Computer-implemented data processing method, system, device and program product
Patent Information
- Application Number
- CN202611010290.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-08
- Publication Date
- 2026-09-25
AI Technical Summary
[0003]针对现有技术存在的反作弊检测计算资源消耗大且隐私合规风险高的问题,本申请通过一种计算机实施的数据处理方法、系统、设备及程序产品,实现基于轻量级时序特征的游戏作弊行为(诸如自瞄和透视等)的高准确度自动检测
[0021]本申请提供的技术方案,通过仅依赖服务器端记录的轻量级时序特征进行检测,无需采集和处理高维游戏画面数据,从数据源头上大幅降低了计算资源消耗,并且彻底避免了因采集画面数据带来的用户隐私合规风险。同时,本申请构建了规则预筛选、频谱特征过滤和模型分类相结合的三层级渐进式检测架构,利用规则层快速剔除无关数据、频谱层过滤正常手动操作、模型层精准识别异常模式,这种由粗到细的分层处理机制在保证高检测准确度的同时,有效平衡了计算效率。此外,本申请创新性地提出了相机射线-目标距离特征和关键帧命中统计判定方法,将抽象的作弊行为转化为可量化的几何和时序指标,不仅提升了模型对自瞄和透视行为的敏感度,还为检测结果提供了可解释的物理依据,增强了反作弊系统的可信度和可维护性。
Smart Images

Figure CN122806083A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer application technology, and in particular to a computer-implemented data processing method, system, device, and program product. Background Technology
[0002] In online games, especially first-person shooter (FPS) games, cheating behaviors such as aimbots and wallhacks severely undermine game fairness. Existing anti-cheat detection solutions mainly fall into two categories: one is traditional methods based on client integrity checks and memory injection detection, which struggle to identify "soft cheating" behaviors that don't modify game files; the other is detection methods based on behavioral analysis. Among these, solutions based on manual rules have poor generalization capabilities and struggle to adapt to constantly evolving cheating variants, while deep learning-based solutions typically require collecting large amounts of game screen data or other high-dimensional features. This not only consumes enormous server computing resources but also poses user privacy compliance risks. Therefore, how to achieve highly accurate automatic detection of cheating behaviors using only lightweight temporal features on the server side without relying on high-dimensional screen data is a pressing technical problem that needs to be solved. Summary of the Invention
[0003] To address the issues of high computational resource consumption and high privacy compliance risks in existing anti-cheating detection technologies, this application proposes a computer-implemented data processing method, system, device, and program product that enables highly accurate automatic detection of game cheating behaviors (such as aimbots and wallhacks) based on lightweight temporal features.
[0004] To achieve the above objectives, the present invention adopts the following technical solution:
[0005] In a first aspect, this application provides a computer-implemented data processing method, the method comprising: receiving lightweight feature data of a target object in a target game by one or more processors, wherein the lightweight feature data is game frame data acquired by a game server and includes static feature data and dynamic feature data; selecting first candidate feature data from the lightweight feature data based on the static feature data in the lightweight feature data and using a pre-screening algorithm by the one or more processors; selecting second candidate feature data from the first candidate feature data based on the dynamic feature data in the first candidate feature data and using a spectral feature screening algorithm by the one or more processors; and classifying the second candidate feature data for anomalies by the one or more processors using a pre-trained model.
[0006] The above solution constructs a three-tiered progressive detection architecture of "rule pre-screening - spectrum filtering - model classification". It relies only on the lightweight frame data already available on the server for layer-by-layer analysis, avoiding the collection and processing of high-dimensional image data. This significantly reduces the consumption of computing resources and avoids privacy compliance risks while ensuring detection accuracy.
[0007] In one possible implementation of the first aspect above, the static feature data is used to describe the contextual features of the target object in a single game match, and includes one or more of the following features: whether the target object activated a scope, whether the target object fired, and whether the target object caused damage to a hit target during the game match; and the dynamic feature data is used to describe the time-related features of the target object in the single game match, and includes one or more of the following features: the position of the game camera associated with the target object, the orientation of the game camera, the position of the hit target, the instantaneous movement speed of the target object in a single game frame of the game match, and the number of shots fired by the target object, the number of hits by the target object, and the hit rate of the target object within several game frames of the game match.
[0008] The above scheme provides a structured data foundation for subsequent hierarchical detection by clearly distinguishing between static features that describe contextual features and dynamic features that describe time-related features. This enables different detection levels to make targeted use of the most relevant feature dimensions, thereby improving the data utilization efficiency of the overall detection process.
[0009] In one possible implementation of the first aspect above, filtering the first candidate feature data from the lightweight feature data further includes: based on the context features described by the static feature data in the lightweight feature data, removing data from the lightweight feature data that describes one or more of the following features: during the game, the target object did not activate the scope; and during the game, the target object activated the scope and fired, but the target object did not cause damage to the hit object.
[0010] The above solution utilizes game logic rules to quickly eliminate data that clearly does not meet the prerequisites for aimbot or wallhack cheating (such as invalid shots that are not aimed or do not cause damage), achieving efficient data pruning at the very beginning of the detection chain and significantly reducing the processing load of subsequent computationally complex steps.
[0011] In one possible implementation of the first aspect above, selecting the second candidate feature data from the first candidate feature data further includes: arranging, in chronological order, a first subset of the time-related features described by the dynamic feature data in the first candidate feature data to generate a corresponding first feature sequence; converting the multiple first feature sequences into corresponding time spectrograms using short-time Fourier transform; comparing the spectral features of the multiple time spectrograms with the corresponding abnormal spectral features and determining the similarity difference value; and removing data from the first candidate feature data whose similarity difference value is greater than a first threshold.
[0012] The above scheme converts one-dimensional time-series signals to the time-frequency domain for analysis. It utilizes the physical difference that the mechanical operations generated by auto-aiming and wallhack lock programs have fixed frequency characteristics in the frequency domain, while normal player operations exhibit random wide-band characteristics. By comparing the spectrum similarity, it effectively filters out normal manual operation data and further narrows down the range of suspicious samples.
[0013] In one possible implementation of the first aspect described above, the first subset features include one or more of the following features: the position of the game camera, the orientation of the game camera, and the instantaneous movement speed of the target object in a single game frame of the game match.
[0014] The above scheme selects camera movement and character movement features, which are most sensitive to cheating behavior, as the objects of spectrum analysis because these features directly reflect the player's aiming control mode and can maximize the discriminative power of the spectrum filtering layer.
[0015] In one possible implementation of the first aspect above, anomaly classification of the second candidate feature data further includes: calculating the distance between the hit object and the ray of the game camera in a single game frame of the game; arranging the second subset features of the time-related features described by the dynamic feature data of the first candidate feature data and the distance in chronological order to generate a second feature sequence; inputting the second feature sequence into the pre-trained model; and receiving the anomaly classification result output by the pre-trained model.
[0016] The above scheme innovatively introduces the geometric feature of "camera ray-target distance", which transforms the abstract magnetic attraction or perspective locking cheating behavior into a quantifiable time-series indicator. Furthermore, by combining multi-dimensional dynamic features with the pre-trained model, the model can capture abnormal spatiotemporal patterns of continuous close proximity to the target that are difficult for normal players to maintain, thereby improving classification accuracy.
[0017] In one possible implementation of the first aspect above, the second subset features include one or more of the following features: the orientation of the game camera, the instantaneous movement speed of the target object, and the hit rate of the target object over several game frames in the game.
[0018] The above scheme selects feature combinations directly related to aiming stability and shooting effectiveness to input into the model, avoiding the interference of redundant features on model training. This helps the model focus on the core representation of cheating behavior and enables the model to learn long-range dependencies across feature dimensions while capturing local features, thereby optimizing for specific cheating detection tasks.
[0019] In one possible implementation of the first aspect above, the method further includes: for data with abnormal results, identifying keyframes in the game, wherein frames with a distance less than a second threshold and one or more frames before and after them are identified as keyframes; calculating the number of hits of the target object during the keyframes of the game; comparing the number of hits with the number of normal hits and determining a similarity difference value; and identifying data with a similarity difference value greater than a third threshold as abnormal data.
[0020] The above scheme adds a statistical interpretability verification step after model determination. By quantifying the hit performance during keyframes and comparing it with the normal baseline, it provides intuitive physical evidence to support the model's classification results, enhancing the credibility and traceability of the detection results.
[0021] The technical solution provided in this application detects cheating by relying solely on lightweight temporal features recorded on the server side, eliminating the need to collect and process high-dimensional game screen data. This significantly reduces computational resource consumption at the data source and completely avoids user privacy compliance risks associated with collecting screen data. Furthermore, this application constructs a three-tiered progressive detection architecture combining rule pre-screening, spectral feature filtering, and model classification. The rule layer quickly removes irrelevant data, the spectral layer filters normal manual operations, and the model layer accurately identifies abnormal patterns. This coarse-to-fine layered processing mechanism effectively balances computational efficiency while ensuring high detection accuracy. In addition, this application innovatively proposes a camera ray-target distance feature and keyframe hit statistics method, transforming abstract cheating behaviors into quantifiable geometric and temporal indicators. This not only improves the model's sensitivity to aimbot and wallhack behaviors but also provides interpretable physical evidence for the detection results, enhancing the credibility and maintainability of the anti-cheating system.
[0022] Secondly, this application provides a data processing system, the system comprising: one or more processors; and one or more memories, the one or more memories being coupled to the one or more processors and storing instructions, the instructions, when executed by the one or more processors, causing the one or more processors to perform data processing operations, the operations comprising: receiving lightweight feature data of a target object in a target game, wherein the lightweight feature data is game frame data acquired by a game server and includes static feature data and dynamic feature data; based on the static feature data in the lightweight feature data and using a pre-screening algorithm, selecting first candidate feature data from the lightweight feature data; based on the dynamic feature data in the first candidate feature data and using a spectral feature screening algorithm, selecting second candidate feature data from the first candidate feature data; and using a pre-trained model to perform anomaly classification on the second candidate feature data.
[0023] Thirdly, this application provides a non-transitory computer-readable medium storing instructions that, when executed by one or more processors, cause the one or more processors to perform data processing operations, the operations including: receiving lightweight feature data of a target object in a target game, wherein the lightweight feature data is game frame data acquired by a game server and includes static feature data and dynamic feature data; filtering out first candidate feature data from the lightweight feature data based on the static feature data and using a pre-screening algorithm; filtering out second candidate feature data from the first candidate feature data based on the dynamic feature data and using a spectral feature filtering algorithm; and classifying the second candidate feature data for anomalies using a pre-trained model.
[0024] Fourthly, this application provides a computer program product implemented on a non-transitory computer-readable medium and including instructions that, when executed by one or more processors, cause the one or more processors to perform data processing operations, the operations including: receiving lightweight feature data of a target object in a target game, wherein the lightweight feature data is game frame data acquired by a game server and includes static feature data and dynamic feature data; filtering out first candidate feature data from the lightweight feature data based on the static feature data and using a pre-screening algorithm; filtering out second candidate feature data from the first candidate feature data based on the dynamic feature data and using a spectral feature filtering algorithm; and classifying the second candidate feature data for anomalies using a pre-trained model.
[0025] The beneficial effects of the second to fourth aspects can be found in the first aspect and the beneficial effects of any possible implementation of the first aspect, and will not be repeated here. Attached Figure Description
[0026] Figure 1 This is a schematic diagram of the data processing method in the embodiments of this application;
[0027] Figure 2A This is a schematic diagram of the target object velocity timing signal in an embodiment of this application;
[0028] Figure 2B This is a schematic diagram of the camera orientation timing signal in an embodiment of this application;
[0029] Figure 2C This is a schematic diagram of the time spectrum corresponding to the camera pitch angle timing signal in an embodiment of this application;
[0030] Figure 3 This is a schematic diagram of the camera ray-target distance geometry in an embodiment of this application;
[0031] Figure 4A This is a schematic diagram comparing the aiming curves of cheating players and normal players in an embodiment of this application;
[0032] Figure 4B This is a schematic diagram of the target distance timing signal of the cheating player in an embodiment of this application;
[0033] Figure 4C This is a schematic diagram of the target distance timing signal for a normal player in an embodiment of this application;
[0034] Figure 5A This is a box plot comparison diagram of keyframe hit counts between cheating players and normal players in an embodiment of this application.
[0035] Figure 5B This is a schematic diagram comparing the keyframe hit count quantiles of cheating players and normal players in an embodiment of this application.
[0036] Figure 6 This is a block diagram of the electronic device in the embodiments of this application;
[0037] Figure 7 This is a block diagram of a system-on-chip (SoC) in the embodiments of this application. Detailed Implementation
[0038] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0039] like Figure 1 As shown, this embodiment provides a computer-implemented data processing method that constructs a three-tiered progressive detection architecture combining rule pre-screening, spectral feature filtering, and model classification. The method mainly includes the following steps:
[0040] Step S10: One or more processors receive lightweight feature data of the target object in the target game. The lightweight feature data is game frame data obtained by the game server and includes static feature data and dynamic feature data.
[0041] Specifically, game frame data refers to structured numerical state data automatically recorded and maintained by the game engine during each game state update (i.e., each frame or each logical tick). This data originates directly from the internal operating state of the game engine, including but not limited to physical quantities such as the position coordinates, rotation angle, and movement speed of game objects in three-dimensional space, as well as discrete game event flags such as whether the scope is activated, whether a shot is fired, or whether damage is caused. Compared to high-dimensional game screen data (e.g., pixel-level image data obtained by taking frame-by-frame screenshots or recording the game's rendered screen, where the data volume of a single frame typically reaches millions of pixels), game frame data has inherently lightweight characteristics: the data recorded in each frame consists of only a limited number of numerical fields, such as floating-point coordinates, Boolean flags, and integer counters, and its data volume per frame is typically only a few hundred bytes to several thousand bytes, far lower than the megabyte level of image data; at the same time, game frame data is authoritative state data verified by the server, and its reliability is higher than that of raw input logs and screen capture data, which are easily tampered with by clients. It is precisely because of this lightweight nature of the data layer that this application can effectively detect cheating behavior by performing time-series analysis on existing structured state data on the server side without collecting or processing any game screen content. This significantly reduces computational resource consumption and fundamentally avoids the privacy compliance risks caused by collecting user game screens. The collection frequency of lightweight feature data can be set to 30 frames per second (30fps), which matches the server refresh rate (tickrate) of mainstream FPS games, minimizing data transmission and storage overhead while ensuring that behavioral details are not lost. It should be understood that 30fps is only one optional implementation method. In other implementation methods, the collection frequency can also be dynamically adjusted to 60fps, 128fps, or other values according to the update frequency of the specific game, as long as the temporal resolution requirement for capturing continuous player actions is met.
[0042] As one embodiment, static feature data is used to describe the contextual characteristics of a target object in a single game match, and includes one or more of the following features: whether the target object activated a scope, whether the target object fired, and whether the target object caused damage to a target during the game match. The game match begins and the detection process is triggered when the target object enters combat, for example, when a target object enters the target object's firing range, or when a target object fires at the target object. It should be understood that static feature data may also include other features, such as the type of shooting equipment held by the target object, the type of game character used by the target object, the target object's game level, etc. These static features constitute the preconditions for determining whether cheating behavior exists and provide auxiliary judgment and preliminary plausibility verification.
[0043] As one embodiment, dynamic feature data is used to describe the time-related characteristics of a target object in a single game session, and includes one or more of the following features: the position of the game camera associated with the target object, the orientation of the game camera, the position of the hit object, the instantaneous movement speed of the target object in a single game frame of the game session, and the number of shots fired by the target object, the number of hits by the target object, and the hit rate of the target object over several game frames of the game session. Specifically, the position of the game camera can be represented by x, y, and z coordinates, and the displacement difference between consecutive game frames can be further calculated. This displacement difference can be represented by a displacement vector including positive and negative x, y, and z axis displacement differences, used to measure the smoothness of camera movement. The orientation of the game camera can be represented by pitch and yaw angles, and the sine values of pitch and yaw angles can be further calculated as core timing signals characterizing changes in viewpoint. The position of the target can be represented by x, y, and z coordinates. The instantaneous movement speed of the target can be represented by a velocity vector including positive and negative x, y, and z axis instantaneous movement rates and a velocity scalar whose magnitude is equal to the magnitude of the velocity vector. Several game frames in a game session can be set to 240 frames, 120 frames, 60 frames, 30 frames, etc., and the hit rate is the ratio of the number of hits to the number of shots, used to measure the real-time hit rate change in a single game session.
[0044] By explicitly dividing the data into static and dynamic features, this embodiment provides a structured data foundation for subsequent hierarchical detection, enabling different detection levels to selectively utilize the most relevant feature dimensions and avoiding computational redundancy and noise interference caused by mixing all features.
[0045] In step S20, one or more processors select first candidate feature data from the lightweight feature data based on the static feature data in the lightweight feature data and using a pre-screening algorithm.
[0046] As one embodiment, selecting first candidate feature data from lightweight feature data further includes: removing data describing one or more of the following features from the lightweight feature data based on the context features described by the static feature data in the lightweight feature data: during a game, the target object did not activate the scope; and during a game, the target object activated the scope and fired, but the target object did not cause damage to the hit object.
[0047] This step essentially performs computational pruning at the very beginning of the detection chain. The weapon position curves of normal players exhibit numerous random fluctuations outside of combat. Sending all this data to the subsequent high-frequency analysis module would result in a huge waste of computational power. By removing data from players who haven't used the scope or caused damage, the system can quickly eliminate samples that clearly lack the prerequisites for aimbot or wallhack cheating. For example, data generated during tactical reloading, map movement, or ineffective shooting will be directly filtered. This hard-filtering mechanism based on game logic rules has a much lower execution complexity than subsequent spectrum analysis and model inference, reducing the amount of invalid data processing by over 70% with extremely low computational cost. This significantly reduces server load, allowing the system to focus on actual attack behaviors that might affect game balance. Furthermore, as described above, when static feature data includes elements such as the type of weapon the target is holding, the type of game character the target is using, and the target's game level, data where the weapon type, game character type, game level, and damage caused by the target are clearly inconsistent can be quickly identified and sent to the subsequent high-frequency analysis module for accurate judgment.
[0048] In step S30, one or more processors select second candidate feature data from the first candidate feature data based on the dynamic feature data in the first candidate feature data and using a spectral feature filtering algorithm. This step utilizes signal processing techniques to distinguish between human manual operation and program-assisted operation in the frequency domain.
[0049] As one embodiment, selecting second candidate feature data from the first candidate feature data further includes: firstly, arranging the first subset of time-related features described by the dynamic feature data in the first candidate feature data in chronological order to generate a corresponding first feature sequence. In this embodiment, the first subset of features includes one or more of the following features: the position of the game camera, the orientation of the game camera, and the instantaneous movement speed of the target object in a single game frame of a game match. The reason for selecting these three features as the objects of spectrum analysis is that they directly reflect the player's control loop of the viewpoint. Programs such as auto-aim and wallhack typically correct the camera orientation through PID controllers or similar feedback mechanisms. This mechanical closed-loop control leaves a specific frequency fingerprint in the frequency domain; while the position and orientation of the camera and the player's movement speed can help identify the abnormal movement patterns in wallhack cheats that ignore obstacles and continuously and smoothly track targets. Figure 2A A schematic diagram showing the instantaneous movement velocity of the target object along the x, y, and z axes as a function of time is shown. Figure 2B A schematic diagram showing the changes in the game camera's pitch and yaw angles over time is shown.
[0050] Next, the multiple first feature sequences are converted into corresponding time spectrograms using a short-time fourier transform (STFT). The time spectrogram maps the one-dimensional time-series signal to a three-dimensional space of time-frequency-intensity. In specific implementations, the STFT can use a Hanning window as the window function, with a window size of 64 or 128 frames and a step size of half the window size, to achieve a balance between time resolution and frequency resolution. Figure 2C The diagram shows the time spectrum of the game camera's pitch angle, where the x-axis represents time, the y-axis represents frequency, and the color depth represents the signal intensity at a specific time and frequency. Cheat programs such as aimbots and wallhacks, driven by fixed algorithm parameters, tend to generate camera rotation signals concentrated at certain narrowband frequencies, appearing as clear, continuous horizontal bright bars in the time spectrum. In contrast, the manual operation of a normal player, limited by physiological limits and the randomness of neural responses, exhibits a broadband, chaotic energy distribution that changes rapidly over time.
[0051] Subsequently, the spectral features of multiple time-spectrum maps are compared with the corresponding abnormal spectral features to determine the similarity difference value; and data with a similarity difference value greater than a first threshold are removed from the first candidate feature data. Here, abnormal spectral features refer to standard cheating spectral templates extracted in advance from known cheating samples. The similarity difference value can be calculated using methods such as cosine similarity, Euclidean distance, or Pearson correlation coefficient. In an optional embodiment, the first threshold is set to a range of 0.7 to 0.9. When the similarity difference value is greater than this threshold, it indicates that the spectral pattern of the current data differs significantly from the standard template and is more consistent with normal human operation characteristics, therefore it is removed. It should be noted that setting the first threshold is a trade-off: if the threshold is set too low (e.g., below 0.6), although more suspicious samples can be retained, it will lead to a large number of high-level operations by normal players being misjudged as suspected cheating, increasing the processing pressure and false alarm risk of subsequent model layers; if the threshold is set too high (e.g., above 0.95), it may miss those advanced standard cheats disguised by parameter randomization. The range of 0.7 to 0.9 is an optimal range derived from large-scale real-world data statistics. It can effectively capture the vast majority of abnormal spectrum patterns while ensuring that more than 99% of normal players are quickly allowed to pass.
[0052] Step S40: One or more processors use a pre-trained model to perform anomaly classification on the second candidate feature data.
[0053] After the aforementioned two layers of screening, the remaining second-candidate feature data constitutes a highly condensed set of suspicious samples. At this point, a computationally intensive deep learning model is invoked for refined classification, ensuring both detection accuracy and maximizing overall system performance. This coarse-to-fine, progressive architecture allows this application to achieve highly accurate automatic detection of cheating behavior using only lightweight temporal features, without relying on high-dimensional image data. This fundamentally solves the problems of high computational resource consumption and high privacy compliance risks associated with traditional solutions.
[0054] As one embodiment, anomaly classification of the second candidate feature data further includes: first, calculating the distance between the hit object and the ray of the game camera in a single game frame of the game.
[0055] like Figure 3 As shown, in the 3D game coordinate system, based on the camera position and orientation of the current frame, a spatial ray L is constructed, extending infinitely from the camera origin along the target object's viewpoint. Using a vector projection algorithm, the vertical distance d from the hit object's position to this ray L is calculated. The physical meaning of this distance d is the absolute deviation between the firing player's aiming line of sight and the hit player's in 3D space. Figure 4A The diagrams show the changes in weapon position (or aiming point) over time for cheaters and normal players, respectively. When auto-aim or wallhacks are active, the program forces the camera ray to focus on the target, resulting in a very stable aiming curve. This causes the distance d to approach zero or remain within a very small threshold for several consecutive frames. Normal players, however, are limited by physiological reactions and hand tremors, causing their aiming curve to drift over a wide range, making it difficult for their ray to accurately pass through a moving target for an extended period. As a result, as... Figure 4B As shown, the target distance of cheating players exhibits a high-density clustering around 0 over time, while... Figure 4C As shown, the target distance for normal players exhibits a wide distribution characteristic that fluctuates around the target over time, with a significant statistical difference between the two. The geometric characteristics of the camera ray-target distance directly reflect the geometric nature of cheating behavior in three-dimensional space. As long as the cheat maintains a lock-on state with the target, the spatial distance between the ray and the target cannot be concealed. Therefore, this feature has stronger anti-evasion capabilities and robustness.
[0056] Next, after acquiring the aforementioned geometric features, they need to be combined with other dynamic features to form a complete model input. Specifically, in chronological order, the second subset of features from the time-related features described by the dynamic feature data of the first candidate feature data, along with the aforementioned distances, are arranged to generate a second feature sequence. In this embodiment, the second subset of features includes one or more of the following: the orientation of the game camera, the instantaneous movement speed of the target object in a single game frame, and the hit rate of the target object over several game frames. The design logic of this feature combination is to construct a multi-dimensional behavioral profile: the camera ray-target distance provides geometric evidence of spatial locking; the camera orientation and the player's instantaneous movement speed describe the stability and consistency of the operation, used to distinguish between mechanical tracking and human manual fine-tuning; and the hit rate provides result verification of shooting effectiveness. This structured temporal input can be effectively parsed by pre-trained models such as TimesNet, enabling them to capture local features while also learning long-range dependencies across feature dimensions. This allows for optimization for specific cheating detection tasks, accurately identifying cheating patterns that may not be obvious in a single dimension but are significantly abnormal in a multi-dimensional joint distribution.
[0057] Subsequently, the generated second feature sequence is input into the pre-trained model. During the pre-training phase, the original lightweight feature time series data is randomly masked, obscuring some data points, and then input into the model to train it to predict the masked data points. This allows the model to learn the inherent contextual relationships and patterns of the time series data, enhancing its sensitivity to data anomalies and thus enabling it to possess powerful time series pattern recognition capabilities.
[0058] Finally, the anomaly classification results output by the pre-trained model are received. By transforming abstract cheating behaviors into quantifiable geometric and temporal indicators, this embodiment not only improves the model's sensitivity to aimbot and wallhack detection, but also provides an intuitive physical basis for subsequent judgment results, avoiding the interpretability problems faced by pure black-box models in anti-cheating scenarios. It should be understood that although this embodiment lists specific feature combinations and calculation methods, in other embodiments, the composition of the second subset features can be adjusted according to the specific game type, or an equivalent geometric distance calculation method (such as sphere intersection test) can be used. As long as it can achieve the function of quantifying the spatial relationship between the aiming line and the hit object, it should be covered within the protection scope of this application.
[0059] As one implementation, for data identified as having abnormal results by the pre-trained model, a statistically based interpretability verification mechanism is further introduced to address the interpretability challenges faced by pure black-box models in anti-cheating scenarios and provide fallback verification. Specifically, this mechanism includes: for data with abnormal results, identifying keyframes in the game, where frames where the distance between the target and the game camera's ray is less than a second threshold, along with one or more frames before and after them, are identified as keyframes. Defining moments with a distance less than the second threshold as keyframes is because only when the aiming line of sight is extremely close to the target in space can subsequent hits possess the physical prerequisite to distinguish between cheating and high-level skill. Simply calculating the hit rate for the entire game is easily influenced by occasional player highlights or luck; focusing on hit performance in a spatially locked state allows for precise identification of unnatural gains caused by program assistance. Meanwhile, extending the time window of the keyframe to one or more frames before and after (e.g., 3 or 5 frames before and after) is to accommodate network transmission jitter, server tickrate synchronization errors, and minor timing offsets that may be caused by client interpolation algorithms. This ensures that the statistical window can fully cover the actual crossfire process and avoids missing key evidence due to single-frame alignment deviations.
[0060] After determining the keyframes, the number of times the target object is hit during the keyframe period of a game is calculated. This number of hits refers to the total number of effective shots that actually cause damage to the target object within the extended keyframe time window. Subsequently, the number of hits is compared with the number of normal hits, and the similarity difference value is determined. It should be noted that the similarity comparison here is more statistically inclined towards measuring distributional dissimilarity. The number of normal hits can be a single fixed value, or a dynamic baseline constructed based on massive historical game data, which comprehensively considers contextual factors such as game mode, weapon type, engagement distance, and player rank. In practice, the similarity difference value can be calculated using Z-score normalization, the Kolmogorov-Smirnov test statistic, or the more intuitive multiple ratio (i.e., the current number of hits divided by the 99th percentile of normal players under the same conditions). This design transforms the abstract model judgment results into quantifiable and verifiable objective indicators.
[0061] In actual business data verification, cheaters and normal players exhibited a highly significant distributional separation in the keyframe hit count metric. Statistical data shows that in the sample set confirmed to be cheating methods such as aimbots and wallhacks, the average number of hits during keyframes was as high as 38.82, with a median of 6 and a third-quarter rank of 65. In contrast, normal players' values for the same metric were generally concentrated in the lower range and were more compactly distributed. Figure 5AThe diagram shows the keyframe hit counts for cheating players and normal players, respectively, which visually demonstrates that the two sets of data boxes almost do not overlap at all. Figure 5B The diagram shows the keyframe hit count percentiles for cheaters and legitimate players, further confirming an order-of-magnitude difference at the high percentiles. Based on this significant statistical gap, data with similarity differences exceeding a third threshold are identified as anomalous. This third threshold is not arbitrarily chosen but determined by plotting ROC curves on a large number of labeled samples, selecting the point with the maximum Youden index or the optimal F1-score. For example, if the multiple ratio is used as the difference value, the third threshold can be set between 3.0 and 5.0, meaning that a player is ultimately identified as anomalous only when their hit rate in locked-down state exceeds three times the 99th percentile of top legitimate players.
[0062] It should be understood that the statistical verification steps described in this embodiment are not a simple repetition of the aforementioned model classification process, but rather constitute a dual verification architecture of model + statistics. From a technical perspective, this mechanism plays two key roles: First, as a confidence enhancer, when the model output is abnormal and the statistical indicators also significantly deviate from the baseline, it can execute measures such as banning with extremely high confidence, significantly reducing the cost of manual review; second, as a false positive remover and security fallback, deep learning models may experience illusions due to adversarial attacks or data distribution drift. In such cases, if the statistical indicators show that the player's keyframe hit count is within the normal range, the case can be marked as a low-confidence anomaly and transferred to the manual review queue, rather than being automatically penalized directly. This white-box statistical fallback mechanism not only compensates for the uninterpretable nature of neural networks and enhances the credibility and traceability of detection results at the legal compliance level, but also covers post-processing verification protection points independent of the model, improving the robustness and security of the overall anti-cheating system.
[0063] This application provides a data processing system, including one or more processors and one or more memories. The one or more memories are coupled to the one or more processors and store instructions. When executed by the one or more processors, the instructions cause the one or more processors to perform the data processing operations described in the above embodiments. The specific functions and corresponding technical effects can be found in the above embodiments. Figures 1 to 5B The methods explained will not be elaborated here.
[0064] Now for reference Figure 6 The diagram shown is a block diagram of an electronic device 1200 according to an embodiment of this application. The electronic device 1200 may include one or more processors (corresponding to...) coupled to a controller hub 1203. Figure 6The first processor 1201 is described above. In at least one embodiment, the controller hub 1203 communicates with the first processor 1201 via a multi-branch bus such as a front-side bus (FSB), a point-to-point interface such as a quick-path interconnect (QPI), or a similar connection. The first processor 1201 executes instructions that control general types of data processing operations. In one embodiment, the controller hub 1203 includes, but is not limited to, a graphics memory controller hub (GMCH) (not shown) and an input / output hub (IOH) (which may be on a separate chip) (not shown), wherein the GMCH includes memory and a graphics controller and is coupled to the IOH.
[0065] Electronic device 1200 may also include a coprocessor coupled to controller hub 1203 (corresponding to...) Figure 6 The first coprocessor 1202 and memory 1204 are integrated within the processor (as described in this application). Alternatively, one or both of the memory and GMCH can be integrated within the processor (as described in this application), with memory 1204 and the first coprocessor 1202 directly coupled to the first processor 1201 and the controller hub 1203, which is located on a single chip with the IOH. Memory 1204 can be, for example, dynamic random access memory (DRAM), phase change memory (PCM), or a combination of both. In one embodiment, the first coprocessor 1202 is a dedicated processor, such as a high-throughput MIC processor (many integerized core, MIC), a network or communication processor, a compression engine, a graphics processor, a general-purpose computing on GPU (GPGPU), or an embedded processor, etc. Optional properties of the first coprocessor 1202 are indicated by dashed lines. Figure 6 middle.
[0066] As a computer-readable storage medium, memory 1204 may include one or more tangible, non-transitory computer-readable media for storing data and / or instructions. For example, memory 1204 may include any suitable non-volatile memory such as flash memory and / or any suitable non-volatile storage device such as one or more hard-disk drives (HDDs), one or more compact disc (CD) drives, and / or one or more digital versatile disc (DVD) drives.
[0067] In one embodiment, electronic device 1200 may further include a network interface controller (NIC) 1206. Network interface 1206 may include a transceiver for providing a radio interface for electronic device 1200 to communicate with any other suitable device (such as a front-end module, antenna, etc.). In various embodiments, network interface 1206 may be integrated with other components of electronic device 1200. Network interface 1206 can implement the functions of the communication unit in the above embodiments.
[0068] Electronic device 1200 may further include input / output (I / O) device 1205. I / O device 1205 may include: a user interface designed to enable a user to interact with electronic device 1200; a peripheral component interface designed to enable peripheral components to also interact with electronic device 1200; and / or sensors designed to determine environmental conditions and / or location information related to electronic device 1200.
[0069] It is worth noting that, Figure 6 This is merely an example. That is, although... Figure 6 The electronic device 1200 shown includes multiple devices such as a first processor 1201, a first coprocessor 1202, a controller hub 1203, and a memory 1204. However, in actual applications, devices using the methods of this application may include only a portion of the devices in the electronic device 1200. For example, it may include only the first processor 1201 and the network interface 1206. Figure 6 The properties of the optional devices are shown in dashed lines. According to some embodiments of this application, the memory 1204, which is a computer-readable storage medium, stores instructions that, when executed on a computer, cause the electronic device 1200 to perform the data processing method according to the above embodiments. Specific details can be found in the methods described in the above embodiments, and will not be repeated here.
[0070] Now for reference Figure 7The diagram shown is a block diagram of a SoC (system on chip) 1300 according to an embodiment of this application. Figure 7 In the diagram, similar components share the same reference numerals. Additionally, dashed boxes are an optional feature for more advanced SoCs. Figure 7 In the SoC 1300, interconnect unit 1350 is coupled to the processor (corresponding to...). Figure 7 The system includes a second processor 1310, a system agent unit 1380, a bus controller unit 1390, an integrated memory controller unit 1340, and one or more coprocessors (corresponding to...). Figure 7 The second coprocessor 1320 may include integrated graphics logic, an image processor, an audio processor, and a video processor; a static random access memory (SRAM) unit 1330; and a direct memory access (DMA) unit 1360. In one embodiment, the second coprocessor 1320 includes a dedicated processor, such as a network or communication processor, a compression engine, a GPGPU, a high-throughput MIC processor, or an embedded processor.
[0071] The static random access memory (SRAM) cell 1330 may include one or more computer-readable media for storing data and / or instructions. The computer-readable storage medium may store instructions, specifically, temporary and permanent copies of those instructions. These instructions may include, when executed by at least one unit in the processor, causing the SoC 1300 to perform a data processing method according to the above embodiments, as detailed in the methods described above, which will not be repeated here.
[0072] Various embodiments of the mechanisms disclosed in this application can be implemented in hardware, software, firmware, or combinations of these implementation methods. Embodiments of this application can be implemented as computer programs or program code executable on a programmable system, the programmable system including at least one processor, a storage system (including volatile and non-volatile memory and / or storage elements), at least one input device, and at least one output device.
[0073] Program code can be applied to input instructions to execute the functions described in this application and generate output information. The output information can be applied to one or more output devices in a known manner. For the purposes of this application, the processing system includes any system having a processor such as a digital signal processor (DSP), microcontroller, application-specific integrated circuit (ASIC), or microprocessor.
[0074] The program code can be implemented using a high-level procedural language or an object-oriented programming language to communicate with the processing system. Assembly language or machine language can also be used when needed. In fact, the mechanisms described in this application are not limited to any particular programming language. In either case, the language can be a compiled language or an interpreted language.
[0075] In some cases, the disclosed embodiments may be implemented in hardware, firmware, software, or any combination thereof. The disclosed embodiments may also be implemented as instructions carried or stored thereon on one or more temporary or non-temporary machine-readable (e.g., computer-readable) storage media, which may be read and executed by one or more processors. For example, the instructions may be distributed via a network or through other computer-readable media. Therefore, machine-readable media may include any mechanism for storing or transmitting information in a machine-readable (e.g., computer-readable) form, including but not limited to floppy disks, optical disks, CD-ROMs, compact disc read-only memory (CD-ROMs), magneto-optical disks, read-only memory (ROM), random access memory (RAM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic cards or optical cards, flash memory, or tangible machine-readable storage for transmitting information (e.g., carrier waves, infrared signals, digital signals, etc.) using the Internet in the form of electrical, optical, acoustic, or other forms of propagated signals. Therefore, machine-readable media include any type of machine-readable medium suitable for storing or transmitting electronic instructions or information in a machine-readable (e.g., computer-readable) form.
[0076] In the accompanying drawings, some structural or methodological features may be shown in a specific arrangement and / or order. However, it should be understood that such a specific arrangement and / or order may not be necessary. Rather, in some embodiments, these features may be arranged in a manner and / or order different from that shown in the accompanying drawings. Furthermore, including structural or methodological features in a particular figure does not imply that such features are required in all embodiments, and in some embodiments, these features may be omitted or may be combined with other features.
[0077] This application also provides a computer-readable storage medium, the specific functions and corresponding technical effects of which can be referred to the above embodiments. Figures 1 to 5B The methods explained will not be elaborated here.
[0078] This application also provides a computer program product, which includes a computer program or instructions. When the computer program or instructions are loaded and executed by a processor, they implement the data processing method described in the above embodiments. The specific functions and corresponding technical effects of this product can be found in the above embodiments. Figures 1 to 5B The methods explained will not be elaborated here.
[0079] It should be noted that the order of the embodiments described above is merely for descriptive purposes and does not represent the superiority or inferiority of the embodiments. Furthermore, specific embodiments have been described above. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps described in the claims can be performed in a different order than that shown in the embodiments and still achieve the desired result. Additionally, the processes depicted in the drawings do not necessarily require a specific or sequential order to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0080] It should be noted that all units / modules mentioned in the device embodiments of this application are logical units / modules. Physically, a logical unit / module can be a physical unit / module, a part of a physical unit / module, or a combination of multiple physical units / modules. The physical implementation of these logical units / modules themselves is not the most important factor; the combination of functions implemented by these logical units / modules is the key to solving the technical problems proposed in this application. Furthermore, to highlight the innovative aspects of this application, the above-described device embodiments of this application have not introduced units / modules that are not closely related to solving the technical problems proposed in this application. This does not mean that the above-described device embodiments do not contain other units / modules.
[0081] It should be noted that in the examples and description of this application, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one" does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0082] Although this application has been illustrated and described with reference to certain preferred embodiments thereof, those skilled in the art should understand that various changes in form and detail may be made thereto without departing from the spirit and scope of this application.
Claims
1. A computer-implemented data processing method, characterized in that, The method includes: Lightweight feature data of a target object in a target game is received by one or more processors, wherein the lightweight feature data is game frame data obtained by the game server and includes static feature data and dynamic feature data; The one or more processors select first candidate feature data from the lightweight feature data based on the static feature data in the lightweight feature data and using a pre-screening algorithm; The one or more processors, based on the dynamic feature data in the first candidate feature data and using a spectral feature filtering algorithm, filter out second candidate feature data from the first candidate feature data; and The one or more processors use a pre-trained model to perform anomaly classification on the second candidate feature data.
2. The method according to claim 1, characterized in that, in, The static feature data is used to describe the contextual features of the target object in a single game match, and includes one or more of the following features: whether the target object activated a scope during the game match, whether the target object fired a shot, and whether the target object caused damage to a target. The dynamic feature data is used to describe the time-related characteristics of the target object in the single game match, and includes one or more of the following features: the position of the game camera associated with the target object, the orientation of the game camera, the position of the hit object, the instantaneous movement speed of the target object in a single game frame of the game match, and the number of shots fired by the target object, the number of hits by the target object, and the hit rate of the target object within several game frames of the game match.
3. The method according to claim 2, characterized in that, Filtering the first candidate feature data from the lightweight feature data further includes: Based on the contextual features described by the static feature data in the lightweight feature data, remove data from the lightweight feature data that describes one or more of the following features: during the game, the target object did not activate the scope; and during the game, the target object activated the scope and fired, but the target object did not cause damage to the hit object.
4. The method according to claim 2 or 3, characterized in that, Filtering the second candidate feature data from the first candidate feature data further includes: According to the time order, the first subset of features in the time-related features described by the dynamic feature data in the first candidate feature data are arranged to generate the corresponding first feature sequence; Multiple first feature sequences are converted into corresponding time spectrum diagrams by using short-time Fourier transform; The spectral features of multiple time-spectral plots were compared with the corresponding anomalous spectral features, and the similarity difference value was determined; and Remove data from the first candidate feature data whose similarity difference value is greater than the first threshold.
5. The method according to claim 4, characterized in that, The first subset of features includes one or more of the following features: the position of the game camera, the orientation of the game camera, and the instantaneous movement speed of the target object in a single game frame of the game match.
6. The method according to claim 2, characterized in that, Anomaly classification of the second candidate feature data further includes: Calculate the distance between the hit object and the ray from the game camera in a single game frame of the game session; Arrange the second subset features and the distance in chronological order of the time-related features described by the dynamic feature data of the first candidate feature data to generate a second feature sequence; The second feature sequence is input into the pre-trained model; and Receive the anomaly classification results output by the pre-trained model.
7. The method according to claim 6, characterized in that, The second subset of features includes one or more of the following features: the orientation of the game camera, the instantaneous movement speed of the target object, and the hit rate of the target object over several game frames in the game.
8. The method according to claim 6 or 7, characterized in that, The method further includes: For data with abnormal results, keyframes in the game are identified, wherein the frames whose distance is less than a second threshold and one or more frames before and after them are identified as keyframes. Calculate the number of times the target object is hit during the keyframes of the game session; The number of hits is compared with the number of normal hits, and the similarity difference value is determined; and Data with similarity differences greater than the third threshold are identified as abnormal data.
9. A data processing system, characterized in that, The system includes: One or more processors; and One or more memories coupled to the one or more processors and storing instructions that, when executed by the one or more processors, cause the one or more processors to perform data processing operations, including: Receive lightweight feature data of a target object in the target game, wherein the lightweight feature data is game frame data obtained by the game server and includes static feature data and dynamic feature data; Based on the static feature data in the lightweight feature data, and using a pre-screening algorithm, the first candidate feature data is selected from the lightweight feature data; Based on the dynamic feature data in the first candidate feature data, and using a spectral feature filtering algorithm, a second candidate feature data is selected from the first candidate feature data; and The second candidate feature data is classified as anomaly using a pre-trained model.
10. A non-transitory computer-readable medium, characterized in that, The non-transitory computer-readable medium storage instructions, which, when executed by one or more processors, cause the one or more processors to perform data processing operations, the operations including: Receive lightweight feature data of a target object in the target game, wherein the lightweight feature data is game frame data obtained by the game server and includes static feature data and dynamic feature data; Based on the static feature data in the lightweight feature data, and using a pre-screening algorithm, the first candidate feature data is selected from the lightweight feature data; Based on the dynamic feature data in the first candidate feature data, and using a spectral feature filtering algorithm, a second candidate feature data is selected from the first candidate feature data; and The second candidate feature data is classified as anomaly using a pre-trained model.
11. A computer program product, characterized in that, The computer program product is implemented on a non-transitory computer-readable medium and includes instructions that, when executed by one or more processors, cause the one or more processors to perform data processing operations, the operations including: Receive lightweight feature data of a target object in the target game, wherein the lightweight feature data is game frame data obtained by the game server and includes static feature data and dynamic feature data; Based on the static feature data in the lightweight feature data, and using a pre-screening algorithm, the first candidate feature data is selected from the lightweight feature data; Based on the dynamic feature data in the first candidate feature data, and using a spectral feature filtering algorithm, a second candidate feature data is selected from the first candidate feature data; and The second candidate feature data is classified as anomaly using a pre-trained model.