Ad fraud rarely looks like an attack. More often it is quiet background noise: a tenth of clicks without a single conversion, a placement that suddenly "takes off" overnight, a batch of leads with identical phone numbers. An anti-fraud system exists to make that background visible and stop it eating your budget.
Let's look at what anti-fraud is, which types of fraud it deals with and what parts it is built from.
What is an anti-fraud system?
An anti-fraud system automatically evaluates events — clicks, impressions, leads, payments — and separates genuine ones from fakes. The term came from banking, where anti-fraud catches fraudulent transactions. In advertising the logic is the same: there is a stream of events, someone pays for each one, and some of them are fake.
Anti-fraud in advertising works at several levels:
- at the ad platform — so it does not charge for clearly invalid clicks and impressions;
- at the CPA network — so it does not pay a publisher for fake leads;
- at the advertiser or affiliate — so they do not buy junk and can see real returns.
These levels do not replace each other: each has its own data and its own interests.
Types of ad fraud
| Fraud type | What it looks like | Who loses |
|---|---|---|
| Bot clicks | A program follows the ad, sometimes imitating a browser | Whoever pays per click |
| Click fraud | Deliberate empty clicks to drain someone else's budget | The advertiser |
| Impression fraud | Ads "shown" in invisible slots or to bots | Whoever pays for impressions |
| Placement fraud | A site in the ad network inflates its own clicks | The traffic buyer in that network |
| Fake leads | A bot or a person with made-up details fills in the form | The CPA network and advertiser |
| Incentivized traffic | People are paid for an action, but it is passed off as regular traffic | The advertiser |
| Source spoofing | Traffic from one place is passed off as another, pricier one | Whoever buys the traffic |
| Attribution hijacking | Someone else's conversion is claimed as one's own | The honest source |
More on clicks in click fraud and how to protect your budget, and on mobile in-app traffic in in-app traffic and fraud.
Invalid traffic: general and sophisticated
Ad measurement splits invalid traffic into two groups. General invalid traffic (GIVT) is what simple rules catch: known robots, data center networks, obvious crawlers. Sophisticated invalid traffic (SIVT) includes bots pretending to be humans, fraud through infected devices and residential proxies. The first kind is filtered at the entrance with almost no errors; the second requires browser and behavior checks, and that is exactly where anti-fraud makes the most mistakes.
How an anti-fraud system works
Nearly every anti-fraud system, from banking to advertising, is built from three parts: rules, scoring and lists.
Rules
A rule is a hard condition: "if X, reject". For example: the country is not on the allowed list, more than three clicks from one address in a day, the request came from a program rather than a browser. Rules are transparent and predictable but blunt: sooner or later any of them will hit an honest user.
A good rule cuts what is clearly not target traffic and leaves borderline cases to scoring.
Scoring
Scoring is an evaluation based on the sum of signals. Each suspicious signal adds a penalty: VPN, hosting network, no JavaScript, an odd combination of language and time zone, no referring site. Individually they mean little — a person on a VPN is still a person. But when penalties add up above a threshold, the event counts as fraud.
Scoring is more flexible than rules: the threshold and signal weights can be tuned to the source. Traffic from a social app's in-app browser often has no referrer, so that signal should weigh almost nothing there, while for search it is the opposite.
Lists
Lists are the system's memory. A blacklist contains addresses, networks and devices already caught in fraud; a whitelist holds your own: the office, test devices, trusted partners. The strongest are shared lists that are fed by data from many clients: a bot caught for one is instantly recognized for all. How such lists work and why other people's lists can be dangerous is covered in IP blacklists and IP reputation.
Learning from your own data
On top of the three parts, a model is sometimes added that learns from history: which clicks later brought payouts and which turned out to be bots. It catches what cannot be described by a simple rule. Its weakness is that it needs history: on a new account it has nothing to learn from.
Anti-fraud for affiliate marketing: what to watch
An affiliate needs anti-fraud in two places: at the entrance (keep fraud off the landing page and offer) and in analytics (see where fraud came from and stop paying for it). How to read the result in numbers is covered in how to check traffic quality.
At the entrance it helps to:
- Filter obvious bots and reviewers before the page is shown.
- Limit the number of clicks from one address, against repeats and click fraud.
- Check the network: VPN, proxy, data centers (in detail in VPN, proxy and data center IPs).
- Check the browser: script execution, traces of automation.
In analytics it helps to:
- Pass the placement or zone into a campaign parameter so you can see fraud per placement.
- Match clicks with conversions via postback, so you can see which "clean" clicks actually bring nothing.
- Watch rejected and trash statuses in the CPA network (see conversion statuses).
- Block junk placements in the ad network itself, not just filter them on your side: that is how you stop paying for them.
Tip. A filter on your side does not refund a click you have already paid for. It protects the landing page and the stats; the savings come when you use its data to exclude placements and addresses in the ad account.
Anti-fraud at the platform and the CPA network
It helps to understand what other anti-fraud systems see — it makes talking to them easier and their decisions less surprising.
The ad platform sees the impression and the click: device, address, user account, the user's history on the platform. It catches crude invalid traffic well and usually does not charge for it. But after the click the platform goes blind: it does not know whether your landing page opened, whether the script ran on it or whether a lead arrived, unless you send the conversion back.
The CPA network sees the lead and what happened to it: whether the call center reached the person, whether the phone matches earlier ones, whether the order was paid for. Its anti-fraud rejects leads retroactively, sometimes days later when the hold period ends. For an affiliate this is the most painful kind of anti-fraud: the money for the clicks is already spent, and there is no payout.
Your own filter sees what lies between them: the visit to the page itself. It is the only place where you can stop a bot before it fills in a form and damages your relationship with the network.
Tip. When a network rejects leads as fraud, ask for the click IDs or sub IDs of the rejected leads. Matching them with your log, you usually find a common denominator: one placement, one ISP network, one time of day.
Anti-fraud false positives
Every anti-fraud system errs in two directions: it lets fraud through and it cuts honest users. The second error is more dangerous because it is invisible: a real buyer simply never reached the offer, and in the reports it looks like "bad traffic".
Who anti-fraud cuts most often:
- people on VPNs and corporate proxies;
- mobile internet, where thousands of subscribers share one address;
- in-app social browsers and WebViews in apps, which sometimes look like automation;
- old devices and browsers with features turned off;
- people who come back via a bookmark or a forwarded link.
How to catch false positives:
- Look at the reason for every rejection. If a large share is filtered by a single check, that check is suspect.
- Watch the pass rate. A high pass rate is not bad in itself: paid traffic with a verified click ID can have a high pass rate, and that is normal. What is alarming is a pass rate dropping almost to zero: the filter is most likely cutting people.
- Turn on observation without filtering. Let the system first mark whom it would have filtered, and compare that with conversions.
- Change one setting at a time and compare conversion before and after.
How to read rejections is covered in detail in why a click went to the White Page.
How anti-fraud works in ArtisanClo
ArtisanClo is an ad traffic filtering service with a tracker, and its filter is built from the same three parts.
- Rules. Some checks reject a visit immediately: IP blacklists, an obvious headless browser, a program instead of a browser, ad review services, audience rules (country, device, schedule), the clicks-per-IP limit.
- Scoring. Everything else adds up to a trust score: VPN, data center, IPv6, no ISP, no referring site, no JavaScript. Protection toggles decide how much each signal weighs, and strictness is set with the Soft, Balanced and Strict levels, matched to the traffic source.
- Lists. Your own IP blacklist and IP whitelist plus a shared bot list: an address confidently identified as a reviewer or a program for any client immediately gets the White Page in every flow. Real visitors on a questionable network are never added to it.
- Learning. Extra guard learns from your account's history — who paid and who turned out to be a bot — and checks only visits the other rules already let through. It switches itself off if it starts cutting a noticeable share of conversions.
- Transparency. Every click in the log has a decision and a reason out of dozens; statistics show at which step traffic was filtered: Network and request, Browser check, or Check never came back.
- Protection against false positives. Shadow mode (with the PHP file and with Keitaro or Binom) shows whom the filter would have cut without cutting anyone, and flow Diagnostics replays past visits through the current settings and shows which filter cuts traffic that converts.
The tracker and a postback from the affiliate network help tie clicks to leads. Features are on the features page, plans on the pricing page.
Summary
An anti-fraud system is rules for the obvious, scoring for the borderline and lists as memory. A good anti-fraud system is not the one that cuts the most but the one that explains every decision and lets you notice in time when it is hitting real people. In affiliate marketing both halves matter: the filter at the entrance and the analytics that show where the fraud was born.



