Flag sharing, inter-team cooperation (teaming), and prohibited tools such as AI undermine how validly a Capture the Flag (CTF) event measures skills, corrupting the integrity of its scoring information system. GZCTF's only cheating signal is the dynamic flag that catches flag theft. Nothing else feeds a per-team risk profile. This study adds a detection module to the GZCTF backend built on two components. The first is Two-Stage Similarity Analysis: pairwise Longest Common Subsequence and Jaccard scores are blended into a Relative Sequence Index (RSI), after which Confidence Screening Detector (CSD) screening confirms suspicious groups. The second is a tiered Weighted Risk Scoring model that assigns 38 indicators to four evidence tiers (Hard, Strong, Behavioral, Context), caps every non-Hard tier, and gives network or identity correlations no direct score. Evaluation used a controlled simulation of ten team participations on a live instance, with ground-truth labels fixed at design time. Precision reached 1.000 with zero false positives, accuracy 0.900 and F1 0.909, and recall 0.833. The single miss came from collusion evidence attributed to only one member of a pair. An RSI threshold of 0.85 split every colluding pair from benign ones, and teams with purely network or identity correlation scored zero.
Copyrights © 2026