Tag: media buying

  • Video Ad Fraud: How to Detect Fake Views, Hidden Players and Autoplay Abuse

    Video advertising creates a particularly difficult fraud problem because a reported view does not necessarily mean that a real person watched an ad. A player can start in a hidden element, load below the visible part of a page, run without sound in an unattended tab, or be triggered by automated browsing activity. In other cases, the impression may be attached to an app, site or device that does not match the inventory described in the buying interface.

    This does not mean every unusual video campaign is fraudulent. Video metrics are affected by placement design, creative length, browser behavior, consent choices, connection quality, app environments and the way each platform defines a start, view, completion or quartile event. The useful task is not to label every low-quality view as fraud. It is to separate normal delivery variation from patterns that are technically implausible, commercially harmful or inconsistent with the inventory you purchased.

    This guide explains how video ad fraud works, what fraudulent video views look like in data, how hidden players and autoplay abuse operate, and how to investigate suspected video IVT. It is written for media buyers, performance marketers, agencies, ad operations teams and fraud analysts who need evidence they can use with a platform, publisher, exchange or partner.

    What is video ad fraud?

    Video ad fraud is the deliberate or automated generation, manipulation or misrepresentation of video advertising impressions and engagement events. The affected event may be a video start, an impression, a quartile completion, a completed view, a click, an install or a downstream conversion.

    The fraud can occur at several points in the supply chain. A publisher may place a player where a user is unlikely to notice it. A traffic seller may send bots to pages that contain video ads. An intermediary may misrepresent a website, app, device type or placement. A script may create many simultaneous sessions or repeatedly reload a player. A measurement system may then record these events as legitimate video activity.

    Video ad fraud is therefore broader than fake views. It includes any material manipulation that causes an advertiser to pay for video delivery or engagement that does not represent the intended audience opportunity.

    Video IVT and invalid video traffic

    Video IVT means invalid traffic associated with video advertising. It can include general automated traffic, sophisticated bots, non-human browsers, fraudulent crawlers, data-centre traffic, automated app activity, forced interactions and inventory that violates the buyer’s requirements.

    Some invalid traffic is obvious. For example, thousands of video starts may come from a small set of hosting-provider addresses with no meaningful variation in timing or device signals. Some is harder to identify. Sophisticated automation can use residential proxies, rotate identifiers and imitate ordinary page navigation. A campaign may need several independent signals before the traffic can be treated as suspicious.

    It is important to distinguish invalid traffic from poor-quality but human traffic. A user who starts a video and leaves after two seconds may be a real user who was not interested. A hidden player that starts thousands of videos in background tabs is a different problem. The first is weak engagement; the second may be fraudulent or non-compliant inventory.

    Why video campaigns are attractive to fraud operators

    Video inventory can command higher prices than many display placements, while the event stream appears rich and persuasive. Buyers can see starts, quartiles, completion rates, sound-on rates, clicks and sometimes post-view conversions. That creates more opportunities to manufacture a convincing performance story.

    Video also has technical characteristics that make abuse easier to conceal:

    • A player can begin loading without being prominent or even visible to the user.
    • Autoplay can create a start event before a user has made a meaningful choice.
    • Muted playback can run in the background and still produce viewability or completion signals.
    • Long videos create multiple milestones that can be presented as engagement.
    • App and connected-TV environments may expose less granular information than a browser.
    • Different platforms use different definitions for impressions, starts and completed views.
    • Supply chains can contain several resellers, making the original source difficult to identify.

    Fraud does not have to create perfect fake sessions. It only needs to produce enough billable or reportable events to make the campaign appear plausible.

    Common types of video ad fraud

    Fake video starts

    A fake video start occurs when a video start event is recorded without a meaningful user opportunity to watch the ad. The event may be generated by a bot, an automated browser, a forced player, an accidental page interaction or a script that calls the player API directly.

    One start alone proves very little. A user can legitimately start a video and close the page immediately. The stronger signal is a population-level pattern: unusually high starts relative to impressions, large volumes from repetitive sessions, very low active time, or starts that occur at machine-like intervals.

    Buyers should also confirm what the platform means by start. In one reporting system, a start may mean that the first frame loaded. In another, it may be triggered after a defined playback threshold. Comparing start rates across platforms without checking the event definitions can create false alarms.

    Hidden and out-of-view players

    A hidden player is a video element that technically loads and plays but is not reasonably available to the user. It may be placed behind another element, reduced to a tiny size, positioned outside the viewport, covered by an overlay or loaded in a background tab.

    Some implementations are not deliberately fraudulent. A publisher may use a floating player that changes position, or a mobile layout may place a player below the fold. The investigation should therefore examine visibility conditions, player dimensions, page position, sound state, user interaction and whether the ad was allowed to complete.

    Out-of-view playback is especially important for campaigns optimized toward completed views. A player can continue running after the user scrolls away unless the implementation pauses it. If the advertiser pays on a view or completion event, this creates a direct quality and compliance concern even when the original page visit was human.

    Autoplay abuse

    Autoplay is not automatically fraudulent. Many legitimate video environments use autoplay, particularly when the video is muted and placed in-feed. The risk arises when autoplay is used to create video events without a clear user opportunity or when players are stacked, repeatedly triggered or loaded in locations where the user will not notice them.

    Warning signs include a high share of starts with no page engagement, completion rates that remain strong despite almost no sound-on activity, several players starting on one page, repeated starts after refreshes, and video events that continue while the browser tab is hidden.

    Autoplay should be assessed against the campaign’s buying terms. A muted in-feed impression may satisfy one product’s definition of a viewable video impression but fail the advertiser’s own standard for an attentive completed view. Fraud review should document both the technical behavior and the commercial expectation.

    Bot viewing and automated browsing

    Bot viewing happens when automated software loads pages, apps or players and generates video events. The software may be a simple script, a headless browser, a browser with automation controls, a malware-infected device or a more advanced system designed to resemble human activity.

    Basic bot indicators include data-centre networks, impossible navigation speeds, repeated user-agent and screen-size combinations, no mouse or touch activity where those signals are available, and identical event sequences across many identifiers. More advanced traffic may avoid these obvious markers, so analysts should examine relationships between signals rather than relying on a single blocklist.

    A high completion rate is not evidence that the audience was real. An automated browser can play an entire file more consistently than a human viewer. In fact, unusually perfect completion behavior can be more suspicious than a normal distribution of partial views.

    Player stacking and ad density abuse

    Player stacking occurs when multiple video players are loaded in a single page or session, sometimes with only one visible. Each player may request advertising, creating several billable opportunities from one user visit. Some stacked players are hidden; others are placed in tiny containers or moved off-screen.

    Review the number of video requests per page view, the number of simultaneous players, the placement coordinates, player dimensions and whether several ads share the same start timestamp. A normal publisher page may contain more than one legitimate video opportunity, but repeated parallel starts across a large sample deserve investigation.

    Ad pod and impression manipulation

    In streaming, connected-TV and app environments, a pod can contain multiple advertisements. Fraud may involve false pod positions, duplicate requests, repeated ad calls, fabricated quartiles or discrepancies between what the supply platform reports and what the player actually rendered.

    These cases can be difficult to investigate because the buyer may not receive raw player logs. Useful evidence includes pod identifiers, ad break identifiers, creative IDs, timestamps, duration, quartile events, device context, app or channel information and server-side request logs.

    Inventory and app-identity spoofing

    Inventory spoofing occurs when the technical identity of the placement does not match the inventory represented to the buyer. An exchange may report a premium app or channel while the impression was generated elsewhere, or a reseller may pass incomplete or inaccurate app metadata.

    For web video, inspect the domain, page URL, referrer and ads.txt relationship where available. For apps, review the app bundle identifier, store listing, app name, publisher information and sellers.json or supply-chain data. In connected television, examine app, channel, content and device fields, while recognizing that identifiers can be incomplete or normalized differently by each provider.

    How fraudulent video views appear in campaign data

    Fraud rarely announces itself with one definitive metric. Analysts should look for combinations of signals that do not make sense together.

    Unusually high starts or completion rates

    A very high video start rate can result from a strong placement, but it can also indicate forced autoplay, refresh behavior or reporting differences. A very high completion rate may reflect short creative, attentive audiences or a player that runs automatically to the end. The metric becomes more suspicious when it is paired with low interaction, weak site engagement, repetitive device patterns or a large share of traffic from unfamiliar inventory.

    Do not use a universal threshold as a fraud rule. A six-second bumper and a two-minute explainer should not have the same expected completion profile. Compare the same creative, placement type, geography, device category and buying method wherever possible.

    Large volumes of identical event timing

    Human behavior is variable. Bots can be variable too, but simple automation often leaves timing fingerprints. Look for many starts occurring at exactly the same delay after impression, identical quartile timing, repeated page-load-to-start intervals and batches of completions that cluster around the creative duration.

    Timing analysis should account for legitimate causes such as server batching, reporting windows and player buffering. Raw event timestamps are more useful than daily totals when investigating this pattern.

    Low engagement paired with high video consumption

    A campaign can legitimately have low clicks. Video is often used for awareness, and click-through rate is not a sufficient quality measure. However, if a source produces large numbers of completed views while showing almost no scroll, touch, cursor, page-depth or post-view behavior, the combination deserves review.

    Use engagement as supporting evidence, not as a standalone verdict. Safari privacy controls, in-app browsers, consent restrictions and cross-domain measurement gaps can reduce the signals available for real users.

    Geographic and language inconsistencies

    Compare the campaign’s target geography with IP-derived location, device locale, time zone, content language and publisher location. A mismatch does not prove fraud: travelers, VPNs, multilingual users and international data centres can all create legitimate differences. A concentrated pattern across one source, however, may indicate routing or inventory misrepresentation.

    Device and browser repetition

    Repeated combinations of operating system, browser version, screen size, language and device model can indicate automation or a limited device pool. The same combination may also be normal for a controlled corporate environment, a connected-TV platform or a popular mobile device, so compare it with other sources and with the scale of the traffic.

    Be careful with device identifiers. Cookies can be deleted, mobile identifiers can be reset, and privacy mechanisms can reduce stability. A large number of identifiers does not prove unique human viewers, and a small number does not automatically prove fraud.

    A practical investigation workflow

    Step 1: Define the event and the buying promise

    Start by writing down what was purchased and what was counted. Was the objective an impression, a viewable impression, a video start, a completed view, a click or a conversion? What did the contract or platform documentation say about player size, audibility, viewability, autoplay, inventory type and user initiation?

    This step prevents the investigation from becoming a debate about vague quality. A muted autoplay impression may be valid under one product definition while failing an internal brand standard. Both facts can be recorded without treating them as identical.

    Step 2: Preserve raw evidence

    Export data before making large campaign changes. Preserve logs or reports containing timestamp, campaign, ad group, creative, placement, publisher, domain or app, device type, operating system, browser, geography, IP or truncated network information where permitted, user-agent, player events and conversion details.

    Keep the original export and record the extraction time, timezone, filters and attribution window. Platform interfaces often apply changing definitions or rolling exclusions. A saved raw file gives the investigation a stable reference.

    Step 3: Establish a clean comparison

    Compare suspicious traffic with a more trusted segment. This could be another publisher, a direct deal, an organic audience, a verified app supply path or a period before a placement changed. Match for creative, geography, device and objective where possible.

    The purpose is not to prove that the comparison is perfect. It is to identify which behaviors are unusual for the campaign. For example, a questionable source may have the same start rate as other sources but a much higher share of starts within one second of page load and a much lower rate of meaningful post-view activity.

    Step 4: Break the data into useful dimensions

    Aggregate by placement, publisher, domain, app, exchange, seller, supply path, creative, device category, geography, hour and day. Look for concentration. Fraud often hides in the total campaign but becomes visible when one seller, app bundle, sub-publisher or hour range is isolated.

    Useful calculations include:

    • Starts divided by impressions.
    • Quartile and completion rates by creative and placement.
    • Video starts per page view or session.
    • Multiple starts from the same identifier or page load.
    • Completion events relative to expected creative duration.
    • Traffic share from data-centre or proxy-associated networks.
    • Post-view conversions by source, with attention to attribution bias.
    • Event timing distributions rather than only daily averages.

    Step 5: Inspect the player and placement

    When possible, reproduce the placement in a clean browser and record what happens. Check whether the video is visible, whether it is in the viewport, whether it starts without interaction, whether audio is enabled, whether it pauses when hidden and whether more than one player loads.

    Use browser developer tools or an ad verification product to inspect player dimensions, page position, network calls and event firing. A screenshot or screen recording can be useful, but it is not enough on its own. A placement may behave differently by geography, device, consent state, browser or traffic source.

    Step 6: Validate the supply path

    Ask the buying platform or publisher to identify the seller and inventory source. Review app and web authorization files where applicable, supply-chain objects, publisher IDs, domain information and reseller disclosures. A large number of intermediaries does not prove fraud, but it reduces transparency and makes discrepancies harder to resolve.

    Request a sample of impression-level records, not just a summary chart. Ask which fields are passed from the player, which are inferred, and which are transformed by the platform. Many disputes persist because two systems are reporting different stages of the same event.

    Step 7: Test and contain

    If a source looks suspicious, do not immediately delete every related record. Place it in a controlled holdout, pause spend where appropriate, apply a source-level exclusion, or reduce the budget while collecting more evidence. Compare behavior before and after the change.

    For affiliate or partner traffic, use unique tracking parameters, source-specific postbacks and clear traffic-quality terms. For programmatic campaigns, test a direct or more transparent supply path against the suspect route. Containment should protect spend while preserving enough information to explain the decision.

    Distinguishing fraud from legitimate video behavior

    False positives are expensive. Blocking legitimate inventory can reduce reach, distort learning and create unnecessary conflict with publishers. A sound review considers alternative explanations before assigning a fraud label.

    Short creative and high completion rates

    A six-second creative can have a high completion rate without anything suspicious happening. Compare completion to the actual creative duration and verify whether the platform counts a completion at the end of playback or after a fixed percentage.

    In-feed and muted autoplay

    In-feed video often begins as the user scrolls. Some platforms count the impression when the video enters a viewable area, while others count a player start immediately after loading. Muted playback is common because browsers and apps restrict unsolicited audio. These facts can explain low sound-on rates, but they do not excuse a player that runs outside the user’s view.

    Connected television and shared devices

    CTV traffic can have limited click and interaction data because the user is watching from a television. Shared devices can also make frequency and identifier analysis look unusual. Use content, app, device, household and supply-path information together rather than applying browser-based rules to every environment.

    Privacy controls and measurement loss

    Consent refusal, cookie restrictions, identifier resets and browser privacy features can make real traffic appear less connected. Missing identifiers are not evidence of fraud. They become more useful when combined with implausible timing, inventory discrepancies or repeated technical fingerprints.

    Questions to ask platforms, publishers and sellers

    A useful fraud inquiry is specific. Instead of asking whether traffic is valid, ask questions that can be answered with records or documented behavior.

    • What exactly triggers a video start, quartile and completion event?
    • Was the player visible and within the viewport when the event occurred?
    • Was playback user initiated, muted autoplay or another permitted mode?
    • Does the player pause when it leaves the viewport or browser tab?
    • How many video players can load on one page or in one app session?
    • Which publisher, seller and supply-path fields are passed at impression level?
    • What app bundle, domain, content and device information was observed?
    • Were any automated-traffic exclusions or post-bid filters applied?
    • Are reported views deduplicated, and if so, by which identifier?
    • Can the seller provide a sample of raw timestamps and player events?

    Good answers should explain the measurement process, not simply repeat a quality score. If the source cannot provide the fields needed to test the concern, record that limitation as part of the risk assessment.

    Prevention and controls for video campaigns

    Buy transparent inventory where the objective justifies it

    Direct publisher relationships, curated marketplaces and supply paths with clear seller information can improve investigation. Transparency is not a guarantee of clean traffic, but it gives the buyer more options when a problem appears.

    Use verification and event-level monitoring

    Verification tools can help measure viewability, player behavior, invalid traffic and content suitability. They are most useful when configured to match the actual campaign objective. Monitor trends by source instead of relying on a single campaign-level score.

    Set source-level controls

    Use allowlists, blocklists, app and domain exclusions, frequency limits and supply-path restrictions where appropriate. Treat these as controls that reduce exposure, not as permanent proof that a source is safe. Fraud patterns change, and a previously acceptable source can deteriorate after a traffic or monetization change.

    Separate awareness metrics from response metrics

    Do not optimize a conversion campaign toward the cheapest completed views if completion can be generated without meaningful attention. Compare video delivery with qualified site behavior, incremental conversions, assisted outcomes and brand-lift measures where available.

    Post-view attribution deserves particular caution. A fraudulent or low-quality source can receive credit for conversions that would have occurred anyway, especially when view-through windows are long and the source reaches broad audiences. Test shorter windows, holdouts or incrementality methods when the economics justify it.

    Document a response process

    Define who reviews anomalies, what evidence is required, when spend is paused, how credits are requested and how partners are notified. Include a process for appeals and false positives. A written procedure reduces the chance that a large spike is ignored because the team is unsure who owns the investigation.

    A realistic example: high completion, weak audience evidence

    Imagine a campaign buying 15-second mobile web videos across several exchanges. One supply path reports a 92 percent completion rate, materially above the campaign average. The initial reaction is positive: the creative appears to be performing well.

    The analyst breaks the source down and finds that most starts occur less than one second after the page request. The player is often muted, several pages load the same player dimensions, and a large share of completions comes from a narrow set of browser and screen-size combinations. Session depth is low, and the source has a high number of video starts per page view compared with other publishers.

    None of these findings alone proves fraud. The analyst then reproduces a sample of pages and sees a small floating player that begins automatically near the edge of the viewport. When the page is scrolled, the player continues playing. A second player is also requested on some pages. The buyer asks the seller for impression-level placement data and receives only aggregated reports.

    The reasonable conclusion is not necessarily that every impression was fake. It is that the source did not provide reliable evidence of the intended viewing experience and showed behavior consistent with autoplay and placement abuse. The buyer pauses the supply path, preserves the data, requests clarification and redirects budget to a source with clearer player controls and inventory transparency.

    How to report suspected video fraud

    A strong report is factual, reproducible and limited to what the evidence supports. Include the campaign and date range, the buying objective, the relevant event definitions, affected sources, sample sizes, comparison segments, observed anomalies and requested action.

    Use language such as suspicious, inconsistent with the contracted placement, requires validation or likely invalid traffic when the evidence is not conclusive. Reserve definitive claims for cases where the technical and commercial evidence is strong. This makes the report more credible and gives the counterparty a clear way to respond.

    Attach examples: timestamps, placement URLs, app identifiers, event sequences, player recordings, supply-chain records and calculations. Explain limitations, including missing logs, privacy restrictions, platform discrepancies and the possibility of legitimate explanations. An evidence-aware report is more likely to produce a useful correction than a broad accusation.

    FAQ: video ad fraud and video IVT

    What is a fraudulent video view?

    A fraudulent video view is a reported video viewing event created through automation, hidden or forced playback, misrepresented inventory or another manipulation that does not represent the intended opportunity for a real person to watch the ad. A short or incomplete view is not automatically fraudulent; the surrounding technical and behavioral evidence matters.

    Is autoplay video ad fraud?

    No. Autoplay can be legitimate in feeds, apps and other environments when it follows the platform’s rules and provides an appropriate viewing opportunity. It becomes suspicious when playback is hidden, out of view, repeatedly triggered, stacked with other players or counted in a way that does not match the buying agreement.

    What is video IVT?

    Video IVT is invalid traffic associated with video advertising. It includes automated browsers, bots, non-human requests, forced interactions, spoofed inventory and other traffic that should not qualify as legitimate video delivery under the relevant measurement and buying rules.

    Can a high completion rate indicate fraud?

    It can, but it is not proof. Short creatives, engaged audiences and platform definitions can produce high completion rates legitimately. A high rate is more concerning when paired with machine-like timing, hidden players, repeated devices, low page engagement or unclear inventory.

    How can I detect a hidden video player?

    Inspect the placement in a controlled browser and check player dimensions, CSS position, viewport visibility, overlays, page coordinates, sound state and whether playback pauses when the player is hidden. Use impression-level or verification data where available, because one manual test may not represent every device or traffic segment.

    What data is most useful for investigating video fraud?

    Useful fields include timestamp, placement, domain or app, seller, supply path, creative, player event, player size, viewability status, device, operating system, browser, geography, network information where permitted and downstream conversion data. Raw event timing is particularly valuable for identifying repeated automation patterns.

    Are data-centre IP addresses proof of bot traffic?

    No. Data-centre traffic is a useful risk signal, but legitimate cloud services, corporate networks, proxies and measurement systems can use hosted infrastructure. Treat network classification as one input and combine it with timing, inventory, device and player behavior.

    Why do video starts and impressions differ between platforms?

    Platforms may define and trigger events differently. One may record an impression when an ad response is received, while another may require rendering or a player event. Timezone, deduplication, filtering, reporting delays and attribution settings can also create differences. Confirm the definitions before comparing rates.

    Can low click-through rate prove that video traffic is fraudulent?

    No. Video campaigns often have low click rates, especially when the objective is awareness. Low clicks become more informative when combined with other evidence, such as impossible event timing, hidden playback, suspicious inventory or a sharp difference from comparable sources.

    How should I handle suspected fraud from an affiliate or partner?

    Preserve the raw data, isolate the partner or sub-source, check the agreed traffic terms and request source-level evidence. Pause or cap traffic if financial exposure is continuing. Avoid relying only on a partner’s aggregate dashboard; ask for placement, timestamp, device and event details that can be reconciled with your own records.

    Should I block every source with unusual video behavior?

    Not immediately. First determine whether the behavior has a legitimate explanation and whether the source violates the actual buying requirement. Use a risk-based approach: investigate, contain, request clarification, compare against a trusted segment and document the decision. Broad blocking can remove valid reach and hide the underlying measurement problem.

    How does view-through attribution increase video fraud risk?

    View-through attribution can assign credit to a source even when the user does not click. If a source generates low-quality or fraudulent views, it may receive credit for conversions that were not caused by the video. Use appropriate windows, exclusions, holdouts and incrementality testing where possible.

    What should I do if a platform will not provide impression-level data?

    Record the limitation, request the most detailed available fields, ask how filtering and event definitions work, and reduce exposure if the unanswered questions affect spend or compliance. A lack of transparency is not proof of fraud, but it should influence how much confidence you place in the traffic.

    Semantic map

    The central relationship is that video ad fraud manipulates video advertising events. Hidden players generate non-visible playback. Autoplay abuse creates starts without meaningful user initiation. Bot viewing produces automated video traffic. Video IVT reduces the reliability of campaign measurement. Supply-path transparency improves investigation. Player inspection tests whether reported views match the intended viewing experience. Event-level monitoring helps separate suspicious sources from normal delivery variation.

    • Video ad fraud affects video impressions, starts and completions.
    • Hidden players create out-of-view video playback.
    • Autoplay abuse generates video starts without meaningful attention.
    • Bot viewing produces automated video events.
    • Video IVT distorts campaign reporting and optimization.
    • Supply-path data supports inventory validation.
    • Player inspection tests visibility and playback behavior.
    • Impression-level analysis reveals timing and concentration patterns.

    Final checklist

    Before accepting a video source as healthy, confirm the following:

    • You know exactly what the platform counts as an impression, start, quartile and completion.
    • The player is visible under the conditions promised by the campaign.
    • Playback behavior matches the agreed autoplay, sound and viewability requirements.
    • The number of players and ad requests per page or session is reasonable.
    • Traffic is not concentrated in implausible timing, device or network patterns.
    • Domain, app, seller and supply-path information is consistent with the inventory purchased.
    • Suspicious sources have been compared with a trusted or more transparent segment.
    • Raw reports, timestamps and investigation notes have been preserved.
    • View-through conversions are treated carefully and tested against incrementality where practical.
    • There is a documented process for pausing, challenging and reviewing questionable traffic.

    The goal is not to make every video impression look perfect. Real audiences are messy, measurement is incomplete and different environments behave differently. The goal is to understand what was actually delivered, identify where the evidence breaks down and prevent automated or manipulated viewing from directing budget and optimization decisions.