A survey of behavioral bot detection and the limits of synthetic human input.
Languages: English · Português (pt-BR)
Full article: PAPER.md · Runnable primitives: reference-implementations/ · Bibliography: references.bib
The behavioral layer of modern bot detection scores how you move, not how your traffic looks. This survey pulls together work scattered across security conferences, biometrics journals, HCI, and industry reverse-engineering, and organizes it around a question those communities rarely ask together: given a detector, which way of generating human-like input is the easiest to catch? It also does something English-only overviews rarely do: it brings in the Chinese-language scene (the GeeTest and NetEase behavioral CAPTCHAs, and the slider-trajectory generation ecosystem), where a good part of this research actually happens (Section 4.5).
The automation community treats human-like mouse movement as a smoothness problem and reaches for a library. The research says that is backwards. Once a generation library is public and popular, it becomes the negative example every serious detector trains on, which is the fastest thing for a classifier to learn rather than the hardest to catch. What actually decides detection, across the work reviewed here, is how closely a generator's output matches the statistical spread of real users. The survey walks through what detectors measure, the analytic and data-driven ways to generate input, and the published evidence behind that claim.
PAPER.md: the survey itself.- What the behavioral layer measures (pointer dynamics, keystroke dynamics, event provenance, engine timing, event budgets)
- Synthesizing human input (Fitts, sigma-lognormal, WindMouse; autoencoders, GANs, diffusion)
- The detectability axis (training-set contamination, empirical rankings, session-replay, classifier fragility)
- Discussion, open problems, and scope
reference-implementations/: standard-library Python for the classical motor-control primitives (Fitts's law, sigma-lognormal velocity profile, WindMouse). Illustrative, runnable, not tuned against anything.references.bib: BibTeX for every cited source. All citations verified against the primary source.
This is a synthesis of already-public academic and industry material. It points at no particular live deployment and ships no packaged evasion tool; the reference code stops at textbook motor-control math. The material is dual-use: knowing what makes synthetic input detectable is what a fraud team needs to build better detectors, and what an automation engineer needs to build a more human agent. Please don't use any of it to break a service's terms, commit fraud, or bypass a security control without authorization. Full statement in PAPER.md §6.
@misc{detectability_ceiling,
author = {limawtf},
title = {The Detectability Ceiling: Behavioral Bot Detection and the Limits of Synthetic Human Input},
year = {2026},
note = {https://github.com/limawtf/behavioral-bot-detection}
}MIT. See LICENSE.
A camada comportamental da detecção moderna de bots pontua como você se move, não como o seu tráfego parece. Este survey junta trabalhos espalhados por conferências de segurança, periódicos de biometria, IHC e engenharia reversa da indústria, e os organiza em torno de uma pergunta que essas comunidades raramente fazem juntas: dado um detector, qual jeito de gerar input humano é o mais fácil de pegar? E faz uma coisa que panoramas só-em-inglês raramente fazem: puxa a cena chinesa (os CAPTCHAs comportamentais da GeeTest e da NetEase, e o ecossistema de geração de trajetória pra slider), onde boa parte dessa pesquisa de fato acontece (Seção 4.5).
A comunidade de automação trata movimento de mouse humano como problema de suavidade e recorre a uma biblioteca. A pesquisa mostra que é o contrário. Quando uma biblioteca de geração fica pública e popular, ela vira o exemplo negativo que todo detector sério usa pra treinar: a coisa mais rápida de um classificador aprender, não a mais difícil de pegar. Quem decide a detecção, na literatura revisada aqui, é o quanto a saída do gerador bate com a dispersão estatística de usuários reais. O artigo passa pelo que os detectores medem, pelas formas analíticas e data-driven de gerar input, e pela evidência publicada por trás disso.
PAPER.md: o survey (em inglês).- O que a camada comportamental mede (dinâmica de ponteiro, dinâmica de digitação, proveniência de evento, timing de engine, orçamentos de evento)
- Síntese de input humano (Fitts, sigma-lognormal, WindMouse; autoencoders, GANs, difusão)
- O eixo da detectabilidade (contaminação de dataset de treino, rankings empíricos, session-replay, fragilidade de classificador)
- Discussão, problemas em aberto e escopo
reference-implementations/: Python (só biblioteca padrão) das primitivas clássicas de controle motor (lei de Fitts, perfil de velocidade sigma-lognormal, WindMouse). Ilustrativo, executável, não calibrado contra nada.references.bib: BibTeX de cada fonte citada. Todas as citações foram verificadas contra a fonte primária.
Isto é uma síntese de material acadêmico e de indústria já público. Não aponta pra nenhum deploy vivo específico e não traz gerador empacotado; o código de referência para na matemática de controle motor de livro-texto. O material é dual-use: saber o que torna input sintético detectável é o que um time de antifraude precisa pra construir detector melhor, e o que um engenheiro de automação precisa pra construir um agente mais humano. Por favor, não use nada disso pra furar termos de serviço, aplicar golpe ou passar por cima de controle de segurança sem autorização. Declaração completa em PAPER.md §6.
@misc{detectability_ceiling,
author = {limawtf},
title = {The Detectability Ceiling: Behavioral Bot Detection and the Limits of Synthetic Human Input},
year = {2026},
note = {https://github.com/limawtf/behavioral-bot-detection}
}MIT. Ver LICENSE.