rollerads
Stopping ad fraud: How ad networks screen invalid traffic
More traffic may look good at first, but it doesn’t necessarily mean you will see better results. The number of impressions, clicks, or visits to your website may be higher than before, which might indicate that your campaign is improving.

However, not all of that activity reflects genuine user interest. Some of this traffic may be automated, some could come from computers infected with malware, and some may come from real individuals who were hired to act as if they were regular users.

These different types of invalid traffic need to be identified and filtered out because fraudulent traffic does more than simply waste the marketer's money. It can also distort campaign performance data enough to affect the quality of the decisions you make when optimizing a campaign.

And this isn't a small problem. Estimates suggest that online advertising fraud could cost marketers approximately $170 billion by 2028.

As a result, anti-fraud systems have become an important part of what ad networks do behind the scenes.

What is invalid traffic?

Invalid traffic is a broader category than ad fraud, but fraudulent traffic itself can take many different forms. Some methods are relatively simple and easier to identify. Others are designed to mimic legitimate human activity, making them much harder to detect.

Basic bot traffic
The simplest types of bots can repeatedly visit websites, load ads, and/or click on links. These basic bots often originate from data centers, leaving their own technical or behavioral patterns behind.

They may create hundreds of sessions that all share the same or similar screen sizes, operating systems, devices, etc. In addition, session durations may be suspiciously low. Mouse movements or other interactions may also be non-existent.
None of these signs proves fraud by itself, but a combination of them can make basic bots easier to identify than more advanced forms of fraud.

Even so, they can still artificially increase campaign metrics before being filtered out.

Traffic from infected devices
Another, more complex method of generating fraudulent traffic uses actual devices—phones, routers, computers, smart TVs, etc.—that have been compromised by malicious software ("malware").

These devices may then be used to generate advertising-related activity, such as impressions, clicks, or page visits, without the owner's knowledge.

For example, an impression can be registered when an advertisement loads on an infected device, even though the owner never intentionally viewed or interacted with the ad.

Because this activity comes from an actual consumer device rather than an obvious bot or data-center server, it can be much harder to identify.

Click farms & deceptive incentivized activity
Finally, automation isn't the only means of mimicking engagement.
Real individuals performing repetitive tasks such as viewing advertisements, scrolling through webpages, installing apps, clicking links, or filling out online forms are often organized into what are commonly known as "click farms."

Many common signals may still look human: the device is real, the cursor appears to move naturally throughout the session, and the session itself may last a typical amount of time. What may be missing is genuine interest in the advertised product or service.

For example, a user filling out dozens of lead forms simply because they are being paid to do so is fundamentally different from a potential customer who is genuinely interested in the product.

It is important to note that incentivized traffic itself is not automatically fraudulent. It becomes a problem when that activity is disguised as genuine interest, violates the rules of the offer or network, or is used to artificially inflate campaign results.

Why bad traffic costs more than the click

Ad fraud has a pretty direct impact on an advertiser's budget. If some portion of that budget is being spent on fake impressions, automated clicks, or artificially generated actions, then this spend is unlikely to generate the anticipated returns.
However, the larger issue begins after the fact.

Optimizing your campaigns requires data. Advertisers rely on metrics like CTR, conversion rate, CPA, traffic sources, devices used, and creatives to decide where to increase spending and where to cut back.

Fraudulent traffic can contaminate these metrics. For example, let’s say you identify one new traffic channel as producing a large number of clicks. Without detecting the fraudulent activity behind them, it could appear as though you've identified a valuable traffic source worth increasing spend on.

An advertiser might then raise their bid for that particular source or allocate additional budget toward it. They may also begin adjusting creatives or targeting based upon user behavior that was fabricated from the beginning.

Fraudulent traffic is also a publisher problem

Since advertisers are the ones paying for traffic, invalid traffic is usually discussed in terms of how it affects them. That doesn't mean the damage stops on the advertiser's side. Publishers also have a lot to lose, especially when their business depends on providing access to a legitimate audience.

When a site or traffic source becomes associated with high levels of invalid traffic, advertisers may bid lower on it, blacklist it, or stop buying its traffic altogether.

There are also instances of domain spoofing, where fraudulent inventory sellers misrepresent their inventory as coming from a legitimate publisher's domain. In this case, the real publisher may lose revenue or suffer reputational damage even though they were not involved in the fraud.

This is another example of why traffic quality can't be treated as an issue for just one side of the advertising market. Advertisers need access to real users and legitimate traffic; publishers need advertisers to trust the inventory they provide.

How ad networks detect fraudulent traffic

So how does an ad network actually separate suspicious traffic from legitimate activity?

Most good anti-fraud systems don't use one magical number to identify fraud. Instead, there are multiple layers of fraud detection that can operate at different points during the process.

The first layer can include source verification and whitelisting.

In this case, the ad network may maintain a whitelist of verified publishers, traffic sources, or individual zones that have demonstrated consistent traffic quality. These lists can also be segmented by GEO or vertical based on the type of campaign being run.

For example, a publisher or zone that performs consistently with one type of campaign may perform very differently with another.

This does not mean that no additional monitoring needs to take place; rather, it gives the network a cleaner starting point when evaluating future traffic.

Pre-bid fraud detection
The second layer involves pre-bid or pre-impression fraud detection. Some types of fraud can be identified before an impression is served or charged to the advertiser.

A pre-bid system can quickly evaluate factors like IP address, user agent, device characteristics, domain information, known bot or data-center IP databases, and historical traffic source data.

If an ad request appears to match known fraudulent patterns, the network can filter or reject it before the traffic reaches the advertiser.

Pre-bid fraud detection offers the benefit of speed; however, a simple technical evaluation may miss more sophisticated types of fraudulent activity.

Fraudulent requests may contain realistic-looking headers, appear to come from legitimate devices, or originate from IP addresses that do not appear on any obvious blocklists.

This is where technical checks start to hit their limits. Another layer becomes important when determining whether something suspicious has slipped through the initial checks.

Post-bid behavioral analysis
Post-bid behavioral analysis looks at activity after traffic has entered the advertising system and more information about the interaction becomes available.

Rather than focusing on one abnormality, post-bid analysis can look at the bigger picture and see how different behaviors fit together.

However, none of the signs automatically prove fraud. A legitimate user can behave strangely, and legitimate traffic does not always convert.

This is where false positives and false negatives become important. A false positive happens when legitimate traffic is incorrectly identified as fraudulent. A false negative is the opposite: fraudulent traffic passes through the system as if it were legitimate.

The risk for networks lies in balancing these two problems—allowing bad traffic through versus incorrectly flagging good traffic as bad.

A closer look at how RollerAds filters traffic

RollerAds uses the same general idea of combining several layers rather than relying on one check.

The platform’s anti-fraud engine analyzes traffic using over 20 technical metrics along with other factors related to campaign performance. Approximately 25% of incoming traffic is filtered out before it reaches advertisers.

The technical side of the analysis looks for various types of red flags, including suspicious emulation patterns, discrepancies in device information, mismatches in time zones, and evidence that a device may have been compromised.
But that's not the whole process.

RollerAds also uses more than ten metrics directly tied to performance against CPA goals. This matters because fraudulent traffic does not always display obvious technical problems.

A source could initially look entirely legitimate from a technical standpoint: clean headers, legitimate-looking device data, and none of the more obvious bot patterns.
Even if a source appears technically clean, abnormal performance without a reasonable explanation can trigger a closer look and, if necessary, get the source blocked.

As mentioned earlier, the system also monitors traffic throughout a campaign. Traffic sources that begin to exhibit suspicious behavior can be automatically blocked without waiting for an advertiser to notice the problem and disable them manually.

Final thoughts

Ad fraud continues to evolve, and so do the methods used to detect it. A good ad network should do two things at once: catch suspicious traffic before it affects your campaigns and avoid blocking genuine users just because their behavior doesn’t fit a perfect pattern.

At RollerAds, we continuously update our metrics and refine our detection systems to distinguish invalid traffic from real users. Anti-fraud isn’t a one-time check—it’s an ongoing process, and traffic quality remains one of our top priorities.

If you want to make sure your budget goes toward real users and meaningful actions, get in touch with our team. We’ll help you find the right traffic for your campaigns.