Welcome to the Hangar Open Beta. Please report any issue you encounter on GitHub!
Avatar for uname1337

ai anticheat

Report ultimateac?

UltimateAntiCheat

ML-based KillAura Anti-Cheat for Paper 1.16.5

UltimateAntiCheat is a machine-learning-based Minecraft anti-cheat focused on detecting KillAura through temporal combat behavior rather than relying on a collection of hardcoded thresholds.

Platform: Paper 1.16.5 Java: 8 / 11 Model: MLP neural network Optional dependency: ProtocolLib


Overview

UltimateAntiCheat learns from real player behavior.

Instead of checking individual values such as CPS, reach, or rotation speed and immediately deciding whether a player is cheating, the system collects a sequence of combat-related telemetry, extracts temporal features, and passes them through a trained machine-learning model.

The detection pipeline is:

Confirmed KillAura
       ↓
   /uac rec
       ↓
    Dataset
       ↓
   /uac train
       ↓
  ML Training
       ↓
Legitimate player attacks
       ↓
 Temporal features
       ↓
     Model
       ↓
KillAura probability
       ↓
Multiple predictions
       ↓
Violation buffer
       ↓
    Detection

The model is trained on confirmed examples instead of depending exclusively on manually selected thresholds.


Installation

Requirements

  • Paper 1.16.5
  • Java 8 or Java 11
  • Maven for building the project
  • ProtocolLib is optional

Installing the Plugin

Build the project:

mvn package

After the build is complete, place the generated JAR file into:

plugins/

Restart the server.


Machine Learning Model

A pre-trained model is included with the project:

killaura_model.json

Extract the model and place it into:

plugins/UltimateAntiCheat/models/

After installing the model, run:

/uac train

The training system can also create/update the model using the collected dataset.


Training the Model

UltimateAntiCheat requires both positive and negative examples.

1. Record KillAura Data

Start recording a confirmed cheater:

/uac rec CheaterNick

The player should use KillAura for approximately 3–5 minutes and perform a significant number of attacks.

Stop recording:

/uac stop CheaterNick

This creates training data for the KILLAURA class.


2. Record Legitimate PvP Data

Record a legitimate player:

/uac reclegit GoodNick

The player should participate in normal, legitimate PvP.

Stop recording:

/uac stop GoodNick

This creates training data for the LEGIT class.


3. Collect Multiple Sessions

For better training data, repeat the process with at least:

  • 3 different KillAura players/sessions
  • 3 different legitimate players/sessions

The dataset should contain multiple independent sessions rather than relying on a single player.


4. Train the Model

Run:

/uac train

Training is performed asynchronously.

The training process includes:

Dataset
   ↓
Class balancing
   ↓
Normalization
   ↓
Session split
   ↓
Adam optimizer
   ↓
Training
   ↓
Evaluation
   ↓
Metrics
   ↓
Model storage

The training output includes:

  • Precision
  • Recall
  • F1 score
  • Confusion matrix

Commands

All commands require the uac.admin permission.

Command Description
/uac rec <nick> Record training data for the KILLAURA class
/uac reclegit <nick> Record training data for the LEGIT class
/uac stop <nick> Stop recording data for a player
/uac train Train the MLP model
/uac status <nick> Display the detector status
/uac debug <nick> Display live features, model score, and VL
/uac menu Open the suspicion/detection GUI
/uac reload Reload the configuration and model

Detection System

Detection does not depend on a single model prediction.

For example:

p = 0.93

does not automatically mean that a player is considered a cheater.

Instead, predictions are aggregated over multiple observations.

The detection flow is approximately:

Model prediction
       ↓
Prediction aggregation
       ↓
5 consecutive predictions
       ↓
Confidence accumulation
       ↓
Violation Level (VL)
       ↓
VL decay
       ↓
Sustained detection
       ↓
Punishment

The system uses:

VL += confidence

and allows the violation level to decay over time.

This makes the detector less dependent on isolated predictions.


Observation Mode

By default, punishments are disabled:

violation:
  punish-enabled: false

In this mode:

  • No kicks are performed.
  • No bans are performed.
  • Staff members receive detection flags.
  • Violation Level continues to increase when detections occur.

Punishments can be enabled later:

punish-enabled: true

Reach Guard

The default maximum hit distance is:

reach-guard.max-distance: 3.0

Attacks beyond 3 blocks of eye-to-eye distance are cancelled.

The counter is available through:

/uac menu

and:

/uac status <nick>

Feature Extraction

UltimateAntiCheat analyzes combat behavior using temporal windows rather than isolated clicks.

Each training example contains 21 frames:

T-10 ... T0 ... T+10

where:

T0 = attack

The frames after the attack are collected during the following 10 ticks.


Frame Features

The feature extractor analyzes information such as:

  • Yaw
  • Pitch
  • ΔYaw
  • ΔPitch
  • Rotation speed
  • View direction
  • Distance to target
  • Angle to target
  • ΔAngle
  • Attacker movement speed
  • Target movement speed
  • Relative movement speed
  • Sprint state
  • Sneak state
  • Ground state
  • Jump state
  • Velocity
  • Knockback
  • Ticks after knockback
  • Target switching
  • Movement relative to view direction
  • Ping
  • TPS
  • Number of nearby players
  • Attack interval

Model Input

The model uses 354 input features.

They consist of:

21 × 16 per-frame features
+
18 aggregated window features
=
354 inputs

Aggregated features include information such as:

  • CPS
  • Attack regularity
  • Minimum snap angle
  • Target switches
  • Lag context
  • Other temporal statistics

The raw isAttack value is not included as a model feature.


Neural Network Architecture

The current model architecture is:

354 → 64 → 32 → 1

The network uses:

  • ReLU activation
  • Sigmoid output

Conceptually:

Input
  354
   │
   ▼
 Dense Layer
   64
   │
   ▼
 Dense Layer
   32
   │
   ▼
 Output
    1
   │
   ▼
 Sigmoid
   │
   ▼
KillAura probability

The implementation is written in pure Java and does not require native machine-learning dependencies.


Model Extensibility

The model architecture is exposed through:

CheatModel
ModelRegistry

This provides an extension point for additional cheat detection models, including:

AimAssist
Reach
AutoClicker
Velocity
Fly

The current documentation specifically describes the KillAura model.


Data Leakage Prevention

The training pipeline uses sessionId to separate training and testing data.

A single recording session is never simultaneously placed into both datasets.

Session A ──→ Train

Session B ──→ Train

Session C ──→ Test

This prevents the same session from appearing in both training and testing.

Normalization is also calculated exclusively from the training set.

The normalization method is:

z-score normalization

Train / Serve Consistency

The same components are used during both training and live detection:

FeatureExtractor
       +
Normalizer

The telemetry collection pipeline is shared between training and serving.

This prevents differences between the feature representation used to train the model and the representation used during live detection.


Anti-False-Positive System

The detector does not make decisions solely from one metric.

The model considers environmental and combat context such as:

  • Ping
  • TPS
  • Jitter
  • Knockback
  • Target switching
  • Nearby players
  • Crowd conditions

Confidence can also be dampened when the environment is unstable.

The system specifically avoids making decisions exclusively from:

CPS
Reach
Rotation

Asynchronous Processing

Dataset recording and model training are performed asynchronously.

The server tick thread performs only lightweight sampling.

This design keeps the more expensive operations away from the main tick-processing path.


ProtocolLib

ProtocolLib is an optional soft dependency.

When ProtocolLib is available, UltimateAntiCheat can obtain:

  • Precise click timing through USE_ENTITY
  • Raw rotation packets

Without ProtocolLib, the plugin falls back to Bukkit events.

ProtocolLib available
        ↓
Precise packet-level telemetry

ProtocolLib unavailable
        ↓
Bukkit events

GUI

The command:

/uac menu

opens the suspicion GUI.

Players are separated visually according to the detector's current suspicion:

Top
└── Red — higher detected cheater probability

Bottom
└── Green — lower detected cheater probability

Left-clicking a player allows staff to spectate them.


Debugging

For live debugging, use:

/uac debug <

Sponsors

me😘

Information

Category
Admin Tools
Published
October 2, 2026
License
Unspecified
0Downloads
0Stars
Addon

Pinned Versions

Members

1