Game behavior anomaly detection method based on spatio-temporal feature fusion

Through the fusion of spatiotemporal features and dynamic learning mechanisms, a visual data carrier is generated, and a dual-channel detection model and adaptive clustering algorithm are constructed. This solves the problems of spatiotemporal feature fragmentation and insufficient dynamic evolution capabilities in game behavior detection, and achieves high-precision real-time detection and continuous combat against plug-in behavior.

CN120705712AActive Publication Date: 2025-09-26JIAXIANG INTERACTIVE XIAMEN NETWORK TECH CO LTD

Patent Information

Application Number
CN202511178516.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-22
Publication Date
2025-09-26
Estimated Expiration
2045-08-22

AI Technical Summary

Technical Problem

Existing technology for detecting abnormal gaming behavior suffers from problems such as the fragmentation of spatiotemporal features, delayed recognition of new abnormal patterns, difficulty in detecting collaborative cheating in groups, and insufficient dynamic evolution capabilities of the detection system. These problems result in low detection accuracy and poor real-time performance, making it impossible to effectively respond to rapidly changing cheating methods.

Method used

Through the visualization encoding of behavioral data, a visualization data carrier of spatiotemporal features is generated, a dual-channel detection model is built for real-time anomaly judgment, an adaptive density clustering algorithm is used to mine group anomaly patterns, and a closed-loop self-optimization system is established for dynamic coding rule updates and incremental learning to achieve multi-level response strategies and self-evolution.

Benefits of technology

It significantly improves the accuracy and real-time performance of anomaly detection in gaming behaviors, can accurately identify complex abnormal behaviors, reduce the misjudgment rate, accurately intercept instantaneous cheating behaviors and discover group collaborative cheating patterns, and provide continuously evolving detection capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120705712A_ABST
    Figure CN120705712A_ABST
Patent Text Reader

Abstract

The invention provides a game behavior anomaly detection method based on spatio-temporal feature fusion, which comprises the following steps of: visual coding of behavior data: collecting user operation time sequence data, and performing hue mapping coding according to event types, respectively mapping the basic operation event, the core interaction event, the numerical value change event and the non-operation event into differentiated colors, wherein the numerical value event adopts a gradient color to represent the change intensity; dividing the time sequence data into row vectors based on a preset time unit, generating a two-dimensional behavior map through multi-row stacking, transversely representing time continuity, longitudinally reflecting behavior cycle regularity, and forming a visual data carrier containing spatial-temporal characteristics; and two-channel detection model construction: constructing a double-layer architecture of a supervised detection channel and an enhanced detection channel, wherein the supervised detection channel adopts a deep convolutional neural network to extract map spatial features and is connected with an interpretable classifier to output a behavior compliance probability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of game cheat detection, and in particular relates to a method for detecting abnormal game behavior based on spatiotemporal feature fusion. Background Art

[0002] Current technology for detecting anomaly gaming behavior faces multiple challenges. Traditional rule-based detection systems rely heavily on manual experience and preset conditions, making them incapable of coping with the rapid evolution of new cheating methods. This is especially true when dealing with script-based cheats with temporal camouflage features. Lagging static rule base updates lead to high missed detection rates. While detection methods based on single-dimensional statistical analysis can capture some abnormal numerical fluctuations, they cannot effectively analyze the spatiotemporal correlations between behavioral events. For example, they lack the ability to model the temporal coupling between periodic operations and game context, making it easy for normal players' high-frequency operations during active periods to be misjudged. Existing machine learning models often use single-modal feature inputs, simply converting time series data into statistical indicators or independent event sequences for processing. This breaks the inherent connection between temporal continuity and spatial distribution, resulting in the loss of characteristic information of key behavioral patterns. This is typically manifested in the inability to recognize the grid-like distribution patterns of mechanical operations generated by plug-ins on the two-dimensional space-time plane. While mainstream deep learning solutions can automatically extract features, the poor interpretability of the models makes it difficult for operators to trace the basis for their decisions. Traditional convolutional neural networks also suffer from feature confusion when directly processing raw time-series data, making it impossible to distinguish the microscopic differences between normal player strategic operations and malicious scripts. Existing detection systems generally lack the ability to dynamically evolve. When game versions are updated and new gameplay is introduced, the original models need to be fully retrained, and they cannot quickly adapt to changes in behavioral patterns through incremental learning. Group anomaly detection often uses simple association rules, making it difficult to detect the temporal and spatial synchronization characteristics implicit in cross-account collaborative cheating, such as the distributed behavioral resonance phenomenon formed by gambling gangs within a specific time window. Visual analysis technology mostly remains at the basic chart display level, failing to encode spatiotemporal dimension features into structured images that can be parsed by deep learning models, resulting in inefficient manual review; existing technologies generally have computing delays when processing real-time streaming data, and are unable to complete complex spatiotemporal feature analysis within a millisecond time window, causing some instantaneous cheating behaviors to escape detection; traditional anomaly scoring mechanisms have not established a multi-channel verification system, and single detection results are easily affected by noise interference and misjudgment, and lack a collaborative verification mechanism for supervised learning and unsupervised mining; the feature engineering link still relies heavily on manual design, and has failed to build an automated feature derivation system, resulting in inefficient feature extraction of new variant plug-ins.

[0003] These defects jointly restrict the accuracy and real-time performance of abnormal gaming behavior detection, and there is an urgent need to build a new detection system that integrates spatiotemporal feature analysis and adaptive learning. Summary of the Invention

[0004] The present invention proposes a method for detecting abnormal gaming behaviors based on the fusion of spatiotemporal features. This method solves the problems of existing gaming behavior detection technologies, such as the fragmentation of spatiotemporal features, the lag in the recognition of new abnormal patterns, the difficulty in detecting group collaborative cheating, and the insufficient dynamic evolution capability of the detection system, thereby achieving high-precision real-time detection of complex abnormal behaviors.

[0005] The technical solution of the present invention is implemented as follows: a method for detecting abnormal gaming behavior based on spatiotemporal feature fusion, the method comprising the following steps: Behavioral data visualization coding: This involves collecting user operation time series data and performing hue mapping coding by event type. Basic operation events, core interaction events, numerical change events, and no-operation events are mapped to differentiated colors. Numerical events use gradient colors to represent the intensity of change. Time series data is segmented into row vectors based on preset time units. Multiple rows are stacked to generate a two-dimensional behavior map. This horizontal representation of time continuity and vertical reflection of behavioral cycle regularity creates a visual data carrier with spatiotemporal characteristics. Dual-channel detection model construction: A two-layer architecture consisting of a supervised detection channel and an enhanced detection channel is constructed. The supervised detection channel uses a deep convolutional neural network to extract spatial features of the graph and connects it to an interpretable classifier to output behavioral compliance probabilities. The enhanced detection channel uses the target detection framework to identify periodic distribution features in the graph to capture mechanical behavior patterns. The initial model is generated through historical positive and negative sample training, and dual-channel parallel detection logic is established. Real-time anomaly determination and tracking: Real-time behavioral data is encoded into a standard graph and input into a dual-channel model. The supervision channel calculates the probability of behavioral compliance and combines it with the regular feature recognition results of the enhancement channel to generate an anomaly confidence score. Based on the score threshold, a multi-level response mechanism is triggered to implement real-time interception of high-risk accounts and retain behavioral traces. Suspicious samples are also injected into the anomaly feature library. Mining abnormal group patterns: Based on the abnormal feature library, an adaptive density clustering algorithm is used to identify group behavior patterns with similar spatiotemporal characteristics. The clustering results are then hierarchically verified using expert rules to extract script features, collaboration features, and new variant features. The verified feature parameters are then injected back into the detection model to expand the anomaly recognition dimension. Closed-loop self-optimization system: Establishes a dynamic coding rule update mechanism, characterizes new abnormal behaviors by adding a new hue layer and supports semi-transparent overlay and fusion, builds incremental learning trigger conditions, and automatically optimizes model parameters to be compatible with new and old features when new abnormalities accumulate to a set scale. At the same time, a three-level early warning strategy is established based on the danger level of the abnormal pattern, and differentiated disposal plans are implemented respectively, namely real-time blocking, manual review and continuous tracking.

[0006] Existing technology for detecting anomaly in gaming behavior suffers from multiple flaws. Traditional rule-based systems rely on manually pre-set conditions, making them difficult to cope with the rapid changes in scripts and cheats. This is especially true when dealing with cheating behaviors characterized by temporal camouflage. Static rule updates lag, leading to a high rate of missed detections. While statistical analysis methods can capture numerical anomalies, they cannot analyze the spatiotemporal correlations between events. For example, they lack modeling of the temporal coupling between periodic operations and game scenarios, leading to misjudgment of high-frequency operations by normal players during active periods. Unimodal machine learning models simplify time series data into statistical indicators or independent sequences, breaking spatiotemporal continuity and causing the loss of the gridded spatiotemporal distribution characteristics generated by cheat programs. The poor interpretability of deep learning models makes it difficult for operators to trace the basis for their decisions, and traditional convolutional networks confuse the microscopic differences between normal strategies and malicious scripts when processing raw time-series data. The system lacks the ability to dynamically evolve, requiring full retraining after game version updates and unable to quickly adapt to new behavioral patterns through incremental learning. Group detection uses simple association rules, making it difficult to detect spatiotemporal synchronization features in cross-account collaborative cheating (such as the behavioral resonance of card-playing gangs). Visualization technology remains at the basic chart level and does not encode spatiotemporal features into structured images, resulting in inefficient manual review. Real-time streaming data processing has computing delays and cannot complete complex spatiotemporal analysis within millisecond windows, making it easy for instantaneous cheating behaviors to escape detection; traditional anomaly scoring lacks multi-channel verification, and single detection results are easily affected by noise, lacking supervised and unsupervised collaborative verification; feature engineering relies on manual design, and the efficiency of feature extraction for new variant plug-ins is low.

[0007] The core difficulties of these problems lie in: how to effectively integrate spatiotemporal features to capture the grid distribution patterns of mechanical behavior; how to build a dynamically evolving detection model to adapt to rapidly iterating cheating methods; how to improve the deep learning model's feature extraction capabilities for temporal behavior patterns through visual coding; how to balance computational efficiency and the accuracy of complex spatiotemporal analysis in real-time detection; how to establish a multi-level verification mechanism for group anomalies to identify hidden collaborative cheating patterns; and how to achieve self-evolution of the detection system without destroying its original recognition capabilities.

[0008] As a preferred embodiment, the collaborative mechanism of the supervised detection channel and the enhanced detection channel includes a dynamic weight allocation module, which automatically adjusts the fusion weight of the dual-channel output results according to the spatiotemporal distribution characteristics of the real-time behavior map, wherein the proportion of periodic feature recognition results increases exponentially with the length of the detection period.

[0009] As a preferred embodiment, the dynamic weight allocation module includes a spatiotemporal coupling analysis unit, and the following adjustment mechanism is designed specifically for the characteristics of game behavior data: Time-segment sensitive adjustment: Divide time segments according to the game operation cycle and establish a time segment feature vector library. When real-time detection enters a specific segment, it automatically matches the corresponding historical spatiotemporal distribution pattern and dynamically adjusts the dual-channel weight baseline value; Spatial density perception adjustment: The behavior map is gridded and divided into blocks, and the spatial distribution dispersion index of event clusters is calculated. When the event distribution within the grid unit is detected to show a high-density rectangular arrangement feature, the weight strengthening mechanism of the enhanced detection channel is triggered; Spatiotemporal coupling attenuation factor: Construct a weight dynamic update function and adaptively configure it according to the game scene type analyzed in real time; Game stage context adaptation: Access the game status interface to obtain the current player's stage, set an upper threshold for the weight increase of periodic features during the resource settlement period, and avoid misjudgment of normal high-frequency operations.

[0010] As a preferred embodiment, the behavior map generation process includes a timing compression compensation mechanism, which automatically enables a nonlinear time axis compression algorithm when continuous no-operation events are detected, thereby amplifying the time resolution of key behavior events while maintaining the total pixel dimension.

[0011] As a preferred embodiment, the closed-loop self-optimization system includes an adversarial incremental training module, which simultaneously injects normal samples that have been perturbed during the model parameter optimization stage, and ensures that the ability to recognize newly added abnormal features does not affect the judgment accuracy of the original samples through the adversarial loss function constraint.

[0012] As a preferred implementation, the expert rule verification process adopts a multi-layer cascade verification architecture. The first layer screens potential abnormal groups through convolutional feature similarity, the second layer uses graph neural networks to analyze the association topology between accounts, and the final layer verifies the rationality of abnormal patterns based on the contextual semantics of the game scene.

[0013] As a preferred embodiment, the hue mapping code includes a dynamic expansion mechanism. When a new abnormal behavior feature is detected, an auxiliary hue layer is added while retaining the basic color system, and the fusion representation of multi-dimensional behavior features is achieved through transparency superposition.

[0014] As a preferred embodiment, the trigger logic of the enhanced detection channel is set to: automatically activate when the behavior compliance probability output by the supervision channel is lower than a first threshold, and synchronously increase the danger level of the abnormal confidence score after detecting periodic distribution characteristics.

[0015] After adopting the above technical solution, the beneficial effects of the present invention are as follows: This method significantly improves the comprehensive performance of abnormal game behavior detection through an original spatiotemporal feature fusion mechanism and dynamic evolution system: the pioneering multi-dimensional hue coding converts temporal behavior into a visual map containing spatiotemporal distribution characteristics, breaking through the limitations of traditional single-dimensional feature processing, enabling convolutional neural networks to accurately capture the grid distribution pattern unique to cheating operations; the constructed dual-channel detection architecture innovatively integrates deep learning and target detection technology, outputs compliance probability through the interpretable classifier of the supervision model, and combines it with the periodic feature recognition of the enhanced channel to form a dual verification mechanism, effectively distinguishing the micro differences between strategic operations and scripted behaviors, and significantly reducing the false positive rate; The real-time detection process adopts a multi-level response strategy, completing spatiotemporal feature analysis and risk level determination within a millisecond window, achieving precise interception of instantaneous cheating behavior. The group anomaly mining module, through the synergy of adaptive density clustering algorithm and expert rule verification, can detect distributed collaborative cheating patterns that are difficult to identify with traditional methods, such as the spatiotemporal synchronization characteristics of gambling gangs. The closed-loop self-optimization system uses dynamic coding rule updates and incremental learning mechanisms to enable the detection model to autonomously absorb new abnormal features, avoiding system failures caused by version updates. At the same time, an adversarial training protection mechanism is used to ensure that new feature learning does not affect the original detection capabilities. The nonlinear gradient color mapping in the visual coding enhances the feature contrast of key numerical ranges, improving the efficiency of manual review. The three-level early warning strategy, combined with spatiotemporal correlation analysis, implements coordinated monitoring of low-risk cluster anomalies, effectively identifying hidden collaborative risks. A feature feedback channel injects verified anomaly patterns back into the model, fostering a continuously evolving detection capability. The overall solution achieves breakthroughs in detection accuracy, real-time response, pattern discovery, and system adaptability, providing comprehensive technical support for secure gaming operations. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0017] Figure 1 is a flow chart of the method of the present invention; Figure 2 This is a structural diagram of the AI ​​behavior data detection system of the present invention; Figure 3 This is the abnormal account behavior diagram of the present invention; Figure 4 This is the image data diagram of abnormal account behavior converted into image data in the present invention; Figure 5 This is the negative sample library of the present invention; Figure 6 This is the positive sample gallery of the present invention; Figure 7 This is a comparison diagram of the regular behavior of abnormal samples in the present invention; Figure 8 This is a data graph showing regular behavior of abnormal samples in the present invention; Figure 9 This is the script behavior marker diagram detected by AI in the present invention. DETAILED DESCRIPTION

[0018] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.

[0019] Example: like Figure 1 As shown, a method for detecting abnormal gaming behavior based on spatiotemporal feature fusion includes the following steps: Behavioral data visualization coding: This involves collecting user operation time series data and performing hue mapping coding by event type. Basic operation events, core interaction events, numerical change events, and no-operation events are mapped to differentiated colors. Numerical events use gradient colors to represent the intensity of change. Time series data is segmented into row vectors based on preset time units. Multiple rows are stacked to generate a two-dimensional behavior map. This horizontal representation of time continuity and vertical reflection of behavioral cycle regularity creates a visual data carrier with spatiotemporal characteristics. Dual-channel detection model construction: A two-layer architecture consisting of a supervised detection channel and an enhanced detection channel is constructed. The supervised detection channel uses a deep convolutional neural network to extract spatial features of the graph and connects it to an interpretable classifier to output behavioral compliance probabilities. The enhanced detection channel uses the target detection framework to identify periodic distribution features in the graph to capture mechanical behavior patterns. The initial model is generated through historical positive and negative sample training, and dual-channel parallel detection logic is established. Real-time anomaly determination and tracking: Real-time behavioral data is encoded into a standard graph and input into a dual-channel model. The supervision channel calculates the probability of behavioral compliance and combines it with the regular feature recognition results of the enhancement channel to generate an anomaly confidence score. Based on the score threshold, a multi-level response mechanism is triggered to implement real-time interception of high-risk accounts and retain behavioral traces. Suspicious samples are also injected into the anomaly feature library. Mining abnormal group patterns: Based on the abnormal feature library, an adaptive density clustering algorithm is used to identify group behavior patterns with similar spatiotemporal characteristics. The clustering results are then hierarchically verified using expert rules to extract script features, collaboration features, and new variant features. The verified feature parameters are then injected back into the detection model to expand the anomaly recognition dimension. Closed-loop self-optimization system: Establishes a dynamic coding rule update mechanism, characterizes new abnormal behaviors by adding a new hue layer and supports semi-transparent overlay and fusion, builds incremental learning trigger conditions, and automatically optimizes model parameters to be compatible with new and old features when new abnormalities accumulate to a set scale. At the same time, a three-level early warning strategy is established based on the danger level of the abnormal pattern, and differentiated disposal plans are implemented respectively, namely real-time blocking, manual review and continuous tracking.

[0020] In the practical application of game cheat detection, this solution achieves accurate identification and continuous countermeasures against cheating behavior through the fusion of spatiotemporal features and a dynamic learning mechanism. The system first connects to the real-time log stream of the game server to collect player action event sequences. This includes core interaction events such as character movement, skill release, and item trading, as well as numerical operation events such as currency changes and equipment attribute modifications. The data preprocessing module performs feature mapping on the raw event stream according to pre-set spatiotemporal encoding rules: basic operation events (such as movement commands) are marked in blue, core interaction events (such as entering a dungeon) are mapped in yellow, numerical gain and loss events are coded using a gradient from red to dark red and from green to dark green, respectively, and periods of inactivity are filled in black. Using 1 second as the basic time unit, the encoding engine converts 300 seconds of action sequences into horizontal rows of pixels, then stacks 288 rows vertically to construct a 24-hour action map, forming a two-dimensional spatiotemporal feature matrix that combines temporal continuity and cyclical regularity.

[0021] When detecting script cheats, the spatiotemporal encoding mechanism effectively captures the typical characteristics of cheating behavior. For example, an automatic gold farming script triggers repeated operations at fixed intervals, which manifests as a matrix of evenly spaced yellow core events in the behavior map. Speed-changing cheats, on the other hand, exhibit unnatural color block mutations in the gradient color distribution due to abnormal operation frequency. The encoded standard map is input into a dual-channel detection model. The supervised detection channel utilizes a modified VGG19 network structure, extracting spatial texture features (such as color distribution gradients and event cluster morphology) through convolutional layers. After global average pooling, it is connected to an interpretable logistic regression classifier, outputting a behavior compliance probability value trained on historical samples. Simultaneously, the enhanced detection channel, based on the YOLOv8 object detection framework, uses an anchor box mechanism to scan the map for periodically arranged rectangular feature regions, identifying the grid-like distribution pattern characteristic of mechanical operations. The dual-channel output results are collaboratively judged through a dynamic weight fusion module: during peak gaming periods, the enhanced channel's detection weight for periodic features increases exponentially, effectively responding to scenarios with concentrated outbreaks of script plug-ins; when high-density rectangular arrangement features are detected, the system automatically increases the danger level threshold of the anomaly confidence score.

[0022] The real-time judgment phase utilizes a streaming processing architecture. When an account's behavior graph, analyzed by a dual-channel model, shows an anomaly confidence score exceeding a preset threshold, the real-time interception module immediately freezes the account's transaction capabilities and simultaneously activates the behavior trajectory tracking submodule, recording subsequent operational events and generating a derivative graph. Suspicious samples are simultaneously injected into the anomaly feature library, triggering a cluster anomaly mining process. An adaptive density clustering algorithm groups negative samples based on spatiotemporal feature similarity (e.g., the graph structure similarity index (SSIM) and the KL divergence of event distributions) to identify clusters of cheats with similar characteristics. For example, the behavior graphs of distributed gold farming accounts may exhibit synchronized, periodic yellow event bands within a specific time window; whereas, new variants of cheats may exhibit an asymmetric, gradient distribution of color blocks. The expert verification system employs a multi-layer cascade strategy: the first layer uses convolutional feature matching to identify clusters similar to known cheat patterns; the second layer applies graph neural networks to analyze topological relationships between accounts, such as device fingerprint associations and IP addresses; and the final layer incorporates semantic verification of the game scenario (e.g., whether the anomalous operation conforms to the current dungeon mechanics) to eliminate misclassified samples due to improved player skill.

[0023] The closed-loop optimization system uses a feature feedback channel to reverse-inject identified new cheat patterns into the coding rule base and detection model. When illegal item transactions are detected using third-party interfaces, a purple coding layer is dynamically added to represent these events, creating a hybrid feature representation using a semi-transparent overlay on the original graph. The incremental learning module freezes the original convolution kernel parameters during model updates and trains only on the newly added feature dimensions, ensuring that historical detection capabilities are not affected. To address the frequent changes in attack patterns by cheat developers, the system incorporates an adversarial sample generator that simulates the variation patterns of cheat features (such as randomly perturbing event intervals and adding noise events) to enhance model robustness. A multi-level response strategy dynamically adjusts the response based on the threat level: accounts detected with known script features are immediately banned; suspicious accounts with new features are manually reviewed while the group behavior patterns of their associated accounts are continuously tracked; and data collection frequency is reduced for low-risk anomalies to optimize system load. Through the closed-loop operation of the above process, the system forms an evolutionary detection capability in continuous confrontation: the dynamic expansion of spatiotemporal coding rules solves the problem of feature solidification of traditional methods; the collaborative judgment mechanism of the dual-channel model breaks through the accuracy bottleneck of a single detection dimension; the combination of group feature mining and incremental learning effectively curbs the spread of plug-in variants, and ultimately builds an intelligent security protection system that adapts to the complex gaming ecosystem.

[0024] Implementation 1: Collaborative Mechanism of Dynamic Weight Allocation Module In daily game operations, the dynamic weight allocation module uses a spatiotemporal coupling analysis unit to achieve intelligent detection strategy adjustments. Taking the detection of plug-ins in massively multiplayer online role-playing games (MMORPGs) as an example, during the game activity period (such as the weekend dungeon opening period), the system automatically retrieves historical data from the period feature vector library for the same period, identifies the spatiotemporal distribution characteristics of the high incidence of script plug-ins in this period (such as intensive scheduled task triggering), and enhances the weight baseline value of the detection channel and strengthens the sensitivity to periodic features; when it is detected that the player is in the resource settlement stage (such as the guild war reward distribution period), the module obtains contextual information through the game status interface and sets an upper limit threshold for the increase in the weight of periodic features (such as no more than 30% of the baseline value) to avoid the high-frequency clicks of normal players when receiving rewards being mistakenly judged as script operations; for abnormalities caused by new speed-changing plug-ins The spatial density perception and adjustment unit uses a grid-based block calculation (dividing a 300×288 pixel map into 10×10 grids). When the event density within a grid cell exceeds a critical value and its shape factor conforms to rectangular characteristics, the system automatically increases the weight of the enhancement channel to a dominant position (≥70%), ensuring timely detection of cheat signatures. The spatiotemporal coupling attenuation function dynamically adjusts parameters based on real-time stress test data from competitive scenarios. For example, during peak PVP (player versus player) play, the time decay coefficient β is set to 0.05 to prolong the impact of periodic features, while in social interaction scenarios, it is adjusted to 0.02 to reduce false triggers. This mechanism significantly improves detection accuracy in real-world scenarios. For example, after a version update, a variant gold farming script appeared, whose operation interval changed from a fixed 300-second interval to a random 250-350 second interval. Through spatiotemporal coupling analysis, the system automatically reduced the weight of the time dimension while increasing the weight of spatial density detection, successfully capturing the variant within 24 hours.

[0025] Implementation Method 2: Timing Compression Compensation Mechanism Temporal compression compensation demonstrates unique value in detecting idle scripts in open-world games. When a player character remains idle for extended periods (such as during automatic resource gathering), long black blocks of inactivity appear in the behavioral graph. Traditional encoding methods dilute key events (such as sudden combat triggers). This solution, using a nonlinear timeline compression algorithm, automatically activates dynamic timeline scaling when it detects a period of inactivity exceeding 50 seconds. This compression algorithm compresses the pixel rows during this inactivity period to one-fifth their original length, while simultaneously expanding the time window containing subsequent key events (such as skill combos during encounters with enemy players) to three times the resolution. For example, a studio account continuously idles and mines between 3:00 AM and 5:00 AM, triggering item trades only at the top of the hour. This compression mechanism compresses the 180-minute inactivity period in two hours of behavioral data into 36 rows of pixels, while expanding the hourly window containing trade events to six rows of high-resolution pixels. This allows the YOLOv8 model to clearly identify clusters of trades triggered at the exact top of the hour (represented as vertically aligned yellow rectangular bands). This processing method is particularly important in anti-cheating in sandbox games. In an actual case, the compression mechanism amplified the short-term burst operations of the stealth plug-in (such as triggering the stealth skill 10 times in succession within 0.5 seconds), forming obvious bright stripes in the behavior map, helping the supervision detection channel to mark suspicious samples in the first round of screening, completing feature locking earlier than traditional methods.

[0026] Implementation 3: Adversarial Incremental Training Module The adversarial incremental training module in this solution builds a robust feature isolation barrier against adversarial attacks launched by cheat developers against detection models. When the system discovers a new type of phishing cheat (such as an information hijacking script disguised as a normal transaction) through group anomaly mining, the incremental training process begins: First, 5% of the data is randomly sampled from the normal sample library. Perturbed samples are generated by adding Gaussian noise (σ=0.1) and time axis jitter (±3 seconds offset). These samples are then mixed with the new anomalous samples in a 4:1 ratio and fed into the training set. During model optimization, the adversarial loss function simultaneously constrains the cosine similarity (threshold ≥ 0.85) and classification boundary distance (≥ 0.3 feature space units) between the new and old feature spaces, ensuring that the newly added phishing cheat identification dimension (such as the unusual hue flashing pattern of the transaction confirmation box) does not encroach on the original feature space. In a real-world deployment, this mechanism successfully defended against gradient attacks against the detection model. When cheating groups attempted to cheat by fine-tuning the operation interval parameters (making the periodic characteristics of the behavior graph closer to the fluctuations of normal player behavior), the integrity of the original feature space preserved by adversarial training enabled the model to accurately identify variant samples through color distribution gradient anomalies (the red transaction confirmation block of the new cheat had a 0.5% hue shift). Traditional full-update models had a very low recognition rate under such attacks.

[0027] Implementation 4: Multi-layer cascade verification architecture In the cross-server battlefield collaborative cheat detection scenario, a multi-layer cascaded verification architecture effectively solves the challenge of identifying complex cheating behaviors. In the first-layer convolutional feature matching phase, the system calculates the SSIM (structural similarity index) between the behavior graph of suspicious groups and known cheat patterns, screening candidate groups with a similarity greater than 0.6. In the second-layer graph neural network analysis phase, an account association topology graph is constructed (nodes represent accounts, and edge weights integrate metrics such as device fingerprint overlap, IP geographic proximity, and transaction network density). The GraphSAGE algorithm is used to extract subgraph features, identifying three hidden association clusters (containing 12, 8, and 5 accounts, respectively). In the final layer, semantic verification, combined with battlefield log analysis, revealed that accounts in the first association cluster exhibited unusually synchronized movement during the stronghold capture phase (with a position update error of less than 0.5 meters per second), but their operations were consistent with the battlefield advancement strategy, leading to the identification of a high-level player team. Accounts in the second association cluster exhibited regular movement during the resource collection phase, following the optimal path on the map, with a standard deviation of less than 50ms. Based on the game scenario rules, this indicates an automated script. The false positive rate is lower than that of traditional single-layer detection. The new collaborative plug-in mode discovered (avoiding device detection by alternating logins) is reversely injected into the feature library, becoming an important basis for subsequent detection.

[0028] Implementation 5: Dynamic Hue Expansion Mechanism When a new type of perspective cheat exploiting a game engine vulnerability is detected, the dynamic hue expansion mechanism responds swiftly. This type of cheat triggers detection commands in non-visible areas, making this behavior uncharacteristically represented by traditional encoding systems. The system automatically adds a semi-transparent purple auxiliary layer (60% transparency) on top of the base hue layer, mapping the perspective commands as purple spots of varying shades (the color depth is positively correlated with the command triggering frequency). In the behavioral graph, a normal player's detection events are randomly distributed, while perspective cheats form dense purple clusters in specific coordinate areas (such as behind walls). In an actual match, this mechanism completed feature adaptation within eight hours: the first sample detected a cluster of unknown coordinate-based events, and the feature library automatically assigned a backup hue channel. After three rounds of incremental training, the newly added purple feature layer successfully identified 12 variations of perspective cheats, including advanced versions that utilize time-delayed triggering and area-slicing scanning. The semi-transparent overlay design ensures that historical detection capabilities are not affected. The introduction of the new hue layer improves the accuracy of the existing script detection model for traditional gold-farming scripts.

[0029] Implementation 6: Enhanced detection channel trigger logic The enhanced detection channel's intelligent triggering mechanism plays a key role in detecting fake popularity and boosting traffic in social games. When the compliance probability output by the supervision channel for a livestream account drops to 0.35 (with a threshold of 0.4), the enhanced detection channel is automatically activated. The YOLOv8 model scans the entire behavioral graph and detects that gift-giving events display equally spaced red vertical stripes at every 5-minute boundary (a characteristic of a timed gift-giving script). The model immediately raises the anomaly confidence score from 0.6 to 0.89, triggering a high-risk response. The system also performs a secondary verification based on the game context (normal gift-giving frequency during inactive periods should be less than 10 times per minute). This mechanism, applied to a virtual idol livestreaming platform, increased the recall rate of boosting traffic detection to 93.5%, while maintaining a false block rate of less than 0.03% for legitimate users. For a variant boosting script (using a hybrid random interval and fixed period pattern), the enhanced channel analyzes the spectral characteristics using Fourier transforms. It identifies the hidden fundamental frequency period at a supervision channel probability of 0.38, enabling early warning 14 minutes earlier than traditional single-channel detection.

[0030] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.

Claims

1. A method for detecting abnormal gaming behavior based on spatiotemporal feature fusion, characterized in that: The method comprises the following steps: Behavioral data visualization coding: Collect user operation time series data, perform hue mapping coding by event type, and map basic operation events, core interaction events, value change events, and no operation events into different colors. Value events use gradient colors to represent the intensity of change. Based on the preset time unit, the time series data is divided into row vectors, and a two-dimensional behavior map is generated by stacking multiple rows. The horizontal representation of time continuity and the vertical reflection of the behavioral cycle regularity form a visual data carrier with spatiotemporal characteristics. Dual-channel detection model construction: A two-layer architecture consisting of a supervised detection channel and an enhanced detection channel is constructed. The supervised detection channel uses a deep convolutional neural network to extract spatial features of the graph and connects it to an interpretable classifier to output behavioral compliance probabilities. The enhanced detection channel uses the target detection framework to identify periodic distribution features in the graph to capture mechanical behavior patterns. The initial model is generated through historical positive and negative sample training, and dual-channel parallel detection logic is established. Real-time anomaly determination and tracking: Real-time behavioral data is encoded into a standard graph and input into a dual-channel model. The supervision channel calculates the probability of behavioral compliance and combines it with the regular feature recognition results of the enhancement channel to generate an anomaly confidence score. Based on the score threshold, a multi-level response mechanism is triggered to implement real-time interception of high-risk accounts and retain behavioral traces. Suspicious samples are also injected into the anomaly feature library. Mining abnormal group patterns: Based on the abnormal feature library, an adaptive density clustering algorithm is used to identify group behavior patterns with similar spatiotemporal characteristics. The clustering results are then hierarchically verified using expert rules to extract script features, collaboration features, and new variant features. The verified feature parameters are then injected back into the detection model to expand the anomaly recognition dimension. Closed-loop self-optimization system: Establishes a dynamic coding rule update mechanism, characterizes new abnormal behaviors by adding a new hue layer and supports semi-transparent overlay and fusion, builds incremental learning trigger conditions, and automatically optimizes model parameters to be compatible with new and old features when new abnormalities accumulate to a set scale. At the same time, a three-level early warning strategy is established based on the danger level of the abnormal pattern, and differentiated disposal plans are implemented respectively, namely real-time blocking, manual review and continuous tracking.

2. The method for detecting abnormal gaming behavior based on spatiotemporal feature fusion according to claim 1, characterized in that: The collaborative mechanism between the supervised detection channel and the enhanced detection channel includes a dynamic weight allocation module, which automatically adjusts the fusion weight of the dual-channel output results according to the spatiotemporal distribution characteristics of the real-time behavior map, where the proportion of periodic feature recognition results increases exponentially with the length of the detection period.

3. The method according to claim 2, characterized in that The dynamic weight allocation module includes a spatiotemporal coupling analysis unit, which is specifically designed to adjust the following mechanisms based on the characteristics of game behavior data: Time-segment sensitive adjustment: Divide time segments according to the game operation cycle and establish a time segment feature vector library. When real-time detection enters a specific segment, it automatically matches the corresponding historical spatiotemporal distribution pattern and dynamically adjusts the dual-channel weight baseline value; Spatial density perception adjustment: The behavior map is gridded and divided into blocks, and the spatial distribution dispersion index of event clusters is calculated. When the event distribution within the grid unit is detected to show a high-density rectangular arrangement feature, the weight strengthening mechanism of the enhanced detection channel is triggered; Spatiotemporal coupling attenuation factor: Construct a weight dynamic update function and adaptively configure it according to the game scene type analyzed in real time; Game stage context adaptation: Access the game status interface to obtain the current player's stage, set an upper threshold for the weight increase of periodic features during the resource settlement period, and avoid misjudgment of normal high-frequency operations.

4. The method for detecting abnormal gaming behavior based on spatiotemporal feature fusion according to claim 1, characterized in that: The behavior map generation process includes a timing compression compensation mechanism, which automatically enables a nonlinear time axis compression algorithm when continuous no-operation events are detected, thereby amplifying the temporal resolution of key behavior events while maintaining the total pixel dimension.

5. The method for detecting abnormal gaming behavior based on spatiotemporal feature fusion according to claim 1, characterized in that: The closed-loop self-optimization system includes an adversarial incremental training module, which synchronously injects normal samples that have been perturbed during the model parameter optimization phase. The adversarial loss function constraint ensures that the ability to recognize newly added abnormal features does not affect the judgment accuracy of the original samples.

6. The method for detecting abnormal gaming behavior based on spatiotemporal feature fusion according to claim 1, characterized in that: The expert rule verification process adopts a multi-layer cascade verification architecture. The first layer screens potential abnormal groups through convolutional feature similarity, the second layer uses graph neural network to analyze the association topology structure between accounts, and the final layer verifies the rationality of abnormal patterns based on the contextual semantics of the game scene.

7. The method for detecting abnormal gaming behavior based on spatiotemporal feature fusion according to claim 1, characterized in that: The hue mapping code includes a dynamic expansion mechanism. When a new abnormal behavior feature is detected, an auxiliary hue layer is added while retaining the basic color system, and the fusion representation of multi-dimensional behavior features is achieved through transparency superposition.

8. The method for detecting abnormal gaming behavior based on spatiotemporal feature fusion according to claim 1, characterized in that: The trigger logic of the enhanced detection channel is set to: automatically activate when the behavior compliance probability output by the supervision channel is lower than the first threshold, and synchronously increase the danger level of the abnormal confidence score after detecting the periodic distribution characteristics.

Citation Information

Patent Citations

  • Anomaly detection method and device for MMORPGs

    CN107158707A

  • Game user abnormal transaction behavior identification method and system

    CN120146856A

  • System and method for outlier detection in gaming

    US20200211325A1

Cited By

  • Electromechanical fault diagnosis method for electronic parking brake system

    CN121608721A

  • A method for diagnosing electromechanical faults in an electronic parking brake system

    CN121608721B