Add emblem heuristic for cheat detection (beta-2.2.7) - #78
Open
owens1127 wants to merge 2 commits into
Open
Conversation
Prod analysis of cheat_level>=2 players on flagged runs showed overrepresented emblems; apply a weak gated player-level signal for high-lift legendaries and default class emblems when other signals are already present. Co-authored-by: Cursor <cursoragent@cursor.com>
Include all emblem hashes with >=3 cheater wearers and >=80x lift on flagged runs from the segmented prod scan, not just the initial top seven. Co-authored-by: Cursor <cursoragent@cursor.com>
There was a problem hiding this comment.
Pull request overview
This PR adds a new player-level emblem-based signal to the cheat detection heuristic, records it via a new SuspiciousEmblem bit, and bumps the cheat-check version to beta-2.2.7.
Changes:
- Introduces
emblemCheatProbabilityand supporting hash allowlists for suspicious legendary and default-class emblems. - Integrates the emblem probability boost into the per-player probability calculation and explanation output.
- Adds a new reason-bit (
SuspiciousEmblem) and updatesCheatCheckVersiontobeta-2.2.7.
Reviewed changes
Copilot reviewed 4 out of 4 changed files in this pull request and generated 2 comments.
| File | Description |
|---|---|
| lib/services/cheat_detection/types.go | Adds the SuspiciousEmblem reason bit in the shared bitmask enum. |
| lib/services/cheat_detection/methods.go | Applies emblem-derived probability and explanation to per-player results. |
| lib/services/cheat_detection/entry.go | Bumps CheatCheckVersion to beta-2.2.7. |
| lib/services/cheat_detection/emblem_heuristics.go | Implements the emblem allowlists, selection logic, and explanation string. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Comment on lines
+15
to
+17
| // suspiciousLegendaryEmblemHashList is from prod analysis (cheat_level >= 2, flagged runs, | ||
| // last 12 months, 3-month instance chunks × last_seen buckets): emblem_hash with | ||
| // >= 3 cheater wearers and >= 80× lift vs clean players on flagged runs. |
Comment on lines
+172
to
+178
| if _, ok := suspiciousLegendaryEmblemHashes[hash]; ok { | ||
| if boost < 0.06 { | ||
| boost = 0.06 | ||
| matchedHash = hash | ||
| } | ||
| continue | ||
| } |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
cheat_level >= 2accounts on flagged runs (segmented bylast_seenand 3-month instance windows).PlayerThreshold(avoids false positives on new legitimate accounts).SuspiciousEmblem; bumps cheat check version tobeta-2.2.7.Test plan
gofmt -won touched filesgo build ./lib/services/cheat_detection/...strings bin/hermes | grep beta-2.2.7suspicious emblem <hash>beta-2.2still aggregates flags for cheat-level promotion)Deploy
Services-only. After merge:
ssh raidhub→git pull→make hermes→sudo systemctl restart hermes. No Postgres migration or API/Website dependency.Made with Cursor