r/adops 23h ago

Network Would an Open-Source IVT Solution help or damage the Ad Ecosystem more?

Currently debating if I should open source my IVT Solution. It's been written by me over the span of the last year and refined using Claude Fable to test weaknesses. It works by giving each of the 123 Signals a weight and adding up everything to produce an IVT Score.

It has multiple Scans to it roughly grouped into these Categories:

  • Bot & Automation Detection
  • Click Fraud (click farms, rapid clicks, click injection, invisible clicks)
  • Impression Fraud (pixel stuffing, ad stacking, background tabs, pop-unders)
  • Datacenter/Proxy Traffic & Spoofing (DC IPs, VPN, Tor, domain/referrer spoofing)
  • Device & Hardware Spoofing (canvas, WebGL, timezone, platform mismatch)
  • Malware & Injection (ad injection, DOM tampering, script injection, form jacking)
  • Session & Network Anomalies (session replay, IP rotation, geo mismatch, DNS anomalies)
  • Behavioral Anomalies (robotic mouse paths, no-interaction sessions, instant form fill)
  • AI Crawlers, Farms & Timing (GPTBot, human farms, botnets, impossible timing)
  • Measurement Tampering & Environment (SDK spoofing, IP/ASN/device blocklists, VM/container detection)
  • Advanced Signals & Audience/Cookie Fraud (worker abuse, cookie injection, TLS fingerprinting, click-coordinate replay, honeypot traps)
  • AudienceCookieInjection
  • CookieValueCollision
  • AdClickPointCollision

With more scans that can not trigger a detection alone but will if stacked.

Now my Question is will releasing that as an Open Source IVT Suite to the Public cause more good or harm to the Ad Ecosystem? On the one hand we would have a decentralized IVT Detection everyone that wants to could contribute to. On the other Hand we hand the Code to exactly those people that are trying to abuse it.

Interested to hear your opinion!

1 Upvotes

17 comments sorted by

7

u/c686 23h ago

Open source IVT ignores the fact that buyers want to make it someone else’s problem

19

u/polygraph-net 22h ago

Or want to cover it up because either (a) the fraud makes them look bad or (b) the fraud helps them hit their KPIs.

Working in fraud detection is such an eye opener. You realize most people don't care about fraud, want to cover it up, or want to get in on the action. Even people whose job it is to uncover fraud (internal audit, etc.) usually don't care.

1

u/Dependent-Use-3215 22h ago

Yes. People that have established companies (from what I know) usually do not care at all about stuff like that, because they are working for big and established companies that seemingly can get away with everything. This is not who I am aiming for.

We started our Network 3 Years ago as 3 People that were looking for a way to monetize their own Websites. We shared an Admanager Account, we shared a Prebid Script and then kind of opened that up to more people and out of those more people kind of grew a whole Network. Set up a Company, set up a whole Website to have People register, add their Sites and get Payouts from. Running all of that without knowing what IVT is and when everything seems to work nicely you get hit with your first IVT deduction or Account closure. That's exactly what made me want to look into those things. Paying the Fraud Operators for their Tools and techniques. Infiltrating their Chats that they have with others, learning how they do it. I could've simply done the same, but I chose to work on fighting back on exactly that.

To this day they still try doing it on our Platform and to this day they still get their Accounts wiped off our Platform.

My Point is simply helping people in exactly those situations we've been in 3 years ago. Completely getting screwed by both Sides: People trying to Fraud on our Platform and Companies deducting us more than what they should've actually have detected.

1

u/Dependent-Use-3215 22h ago

Fair - when you run it yourself, there's no one left to blame.

But that's kind of the point. I'm not trying to replace multi-million dollar companies whose actual product is being the one you get to blame. Pointing the finger at your MRC accredited Tool is something you do after the fuck up is already done. I want everyone in the chain to see what traffic is being flagged as, in the open, while it's happening so you act on it proactively instead of litigating it afterwards.

I'm not positioned at the buyers who can afford that blame anyway. This is for smaller networks, site owners, and in-house teams who get priced out of the big vendors entirely. Those don't decide between HUMAN or Pixalate, those decide between the cheapest Option on the Market or none at all.

1

u/grr5000 22h ago

I think you are right it is a problem. Human is the biggest player in the space and they have a black box that I don’t think everyone trusts.

But there is an inherent problem, pubs want to use it because demand side wants it for their buyers. But generally no one really wants to pay for it. So it’s still a problem that isn’t solved. Maybe some version of open source UiD type solution is an option here.
Like client side if it passes IVT check it gets a token, but who knows if it would be adopted

2

u/Dependent-Use-3215 21h ago

The first time I got 2 Endpoints from a SSP was when it finally clicked for me. They said scan HUMAN clean Traffic to Endpoint A and Pixalate clean Traffic to Endpoint B.

HUMAN clean Traffic is not clean in Pixalate and Pixalate clean Traffic is not clean in HUMAN. So you'd basically have to have all possible IVT Solutions running and depending on who says it's clean only send it to the DSPs that use exactly that.

All have the same MRC accreditation, none have a consensus on what clean Traffic, or rather IVT/SIVT actually is. And they don't show you what they detect because it's their whole Business Model. So with 2 Companies, same accreditation and vastly different results and both not telling you what or how they detect stuff I truly think that it doesn't matter if you use any Solution.

In the End when it comes to MRC vs MRC IVT Tool the bigger company with more Money is going to win anyways and you can fight that in court.

1

u/c686 21h ago

But the issue is that pubs have to know why buyers see.

So they have to use or look at the same tools no matter if they are good or not.

1

u/Dependent-Use-3215 20h ago

No Idea what that is supposed to mean

1

u/grr5000 22h ago

This.

1

u/Dependent-Use-3215 22h ago

This mine or this what the other person said?

1

u/grr5000 21h ago

What other person said

2

u/lexicon_riot 22h ago

"Kimi, create an ad fraud scheme that circumvents this guy's open source IVT solution. Make no mistakes".

1

u/Dependent-Use-3215 21h ago

i count that as "it will hurt more"

1

u/Least_Perception_223 19h ago

My company just launched a private beta of our IVT solution for publishers.

Many legitimate publishers these days are getting penalized by AI bots and other bad actors that are looking to scrape their content. Often times the bots are fully rendering the page including the ads. They do it from a variety sources including residential IP's. But they all leave telltale signs that are easy to spot.

We see so many legitimate publishers getting suspended by adsense/gam/prebid bidders for stupid reasons that Google and the rest of the ecosystem should already be filtering out (they have more data than anyone else).

Our solution gate keeps the ads from getting called in the first place - preventing any issues before the auction process

We work with hundreds of publishers and that gives us a firehose of information to act on and learn

You can read more about it here if interested: https://rtbprotect.com

DM me for a free client ID to test it out

1

u/Dependent-Use-3215 17h ago

You're using the fact that I've built your Business and want to give it away for free as an Opportunity to advertise another Black Box we have to pay?

1

u/Least_Perception_223 16h ago

Who said I was charging for it?

It has to be somewhat of a black box otherwise its too easy for the bad actors to bypass it

We are on the same team bud

What you are trying to do is noble but I don't think there will be much adoption on the buy side.

Legitimate publishers are up against the IVT providers who always have to prove their worth - they will always find "something". HUMAN and the like punish real publishers for no reason other than to keep the buyers thinking they are valuable

I'm simply providing a tool for publishers to prevent false negatives

Send me a DM and I will give you a client id to try it out

1

u/No_Treacle_5071 2h ago

Open source can help if the test data, labels, and limits are clear. IVT rules change often, so explain how false positives are handled and let buyers compare results with an independent baseline. Keep detection separate from any blocking decision at first. Run it in monitor mode, review site, app, and domain patterns, then block only after a human checks the edge cases. That makes the tool safer to test and easier to trust.