## 1. The Evolution of Bot Detection
For over two decades, behavioral biometrics in web applications has centered on a single fundamental premise: machine-generated automation lacks the physical subtleties, neuromuscular tremor, and motor hesitation of a human hand.
Defenders developed three main layers: 1. Behavioral Machine Learning (e.g. Random Forest): Detects statistical regularities such as over-smooth Bézier curves, constant velocity, and unrealistic acceleration derivatives (jerk variance). 2. Historical Similarity / Embedding Comparison (e.g. DTW, LSTM autoencoders): Flags exact duplicates or near-identical replayed sessions against a stored trajectory library. 3. Context & Click-Target Validation: Checks whether click coordinates align with legitimate, interactive UI bounding boxes in a logical sequence.
2. The Unsolved Gap: Processed Replay
Two independent IEEE studies exposed the boundary of these defenses: * Salman & Bicakci (IEEE Access, 2026): Evaluated a 6-level ladder of bot sophistication across 1,140 real sessions. Every defense succeeded against synthetic bots-until processed replay (Attack 6), where an adversary splices fragments from multiple genuine sessions. Salman & Bicakci declared processed replay explicitly out of scope. * Sadeghpour & Vlajic (IEEE CSR, 2024 - ReBotDetector): Built an LSTM-autoencoder for session replay, but acknowledged it only detects replayed sessions with near 1.0 cosine similarity to a single recorded session. It cannot detect composite sessions built from multiple donors.
3. The CORROBORATE Paradigm Shift
Because every fragment in a processed replay attack originated from a real human, single-channel mouse statistics look completely genuine. CORROBORATE solves this by analyzing the cross-modal temporal coupling between channels (mouse, keystrokes, scroll, focus). While individual fragments are human, the timing relationships across modalities break down at the splice seams.