoted as

[0142]

[0143] Obtain the time difference between the current operation data and the last element in the historical data set, defined as the analysis difference, denoted as b;

[0144] If then continuously obtain the operation data of the target user. That is, the user may have a situation of not playing the game for a long time. In this case, the game difficulty may be adjusted down accordingly, allowing the user to upgrade quickly and enhancing the user's game experience. At this time, the data is inaccurate, and it is only necessary to continuously obtain the operation data of the target user;

[0145] If then obtain the training model;

[0146] Through the training model, according to the average difference, make T predictions to obtain T predicted values, denoted as :

[0147]

[0148] where t = {1, 2,..., T};

[0149] Set a mean function to calculate the mean of the predicted values, denoted as μ:

[0150]

[0151] Set a variance function to calculate the variance of the predicted values, denoted as:

[0152]

[0153] Generate a prediction range for each prediction, denoted as [E min , E max :

[0154] E min = μ - k × σ;

[0155] E max = μ + k × σ;

[0156] where k is a coefficient determined according to the confidence level;

[0157] Extract the prediction range of the current operation data according to the analysis difference, denoted as

[0158] If E current ≥ E max_c · (1 + 15%), continuously obtain the operation data of the target user, indicating that the similarity between the current operation data of the user and the estimated operation data is relatively high, and it can be considered that the user is operating himself;

[0159] If E current < E max_c · (1 + 15%), perform operation analysis on the user, indicating that the similarity between the current operation data of the user and the estimated operation data is relatively low, and it can be considered that there are abnormalities in the user's game operations, and further analysis needs to be combined with other data.

[0160] Among them, the obtaining of the training model is specifically:

[0161] S1. Set an initial data model, defined as the initial model, denoted as M, and its parameters are θ;

[0162] Randomly initialize the model parameters, denoted as θ0;

[0163] S2. Obtain all feature vectors X h ;

[0164] Take each feature vector X h as the analysis feature vector in turn according to its time sequence in the historical dataset;

[0165] Take each sample in the analysis feature vector as the analysis feature sample in turn, denoted as xii ;

[0166] S1. Calculate the predicted output of the computational model, denoted as :

[0167]

[0168] where θ nt represents the model parameters at the nt-th iteration;

[0169] S3. Extract the true value of the analysis feature sample, denoted as p i ;

[0170] S4. Generate a loss function based on the predicted output and the true value, denoted as

[0171] S5. Calculate the gradient of the loss function with respect to the model parameters, denoted as

[0172] The gradient represents the partial derivative of the loss function L with respect to each model parameter θ j , specifically:

[0173]

[0174] S6. Set an optimization function to update the model parameters:

[0175]

[0176] where η is the learning rate, controlling the step size of each update;

[0177] S7. Set an iteration threshold, denoted as nt_t, and the iteration threshold is 8;

[0178] Repeat steps S1 - S6 until nt > nt_t and then stop.

[0179] Through the above method, according to the change of the player's game promotion speed within a certain period of time, it is judged whether there is a possibility of cheating such as using external aids or having someone else play on behalf of the player. Based on the player's historical operation situation in this game, an estimated model is generated to judge the approximate ability range that the player can reach at each stage with their own operation habits and operation data. Thus, according to the player's current operation situation, it is judged whether there is a possibility of cheating such as using external aids or having someone else play on behalf of the player. When the player's game promotion speed within a certain period of time exceeds the maximum value estimated by the model to a certain extent, combined with the situation of the accounts logged in by the player's current game IP in the game and whether the player's current game operation habits are similar to those of other players in the game, it is judged whether there is a situation of cheating such as using external aids or having someone else play on behalf of the player, reducing the inaccurate monitoring situation during the game monitoring process, avoiding damaging the fairness of the game, and enhancing the game experience of normal players.

[0180] Embodiment 2. This embodiment is an improvement made on the basis of Embodiment 1. For the method for monitoring and identifying the behavior of preventing game cheating, the operation analysis of the user includes user address analysis, specifically:

[0181] Obtain the user's current game IP, denoted as IP current ;

[0182] Obtain all the historical game IPs of the user to form a historical IP set, denoted as IP history ;

[0183] Set an account threshold, denoted as IP threshold , and the account threshold is 3;

[0184] Use the matching function Match_IP(·) to judge whether the user's current IP is normal:

[0185]

[0186] If Match_IP(IP current ) = True, it is determined that the user's current IP is normal;

[0187] If Match_IP(IP current ) = False, it is determined that the user's current IP is suspicious, and perform suspicious IP analysis.

[0188] Among them, the suspicious IP analysis is specifically:

[0189] Query the database of the target game;

[0190] Obtain all the accounts used by the current game IP IP current in the target game to form an account set, denoted as A IP ;

[0191] Calculate the size of the account set, denoted as |A IP |;

[0192] Set up an account matching function Match_account(·) to determine whether the user's current IP is abnormal:

[0193]

[0194] If Match_account(|A IP |) = True, it is determined that the user's current IP is normal;

[0195] If Match_account(|A IP |) = False, it is determined that the user's current IP is abnormal.

[0196] This embodiment also provides that the operation analysis of the user further includes user habit analysis, specifically:

[0197] For each historical login time in the historical dataset, obtain all the operations at each historical login time to form a historical operation sequence, denoted as O h = {o h1 , o h2 ,..., o hn};

[0198] Among them, each o hi represents an operation of the player at the historical login time;

[0199] Obtain all the operations of the target user at the current login time to form a current operation sequence, denoted as O c = {o c1 , o c2 ,..., o cn};

[0200] Among them, each o ci represents an operation of the player at the current login time;

[0201] Set a similarity threshold, denoted as T consistent , and the similarity threshold T consistent is a threshold set according to the difficulty level of the game, such as 0.8;

[0202] For each operation o hi and o ci , extract the feature vectors, denoted as ch h and ch c , where the features include operation type, operation time interval, and operation order, etc.;

[0203] Calculate the current operation sequence O at the current login time through the comprehensive similarity function c and the historical operation sequence O h The comprehensive similarity is denoted as P consistent :

[0204]

[0205] where g is the number of operations in the current operation sequence O c and c is the index of the c-th operation in the current operation sequence O c The similarity of the c-th operation ch h axsimilarity(ch h and ch c ) represents the similarity of the c-th operation ch c at the current login time to the most similar operation ch h found in the historical operation sequence O h where h is the operation index in the historical operation sequence O h and its value range is from 1 to the number of historical operations;

[0206] In the comprehensive similarity function, similarity(ch h and ch c ) is the similarity between each current operation and the historical operation, and the specific formula is:

[0207]

[0208] where ||ch h || represents the modulus of the vector ch h reflecting the magnitude of the vector ch h ||ch c || represents the modulus of the vector ch c reflecting the magnitude of the vector ch c ;

[0209] The formula for calculating the modulus of the vector ch h is:

[0210] The formula for calculating the modulus of the vector ch c is:

[0211] Set a habit matching function to determine whether the user's current operation is normal:

[0212]

[0213] Obtain Match_operate(P consistent) The number of those equal to True is defined as the consistent number and denoted as N consistent ;

[0214] Obtain the number of historical login times in the historical dataset, which is defined as the collection number and denoted as N gather ;

[0215] If then it is determined that the user's current operation is normal;

[0216] If then it is determined that the user's current operation is suspicious, and perform suspicious operation analysis.

[0217] Among them, the said suspicious operation analysis is specifically:

[0218] Obtain the current operation sequence O of the target user c ;

[0219] Query the database of the target game;

[0220] Obtain the operation sequences of all users in the target game to form a set of user operation sequences, denoted as U = {U1, U2,..., U k};

[0221] Set a similarity threshold, denoted as T common , and the similarity threshold T common is a threshold set according to the difficulty level of the game, such as 0.8;

[0222] Obtain the feature vector ch of each operation o ci ; c ;

[0223] For each operation u in each user operation sequence U k , extract the feature vector, denoted as ch k,i , among which the features include operation type, operation time interval, and operation order, etc.; k,i

[0224] Set a sequence similarity function to calculate the similarity between the current operation sequence O c and each user operation sequence U k :

[0225] P common = similarity(O c , U k );

[0226]

[0227] Among them, dtw(l Oc , l Uk ) is O cand U k The DTW distance between them is used to measure the similarity of two time series. l Oc is the length of O c ; l Uk is the length of U k ;

[0228] Set an operation matching function to determine whether the user's current operation is abnormal:

[0229]

[0230] Set the user threshold, denoted as User threshold , and the user threshold is 2;

[0231] Obtain the number of times when Match_user(P common ) = True, which is defined as the similarity number, denoted as User similar ;

[0232] If User similar < User threshold , it is determined that the user's game operation is normal;

[0233] If User similar ≥ User threshold , it is determined that the user's game operation is abnormal.

[0234] This embodiment also provides that the operation analysis of the user further includes comprehensive data analysis, specifically:

[0235] If it is determined that the user's game operation is abnormal and the user's current IP is abnormal, it is determined that the user's game operation data for this time is abnormal, and the user's account is subject to a violation handling, that is, there is a possibility of game cheating in the user's game this time, and the user's account is punished in the form of being deactivated for a period of time, etc.;

[0236] If it is determined that the user's game operation is normal or the user's current IP is normal, it is determined that the user's game operation data for this time is normal, and then the operation data of the target user can be continuously obtained.

[0237] Embodiment 3, this embodiment is an improvement made on the basis of Embodiment 2. In this embodiment, the obtaining of all historical operation data of the target user to generate a historical data set is specifically:

[0238] Obtain all historical login times of the target user in the target game to form a historical time set, denoted as H = {H1, H2,..., H m};

[0239] where m is the number of logins;

[0240] Obtain the historical operation data of the target user at each historical login time, form a historical operation set, denoted as H h_s ={h h1 , h h2 ,..., h hi}, and the historical operation data includes operation frequency, operation sequence, operation reaction time, skill usage success rate, task completion time, score situation, etc.;

[0241] where hi is the number of samples;

[0242] Through the sample determination function Ab(·), for each historical operation set H at each historical login time h_s in each sample h hj , determine whether it is an outlier:

[0243]

[0244] where Ab1 is abnormal, Ab0 is normal, L and U are respectively the lower and upper limits of the set normal sample values, and are the determination conditions for outliers set based on statistical methods or domain knowledge;

[0245] For each historical operation set H at each historical login time h_s , remove all outliers in this historical operation set H h_s , and define the obtained set as the net set, denoted as H clean_h ;

[0246] Through the error determination function, for each sample h in the net set H at each historical login time clean_h in hj , determine whether it is error data:

[0247]

[0248] where Wr1 is error data, Wr0 is correct data, Lo is too many missing values, and Fo is incorrect format;

[0249] For each net set H at each historical login time clean_h , remove all error data in this net set H clean_h , and define the obtained set as the cleaned set, denoted as H h_s ', where the number of samples is i';

[0250] For each cleaned set H at each historical login time h_s ', extract key features from the cleaned set H h_s ' to obtain a feature vector, denoted as X h ={x1, x2,..., x hm};

[0251] Among them, hm is the number of features;

[0252] The key features include basic operation features, game behavior features, game progress features, operation mode features, game resource features, network features, and habitual features, etc.;

[0253] Among them, the basic operation features include operation frequency, operation reaction time, and operation intensity change. The game behavior features include skill usage success rate, task completion time, and score efficiency. The game progress features include level promotion speed and game stage duration. The operation mode features include operation sequence mode and skill combination usage frequency. The game resource features include resource acquisition efficiency and resource consumption mode. The network features include game IP address and IP address usage frequency. The habitual features include game time period preference and operation habit consistency;

[0254] The operation frequency is the number of operations of the player per unit time, such as the number of clicks per second, key press frequency, etc., specifically:

[0255] The operation reaction time is the average response time of the player to game events, such as the time from the event occurrence to the player's reaction, specifically:

[0256] Among them, ti i is the reaction time for each time, and l is the number of events;

[0257] The operation intensity change is the change situation of the player's operation intensity (such as key press force, touch screen operation intensity), and is measured by statistically calculating the standard deviation or range of the operation intensity;

[0258] The skill usage success rate is the ratio of the player's successful execution of skill operations, specifically:

[0259] The task completion time is the time spent by the player to complete a specific game task, specifically: T co = t end - t start ;

[0260] The score efficiency is the score obtained by the player per unit time, specifically:

[0261] The level promotion speed is the speed at which the player promotes to a new level, specifically:

[0262] The game stage duration is the average time the player stays in each game stage, specifically:

[0263] Among them, di i is the duration of each stage, and st is the number of stages;

[0264] The operation sequence pattern is the sequence and combination pattern of the player's operations, which is converted into numerical features through sequence analysis or one-hot encoding to analyze and judge the player's operation habits;

[0265] The usage frequency of the skill combination is the frequency of the player using a specific skill combination, specifically:

[0266] The resource acquisition efficiency is the efficiency of the player acquiring in-game resources (such as gold coins, items), specifically:

[0267] The resource consumption pattern is the pattern and frequency of the player consuming in-game resources, which is measured by statistically analyzing the distribution and frequency of resource consumption;

[0268] The game IP address is the IP address when the player plays the game, which is used to detect whether the player plays the game at multiple different IP addresses;

[0269] The usage frequency of the IP address is the frequency of each IP address being used, specifically:;

[0270] The game time period preference is the game time period preferred by the player, which is determined by statistically analyzing the game duration of the player at different time periods;

[0271] The consistency of the operation habit is the consistency between the player's operation habit and the historical operation, which is measured by comparing the similarity between the current operation characteristics and the historical characteristics;

[0272] Integrate the historical time set, the cleaned set H of each historical login time h_s ' and the feature vector X corresponding to each cleaned set H h_s ' to form a historical data set. h

[0273] This embodiment also provides that the current operation data of the target user is specifically:

[0274] Obtain the current login time of the target user in the target game, denoted as H c ;

[0275] Obtain the current operation data of the target user at the current login time to form a current operation set, denoted as H c_s ={h c1 , h c2 ,..., hci}, where the current operation data includes operation frequency, operation sequence, operation reaction time, skill usage success rate, task completion time, and score, etc.;

[0276] Among them, ci is the number of samples;

[0277] Through the sample determination function Ab(·), for the current operation set H at the current login time c_s in each sample h cj , determine whether it is an outlier:

[0278]

[0279] Among them, Ab1 is abnormal, Ab0 is normal, L and U are respectively the lower and upper limits of the set normal sample values, and are the determination conditions for outliers set based on statistical methods or domain knowledge;

[0280] For the current operation set H at the current login time c_s , remove all outliers in this current operation set H c_s , and define the resulting set as the net set, denoted as H clean_c ;

[0281] Through the error determination function Wr(·), for each sample h in the net set H at the current login time clean_c in cj , determine whether it is error data:

[0282]

[0283] Among them, Wr1 is error data, Wr0 is correct data, Lo is too many missing values, and Fo is incorrect format;

[0284] For the net set H at the current login time clean_c , remove all error data in this net set H clean_c , and define the resulting set as the cleaned set, denoted as H c_s ', where the number of samples is i';

[0285] For the cleaned set H at the current login time c_s ', extract key features from the cleaned set H c_s ' to obtain a feature vector, denoted as X c = {x1, x2,..., x cm};

[0286] Among them, cm is the number of features;

[0287] Integrate the current login time, the cleaned set H at the current login time c_s' and the cleaning set H c_s ' the corresponding feature vector X c , to form the current data set.

[0288] In this embodiment, according to the change of the player's game promotion speed within a certain period of time, it is judged whether there is a possibility of cheating such as using cheats or having a substitute player. According to the player's historical operation situation of this game, a predicted model is generated to judge the approximate ability range that the player can reach at each stage with his own operation habits and operation data. Thus, according to the player's current operation situation, it is judged whether there is a possibility of cheating such as using cheats or having a substitute player. When the player's game promotion speed within a certain period of time exceeds the maximum value predicted by the model to a certain extent, combined with the situation of the accounts logged in by the player's current game IP in the game and whether there is a similar situation with other players in the game according to the player's current game operation habits, it is judged whether there is a situation of cheating such as using cheats or having a substitute player, reducing the inaccurate monitoring situation in the process of game monitoring, avoiding damaging the fairness of the game, and improving the game experience of normal players who play the game.

Claims

1. A method for behavior monitoring and recognition to prevent game cheating, characterized in that: Including: Obtain the current operation data of the target user, denoted as E current ; Obtain all historical operation data of the target user to generate a historical data set; Extract the time difference between each element in the historical dataset and its previous adjacent element, which is defined as the interval difference and denoted as a = {a1, a2,..., a n}; Calculate the average value of the interval differences, which is defined as the average difference and denoted as Obtain the time difference between the current operation data and the last element in the historical data set, defined as the analysis difference and denoted as b; If continuously obtain the operation data of the target user; If then obtain the training model; By training the model, T predictions are made based on the mean difference, and T predicted values are obtained, denoted as where t = {1, 2,..., T}; Set a mean function to calculate the mean of the predicted value, denoted as μ: Set a variance function to calculate the variance of the predicted value, denoted as: Generate a prediction range for each prediction, denoted as [E min , E max : E min = μ - k × σ; E max = μ + k × σ; where k is a coefficient determined according to the confidence level; Extract the prediction range of the current operation data according to the analysis difference, denoted as If E current ≥ E max_c · (1 + 15%), continuously obtain the operation data of the target user; If E current <E max_c ·(1 + 15%), then perform operation analysis on the user.

2. The method for behavior monitoring and recognition of preventing game cheating according to claim 1, characterized in that: The obtaining of the training model is specifically as follows: S1. Set an initial data model, defined as the initial model and denoted as M, with its parameters being θ; Randomly initialize the model parameters, denoted as θ0; S2. Obtain all feature vectors X in the historical dataset h ; Take each feature vector X h in turn as the analysis feature vector according to its chronological order in the historical dataset; Each sample in the analysis feature vector is sequentially identified as an analysis feature sample, denoted as xi i ; S1. Calculate the predicted output of the computational model, denoted as where, θ nt represents the model parameters at the nt-th iteration; S3. Extract the true value of the analysis feature sample and denote it as p i ; S4. Generate a loss function based on the predicted output and the true value, denoted as S5. Calculate the gradient of the loss function with respect to the model parameters, denoted as S6. Set an optimization function to update the model parameters: where η is the learning rate, controlling the step size of each update; S7. Set an iteration threshold, denoted as nt_t; Repeat steps S1 - S6 until nt > nt_t and then stop.

3. The method for behavior monitoring and recognition of preventing game cheating according to claim 1, characterized in that: The operation analysis of the user includes user address analysis, specifically: Obtain the current game IP of the user, denoted as IP current ; Obtain all the historical game IPs of the user to form a historical IP set, denoted as IP history ; Set the account threshold, denoted as IP threshold ; Judge whether the current IP of the user is normal through the matching function Match_IP(·); If Match_IP(IP current ) = True, it is determined that the user's current IP is normal; If Match_IP(IP current ) = False, it is determined that the user's current IP is suspicious, and the suspicious IP analysis is executed.

4. The behavior monitoring and recognition method for preventing game cheating according to claim 3, characterized in that: The analysis of the suspected IP is specifically: Query the database of the target game; Get the current game IP current All the accounts used in the target game form an account set, denoted as A IP ; Calculate the size of the account set, denoted as |A IP |; Set an account matching function Match_account(·) to judge whether the current IP of the user is abnormal; If Match_account(|A IP |) = True, it is determined that the user's current IP is normal; If Match_account(|A IP |) = False, it is determined that the user's current IP is abnormal.

5. The method for behavior monitoring and recognition of preventing game cheating according to claim 3, characterized in that: The operation analysis of the user also includes user habit analysis, specifically: For each historical login time in the historical dataset, all operations at each historical login time are respectively obtained to form a historical operation sequence, denoted as O h ={o h1 , o h2 ,..., o hn}; Among them, each o hi represents an operation of the player at the historical login time; Obtain all the operations of the target user at the current login time to form the current operation sequence, denoted as O c ={o c1 , o c2 ,..., o cn}; Among them, each o ci represents an operation of the player at the current login time; Set the similarity threshold, denoted as T consistent ; For each operation o hi and o ci respectively extract the feature vectors, denoted as ch h and ch c ; Calculate the comprehensive similarity between the current operation sequence O at the current login time and the historical operation sequence O through the comprehensive similarity function, denoted as P c and the historical operation sequence O h with the comprehensive similarity denoted as P consistent : where g is the number of operations in the current operation sequence O c and c is the index of the c-th operation in the current operation sequence O c , indicating the similarity of the c-th operation ch for the current login time c to the operation ch h that is most similar to it in the historical operation sequence O h , where h is the operation index in the historical operation sequence O h and the value range is from 1 to the number of historical operations; In the comprehensive similarity function, similarity(ch h , ch c ) is the similarity between each current operation and historical operations, and the specific formula is as follows: Among them, ||ch h || represents the modulus length of the vector ch h , reflecting the magnitude of the vector ch h ; ||ch c || represents the modulus length of the vector ch c , reflecting the magnitude of the vector ch c ; Set a habit matching function to judge whether the current operation of the user is normal; Obtain the quantity of Match_operate(P consistent ) = True, define it as the consistent quantity, and denote it as N consistent ; Obtain the number of historical login times in the historical dataset, which is defined as the collection quantity and denoted as N gather ; If it is determined that the user's current operation is normal; If it is determined that the user's current operation is suspicious, perform a suspicious operation analysis.

6. The behavior monitoring and recognition method for preventing game cheating according to claim 5, characterized in that: The analysis of the suspected operation is specifically: Obtain the current operation sequence O of the target user c ; Query the database of the target game; Obtain the operation sequences of all users in the target game to form a set of user operation sequences, denoted as U = {U1, U2,..., U k}; Set the similarity threshold, denoted as T common ; Obtain the feature vector ch of each operation o ci ; c ; For each user operation sequence U k for the operation u k,i in it, extract the feature vector, denoted as ch k,i ; Set a sequence similarity function to calculate the current operation sequence O c and each user operation sequence U k for similarity: P common = similarity(O c , U k ); Among them, dtw(l Oc , l Uk ) is the DTW distance between O c and U k , which is used to measure the similarity between two time series. l Oc is the length of O c , and l Uk is the length of U k ; Set an operation matching function to judge whether the current operation of the user is abnormal; Set the user threshold, denoted as User threshold ; Obtain the quantity of Match_user(P common ) = True, define it as the similar quantity, and denote it as User similar ; If User similar <User threshold , it is determined that the user's game operation is normal; If User similar ≥User threshold , it is determined that the user's game operation is abnormal.

7. The method for behavior monitoring and recognition of preventing game cheating according to claim 6, characterized in that: The operation analysis of the user also includes comprehensive data analysis, specifically: If it is determined that the user's game operation is abnormal and it is determined that the user's current IP is abnormal, then it is determined that the user's current game operation data is abnormal, and the user account is subject to violation handling; If it is determined that the user's game operation is normal or it is determined that the user's current IP is normal, then it is determined that the user's current game operation data is normal, and then continuously obtain the operation data of the target user.

8. The method for monitoring and identifying behaviors to prevent game cheating according to claim 1, characterized in that: The obtaining of all historical operation data of the target user to generate a historical data set is specifically: Obtain all the historical login times of the target user in the target game to form a set of historical times, denoted as H = {H1, H2,..., H m}; where m is the number of logins; Obtain the historical operation data of the target user at each historical login time to form a historical operation set, denoted as H h_s ={h h1 , h h2 ,..., h hi}; where hi is the number of samples; Through the sample determination function Ab(·), for each historical operation set H of each historical login time h_s for each sample h hj in it, determine whether it is an outlier: where Ab1 is abnormal, Ab0 is normal, and L and U are respectively the lower and upper limits of the set normal sample values; For the historical operation set H for each historical login time h_s , remove all outliers from the historical operation set H h_s . The resulting set is defined as the net set, denoted as H clean_h ; For each net set H of historical login times, through the error determination function clean_h for each sample h hj in it, determine whether it is incorrect data: where Wr1 is incorrect data, Wr0 is correct data, Lo is too many missing values, and Fo is incorrect format; For each net set H of historical login times clean_h , remove all the incorrect data in the net set H clean_h , and define the resulting set as the cleaned set, denoted as H h_s ', where the number of samples is i'; For the cleaning set H of each historical login time h_s ', extract key features from the cleaning set H h_s ' to obtain a feature vector, denoted as X h = {x1, x2,..., x hm}; where hm is the number of features; Integrate the historical time set and the cleaning set H for each historical login time h_s ' and each cleaning set H h_s ' corresponding feature vector X h , to form a historical data set.

9. The method for behavior monitoring and recognition of preventing game cheating according to claim 1, characterized in that: The obtaining of the current operation data of the target user is specifically: Obtain the current login time of the target user in the target game, denoted as H c ; Obtain the current operation data of the target user at the current login time to form a current operation set, denoted as H c_s ={h c1 , h c2 ,..., h ci}; where ci is the number of samples; Through the sample determination function Ab(·), for each sample h in the current operation set H at the current login time c_s in the set cj , determine whether it is an outlier: where Ab1 is abnormal, Ab0 is normal, and L and U are respectively the lower and upper limits of the set normal sample values; For the current operation set H at the current login time c_s , remove all outliers from this current operation set H c_s . The resulting set is defined as the net set, denoted as H clean_c ; Through the error determination function Wr(·), for each sample h in the net set H of the current login time clean_c to determine whether it is incorrect data: cj ​ where Wr1 is incorrect data, Wr0 is correct data, Lo is too many missing values, and Fo is incorrect format; For the net set H of the current login time clean_c , remove all the incorrect data in this net set H clean_c . The resulting set is defined as the cleaned set, denoted as H c_s ', where the number of samples is i'; For the cleaned set H of the current login time c_s ', extract key features from the cleaned set H c_s ' to obtain a feature vector, denoted as X c = {x1, x2,..., x cm}; where cm is the number of features; Integrate the current login time and the cleaned set H of the current login time c_s ' and the cleaned set H c_s ' and the corresponding feature vector X c , to form the current dataset.

Citation Information

Patent Citations

  • Resource optimization method in multi-open scene of cloud game based on reinforcement learning

    CN115845362A

  • Abnormal team formation detection method and device, terminal and computer readable storage medium

    CN116474359A

  • Collaborative strategy generation method, system and equipment for multi-player game

    CN119425099A

  • Methods and systems for monitoring a game to determine a player-exploitable game condition

    US7517282B1

Cited By

  • Cloud game vulnerability analyzing and monitoring system based on cloud computing

    CN121167735A