Counter-Strike’s Anti-Cheat Tech Now Judges How You Play

—TechRound does not recommend or endorse any financial, investment, gambling, trading or other advice, practices, companies or operators. All articles are purely informational—

For most of the history of online gaming, anti-cheat software hunted for the cheat itself. It looked for a known program, a modified file or code injected into the game. In Counter-Strike 2 that approach is under pressure and the pressure comes from hardware.

Two kinds of cheat now cause the most trouble. A DMA cheat uses a separate device, usually a PCIe card, to read the game’s memory from a second computer, so nothing suspicious runs on the player’s own machine. An AI cheat skips the game’s memory altogether. A capture card sends the screen to a second PC, an object detection model finds the enemies and the mouse is moved on the player’s behalf. To a check that only looks for cheat software, both can pass as a person at a keyboard.

Neither is a fringe problem. FACEIT, the third-party platform that runs its own Counter-Strike matchmaking and anti-cheat, says AI and DMA cheats accounted for 40% of the cheating bans it issued in May 2026. Its kernel-level anti-cheat already catches many of them. The newest work at both FACEIT and Valve is about catching the rest.

 

Valve Started Watching Behaviour In 2018

 

At the Game Developers Conference in 2018, Valve programmer John McDonald described VACnet, a deep learning system that studies players’ in-game behaviour, separately from VAC’s checks for cheat software. As PC Gamer reported from the talk, VACnet looked at how a player’s view moved in the half second before each shot and the quarter second after. It then judged sequences of 140 shots taken from an eight-round window.

The model learned from verdicts in Overwatch, the tool that let players review replays of reported players. McDonald’s numbers explained why Valve kept going. Cases reported by players ended in a conviction 15 to 30% of the time, while cases submitted by VACnet were upheld 80 to 95% of the time. Even then, VACnet’s suspicions went to human jurors rather than straight to a ban.

In its release notes of 19 August 2024, Valve announced initial testing of VacNet 3.0 on a limited set of matches and asked anyone who believed their match had been “incorrectly cancelled” to get in touch. In July 2026 it fixed a bug that had allowed malicious players to avoid being processed by VACnet.

 

The Training Data Became The Target

 

A behavioural model is only as good as the examples it learns from, and in August 2026 Valve went back to human reviewers for more of them. Its new CS2 Video Review site calls itself the “Counter-Strike 2 VacNet labeling portal” and is open only to invited players. According to reports, reviewers watch short clips, and their verdicts are used to train VACnet’s models instead of punishing the player shown.

That design has an obvious weak point, and it was tested within days. Community reports described cheaters marking obvious cheating clips as clean, along with claims of an automated tool and of cheaters inviting each other into the review pool to multiply the false labels. Valve has not confirmed the tool or said how it protects the portal.

Whatever the scale turns out to be, the episode shows where the fight has moved. When a model learns from people, poisoning their input can be easier than beating the model itself.

FACEIT Moved The Check Into The Match

 

FACEIT has taken a different route with Human Input Detection, which it set to go live with its Season 9 on 5 August 2026. It is a machine learning layer inside the platform’s existing kernel-level anti-cheat. Instead of reviewing clips after the fact, it reads a player’s in-game inputs in real time, from the start of a match to the end, and flags input that no human could realistically produce.

According to FACEIT’s own FAQ, the model learns continually from FACEIT matches and from the highest-ranked players in Counter-Strike. It is aimed at the hardest cases, cheats built to be subtle and methods nobody has catalogued yet, and in testing it proved especially effective against AI cheats.

Two design choices stand out. A flag never leads to a ban on its own: it is weighed alongside the platform’s other anti-cheat signals first. FACEIT also holds back some bans after a cheat is confirmed, so it can take down several accounts at once before the cheat’s developer can warn customers.

On privacy, FACEIT says the system reads only in-game inputs, limited to the game window, encrypts them and records nothing once the player leaves. Accessibility hardware, it adds, is treated as part of normal human play.

 

The Hard Part Is The Edge Cases

 

Behavioural detection solves one problem and creates another. A cheat hidden on separate hardware still has to move the crosshair, and that movement can be measured. But the best human players also do things that look impossible to most people, and some players use unusual controllers or adaptive hardware. Every behavioural system has to decide where exceptional ends and inhuman begins. FACEIT’s answer is that a single signal is never enough.

Cheat developers are working the other side of that line. Commercial AI cheats already advertise “natural” aim, built to move like a real hand, which is exactly what a behavioural model has to tell apart from the real thing. That turns anti-cheat into an arms race over statistics, with both sides studying the same data about how people play.

Some publishers go after the hardware directly, as Riot Games did with Valorant in May 2026 by updating its Vanguard anti-cheat to block DMA devices. In Counter-Strike, Valve and FACEIT have put their newest work into behaviour.

 

What Changes For Players

 

Anti-cheat now judges how you play as well as what is installed on your PC. For honest players, that should mean fewer cheaters who never trip a software scan. It also means each system is only as reliable as the data the community helps to produce, from Valve’s review clips to FACEIT’s matches, and cheaters have already shown they will try to corrupt it.

—TechRound does not recommend or endorse any financial, investment, gambling, trading or other advice, practices, companies or operators. All articles are purely informational—