Ad fraud tooling: the market and what it catches
By Isaac Turner, Measurement Editor — Archive date: 5 min read
View author profile
How install hijacking, click flooding, SDK spoofing and bots get caught, which layer catches what, and a rejection-rate sanity check for buyers.
Uber's long-running fraud lawsuit against a set of mobile ad networks, which put concrete internal numbers on how much of the company's attributed install volume turned out to be fabricated, remains the clearest public illustration of why fraud tooling exists as a distinct market rather than a checkbox inside an MMP. Mobile ad fraud: the lessons from Uber's own lawsuit covered what that case revealed about the mechanics. This piece is about the tooling layer built to catch those mechanics before they cost a studio real spend.
The fraud types worth naming precisely
Install hijacking, sometimes called click injection on Android, exploits the last-click attribution window by firing a fraudulent click the instant a legitimate organic install begins; the fraudster steals credit for an install that would have happened anyway. Click flooding is the cruder cousin. It fires large volumes of clicks against many devices in the hope that a small share coincide with a real organic install inside the attribution window, so it works through probability rather than device-level timing tricks.
SDK spoofing fabricates attribution events with no real device and no real ad impression behind them at all, either by replaying legitimate-looking traffic through a server or by manipulating an SDK integration on a compromised or emulated device. Device farms and bots sit at the crude end of the same spectrum. Physical or emulated devices cycle through installs and opens and then through in-app events to look like a real, engaged cohort, and the better-run farms tune that activity specifically to mimic the retention curve a buyer is watching for.
Which layer catches what
Start with the MMP. AppsFlyer and Adjust both bundle fraud protection by default, as does Singular, and that layer is generally strong on click flooding and install hijacking, because both leave timing signatures visible in the MMP's own attribution logs: clicks and installs arriving implausibly close together, or click volume wildly out of proportion to impression volume from the same source. It's weaker on sophisticated SDK spoofing, where whoever built the fraudulent traffic engineered it specifically to avoid the timing anomalies an MMP watches for.
Standalone fraud vendors exist largely to cover that gap. They run device fingerprinting and behavioural analysis across the full user session rather than just the attribution moment, plus device-farm detection based on hardware and network fingerprints that look identical across thousands of nominally distinct devices. These vendors tend to run as an overlay on top of MMP data rather than a replacement for it, flagging installs the MMP passed as clean but which a deeper behavioural check catches.
Network-side tools, the fraud filtering a network runs on its own supply before it ever reaches an MMP, are the least visible layer to a buyer and the most variable in quality across networks.
A network with weak internal filtering will show artificially high volume at an artificially low CPI. The only way a buyer detects that gap is by comparing a network's raw delivered volume against what independent fraud tooling later confirms as clean.
A rejection-rate sanity check
Rejection rate, the share of attributed installs a fraud layer flags and excludes, is a useful diagnostic only in context. A rate near zero across an entire network is a red flag, not a compliment; no channel at scale is genuinely fraud-free, and a network reporting zero rejections is more likely under-filtering than actually clean. A rejection rate that is unusually high relative to a network's peers deserves the opposite question: is the filter aggressive enough that it's also cutting legitimate installs, particularly from smaller or newer publishers whose traffic patterns simply look less familiar to the model?
The practical check worth running quarterly is a side-by-side comparison of rejection rates by network. Flag any network whose rate is a clear outlier in either direction, then investigate rather than blindly trusting a clean-looking number or blindly cutting a network for a high one. Pair that with a manual spot check, a handful of accounts from a flagged network reviewed for plausible session behaviour, since automated rejection scores are themselves models and can be wrong in both directions.
What this means for budget allocation
Fraud tooling isn't a one-off purchase decision so much as a layered posture. MMP-level protection catches the obvious cases. A standalone vendor is worth the added cost once spend on any single channel is large enough that a few percentage points of hidden fraud represents real money, and network-side quality should factor into media planning the same way CPI and retention do.
A network that is cheap because its fraud filtering is weak isn't actually cheap once you price in the fraudulent share of its volume.
Related archive reading
These articles provide related context and remain subject to their stated review status.
Featured
Related posts
market intelligence
measurement
·1 min read
Retention percentile charts for F2P: what GameAnalytics-style cuts miss
market intelligence
measurement
·2 min read
Sensor Tower’s $82 billion figure is an IAP measure
market intelligence
measurement
·2 min read
The 52 billion download headline crosses platforms
market intelligence
measurement
·2 min read
One casual-gaming report contains several data populations
More from the Market Intelligence desk
market intelligence
media buying
·1 min read
Lunar New Year UA gates from an official calendar, not a CPI myth
market intelligence
media buying
·2 min read
WeChat Mini Games upgrades 2026 IAP / virtual-payment incentives for debut titles
market intelligence
media buying
·2 min read
WeChat Mini Games IAA incentives from 20 August 2026: 3-minute lifetime, 180-day option
creative strategy
market intelligence
·1 min read