Position Paper

Continuous Cheat Detection with Calibrated Decision Models

Abstract

Anti-cheat for competitive online games has escalated from client-side scanners to kernel drivers and hardware attestation, yet cheats that run entirely off the host, such as direct memory access hardware or screen capture with hardware input injection, evade these defenses or are addressed by them only indirectly. Whatever form a cheat takes, it must change what the player does, and the game server observes what the player does. This position paper argues that behavioral anti-cheat is therefore a necessary complement to integrity protection, frames it as continuous cheat detection, and proposes an architecture for making it fast, calibrated, and accountable. The design has not yet been implemented or evaluated. From continuous behavioral authentication, it borrows enrollment, population and player templates, session-level trust, and error rates reframed as false bans and missed cheaters. From System One decision models such as Jev and its open-weight alternatives, it takes fast, single-pass, typed decisions with probabilities, recalibrated on each game’s own data. A decision model scores each window of play, its outputs update session trust, and a policy with cost-derived thresholds applies soft actions at moderate suspicion and escalates high or ambiguous suspicion to slower reasoning models or human review, which by default must confirm any ban. We argue that measured calibration, which to our knowledge recent anti-cheat systems do not report, is what lets ban thresholds follow from the costs of errors, and we address fairness for elite players and for players using accessibility hardware. The architecture is designed to be model- and genre-agnostic, with competitive first-person shooters as the running example. Early independent tests of decision models are mixed, so our staged research agenda first tests them against a calibrated conventional classifier. We invite collaboration.

Keywords anti-cheat; cheat detection; behavioral biometrics; continuous authentication; calibration; decision models; online games; first-person shooters; game security; trust and safety

The Architecture

Pipeline diagram: server telemetry goes to a behavioral encoder, then a System 1 decision model, then session trust, then an escalation policy. The policy chooses no action, a soft action, or System 2 review by a reasoning model or a human. A ban, subject to appeal, follows only a confirmed review, or an optional direct path.
Figure 1. A fast decision model scores each observation window. Its recalibrated outputs build up session trust, and an escalation policy decides whether to take no action, take a soft action, or escalate to slower System 2 review. Direct automatic bans (dashed) are an optional path that each developer configures. © 2026 Heath Howren, CC BY 4.0.

How to Cite

APA

Howren, H. (2026). Continuous Cheat Detection with Calibrated Decision Models. Zenodo. https://doi.org/10.5281/zenodo.23138396

BibTeX
@misc{howren_2026_23138396,
  author    = {Howren, Heath},
  title     = {Continuous Cheat Detection with Calibrated Decision Models},
  month     = oct,
  year      = 2026,
  publisher = {Zenodo},
  doi       = {10.5281/zenodo.23138396},
  url       = {https://doi.org/10.5281/zenodo.23138396}
}

Collaboration

The research agenda starts by testing decision models against a calibrated conventional classifier. That takes real match data. If you run a game, work in anti-cheat, or study cheating and want to help test it, email heath@gamereversal.club. Funding and data partnerships are both welcome.

Declarations

Independent research. The views in this paper are the author’s own. Game Reversal Club is a personal project, funded and run independently, and the author has no financial relationship with any company whose products the paper names.

Free to share. The paper is licensed CC BY 4.0. Share it, quote it, or build on it, with credit to the author. Link to the DOI so readers get the current version.