A gaming monitor displays FPS footage beside a dashboard analyzing player identities, fingerprints, and input patterns.
Counter-Strike 2 has a cheater problem, and the cheaters have a cheap workaround. A ban hits an account, so the cheater makes a new one. A Norwegian master's student now says there's a way to recognise the person behind the account instead. The method uses only the match demos CS2 already records.

A gaming monitor displays FPS footage beside a dashboard analyzing player identities, fingerprints, and input patterns. What the researcher built​

The work was a master's thesis at the Norwegian University of Science and Technology (NTNU). It uses behavioral biometrics to identify players from how they use their mouse and keyboard. It works entirely from the match demos CS2 already records, and it produces what the researcher calls a "CS-fingerprint" for each player. The researcher posted the results on the r/GlobalOffensive subreddit as u/Magga_. In the post, they say the method recognises the player behind an account using only the demos CS2 already records.

The aim is not to detect cheats. The research question was whether the way you use your keyboard and mouse is consistent and distinct enough to recognise a player across demos. That makes this an identity-linking tool. A match between two accounts says "probably the same human". It does not say "cheated".

Why the signals might be distinctive​

The researcher's explanation is muscle memory. Flicks, counter-strafes, spray control and utility use are repeated constantly under pressure, and these habits eventually become automatic. This is the researcher's hypothesis about why the signals work, not an independently verified finding about every player.

A related preprint on arXiv, "Account Consistency from Gameplay Traces: Same-Player Verification in Counter-Strike 2", takes a similar approach. It extracts 245 per-demo-player behavioral features, organised into eight sub-representations. I can't confirm from the material I reviewed that this preprint is the same work as the NTNU thesis. I'm mentioning it only to show the same-player verification idea is being studied more widely.

The reported numbers​

Everything below comes from the researcher's own account, as relayed by Tom's Hardware and Dexerto. I didn't find an independently audited result or a publicly indexed copy of the thesis.

  • Dataset: more than 1,000 players.
  • Mouse fingerprint: identified the correct player every time in that dataset.
  • Keyboard fingerprint: identified the correct player 98% of the time.
  • Combined: reportedly separated every known same-player pairing from unrelated accounts.
  • Independence of signals: the two signals measure different movements, so combining them improves detection. The researcher quantified this: across pairs of strangers, the correlation between mouse similarity and keyboard similarity was just 0.11.

The "false positives" that weren't​

The testing had an odd twist. The system appeared to uncover previously unknown smurfs. Several apparent false positives were manually checked and found to be extra accounts belonging to players already in the dataset. Tom's Hardware reports that one person turned out to be linked to four different accounts. After those discoveries were added, the researcher said the system correctly identified all 13 known same-person pairings.

Be careful with "100%". Thirteen known same-player pairs is a small denominator. The result shows the method works on this dataset. It is not a false-positive rate for the real CS2 population. Relabelling flagged pairs as true matches after manual review is also a sensible step, but it makes the final tally less independent than a blind test would be.

A working system, with caveats​

The researcher says this is more than a proof of concept. It is designed to take in demos and link accounts continuously, building a reference for each account as matches arrive. According to Tom's Hardware, it is designed to run within a single 20GB slice of an Nvidia A100 GPU. The researcher's post goes further and claims it is fast enough to check every new match against all of CS2's monthly players. That is a design claim, not a benchmark anyone else has reproduced.

The researcher also lists limits:

  • The test data is "pretty thin", and they want to see it run on the real CS2 population.
  • Shared accounts would break the system, because one account's demos would no longer represent one person.
  • The research does not show that Valve or any other operator has adopted it.

Policy and privacy questions​

The intended use is alongside existing systems. The goal would be to use it with systems such as VAC and Trust Factor, so a ban on one account could follow a player onto another. The researcher's pitch is that "A cheater would get caught once, as a person, and stay caught."

That is also where the problems start. A fingerprint link is probabilistic evidence, not proof of wrongdoing. Any deployment would need to settle several things:

  1. Review and appeals. What happens when a link is wrong, or when two people share an account?
  2. Expiry. The researcher says a ban passed through a link should expire after a set period. In their words, cheating once as a kid shouldn't bar you for life. They call the exact line a policy choice, not a limit of the method.
  3. A new purpose for old data. Players may expect demos to record a match. They may not expect them to be used to connect their separate accounts. The sources I reviewed don't say how long data would be kept or who could access it.
  4. Evasion. Anyone who knowingly changes their input habits, or plays on shared accounts, could try to dodge the system. I'm raising this as general reasoning, not as something the research tested.

Tom's Hardware also points out that players have pushed back on invasive anti-cheat before, citing Riot dropping its always-on anti-cheat requirement.

What PC gamers should take from this​

Nothing here asks you to install anything. It needs no kernel driver, extra telemetry or client changes, which is a notable contrast with heavier anti-cheat. But match demos are not just replays. They can carry enough input detail to work as a behavioral fingerprint.

For now this is an academic result from one researcher's dataset, shared on Reddit, with no sign of rollout. It is a credible step toward bans that stick. How much it can be trusted at the scale of 1.2 million peak players will depend on testing no one has done yet.

 

References

  1. Researcher develops method for fingerprinting cheaters using Counter-Strike mouse and keyboard input patterns Tom's Hardware 2026-10-08T12:10:58+00:00
  2. CS2 player writes master’s thesis on how to ban cheaters forever instead of just accounts - Dexerto dexerto.com
  3. Account Consistency from Gameplay Traces: Same-Player Verification in Counter-Strike 2 arxiv.org