One in five ad impressions on the internet is fake. Not "potentially suspicious" — actually invalid: a bot, a click farm, domain spoofing, or proxy traffic that will never lead to a real conversion. For advertisers, that's wasted budget. For publishers, it's clawed-back payouts and damaged zone reputation. I work with both sides at AdsCompass and see how the same problem looks from opposite ends: a buyer complains about zero CR on a zone, a publisher is puzzled why their eCPM got cut. Often the cause is the same — fraud that wasn't filtered in time. This isn't a theoretical overview of "what is ad fraud." It's a practical guide: which types of fraud actually occur in ad networks running push, pop, and native, how to spot them in your dashboard, and how a platform's anti-fraud system protects both sides.

Key Takeaways
- 20.64% of ad traffic in 2025 was invalid, according to Fraudlogix
- Desktop traffic shows a 27% IVT rate — 40% higher than mobile
- Fraud in pop and push manifests differently than in programmatic display
- Anti-fraud protects both sides: advertiser budgets and publisher payouts
- Any filtering produces false positives — zero-loss protection doesn't exist
How Much Money the Market Loses to Fraud
The scale of the problem is no longer abstract. According to Fraudlogix data for 2025, the average invalid traffic (IVT) rate across 105.7 billion analyzed impressions was 20.64%. Desktop traffic proved most vulnerable — 27.03% IVT, which is 40% higher than mobile. Industry projections estimate global fraud losses at $100+ billion by the end of 2026. For ad networks working with pop, push, and native formats, these figures carry direct implications. Unlike programmatic display, where fraud is more often tied to viewability and MFA sites, in performance formats fraud hits specific metrics: CR, CTR, bounce rate by zone. AdsCompass processes over 900 million impressions daily — at that scale, even 1% of invalid traffic means millions of wasted impressions.
What Types of Fraud Occur in Ad Networks?
Fraud in ad networks running performance formats differs from fraud in programmatic display. Ad stacking and pixel stuffing are less common here — those techniques are designed for banner impressions. What's actively used instead is bot traffic, click farms, domain spoofing, and proxy traffic. IAB classifies invalid traffic into two categories: GIVT (General Invalid Traffic) — search engine crawlers, known data centers, easily filtered by lists — and SIVT (Sophisticated Invalid Traffic) — bots mimicking human behavior, residential proxies, device spoofing. SIVT is the primary threat because it bypasses basic filters. According to HUMAN Security, automated traffic grew eight times faster than human traffic in 2025.
Bot Traffic and Click Farms
Bot traffic generates fake clicks and impressions at industrial scale. Modern bots simulate mouse movement, scrolling, and time on page — simple IP filters don't catch them. Click farms are coordinated groups of real people clicking ads for payment. They generate traffic from real devices and real IPs, making detection harder than with bot traffic. According to a 2026 Clixtell case study, 68% of fraudulent traffic in the analyzed campaign came from click farms, not bots.
Domain Spoofing and Inventory Substitution
Domain spoofing is when a low-quality site presents itself to the ad system as a premium publisher. The advertiser pays CPM for placement on a reputable news portal, while the ad actually serves on a junk-content site. In networks with direct publishers, this type of fraud is less common because sources are verified. But when working through RTB integrations, the risk remains.
Fraud in Push and Pop Formats
In push traffic, fraud most often manifests through fake subscription bases: a bot "subscribes" to notifications, generates impressions, but never converts. In pop traffic, the main vector is proxy and VPN traffic, where a user in one GEO masks themselves as being in another, more expensive one. The advertiser pays Tier-1 rates while the traffic actually comes from Tier-3. This directly impacts campaign ROI. All AdsCompass formats pass through a proprietary anti-fraud system that analyzes traffic at the level of each individual impression.
Why Anti-Fraud Matters for Both Sides — Advertisers and Publishers
Anti-fraud is typically discussed from the advertiser's perspective: "my budget was drained by bots." But publishers suffer just as much — just differently. When an ad network detects invalid traffic from a publisher's zone, the consequences land on them: payout cuts, eCPM downgrades on the zone, and in severe cases — account suspension. The publisher may not even be aware of the problem: for instance, their site became a target for proxy traffic or a botnet generating visits through their domain. For the advertiser, anti-fraud is budget protection. For the publisher, it's reputation protection. For the platform, it's ensuring trust between both sides. AdsCompass works with direct publishers, providing quality control at the source level, while simultaneously protecting advertisers from invalid traffic through filtering at the impression stage.
When Anti-Fraud Works Against You: Honest Limitations
No system filters fraud without side effects. This is a reality few people write about, yet everyone who works with anti-fraud tools in practice encounters it. The first limitation is false positives. Aggressive filtering inevitably blocks some legitimate traffic. Users behind VPNs, corporate proxies, shared IPs in dormitories and coworking spaces — all of them can look suspicious to an automated system. The second is volume loss. The stricter the filter, the less traffic gets through. For campaigns where reach and data collection speed are critical — especially when testing in Tier-2/3 — this can slow down the launch. The third is detection lag. Pre-bid filtering blocks obvious patterns before the impression, but SIVT (sophisticated fraud mimicking human behavior) is only identified post-bid, through behavioral analysis after the click. Time passes between the impression and detection, and part of the budget is spent before the system reacts. AdsCompass uses a combination of pre-bid and post-bid filtering to minimize both problems — but promising zero fraud would be dishonest. Fraud evolves alongside detection, and it's a constant race.
How Anti-Fraud Works at AdsCompass
AdsCompass processes over 900 million impressions daily and applies anti-fraud at the platform level — it's not an optional tool but part of the infrastructure. The system analyzes each impression across a set of parameters: IP reputation, device fingerprint, GEO consistency, behavioral patterns, campaign targeting compliance. Zones with anomalous metrics are automatically downranked in the auction or blocked pending verification. For publishers, this means "clean" zones receive priority in ad demand distribution from 6,500+ active advertisers — resulting in higher bids and stable fill rate. For advertisers, it means budget is spent on verified traffic from direct sources, not through a resale chain where every link adds risk. Working directly with publishers is a separate layer of protection. Unlike networks that aggregate traffic through dozens of intermediaries, AdsCompass controls sources at the onboarding stage. This doesn't eliminate fraud entirely, but it significantly reduces the attack surface.
FAQ
What is IVT and how does GIVT differ from SIVT?
IVT (Invalid Traffic) is the umbrella term for non-legitimate traffic. GIVT is simple invalid traffic: search engine crawlers, known data centers, automated scanners. Filtered by lists. SIVT is sophisticated fraud: bots mimicking human behavior, residential proxies, device spoofing. Requires behavioral analysis to detect. According to Statista, the share of SIVT in total fraud volume grows annually.
Can anti-fraud block legitimate traffic?
Yes. False positives are an unavoidable part of any automated filtering. Users behind VPNs, corporate proxies, or on shared IPs get caught by filters. At AdsCompass, the false positive rate is minimized through a combination of pre-bid and post-bid analysis, but eliminating errors entirely is not possible.
How can I verify traffic quality before launching a campaign?
Run a test campaign with a minimal budget for 24–48 hours. Collect data on CTR, bounce rate, and CR by zone. Add zones with anomalous metrics to a black-list before the main launch. On AdsCompass, zone-level targeting and white/black-lists are available in the self-serve dashboard.
Do publishers need anti-fraud or is it only for advertisers?
Both sides need it. Advertisers lose budget on invalid traffic. Publishers lose payouts and zone reputation when the network detects fraud on their sources. Platform-level anti-fraud protects both simultaneously.
What percentage of fraud is considered acceptable?
Zero IVT rate is not achievable in practice. Per Fraudlogix benchmarks, the market average is around 20%. Optimized campaigns with pre-bid filtering hold IVT below 1%. A working benchmark for buyers: if campaign IVT stays consistently below 3–5%, filtering is performing correctly.
Does anti-fraud protect against click farms?
Partially. Click farms use real devices and real IPs, making them harder to detect than bot traffic. Anti-fraud systems identify click farms through behavioral analysis: identical time on site, no scrolling, synchronized click patterns. But no system on the market can guarantee 100% click farm detection.
About the Author
Vlada, Business Developer at AdsCompass. Works with advertisers and publishers in digital advertising, specializing in performance formats and international markets. Helps partners build traffic acquisition and monetization strategies across 200+ GEOs.