Skip to content
ArionAC Dashboard

Detection

Evidence and confidence

How observations become decaying evidence and player risk, and why confidence, correction and punishment are separate.

From observation to action

A detector observes a measurable state: for example a prediction offset, an attack ray missing every supported target pose, or invalid packet data. It attaches its context and reliability. The evidence manager decides what contribution is accepted into the player’s risk profile.

Observation → Evidence Manager → Player Risk
                                      ↓
                            Alert / Correction / Punishment

Related observations share correlation families, so several detectors describing the same underlying event are not automatically independent proofs. Incomplete or unsupported observations must not become confident accusations.

Read the numbers correctly

ValueMeaning
Evidence (EV)The accepted amount of recent supporting material, reduced over time. Different observations can add different weights.
Confidence / supportA rounded model-support index that depends on the observation and context. It is not an empirically certified probability that a person is cheating.
RiskA bounded summary of the current risk profile. It is not a ban verdict.
VLA compact staff-facing value or legacy per-check counter, depending on the view. Historical counters are not automatically new trusted live evidence.

An alert may look like Arion » Player • Movement.Prediction ×3 | +3.1 EV | 70% | VL 8.2. This is an illustrative format, not a fixed weight or confidence. Repeated alerts are grouped or rate-limited; the actual accepted contribution can differ by event.

Use /arionac risk <player> to inspect domains, recent evidence, support and connection safety together. Hover details or logs can give the underlying context.

Evidence decays

Live evidence has a configurable half-life. With the default 15 seconds, an isolated contribution loses half its value after 15 seconds without reinforcing evidence. Repeated relevant observations can accumulate faster than this decay.

evidence:
  HALF-LIFE-SECONDS: 15.0
  MIN-PUNISHMENT-EVIDENCE: 30.0
  MIN-DETERMINISTIC-SAMPLES: 5
  MIN-DETERMINISTIC-SPAN-MS: 500

violations.DECAY-INTERVAL-SECONDS (30) and violations.DECAY-AMOUNT (1.0) apply to archived legacy counters. They do not replace the live evidence half-life.

Correction is not punishment

A permitted physical correction can remove an unsupported movement advantage without declaring a player ban-eligible. Likewise, a staff alert can be informative without authorizing an automatic action.

Automatic punishment requires the global policy, sufficient eligible evidence and reliable context, and must also be enabled in punishment.ENABLED. Crossing the numeric evidence threshold alone does not bypass these requirements. Statistical detections without released calibration and incomplete timing evidence are not automatic ban anchors.

Movement.Prediction and Movement.Velocity can report supporting evidence while their observations remain ineligible for automatic sanctions. Keep automatic punishment off until you have evaluated your own legitimate server mechanics.