Game player cheating detection method, device, equipment and medium
By analyzing the touch positions and timing event sequences of game players using a zero-trust security model and graph neural networks, the problem of insufficient behavioral data for newly registered players is solved, enabling accurate identification and prevention of cheating behavior and improving the accuracy and robustness of game cheat detection.
Patent Information
- Application Number
- CN202511107607.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-08
- Publication Date
- 2026-01-02
- Estimated Expiration
- 2045-08-08
AI Technical Summary
In existing technologies, game cheat detection methods lack historical behavior data of newly registered game players, have weak identification capabilities, and newly registered players may bypass the initial anti-cheat detection and use cheating tools, resulting in low detection accuracy and difficulty in dealing with cheating and cheating behavior evaded by accounts created in bulk by black and gray market operators.
A zero-trust security model is used to continuously monitor the game behavior characteristics of newly registered game players. By constructing graph objects and graph neural network models, the system analyzes touch position sequences and touch timing event sequences, updates risk assessments in real time, and re-verifies players in non-game battles, dynamically adjusting verification strategies.
It significantly improves the accuracy of detecting cheating by newly registered game players, reduces the risk of false positives and false negatives, can identify batch cheating accounts, prevents early-stage hidden cheating behavior, enhances the ability to combat the mutation of cheat scripts, and ensures game fairness and economic security.
Smart Images

Figure CN120754539B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of computer, in particular to a game player cheating detection method, a corresponding device, an electronic device and a computer readable storage medium. BACKGROUND
[0002] In recent years, with the popularity of mobile Internet and smart devices, mobile games have developed rapidly and gradually become the largest and fastest-growing segment of the gaming industry. However, with the development of mobile games, the fairness of mobile games has become increasingly prominent, and the problem of mobile game plug-ins is the most serious, which has harmed the interests of game players and game manufacturers. The simulation click type plug-in is the most common cheating method in mobile games. The plug-in player can achieve game behaviors such as batch hanging, automatic task, automatic resource collection, and automatic reward collection through the simulation click tool, which has a great negative impact on the game fairness and economic system.
[0003] At present, the traditional game plug-in detection method has the following technical defects, mainly including:
[0004] Firstly, the detection of game plug-ins is generally the detection of click type plug-ins by device information analysis, game environment detection, and abnormal game process detection, etc. physical methods. Even for the processing of screen touch data, the detection personnel needs to identify the plug-in by the characteristics of the screen touch data, and needs to compare and process the characteristics one by one. The above two methods both need to process a large amount of data, and due to the change of physical conditions and the update of screen touch data characteristics, the above comparison method will also have the problems of false detection and missed detection, resulting in low accuracy of detection of plug-in players.
[0005] Secondly, the historical behavior data of newly registered game players is relatively lacking at the initial registration, and the anti-cheating model has not accumulated enough behavior data. The game anti-cheating system is difficult to distinguish between normal operation fluctuations and cheating abnormalities, and has weak recognition ability for plug-in scripts, resulting in that the newly registered game players use plug-in scripts to batchly brush props;
[0006] Thirdly, black and gray production studios create a large number of new game accounts through automatic tools for plug-in resource brushing, proxy practice or game economic destruction;
[0007] Fourthly, there are cheating risks such as bypassing the initial anti-cheating detection after the initial login verification and enabling cheating tools in the later period for newly registered game players. For example, some cheaters may hide their cheating behavior in the first game battle after login, and enable plug-in scripts in the second game battle.
[0008] In summary, the game plug-in detection method in the prior art has the problems of weak recognition ability of the new registered game player to the plug-in script in the initial registration period of the new registered game player, and bypassing the initial anti-cheating detection and enabling the cheating tool in the later period after the initial login verification of the new registered game player. The applicant makes corresponding exploration to solve the problems. SUMMARY
[0009] The purpose of the present application is to solve the above problems and provide a game player cheating detection method, a corresponding device, an electronic equipment and a computer readable storage medium.
[0010] To achieve the various purposes of the present application, the present application adopts the following technical solutions:
[0011] A game player cheating detection method is proposed to adapt to one of the purposes of the present application, comprising:
[0012] A preset zero trust security model is called to continuously monitor the new registered game player who has passed the login verification, and a new registered game player sample set is obtained, wherein the new registered game player sample set includes new registered game player samples corresponding to a plurality of new registered game players, each new registered game player sample includes basic information of the game player and game behavior feature data, the game behavior feature data includes a touch position sequence and a touch timing event sequence in each game battle, the touch position sequence represents a plurality of touch positions of the game player in the process from the touch press event to the touch release event of each target skill control in each game battle, and the touch timing event sequence represents the occurrence order and occurrence time of the touch press event and the touch release event of each target skill control in each game battle;
[0013] A first graph object for training the cheating player recognition model is constructed according to each historical game player sample in the historical game player sample set, the new registered game player sample is constructed as a new node in the first graph object, and the first graph object is updated to construct a second graph object;
[0014] The second graph object is input into the cheating player recognition model trained to the convergent state, to predict the first risk probability that the new registered game player corresponding to the new registered game player sample belongs to the cheating game player;
[0015] According to the first risk probability, a re-verification strategy of the new registered game player is determined, the new registered game player is re-verified in a non-game battle link according to the re-verification strategy to determine a re-verification result, and whether the new registered game player is banned is decided according to the re-verification result;
[0016] The above steps are cyclically executed until the newly registered game player exits the target game, so as to complete the cheating detection of the game player.
[0017] Optionally, the step of determining the touch position sequence and the touch timing event sequence in each game battle includes:
[0018] In response to a touch press event of a target skill control of the game player acting on the target game, a plurality of touch positions of the game player from the touch press event to a touch release event of the target skill control in each game battle are acquired according to a preset time granularity, so as to construct a touch position sequence corresponding to each target skill control;
[0019] The touch timing event sequence is constructed according to the occurrence order and occurrence time of the touch press event and the touch release event of the target skill control.
[0020] Optionally, the step of determining the re-verification strategy of the newly registered game player according to the first risk probability, performing re-verification on the newly registered game player in a non-game battle link according to the re-verification strategy to determine a re-verification result, and deciding whether to ban the newly registered game player according to the re-verification result includes:
[0021] When the first risk probability of the newly registered game player corresponding to the new registered game player sample is lower than a preset first risk probability threshold, the newly registered game player is determined as a low-risk cheating game player, and the newly registered game player is authorized to continue the game.
[0022] The cheating player identification model is called to continuously monitor the game behavior feature data of the newly registered game player to update the first risk probability to determine a second risk probability, and when the second risk probability falls within a preset second risk probability interval, the newly registered game player is determined as a medium-risk cheating game player.
[0023] The game anti-cheating system triggers a sliding verification request to be sent to the newly registered game player in a non-battle link of the game, and when the game anti-cheating system detects that the sliding verification result returned by the newly registered game player is passed, the newly registered game player is authorized to continue the game, and when the game anti-cheating system detects that the sliding verification result returned by the newly registered game player is not passed, the newly registered game player is banned for a first preset time length.
[0024] When the game anti-cheating system detects that the sliding verification result returned by the newly registered game player is passed, the newly registered game player is authorized to continue playing the game, and the cheating player identification model is called to continuously monitor the game behavior feature data of the newly registered game player to update the second risk probability to determine a third risk probability, and when the third risk probability falls within a third risk probability interval, the newly registered game player is determined as a high-risk cheating game player.
[0025] The game anti-cheating system triggers the biological feature verification request to be sent to the newly registered game player in a non-battle link of the game, so that the game anti-cheating system detects that the biological feature verification result returned by the newly registered game player is passed, and the newly registered game player is authorized to continue playing the game, and if the biological feature verification result is not passed, the newly registered game player is banned for a second preset time length to complete the cheating detection of the game player, wherein the second preset time length is greater than the first preset time length.
[0026] Optionally, before the step of obtaining the new registered game player sample set, the method comprises:
[0027] Obtaining a historical game player sample set, wherein the historical game player sample set comprises a plurality of historical game player samples and corresponding supervision labels, wherein the historical game player sample comprises basic information of a game player and game behavior feature data; the supervision label represents whether the historical game player belongs to a cheating game player; the game behavior feature data comprises a touch position sequence, a touch timing event sequence, a damage output value, a skill release frequency, a prop acquisition rate, and a task completion time length in each game battle; the basic information of the game player comprises a game player identity account and identity account attribute information; the identity account attribute information comprises an account level, an account registration time, a registration IP address, a device unique identifier, and a number of accounts logged in by the device at the same time;
[0028] According to each historical game player sample in the historical game player sample set, a first graph object for training a cheating player identification model is constructed, wherein the historical game player sample is used to construct a node of the first graph object;
[0029] The constructed first graph object is input into a preset cheating player identification model, and each historical game player sample is trained with a corresponding supervision label until the cheating player identification model is trained to a convergent state to determine a cheating player identification model trained to the convergent state.
[0030] Optionally, the step of constructing a first graph object for training a cheating player identification model according to each historical game player sample in the historical game player sample set comprises:
[0031] constructing a corresponding node in the first graph object based on a game player identity account of a historical game player sample in the historical game player sample set;
[0032]
[0033] introducing game behavior feature data corresponding to each historical game player sample and its corresponding supervision label into the graph object, and associating with the corresponding node in the graph object, to construct the first graph object.
[0034] Optionally, based on the identity account attribute information, the touch position sequence, the touch timing event sequence in the historical game player sample and the preset edge connection rule, it is judged whether the identity account attribute information, the touch position sequence and the touch timing event sequence of any two nodes in the first graph object satisfy the edge connection rule, and if so, an edge connection is established between the two nodes.
[0035] detecting whether the device unique identifiers corresponding to any two nodes in the first graph object are the same, and if so, establishing an edge connection between the two nodes;
[0036] comparing whether the registration IP addresses corresponding to any two nodes in the first graph object are the same, and if so, and the registration time interval between the game player identity accounts of the two nodes does not exceed a preset time threshold, then an edge connection is established between the two nodes;
[0037] calculating a first similarity between the touch position sequences corresponding to any two nodes in the first graph object, and calculating a second similarity between the touch timing event sequences corresponding to the two nodes, and if the first similarity and the second similarity both exceed a preset similarity threshold, then an edge connection is established between the two nodes.
[0038] Optionally, the new registered game player represents a game player whose number of participating game battles is lower than a preset number threshold or a game player whose registration time is lower than a preset registration time length; the basic network architecture of the cheating player identification model is a graph neural network model; and the biological features include user face features or user iris features.
[0039] To achieve another object of the present application, a game player cheating detection device is provided, comprising:
[0040] a sample set obtaining module configured to invoke a preset zero trust security model to continuously monitor newly registered game players who have passed login verification, and obtain a sample set of newly registered game players, wherein the sample set of newly registered game players includes a plurality of newly registered game player samples corresponding to the newly registered game players, each newly registered game player sample includes basic information of a game player and game behavior feature data, the game behavior feature data includes a touch position sequence and a touch timing event sequence in each game battle, the touch position sequence represents a plurality of touch positions of the game player in a touch press event to a touch release event process of each target skill control in each game battle, and the touch timing event sequence represents an occurrence order and a time of a touch press event and a touch release event of each target skill control in each game battle;
[0041] a graph object construction module configured to construct a first graph object for training a cheating player identification model according to each historical game player sample in a historical game player sample set, and construct a second graph object by updating the first graph object by adding the newly registered game player sample as a new node in the first graph object;
[0042] a risk probability determination module configured to input the second graph object into the cheating player identification model trained to a convergent state, to predict a first risk probability that the newly registered game player sample corresponds to a new registered game player belongs to a cheating game player;
[0043] a cheating ban control module configured to determine a re-verification strategy for the new registered game player according to the first risk probability, perform re-verification on the new registered game player in a non-game battle link according to the re-verification strategy to determine a re-verification result, and decide whether to ban the new registered game player according to the re-verification result;
[0044] a cheating detection cycle module configured to cyclically execute the above steps until the new registered game player exits the target game, to complete the cheating detection of the game player.
[0045] An electronic device is provided to adapt to another object of the present application, comprising a central processing unit and a memory, the central processing unit is used to invoke a computer program stored in the memory to execute the steps of the game player cheating detection method described in the present application.
[0046] A computer readable storage medium is provided to adapt to another object of the present application, which stores a computer program implemented according to the game player cheating detection method in the form of computer readable instructions, when the computer program is invoked and run by a computer, the steps included in the corresponding method are executed.
[0047] Compared with the prior art, the present application is directed to the problems in the prior art game plug-in detection method that the new registered game player is in the initial registration stage, the historical behavior data is relatively lacking, the identification ability of the plug-in script is weak, and the new registered game player may bypass the initial anti-cheating detection after the initial login verification, and enable cheating tools in the later stage. The present application includes but is not limited to the following beneficial effects:
[0048] Firstly, the game player cheating detection method of the present application collects the touch position sequence and the touch timing event sequence. Since the operation of the simulation click type plug-in is mechanical, and the human operation has natural fluctuations, the fine features of the touch position sequence and the touch timing event sequence can more accurately distinguish between normal operation and cheating behavior. The new registered game player sample is added as a new node to the graph object constructed by the historical game player sample, and the behavior association of the new registered game player with the historical normal game player or the historical cheating game player is mined through the graph neural network. Even if the behavior data of the new registered game player is limited, it can also be assisted by the experience of the historical data to reduce the misjudgment caused by insufficient single data. It can significantly improve the accuracy of the cheating detection of the new registered game player, and greatly reduce the risk of false detection and missed detection.
[0049] Secondly, the game player cheating detection method of the present application can solve the problem of insufficient historical data of the new registered game player, enhance the initial identification ability, and continuously monitor through the zero trust security model. It breaks through the traditional logic of "one-time verification trust" in game cheating detection, continuously monitors the new registered game player who has logged in, collects game behavior data in each game, and dynamically supplements sample information. The new registered game player node is added to the graph object constructed by the historical game player sample in real time, and the historical game player provides a reference for the risk assessment of the new registered game player. For example, if the touch position sequence and the touch timing event sequence of the new registered game player are highly similar to those of the historical cheating player, even if the data is small, the model can quickly identify the risk, which can effectively make up for the short board of insufficient behavior data of the new registered game player, and effectively identify cheating behavior in the initial registration stage, and curb the problem of new number brushing props.
[0050] Thirdly, the game player cheating detection method of the present application can accurately crack black and gray production batch cheating accounts, maintain game economic security, and the black and gray production creates new accounts in batches through automatic tools, uses external plug-ins to brush resources and destroys the game economy. The prior art is difficult to identify such "group cheating" behavior. The present application can capture the common characteristics of batch accounts through the analysis of graph neural network model on graph objects. The touch mode and operation timing of batch cheating accounts are often highly consistent, which is manifested as "strong association" between new nodes in the graph object. The graph neural network can identify "batch similar behavior cluster" through the association strength between nodes, thereby locking multiple cheating accounts at a time, rather than judging individual accounts in isolation, greatly improving the efficiency of cracking black and gray production batch cheating.
[0051] Fourthly, the game player cheating detection method of the present application can effectively deal with the evasion behavior of initial hiding and later cheating, and realize whole-cycle cheating prevention and control. In the prior art, some cheaters hide behavior at the initial login verification, and enable cheating tools later, resulting in missed detection at the initial stage. The zero-trust security model of the present application does not depend on the initial verification result, but performs data collection, graph object update, risk prediction, and re-verification process in the whole game process of the player. Even if the player hides cheating behavior in the first game match, when the cheating tool is enabled in the subsequent game match, the abnormal change of the touch feature will be captured in real time, and the updated graph object will reflect this change. The model can re-predict the risk and trigger re-verification to ensure that the later cheating behavior is discovered in time.
[0052] Fifthly, if the verification is forced in the game match link, it may interrupt the player's operation and affect the experience. The present application performs re-verification in non-game match links, such as during the matching gap, settlement interface, etc. period, which not only ensures the effectiveness of the verification, but also avoids interference in the match process, balancing the anti-cheating demand and the player experience.
[0053] Sixthly, the present application can greatly improve the detection robustness and resist external plug-in feature variation. External plug-in developers will continuously update the script to evade detection, such as adjusting the touch timing, increasing small random fluctuations. The touch position sequence and touch timing event sequence of the present application directly reflect the essential law of operation, that is, the bottom difference between human operation and mechanical operation, rather than surface features. Even if the external plug-in script fine-tunes the parameters, the mechanical nature will still be captured by the graph neural network, such as the abnormality of deep features such as fluctuation range and timing entropy value. Therefore, it has stronger anti-interference ability and higher robustness to feature variation.
[0054] Further, the application solves the problems of low accuracy of cheating detection for new registered game players, insufficient behavior data, difficulty in batch cheating recognition, and missed detection of late cheating in the prior art by using a zero trust security model for continuous monitoring, graph neural network correlation analysis, and dynamic risk assessment, greatly improves the ability to resist script variation of external plug-ins, and provides more reliable protection for the fairness and economic security of mobile games. BRIEF DESCRIPTION OF DRAWINGS
[0055] The above and / or additional aspects and advantages of the present application will become apparent and more readily appreciated from the following description of the embodiments, taken in conjunction with the accompanying drawings, in which:
[0056] Figure 1 A flowchart of a game player cheating detection method in an embodiment of the present application;
[0057] Figure 2 A flowchart of determining a touch position sequence and a touch timing event sequence in each game battle in an embodiment of the present application;
[0058] Figure 3 A flowchart of training a cheating player recognition model in an embodiment of the present application;
[0059] Figure 4 A flowchart of constructing a first graph object for training a cheating player recognition model in an embodiment of the present application;
[0060] Figure 5 A flowchart of determining whether any two nodes of the first graph object are connected by an edge in an embodiment of the present application;
[0061] Figure 6 A flowchart of re-verification of a new registered game player in an embodiment of the present application;
[0062] Figure 7 A principle block diagram of a game player cheating detection device in an embodiment of the present application;
[0063] Figure 8 A structural diagram of a computer device in an embodiment of the present application. DETAILED DESCRIPTION
[0064] Embodiments of the present application are described in detail below, examples of which are shown in the accompanying drawings, in which the same or similar reference numerals represent the same or similar elements or elements having the same or similar functions throughout. The embodiments described below by reference to the accompanying drawings are exemplary and are only used to explain the present application, and cannot be interpreted as limiting the present application.
[0065] It will be further understood that the terms "comprises" and / or "comprising," when used in this specification, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. As used herein, "connected," "coupled," and / or "coupling," can include both direct connections and / or indirect connections (i.e., via one or more other elements). As used herein, "connection" or "coupling" can include a wireless connection or a wireless coupling. As used herein, the term "and / or" comprises all of the associated listed items, one or more of the associated listed items, and all combinations of the associated listed items.
[0066] It will be further understood that, as used herein, the terms "comprises" and / or "comprising," while they can be used in the context of compositions of matter, preferably, are not used in a restrictive sense, for example, to denote the presence of stated features, integers, steps or components thereof, but to denote the presence at least the stated features, integers, steps or components thereof. As used herein, unless otherwise defined, all terms, including technical and scientific terms, have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. It will be further understood that terms, such as those defined in commonly used dictionaries, should be interpreted as having a meaning that is consistent with their meaning in the context of the specification and relevant art and will not be interpreted in an idealized or overly formal sense unless expressly so defined herein.
[0067] Those skilled in the art will understand that, as used herein, the terms "client," "terminal," and "terminal device" include both devices that are solely wireless signal receivers and devices that have both receiving and transmitting hardware that can communicate bi-directionally over a bi-directional communication link. Such devices can include cellular or other communication devices with single-line or multiple-line displays, or no display, Personal Communications Service (PCS) devices that can combine a voice and data function, Personal Digital Assistants (PDAs) that can include a radio frequency receiver, pagers, Internet / intranet access, Web browsers, organizers, calendars, and / or a Global Positioning System (GPS) receiver, conventional laptop and / or palmtop computers, or other devices that have a radio frequency receiver. The terms "client," "terminal," and "terminal device" as used herein can be portable, transportable, installed in a vehicle (aeronautical, maritime, and / or land), or adapted for and / or configured for local and / or distributed operation on Earth and / or any other location in space. The terms "client," "terminal," and "terminal device" as used herein can also be a communication terminal, an Internet terminal, a music / video playing terminal, such as a PDA, a Mobile Internet Device (MID), and / or a mobile phone with music / video playing function, a smart television, a set-top box, and the like.
[0068] As used herein, the terms "server," "client," "service node," and the like refer to hardware that has the equivalent capability of a personal computer, i.e., an electronic device having a central processing unit (including an arithmetic unit and a controller), a memory, an input device, and an output device, and the like necessary components disclosed by the Von Neumann principle, a computer program is stored in the memory, the central processing unit calls the program stored in the external memory into the memory and runs it, executes the instructions in the program, and interacts with the input and output devices, thereby completing a specific function.
[0069] It should be noted that the concept of "server" in the present application can also be extended to the case of a server cluster. According to the principle of network deployment understood by those skilled in the art, the servers should be logically divided, and in physical space, these servers can be independent of each other but can be called through an interface, or can be integrated into a physical computer or a computer cluster. Those skilled in the art should understand this variation and should not be restricted by the implementation of the network deployment of the present application.
[0070] One or more technical features of the present application, unless explicitly specified, can be deployed on a server and accessed by remotely calling the online service interface provided by the server, or can be directly deployed and run on a client to implement access.
[0071] The neural network model referred to or possibly referred to in the present application, unless explicitly specified, can be deployed on a remote server and remotely called by a client, or can be deployed on a client with sufficient device capability for direct calling. In some embodiments, when it runs on a client, its corresponding intelligence can be obtained through transfer learning to reduce the requirement for client hardware running resources and avoid excessive occupation of client hardware running resources.
[0072] The various data involved in the present application, unless explicitly specified, can be remotely stored on a server or stored on a local terminal device, as long as it is suitable for being called by the technical solutions of the present application.
[0073] Those skilled in the art should know that the various methods of the present application, although based on the same concept and described to present commonality among them, are independently executable unless otherwise specified. Similarly, for each embodiment disclosed in the present application, it is based on the same inventive concept, so the same concept and although the concept is different but only for the convenience of appropriate transformation of the concept should be understood as equivalent.
[0074] Unless it is explicitly stated that the various embodiments disclosed in the present application are mutually exclusive, the related technical features involved in each embodiment can be cross combined to flexibly construct new embodiments, as long as such combination does not deviate from the spirit of the present application and can meet the needs of the prior art or solve some aspects of the deficiencies in the prior art. For this variation, those skilled in the art should know.
[0075] Please refer to Figure 1 The game player cheating detection method of the present application includes, in one embodiment thereof:
[0076] At step S10, a preset zero-trust security model is invoked to continuously monitor the newly registered game players that have passed the login verification, and a new registered game player sample set is obtained, wherein the new registered game player sample set includes new registered game player samples corresponding to a plurality of new registered game players, each new registered game player sample includes basic information of a game player and game behavior feature data, the game behavior feature data includes a touch position sequence and a touch timing event sequence in each game battle, the touch position sequence represents a plurality of touch positions of the game player in a touch press event to a touch release event process of each target skill control in each game battle, and the touch timing event sequence represents an occurrence order and a time of a touch press event and a touch release event of each target skill control in each game battle.
[0077] The game player anti-cheating system can invoke a preset zero-trust security model to continuously monitor newly registered game players that have passed the login verification, and obtain a new registered game player sample set, wherein the new registered game player sample set includes new registered game player samples corresponding to a plurality of new registered game players, each new registered game player sample includes basic information of a game player and game behavior feature data, the game behavior feature data includes a touch position sequence and a touch timing event sequence in each game battle, the touch position sequence represents a plurality of touch positions of the game player in a touch press event to a touch release event process of each target skill control in each game battle, and the touch timing event sequence represents an occurrence order and a time of a touch press event and a touch release event of each target skill control in each game battle, wherein the new registered game player represents a game player whose number of game battles participated is lower than a preset number threshold, or a game player whose registration time is lower than a preset registration time length, wherein the preset number threshold can be 5 or 10, etc., and the preset registration time length can be 30 days or 60 days, etc., and a person skilled in the art can determine the preset number threshold and the preset registration time length according to actual business needs, which is not limited here.
[0078] Specifically, in the game player cheating detection method, the zero-trust security model of the present application breaks the traditional security logic of "one-time verification is permanent trust" in traditional game anti-cheating detection, and solves the cheating risk of new registered game players after initial login verification through the mechanism of "continuous verification, dynamic evaluation, and accurate control", such as bypassing the initial anti-cheating detection, enabling cheating tools later, etc. The role of the zero-trust security model of the present application includes:
[0079] Firstly, in traditional security logic, after login verification, the game player is often defaulted as a trusted game player, and only when obvious abnormalities are triggered will the game player be checked again. However, the zero-trust security model emphasizes "never default trust", that is, even if the newly registered game player has passed the initial login verification, all game behavior feature data of the game player will still be continuously monitored from entering the target game to exiting the target game. Whether the game player is in the first game, multiple games, or non-game session, the zero-trust security model will collect the game behavior feature data in real time, avoiding the use of the trust window after the initial verification by the cheater to cheat, for example, the cheating tool is not enabled during the initial login, and is activated after entering the game.
[0080] Secondly, the verification of the zero-trust security model relies on multi-dimensional data cross-verification, rather than a single indicator. In this scenario, the zero-trust security model collects the basic information of the game player and the game behavior feature data of the newly registered game player, especially the fine-grained operation data such as touch position sequence and touch timing event sequence, to build a trusted baseline of individual behavior. For example, the touch position of a human player may have slight jitter, such as irregularity of finger sliding, and the touch timing will fluctuate with the intensity of the game, such as the time interval between skill pressing and releasing. The touch of the cheating tool is often more mechanical, with accurate and unbiased position, fixed timing, etc. By continuously collecting these data and comparing them with the behavior patterns of historical normal game players, the zero-trust security model can quickly identify deviations in the behavior of the newly registered game player from the "trusted baseline", providing a basis for subsequent risk assessment.
[0081] Thirdly, the zero-trust security model dynamically adjusts the control strategy based on risk, rather than strict restrictions in a "one-size-fits-all" manner. If the behavior data of the newly registered game player has low similarity to the historical cheating game player sample, the zero-trust security model will maintain low-intensity monitoring and not interfere with the normal game; if the game behavior feature data is abnormal, it will trigger re-verification, such as requiring secondary verification in non-game sessions, such as slider verification, biometric verification, etc. By dynamically adjusting the verification intensity, both the disturbance to normal game players and the accurate locking of high-risk cheating behavior are reduced.
[0082] Fourthly, the zero-trust security model emphasizes whole-life-cycle verification, that is, the player is in trust evaluation at every stage from logging into the target game to exiting the target game, avoiding the use of "time difference" by cheaters to evade detection. Even if the newly registered game player behaves normally in the early stage, the zero-trust security model will still continuously monitor in every subsequent game session and every operation, for example, some cheaters may hide their cheating behavior in the first game session after login, and activate the external script in the second game session. The zero-trust whole-process monitoring can capture such "late cheating" behavior, ensuring that there is no risk of omission.
[0083] In some embodiments, referring to Figure 2 , the step of determining the touch position sequence and the touch timing event sequence in each game battle includes:
[0084] Step S101, in response to a touch press event of a game player acting on a target skill control of a target game, a plurality of touch positions of the game player in each game battle from the touch press event to the touch release event of the target skill control are acquired according to a preset time granularity, to construct a corresponding touch position sequence of each target skill control;
[0085] Specifically, when playing a mobile phone game, a game player usually controls a virtual character by touching the screen of the mobile phone; therefore, the touch position sequence and the touch timing event sequence data are easy to collect in mobile devices such as mobile phones and tablet computers, and represent the operation behavior of the game player's fingers on the device screen in order to control the virtual character during playing the mobile phone game. Determining the touch position sequence and the touch timing event sequence of the game player in each game battle converts the operation behavior of the game player on the skill control into quantifiable and analyzable sequence data through fine-grained collection and timing processing, and provides key features for the subsequent cheating player identification model to identify the cheating behavior of the game player.
[0086] The touch position sequence represents the touch positions of the touch press event to the touch release event of each target skill control of the game player in each game battle. Specifically, the touch position sequence represents the complete operation process of the game player from pressing the target skill control to releasing the target skill control, and is converted into a spatial position sequence containing a time dimension, accurately depicting the trajectory details of skill operation, such as sliding path, moving speed, and offset amplitude. When the game player presses the target skill control with a finger on the mobile terminal, such as the “big move” and “flash” buttons in mobile games, the system responds to the touch press event in real time through the sensor; from the occurrence of the touch press event to the touch release event of the game player releasing the target skill control, the system records the coordinate position of the current touch point according to a preset time granularity, such as the screen coordinates (x, y) of the mobile terminal, wherein the preset time granularity can be 10 ms or 15 ms, etc.; for example, if the player releases a skill that lasts for 1 second, and the time granularity is 10 ms, 100 continuous position coordinates can be obtained, forming the touch position sequence [(x1, y1), (x2, y2), …, (x100, y100)]. All collected positions of the same target skill control are arranged in time sequence to form the touch position sequence of the target skill control. If the game player uses 3 different skills in a game battle, such as the first target skill control A, the second target skill control B, and the third target skill control C, 3 independent touch position sequences are generated respectively, avoiding the confusion of operation characteristics of different target skill controls.
[0087] The touch position sequence of human operation has natural randomness, such as slight hand jitter when sliding, and the coordinates will fluctuate by 2 to 5 pixels; the touch position sequence of the external script often presents mechanicality, such as straight-line movement, uniform coordinate change, and no random fluctuation, etc., and the spatial feature difference between human operation and external script operation can be directly distinguished through the touch position sequence.
[0088] Step S102, according to the occurrence order and time of the touch press event and the touch release event of the target skill control, a touch time sequence event sequence is constructed.
[0089] Specifically, the operation sequence of the game player on the multiple target skill controls is converted into a touch timing event sequence, which depicts the time rhythm of the operation, such as skill release interval, combo sequence, time regularity of pressing or releasing, etc. The touch timing event sequence represents the occurrence order and time of touch press events and touch release events of each target skill control in each game battle. According to the operation sequence of the game player on the target skill controls, the time sequence of the occurrence of touch press events and touch release events of all target skill controls is recorded. For example, the game player first presses the first target skill control A, which is represented as DOWN_A, and releases the first target skill control A after 1 second, which is represented as UP_A; then presses the second target skill control B, which is represented as DOWN_B, and releases the second target skill control B after 0.5 seconds, which is represented as UP_B, and the touch timing event sequence is represented as [DOWN_A, UP_A, DOWN_B, UP_B]. The touch timing event sequence strictly corresponds to the timeline of each game, ensuring that the operation rhythm within the same game can be traced back, such as whether the skill combo interval of the game player in a certain game battle is abnormal.
[0090] More specifically, the type sequence rhythm of human operation has volatility, such as the combo interval may be 0.8 seconds, 1.2 seconds, 1.5 seconds, etc., with a large standard deviation; while the type sequence rhythm of the external hanging script is highly fixed, such as releasing skills with a fixed 1 second interval, with a standard deviation close to 0, etc.; through the touch timing event sequence, the abnormality of the operation time regularity can be captured, assisting in identifying automated combo and other cheating behaviors.
[0091] The touch position sequence reflects the spatial pattern of the operation trajectory, and the touch timing event sequence reflects the time pattern of the operation rhythm, which together form a complete depiction of skill operation. The touch position sequence and the touch timing event sequence are node attributes of the graph object in the cheating player identification model, and can be connected by calculating the sequence similarity between different players, so that the cheating player identification model can mine cheating groups with similar game behavior feature data, such as multiple accounts using the same external hanging script.
[0092] The core process of converting player skill operation from abstract behavior to structured data is through steps S101 to S102, and the output touch position sequence and touch timing event sequence directly determine the ability of the subsequent cheating player identification model to distinguish between human operation and cheating behavior; through fine-grained spatiotemporal feature collection, key evidence is provided for identifying external hanging scripts disguised as human operation.
[0093] Step S20, constructing a first graph object for training a cheating player identification model according to each historical game player sample in the historical game player sample set, constructing the new registered game player sample as a new node in the first graph object, updating the first graph object to construct a second graph object;
[0094] After obtaining the new registered game player sample set, a first graph object for training a cheating player identification model is constructed according to each historical game player sample in the historical game player sample set, the new registered game player sample is constructed as a new node in the first graph object, and the first graph object is updated to construct a second graph object; wherein the basic network architecture of the cheating player identification model is a graph neural network model.
[0095] In some embodiments, referring to Figure 3 Before the step of obtaining the new registered game player sample set, the method further comprises:
[0096] Step S201, obtaining a historical game player sample set, wherein the historical game player sample set includes a plurality of historical game player samples and their corresponding supervision labels, wherein the historical game player sample includes basic information of a game player and game behavior feature data; the supervision label represents whether the historical game player belongs to a cheating game player; the game behavior feature data includes a touch position sequence, a touch timing event sequence, a damage output value, a skill release frequency, a prop acquisition rate, and a task completion time length in each game battle; the basic information of the game player includes a game player identity account and identity account attribute information; the identity account attribute information includes account level, account registration time, registered IP address, device unique identifier, and the number of accounts logged in simultaneously by the device;
[0097] A historical game player sample set for training a graph neural network model is collected, which can be stored in a game server. A person skilled in the art can filter the historical game player samples by a preset time range or a preset number range. The historical game player sample set includes a plurality of historical game player samples and corresponding supervision labels. The historical game player sample includes basic information of a game player and game behavior feature data. The supervision label represents whether the historical game player belongs to a cheating game player. The game behavior feature data includes a touch position sequence, a touch timing event sequence, a damage output value, a skill release frequency, a prop acquisition rate, and a task completion time length in each game battle. The basic information of the game player includes a game player identity account and identity account attribute information. The identity account attribute information includes an account level, an account registration time, a registration IP address, a device unique identifier, and a number of accounts logged in by the device simultaneously. Each sample corresponds to a supervision label, which explicitly marks whether the game player is a cheating game player. "1" represents that the game player is a cheating game player, and "0" represents that the game player is a normal game player, which provides a basis for the graph neural network model to make a judgment.
[0098] In step S202, a first graph object for training a cheating player identification model is constructed according to each historical game player sample in the historical game player sample set. The nodes of the first graph object are constructed by the historical game player samples.
[0099] Based on the obtained historical game player sample set, a first graph object for training a model is constructed. Each historical game player sample is taken as an independent node in the graph object. Each node corresponds to a unique game player. The basic information and game behavior feature data of the game player are integrated in the node. This process converts scattered player data into a structured graph structure, enabling the model to analyze individual characteristics of a single player and laying a foundation for subsequent capture of associations between game players, thereby breaking through the limitations of single player analysis.
[0100] In step S203, the constructed first graph object is input into a preset cheating player identification model, and each historical game player sample is trained by using the corresponding supervision label until the cheating player identification model is trained to a convergent state, so as to determine the cheating player identification model trained to the convergent state.
[0101] The constructed first graph object is input into a preset graph neural network model, and the graph neural network model is trained in combination with the supervised labels of each historical game player sample. The graph neural network model preliminarily predicts the cheating probability of the game player based on the basic information of the game player of the node in the graph object and the game behavior feature data, determines a prediction result, compares the prediction result with the supervised label, calculates an error, and iteratively optimizes model parameters; the training is repeated until the model prediction error is stable within a preset range, at which time the model has mastered the law of identifying cheating behaviors; and finally, the obtained cheating player identification model trained to a convergent state can be used to accurately predict the cheating risk of a newly registered game player, thereby providing a core decision tool for game anti-cheating.
[0102] In some embodiments, referring to Figure 4 , the step of constructing a first graph object for training a cheating player identification model according to each historical game player sample in a historical game player sample set includes:
[0103] Step S2021, constructing a corresponding node in the first graph object based on the game player identity account of the historical game player sample in the historical game player sample set;
[0104] In order to build a basic skeleton for the graph object, the uniqueness and distinguishability of the nodes are ensured through the unique identity account, so as to avoid confusion of different player samples in the graph object, and to provide clear anchor points for subsequent edge connection and attribute association. An independent node in the graph object is created for each historical game player, so as to ensure that each node corresponds to a unique player entity. The identity account of the game player in the historical game player sample is taken as a unique identifier, and a corresponding node is created in the first graph object for each historical game player. For example, the identity account of the first game player A is Gamer_001, and a node marked as Gamer_001 is created in the graph object; the identity account of the second game player B is Gamer_002, and a node marked as Gamer_002 is created in the graph object, and so on, until the creation of all game player corresponding nodes is completed.
[0105] Step S2022, based on the identity account attribute information, the touch position sequence, the touch timing event sequence and the preset edge connection rule, judging whether the identity account attribute information, the touch position sequence and the touch timing event sequence of any two nodes of the first graph object satisfy the edge connection rule, and if so, establishing edge connection between the two nodes;
[0106] The features of the historical game player samples are analyzed to establish edge connections between nodes, capture potential associations between players, such as common characteristics of cheating groups, and the like; based on the identity account attribute information, the touch position sequence, the touch timing event sequence in the historical game player samples, and a preset edge connection rule, it is judged whether the identity account attribute information, the touch position sequence, and the touch timing event sequence of any two nodes of the first graph object satisfy the edge connection rule, and if so, an edge connection is established between the two nodes; for example, by judging that the device unique identifier of any two nodes in the first graph object is the same, the registered IP address is the same, the number of simultaneously logged-in accounts of the device exceeds a preset threshold, and the like, to determine whether an edge connection is established between the two nodes.
[0107] In step S2023, the game behavior feature data corresponding to each historical game player sample and the corresponding supervision label are introduced into the graph object, associated with the corresponding node in the graph object, to construct the first graph object.
[0108] The game behavior feature data of each historical game player sample is associated with the corresponding node as an attribute. For example, the Gamer_001 node binds its touch position sequence, touch timing event sequence, damage output value, skill release frequency, prop acquisition rate, and task completion time in each game battle; the corresponding supervision label of each historical game player sample is associated with the node as a core attribute, and the game player corresponding to the node is marked as a cheating game player, so as to provide the node with learnable features and training targets. The model learns individual cheating characteristics through node attributes, such as the touch position sequence, touch timing event sequence, damage output value, skill release frequency, prop acquisition rate, and task completion time of a game player in each game battle. The parameters are optimized through the supervision label to learn which feature combination is more likely to correspond to the cheating label, thereby providing complete input information for subsequent model training.
[0109] In further embodiments, please refer to Figure 5 Based on the identity account attribute information, the touch position sequence, the touch timing event sequence in the historical game player samples, and a preset edge connection rule, it is judged whether the identity account attribute information, the touch position sequence, and the touch timing event sequence of any two nodes of the first graph object satisfy the edge connection rule, and if so, an edge connection is established between the two nodes; for example, by judging that the device unique identifier of any two nodes in the first graph object is the same, the registered IP address is the same, the number of simultaneously logged-in accounts of the device exceeds a preset threshold, and the like, to determine whether an edge connection is established between the two nodes.
[0110] In step S20221, it is detected whether the device unique identifiers corresponding to any two nodes in the first graph object are the same, and if so, an edge connection is established between the two nodes.
[0111] determining whether the device unique identifiers of any two nodes in the first graph object are completely consistent, the device unique identifiers including mobile phone IMEI, mobile phone fingerprint, etc., if consistent, it means that the two game players have used the same device to log in to the game, which may be multiple accounts operated by the same person or a group sharing a cheating device, and an edge connection is established between the two nodes. For example, the device unique identifiers of the first game player A and the second game player B are both “Device_123”, and an edge connection is created between the corresponding nodes to mark the device sharing relationship of the two. This step captures the strong cheating signal of device reuse, and the cheating group often registers accounts in batches or operates synchronously through the same device, and the edge connection can make this association explicit, providing a basis for the model to identify group cheating.
[0112] Step S20222, comparing whether the registration IP addresses corresponding to any two nodes in the first graph object are the same, if the same, and the registration time interval between the game player identity accounts of the two nodes does not exceed the preset time threshold, an edge connection is established between the two nodes;
[0113] Comparing whether the registration IP addresses of any two nodes in the first graph object are the same or belong to the same local area network segment; if the registration IP addresses are the same, further calculate the registration time interval of the game player identity accounts corresponding to the two nodes, for example, the third game player C is registered on January 1, 2023 at 10:00, and the fourth game player D is registered on January 1, 2023 at 10:05, the registration time interval is 5 minutes; if the registration time interval does not exceed the preset time threshold, it means that the two accounts may be registered in batches in the same network environment within a short period of time, which may be the registration behavior of a studio or a cheating group, and an edge connection is established between the two nodes, wherein the preset time threshold can be 15 minutes or 30 minutes, etc. Those skilled in the art can determine the preset time threshold according to the actual business scenario as needed, which is not limited here.
[0114] Through this step, batch game accounts registered in a short time with the same registration IP address can be identified, which are often used for group cheating, and the edge connection can convert this implicit network environment association into an explicit relationship in the graph structure.
[0115] Step S20223, calculating the first similarity between the touch position sequences corresponding to any two nodes in the first graph object, and calculating the second similarity between the touch timing event sequences corresponding to the two nodes, if the first similarity and the second similarity both exceed the preset similarity threshold, an edge connection is established between the two nodes.
[0116] The first similarity between the touch position sequences corresponding to any two nodes in the first graph object can be calculated by a dynamic time warping (DTW) algorithm. The continuous position coordinate sequences, such as skill sliding trajectories, of two game players when operating skills are compared to obtain a trajectory similarity range of 0 to 1. The dynamic time warping (DTW) algorithm is an algorithm for measuring the similarity of two time series, especially suitable for comparing data of different lengths in time series data. It can nonlinearly align data on the time axis to minimize the difference between them. The dynamic time warping (DTW) algorithm finds the optimal matching path between two time series through dynamic programming techniques. This path is achieved by establishing a "distance matrix" between the two sequences, which represents the similarity between the two sequences. Then, the dynamic time warping (DTW) algorithm finds a path that minimizes the total distance, so that even if the two sequences are not synchronized in time, they can be matched closely.
[0117] Similarly, the second similarity between the touch timing event sequences corresponding to the two nodes can be calculated by a time interval distribution comparison method. The time sequences of two players pressing or releasing skill controls for target skills, such as the pressing duration of the first target skill control A and the release interval of the second target skill control B, are compared to obtain a time rhythm similarity range of 0 to 1. If both the first similarity and the second similarity exceed a preset similarity threshold, it means that the operation trajectories and rhythms of the two players are highly consistent, and they may use the same cheating script or team practice, and an edge connection is established between the two nodes. The preset similarity threshold can be 0.85, and those skilled in the art can determine the preset similarity threshold according to actual business scenarios as needed, which is not limited herein. For example, the skill touch trajectory similarity of the fifth game player E and the sixth game player F is 0.92, and the timing rhythm similarity is 0.88, both of which exceed the threshold of 0.85, so an edge connection is created between the corresponding nodes. Based on the homogenization of captured game behavior feature data as a cheating signal, the operation of a cheating script or a team practice is often highly consistent, and the edge connection can convert this behavior association into an explicit relationship in the graph structure, assisting the model in identifying hidden operation cheating.
[0118] From the above steps S20221 to S20223, by capturing the strong association at the hardware level through the device unique identifier, by capturing the bulk registration association at the network environment level through the registration IP address and the registration time interval, by capturing the homogenization association at the operation behavior level through the similarity of the touch position sequence and the touch timing event sequence, the three from different dimensions build the edge connection between nodes, so that the graph object can not only reflect the physical association of the players, but also reflect the behavior association, providing a complete association feature basis for the subsequent model to identify individual cheating and group cheating through the graph structure.
[0119] Step S30, inputting the second graph object into the cheating player identification model trained to a convergent state to predict a first risk probability that the new registered game player sample corresponds to a new registered game player belongs to a cheating game player;
[0120] According to each historical game player sample in the historical game player sample set, a first graph object for training the cheating player identification model is constructed, the new registered game player sample is constructed as a new node in the first graph object, and after updating the first graph object to construct a second graph object, the second graph object is input into the cheating player identification model trained to a convergent state to predict a first risk probability that the new registered game player sample corresponds to a new registered game player belongs to a cheating game player;
[0121] Specifically, based on the constructed first graph object, the new registered game player is integrated into the graph neural network model as a new node to form a complete graph structure containing historical and new information, that is, a second graph object, and then the trained model is used to analyze the individual characteristics and association relationships of the new registered game player in the entire network, and finally output the cheating risk probability.
[0122] Based on the new registered game player sample, a node is added in the first graph object, which contains the basic information and game behavior characteristic data of the new registered game player, such as the touch position sequence, the touch timing event sequence and the damage output of the first game battle.
[0123] Determine whether the new registered game player node and the historical game player node satisfy the preset edge connection rule, if the device unique identifier of the new registered game player is the same as that of a certain historical game player, an edge connection is established between them; if the registration IP address of the new registered game player is the same as that of a certain historical game player and the registration time interval is close, an edge connection is established; if the similarity of the touch position sequence and the touch timing event sequence in the new registered game player sample exceeds the preset similarity threshold value, an edge connection is established.
[0124] After the above steps, the first graph object containing only the historical game player sample is updated to the second graph object, the second graph object is input into the trained and converged cheating player identification model, the model simultaneously analyzes the individual characteristics of the newly registered game player and the associated characteristics of the newly registered game player and the historical game player, wherein the individual characteristics of the newly registered game player include whether the touch trajectory is mechanical, whether the damage output is abnormal, whether the device is associated with multiple game player identity accounts, etc.; the associated characteristics of the newly registered game player and the historical game player include whether the device is shared with a known cheating game player, whether the registration IP address is the same as that of a known cheating game player, whether the game behavior characteristic data is highly similar to a cheating group, etc. The cheating player identification model outputs the first risk probability of the newly registered game player belonging to a cheating player by integrating the above information, such as the first risk probability of 0.85, which represents an 85% cheating possibility of the game player.
[0125] From the above embodiments, it can be seen that the traditional method only analyzes the individual behavior of the newly registered game player, which is easy to miss the disguised cheating behavior with strong disguise, such as mild scripts and edge accounts in group cheating. However, the present application uses the associated information of the historical game player, if the newly registered game player has a strong connection with the known cheating node, such as sharing the device or having the same registration IP address, etc., the model will improve the risk assessment of the newly registered game player by the historical cheating label; the update of the graph object ensures that the newly registered game player is not evaluated in isolation, but as a member of the graph neural network, the risk probability is affected by the overall network characteristics, such as a new member of a cheating group, which will be identified due to the dense connection with the group node.
[0126] Further, by dynamically updating the graph structure and the graph neural network model inference, the newly registered game player is included in the associated network of the historical game player for evaluation, which utilizes the real-time behavior characteristics of the newly registered game player and the known risk information of the historical game player, and finally outputs the accurate cheating risk probability, which provides the core basis for the subsequent re-verification strategy and ban decision.
[0127] Step S40, determining a re-verification strategy corresponding to the newly registered game player according to the first risk probability, re-verifying the newly registered game player in a non-game battle link according to the re-verification strategy to determine a re-verification result, and deciding whether to ban the newly registered game player according to the re-verification result;
[0128] Step S50, cyclically executing the above steps until the newly registered game player exits the target game, so as to complete the cheating detection of the game player.
[0129] After the second graph object is input into the trained cheat player identification model to predict a first risk probability that the new registered game player belongs to a cheat game player, a re-verification strategy corresponding to the new registered game player is determined according to the first risk probability, the new registered game player is re-verified in a non-game battle link according to the re-verification strategy to determine a re-verification result, and it is determined whether to ban the new registered game player according to the re-verification result; the steps S10 to S40 are repeatedly executed until the new registered game player exits the target game, so as to complete the cheat detection of the game player.
[0130] Specifically, in order to avoid interrupting the game battle in the re-verification process, for example, a pop-up window in the middle of the game causes the player to make a mistake, and affects the fairness of the game battle; in order to ensure that the verification environment is stable, the player's attention is concentrated in the game battle, and the verification may fail due to possible misoperation. In the non-game battle link, the re-verification of the new registered game player is performed to determine the re-verification result, wherein the non-game battle link includes a matching waiting interface, a main menu interface, a settlement interface after the battle, etc. For example, a new registered game player is determined to be a medium-risk game player after the first game battle, and the game anti-cheat system pops up a verification of "clicking the specified skill icon in order" when the new registered game player returns to the main interface. If the new registered game player can complete it quickly, the cheat risk level is reduced; if it fails many times or operates mechanically, the cheat risk level is increased.
[0131] After the player passes all the verifications, such as a real person completing face recognition and successfully passing behavior verification, it is indicated that the risk probability may be a misjudgment, and the high-risk cheat game player mark is removed, and the new registered game player is continuously monitored and the subsequent game behavior feature data of the new registered game player is collected for re-evaluation. If the player cannot pass the verification, for example, face recognition is not matched, a sliding verification code cannot be completed, or obvious cheat traces are found in the verification, the new registered game player is determined to be a cheat game player, and the new registered game player is banned, for example, temporarily banned, account frozen, etc.
[0132] Some cheat behaviors of the new registered game player are hidden, which may disguise as normal in the early stage, enable a cheat tool in the later stage, or cheat only in some game battles. By calling a zero-trust security model, the cheat risk is detected in the whole cycle of the game, and the game behavior feature data is collected in each game battle to update the second graph object; the cheat risk probability is predicted by re-inputting the cheat risk identification model, and the re-verification process is triggered again until the new registered game player exits the game, so as to ensure that the new registered game player is in risk control at every moment in the game.
[0133] In some embodiments, please refer to Figure 6, determining a re-verification strategy corresponding to the new registered game player according to the first risk probability, performing re-verification on the new registered game player in a non-game battle link according to the re-verification strategy to determine a re-verification result, and determining whether to ban the new registered game player according to the re-verification result, comprising:
[0134] Step S401, calling a preset zero trust security model, when the first risk probability of the new registered game player corresponding to the new registered game player sample belongs to the cheating game player is lower than the preset first risk probability threshold, the new registered game player is determined as a low-risk cheating game player, and the new registered game player is authorized to continue playing the game;
[0135] Step S402, calling the cheating player identification model to continuously monitor the game behavior feature data of the new registered game player to update the first risk probability to determine a second risk probability, when the second risk probability falls within a preset second risk probability interval, the new registered game player is determined as a medium-risk cheating game player;
[0136] Step S403, triggering the game anti-cheating system to send a sliding verification request to the new registered game player in a non-battle link of the game, when the game anti-cheating system detects that the sliding verification result returned by the new registered game player is passed, the new registered game player is authorized to continue playing the game, and when the game anti-cheating system detects that the sliding verification result returned by the new registered game player is not passed, the new registered game player is banned for a first preset time length;
[0137] Step S404, when the game anti-cheating system detects that the sliding verification result returned by the new registered game player is passed, the game anti-cheating system continuously monitors the game behavior feature data of the new registered game player to update the second risk probability to determine a third risk probability after authorizing the new registered game player to continue playing the game, when the third risk probability falls within a third risk probability interval, the new registered game player is determined as a high-risk cheating game player;
[0138] Step S405, triggering the game anti-cheating system to send a biometric feature verification request to the new registered game player in a non-battle link of the game, so that the game anti-cheating system detects that the biometric feature verification result returned by the new registered game player is passed, and the new registered game player is authorized to continue playing the game, and if the biometric feature verification result is not passed, the new registered game player is banned for a second preset time length, to complete the cheating detection of the game player, wherein the second preset time length is greater than the first preset time length; wherein the biometric features include user face features or user iris features.
[0139] Specifically, the re-verification strategy is determined according to a first risk probability that the newly registered game player belongs to a cheating game player, the first risk probability that the newly registered game player belongs to a cheating game player reflects the possibility of cheating of the newly registered game player, different risk probabilities correspond to different intensity of re-verification strategies, the core is that the higher the risk is, the more strict the verification is, and the influence on normal game players is avoided by "one size fits all", wherein, when the first risk probability that the newly registered game player belongs to a cheating game player is less than a preset first risk probability threshold, the game behavior feature data of the newly registered game player is highly matched with the normal game player sample, and no additional verification is needed, only regular monitoring is maintained, and the cheating player identification model is called to continuously monitor the game behavior feature data of the newly registered game player, wherein the first risk probability threshold can be 25% or 30%, etc., and the first risk probability threshold can be determined by the person skilled in the art according to the actual business scene as needed, which is not limited here.
[0140] The first risk probability is updated by continuously monitoring the game behavior feature data of the newly registered game player by calling the cheating player identification model to determine a second risk probability, when the second risk probability that the newly registered game player belongs to a cheating game player falls within a preset second risk probability interval, the newly registered game player is determined as a medium-risk cheating game player, which indicates that the newly registered game player has slight abnormalities, for example, part of the touch position sequence and / or touch timing event sequence is close to the script feature, but does not completely match, which can trigger a light verification, for example, a sliding verification code or a graphical click verification is popped up during a non-battle link, and whether the newly registered game player is operated by a real person is verified; wherein the second risk probability interval can be between 30% and 70%, etc., and the second risk probability interval can be determined by the person skilled in the art according to the actual business scene as needed. When the game anti-cheating system detects that the sliding verification result returned by the newly registered game player is passed, the game anti-cheating system authorizes the newly registered game player to continue playing the game, and when the game anti-cheating system detects that the sliding verification result returned by the newly registered game player is not passed, the newly registered game player is banned for a first preset time length, wherein the first preset time length can be 24 hours, 48 hours or 72 hours, etc., and the first preset time length can be determined by the person skilled in the art according to the actual business scene as needed, which is not limited here.
[0141] When the game anti-cheating system detects that the sliding verification result returned by the newly registered game player is passed, the newly registered game player is authorized to continue playing the game, and the cheating player identification model is called to continuously monitor the game behavior feature data of the newly registered game player to update the second risk probability to determine a third risk probability. When the third risk probability falls within a third risk probability interval, the newly registered game player is determined to be a high-risk cheating game player. The game behavior feature data of the newly registered game player is highly similar to the known cheating game player sample, for example, the touch position has no jitter, the touch timing is fixed, etc. At this time, strict verification needs to be triggered for the newly registered game player, such as requiring face recognition, device environment secondary detection to check whether there is a running external script, and even manual review of operation video, etc. If the game anti-cheating system detects that the biological feature verification result returned by the newly registered game player is passed, the newly registered game player is authorized to continue playing the game. If the biological feature verification result is not passed, the newly registered game player is banned for a second preset time length to complete the cheating detection of the game player. The second preset time length is greater than the first preset time length, and the third risk probability interval can be between 70% and 100%, etc. The second preset time length can be 7 days, 10 days, or 15 days, etc. A person skilled in the art can determine the second preset time length according to the actual business scenario as needed, which is not limited here.
[0142] As can be seen from the above steps S401 to S405, through the logic of risk probability, verification strategy, disposal decision, and cyclic monitoring, closed-loop management of the newly registered game player from risk identification to final disposal is realized, which not only accurately attacks cheating behavior, but also reduces the interference to normal game players. The predicted cheating risk probability is converted into an executable verification action, and the risk control of the player in the whole game cycle is ensured through continuous circulation, that is, even if the cheating behavior is not identified in the early stage, the abnormality in the later stage can still be disposed of in time.
[0143] As can be seen from the above embodiments, compared with the prior art, the present application solves the problems in the prior art that the newly registered game player lacks historical behavior data in the initial registration period, the identification ability of external scripts is weak, and the newly registered game player may bypass the initial anti-cheating detection after the initial login verification, and the like. The present application includes but is not limited to the following beneficial effects:
[0144] Firstly, the game player cheating detection method of the application can distinguish normal operation and cheating behavior more accurately by collecting touch position sequence and touch timing event sequence, because the operation of simulating click type plug-ins is mechanical, while human operation has natural fluctuations. The newly registered game player sample is added as a new node to the graph object constructed by the historical game player samples, and the behavior association of the newly registered game player with the historical normal game player or the historical cheating game player is mined through the graph neural network. Even if the behavior data of the newly registered game player is limited, the experience of the historical data can also be used to assist in judgment, and the misjudgment caused by insufficient single data can be reduced. It can significantly improve the accuracy of cheating detection of newly registered game players, and greatly reduce the risk of false detection and missed detection.
[0145] Secondly, the game player cheating detection method of the application can solve the problem of insufficient historical data of newly registered game players, enhance the initial recognition ability, and continuously monitor through the zero trust security model. The traditional logic of "one-time verification and trust" in game cheating detection is broken, and the newly registered game player who has logged in is continuously monitored throughout the cycle. Game behavior data is collected in each game, and sample information is dynamically supplemented. The newly registered game player node is added to the graph object constructed by the historical game player samples in real time, and the historical game player provides a reference for risk assessment of the newly registered game player. For example, if the touch position sequence and touch timing event sequence of the newly registered game player are highly similar to those of the historical cheating player, even if the data is small, the model can quickly identify the risk, and can effectively make up for the short board of insufficient behavior data of newly registered game players. The cheating behavior can be effectively identified at the initial stage of registration, and the problem of new account brushing props can be prevented.
[0146] Thirdly, the game player cheating detection method of the application can accurately crack black and gray production batch cheating accounts and maintain game economic security. Black and gray production creates new accounts in batches through automated tools, brushes resources with plug-ins, and destroys the game economy. The prior art is difficult to identify such "group cheating" behavior. The application can capture the common characteristics of batch accounts through the analysis of the graph object by the graph neural network model. The touch mode and operation timing of batch cheating accounts are often highly consistent, and are represented as "strong association" between new nodes in the graph object. The graph neural network can identify "batch similar behavior clusters" through the association strength between nodes, so as to lock multiple cheating accounts at one time, rather than judging individual accounts in isolation, greatly improving the efficiency of cracking black and gray production batch cheating.
[0147] Fourthly, the game player cheating detection method of the application can effectively deal with the evasion behavior of initial hiding and later cheating, realize whole-cycle cheating prevention and control, and the existing technology causes initial missed detection because some cheaters hide behavior at initial login verification and enable cheating tools in later period. The zero trust security model of the application does not depend on the initial verification result, but cyclically executes data collection, graph object updating, risk prediction and re-verification process in the whole game process of the player. Even if the player hides cheating behavior in the first game match, when the cheating tool is enabled in the subsequent game match, the abnormal change of the touch feature will be captured in real time, the updated graph object will reflect this change, the model can re-predict the risk and trigger re-verification, and ensure that the later cheating behavior is discovered in time.
[0148] Fifthly, if the verification is forced in the game match link, the player's operation may be interrupted and the experience is affected. The application performs re-verification in the non-game match link, for example, performs verification in the matching gap, settlement interface and other periods, which not only guarantees the effectiveness of the verification, but also avoids the interference in the match process, balances the anti-cheating demand and the player experience.
[0149] Sixthly, the application can greatly improve the detection robustness and resist external plug-in feature variation. The external plug-in developer will continuously update the script to avoid detection, for example, adjust the touch timing, and increase the slight random fluctuation. The touch position sequence and touch timing event sequence of the application directly reflect the essential law of operation, that is, the bottom difference between human operation and mechanical operation, rather than surface features. Even if the external plug-in script fine-tunes the parameters, the mechanical essence will still be captured by the graph neural network, for example, the abnormality of deep features such as fluctuation range and timing entropy value, so the anti-interference ability to feature variation is stronger and the robustness is higher.
[0150] Further, the application solves the problems of low accuracy of cheating detection for new registered game players, insufficient behavior data, difficulty in batch cheating recognition, and missed detection of later cheating in the prior art by using the zero trust security model for continuous monitoring, graph neural network correlation analysis and dynamic risk assessment, and greatly improves the ability to resist external plug-in script variation, which provides more reliable guarantee for the fairness and economic security of mobile games.
[0151] Please refer to Figure 7, a game player cheating detection device provided for adapting to one of the purposes of the application, comprising a sample set acquisition module 1100, a graph object construction module 1200, a risk probability determination module 1300, a cheating ban control module 1400, and a cheating detection cycle module 1500. The sample set acquisition module 1100 is configured to call a preset zero trust security model to continuously monitor newly registered game players who have passed login verification, and acquire a new registered game player sample set, wherein the new registered game player sample set comprises new registered game player samples corresponding to a plurality of new registered game players, each new registered game player sample comprises basic information of a game player and game behavior feature data, the game behavior feature data comprises a touch position sequence and a touch timing event sequence in each game battle, the touch position sequence represents a plurality of touch positions of the game player in the process from a touch press event to a touch release event of each target skill control in each game battle, and the touch timing event sequence represents the occurrence order and time of the touch press event and the touch release event of each target skill control in each game battle. The graph object construction module 1200 is configured to construct a first graph object for training a cheating player identification model according to each historical game player sample in a historical game player sample set, construct the new registered game player sample into a new node in the first graph object, and update the first graph object to construct a second graph object. The risk probability determination module 1300 is configured to input the second graph object into a cheating player identification model trained to a convergent state, to predict a first risk probability that a new registered game player corresponding to the new registered game player sample is a cheating game player. The cheating ban control module 1400 is configured to determine a re-verification strategy of the new registered game player according to the first risk probability, perform re-verification on the new registered game player in a non-game battle link according to the re-verification strategy to determine a re-verification result, and decide whether to ban the new registered game player according to the re-verification result. The cheating detection cycle module 1500 is configured to cyclically execute the above steps until the new registered game player exits the target game, to complete the cheating detection of the game player.
[0152] On the basis of any embodiment of the application, please refer to Figure 8 Another embodiment of the application further provides an electronic device, which can be implemented by a computer device, such as Figure 8As shown, the internal structure diagram of the computer device is shown. The computer device includes a processor, a computer readable storage medium, a memory and a network interface connected by a system bus. Among them, the computer readable storage medium of the computer device stores an operating system, a database and computer readable instructions, the database can store control information sequence, and the computer readable instructions are executed by the processor to enable the processor to implement a game player cheating detection method. The processor of the computer device is used to provide computing and control capability to support the operation of the entire computer device. The memory of the computer device can store computer readable instructions, and the computer readable instructions are executed by the processor to enable the processor to execute the game player cheating detection method of the application. The network interface of the computer device is used to connect and communicate with the terminal. Those skilled in the art can understand, Figure 8 The structure shown in the above embodiment is only a block diagram of part of the structure related to the scheme of the application, and does not constitute a limitation on the computer device to which the scheme of the application is applied. The specific computer device can include more or fewer components than those shown in the figure, or combine certain components, or have a different component arrangement.
[0153] The processor in the embodiment is used to execute the specific functions of each module in Figure 7 The memory stores the program codes and various data required for executing the above-mentioned modules. The network interface is used for data transmission between the user terminal or the server. The memory in the embodiment stores the program codes and data required for executing all modules in the game player cheating detection device of the application, and the server can call the program codes and data of the server to execute the functions of all modules.
[0154] The application also provides a storage medium storing computer readable instructions, which are executed by one or more processors to enable the one or more processors to execute the steps of the game player cheating detection method described in any embodiment of the application.
[0155] The application also provides a computer program product including computer programs / instructions, which are executed by one or more processors to implement the steps of the game player cheating detection method described in any embodiment of the application.
[0156] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiments of the application can be completed by a computer program instructing relevant hardware, and the computer program can be stored in a computer readable storage medium. When the program is executed, the processes of the above-mentioned embodiments of the methods can be included. The storage medium can be a computer readable storage medium such as a magnetic disc, an optical disc, a read-only memory (ROM), or a random access memory (RAM).
[0157] The above only describes some embodiments of the application. It should be pointed out that those skilled in the art can make some improvements and refinements without departing from the principles of the application, and these improvements and refinements should also be considered as the protection scope of the application.
Claims
1. A method for detecting cheating by game players, characterized in that, include: A preset zero-trust security model is invoked to continuously monitor newly registered game players who have passed login verification, and to obtain a sample set of newly registered game players. The sample set of newly registered game players includes multiple samples of newly registered game players. Each sample of newly registered game players includes the basic information of the game player and game behavior feature data. The game behavior feature data includes the touch position sequence and touch timing event sequence in each game. The touch position sequence represents multiple touch positions of the game player in each game from the touch press event to the touch release event of each target skill control. The touch timing event sequence represents the order and time of occurrence of the touch press event and touch release event of each target skill control in each game. A first graph object is constructed based on each historical game player sample in the historical game player sample set to train a cheating player identification model. The newly registered game player sample is constructed as a new node in the first graph object, and the first graph object is updated to construct a second graph object. The second image object is input into the cheating player identification model that has been trained to convergence, so as to predict the first risk probability that the newly registered game player corresponding to the newly registered game player sample is a cheating game player; Based on the first risk probability, a re-verification strategy corresponding to the newly registered game player is determined. Based on the re-verification strategy, the newly registered game player is re-verified in non-game battles to determine the re-verification result. Based on the re-verification result, a decision is made on whether to ban the newly registered game player. The above steps are repeated until the newly registered player exits the target game, thus completing the cheat detection.
2. The game player cheating detection method according to claim 1, characterized in that, The steps for determining the sequence of touch positions and the sequence of touch timing events in each game include: In response to the touch press event of the game player on the target skill control of the target game, the game player obtains multiple touch positions in each game from the touch press event to the touch release event of the target skill control according to a preset time granularity, so as to construct the touch position sequence corresponding to each target skill control; A touch timing event sequence is constructed based on the order and timing of the touch press and release events of the target skill control.
3. The game player cheating detection method according to claim 1, characterized in that, The steps of determining a re-verification strategy corresponding to the newly registered game player based on the first risk probability, re-verifying the newly registered game player in non-game battles according to the re-verification strategy to determine the re-verification result, and deciding whether to ban the newly registered game player based on the re-verification result include: The preset zero-trust security model is invoked. When the first risk probability of the newly registered player corresponding to the newly registered player sample being a cheating player is lower than the preset first risk probability threshold, the newly registered player is identified as a low-risk cheating player and authorized to continue playing the game. The cheating player identification model is invoked to continuously monitor the game behavior characteristics data of the newly registered game player and update the first risk probability to determine the second risk probability. When the second risk probability falls into the preset second risk probability range, the newly registered game player is identified as a medium-risk cheating game player. The game's anti-cheat system is triggered to send a swipe verification request to the newly registered player during non-combat phases of the game. If the anti-cheat system detects that the swipe verification result returned by the newly registered player is successful, it authorizes the newly registered player to continue playing the game. If the anti-cheat system detects that the swipe verification result returned by the newly registered player is unsuccessful, it bans the newly registered player for a first preset duration. When the game anti-cheating system detects that the sliding verification result returned by the newly registered game player is passed, it authorizes the newly registered game player to continue playing the game. Then, it calls the cheating player identification model to continuously monitor the game behavior feature data of the newly registered game player and update the second risk probability to determine the third risk probability. When the third risk probability falls into the third risk probability range, the newly registered game player is identified as a high-risk cheating game player. The game's anti-cheating system is triggered to send a biometric verification request to the newly registered player during non-combat phases of the game. If the anti-cheating system detects that the biometric verification result returned by the newly registered player is successful, it authorizes the newly registered player to continue playing the game. If the biometric verification result is unsuccessful, the newly registered player is banned for a second preset duration to complete the cheating detection. The second preset duration is longer than the first preset duration. The biometric features include user facial features or user iris features.
4. The game player cheating detection method according to claim 1, characterized in that, Before obtaining a sample set of newly registered game players, the following steps are included: A historical player sample set is obtained, comprising multiple historical player samples and their corresponding supervisory labels. The historical player samples include basic player information and game behavior characteristic data. The supervisory labels indicate whether the historical player is a cheater. The game behavior characteristic data includes touch position sequences, touch timing event sequences, damage output values, skill release frequency, item acquisition rate, and task completion time in each game. The basic player information includes the player's account and account attribute information. The account attribute information includes account level, account registration time, registration IP address, device unique identifier, and the number of accounts simultaneously logged in on the device. A first graph object for training a cheater identification model is constructed based on each historical game player sample in the historical game player sample set, wherein the nodes of the first graph object are constructed using the historical game player samples. The constructed first graph object is input into the preset cheating player identification model, and the model is trained using the supervision label corresponding to each historical game player sample until the cheating player identification model is trained to a convergent state, so as to determine the cheating player identification model that has been trained to a convergent state.
5. The game player cheating detection method according to claim 4, characterized in that, The steps of constructing a first graph object for training a cheater detection model based on each historical player sample in the historical player sample set include: Based on the game player identity accounts of the historical game player samples in the historical game player sample set, construct the corresponding nodes in the first graph object; Based on the identity account attribute information, touch position sequence, touch timing event sequence and preset edge connection rules in the historical game player sample, determine whether the identity account attribute information, touch position sequence and touch timing event sequence between any two nodes of the first graph object meet the edge connection rules. If they do, establish an edge connection between the two nodes. The game behavior feature data corresponding to each historical game player sample and its corresponding supervision label are imported into the graph object and associated with the corresponding nodes in the graph object to construct the first graph object.
6. The game player cheating detection method according to claim 5, characterized in that, Based on the identity account attribute information, touch position sequence, touch timing event sequence, and preset edge connection rules in the historical game player sample, the step of determining whether the identity account attribute information, touch position sequence, and touch timing event sequence between any two nodes of the first graph object satisfy the edge connection rules, and if so, establishing an edge connection between the two nodes, includes: Detect whether the unique device identifiers corresponding to any two nodes in the first graph object are the same. If they are the same, establish an edge connection between the two nodes. Compare whether the corresponding registered IP addresses of any two nodes in the first graph are the same. If they are the same, and the registration time interval between the game player identity accounts of the two nodes does not exceed a preset time threshold, then establish an edge connection between the two nodes. Calculate and determine the first similarity between the touch position sequences corresponding to any two nodes in the first graph object, calculate and determine the second similarity between the touch timing event sequences corresponding to the two nodes, and if both the first similarity and the second similarity exceed a preset similarity threshold, then establish an edge connection between the two nodes.
7. The game player cheating detection method according to any one of claims 1 to 6, characterized in that, The newly registered game players are defined as game players who have participated in fewer than a preset number of game battles or whose registration time is less than a preset registration duration; the basic network architecture of the cheating player identification model is a graph neural network model.
8. A device for detecting cheating in games, characterized in that, include: The sample set acquisition module is configured to call a preset zero-trust security model to continuously monitor newly registered game players who have passed login verification and acquire a sample set of newly registered game players. The sample set of newly registered game players includes multiple newly registered game player samples corresponding to multiple newly registered game players. Each newly registered game player sample includes the game player's basic information and game behavior feature data. The game behavior feature data includes the touch position sequence and touch timing event sequence in each game. The touch position sequence represents multiple touch positions of the game player in each game during the process from touch press event to touch release event of each target skill control. The touch timing event sequence represents the order and time of occurrence of touch press event and touch release event of each target skill control in each game. The graph object construction module is configured to construct a first graph object for training a cheating player identification model based on each historical game player sample in the historical game player sample set, construct the newly registered game player sample as a new node in the first graph object, and update the first graph object to construct a second graph object. The risk probability determination module is configured to input the second graph object into a cheating player identification model that has been trained to convergence, so as to predict the first risk probability that the newly registered game player corresponding to the newly registered game player sample belongs to the cheating game player. The cheating ban control module is configured to determine the re-verification strategy corresponding to the newly registered game player based on the first risk probability, re-verify the newly registered game player in non-game battles according to the re-verification strategy to determine the re-verification result, and decide whether to ban the newly registered game player based on the re-verification result. The cheat detection loop module is configured to repeatedly execute the above steps until the newly registered game player exits the target game, thereby completing the cheat detection of the game player.
9. An electronic device comprising a central processing unit and a memory, characterized in that, The central processing unit is used to invoke and run a computer program stored in the memory to perform the steps of the method as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, It stores, in the form of computer-readable instructions, a computer program implemented according to any one of claims 1 to 7, which, when invoked by a computer, executes the steps included in the corresponding method.
Citation Information
Patent Citations
Game testing method and device, electronic equipment and computer readable storage medium
CN118838800A
Secure data channel in a networked gaming system
US20200204368A1