Invalid traffic & fraud · also called Bundle ID spoofing, app misrepresentation
App spoofing
App spoofing is misrepresenting which mobile or CTV app an ad slot belongs to, typically by faking the app's bundle ID, so cheap or fake inventory is sold as a popular app.
Apps are identified in the bid request by a bundle ID or store ID. App spoofing puts a well-known app's ID on inventory that really comes from a different, low-quality app, or from no app at all. It is the in-app and CTV cousin of domain spoofing and counts as SIVT under the MRC IVT guidelines.
It is particularly damaging on connected TV, where prices are high and ads are often stitched server-side, making it harder to verify what app was really running. Some schemes spoof many popular streaming apps at once, generating billions of bid requests from servers pretending to be TVs, frequently combined with device spoofing and SSAI spoofing.
Defences mirror the web: app-ads.txt lets developers declare authorised sellers, published through the developer website listed in the app store; sellers.json and the supplyChain object expose the path; and the Open Measurement SDK lets verification vendors measure from inside a genuinely integrated app. Buyers should favour direct paths and treat surprisingly cheap inventory from premium apps with suspicion.
Think of it like this
It is like a street stall putting a famous brand's logo on a no-name phone case: the barcode says one thing, the product is another.
An example
A DSP finds that a top streaming app appears in 3 billion bid requests a day across 60 sellers, while the app's app-ads.txt lists only four authorised sellers. Traffic from the other 56 is treated as spoofed.
Related terms
Domain spoofing
Domain spoofing is misrepresenting the website where an ad will run, so that inventory from a low-quality or fake site is sold to advertisers as if it came from a premium publisher.
app-ads.txt
app-ads.txt is the version of ads.txt for mobile and CTV apps, a file on the app developer's website that lists which sellers are authorised to sell the app's ad inventory.
CTV fraud
CTV fraud is ad fraud targeting connected TV and streaming inventory, such as spoofed apps, fake devices, SSAI spoofing and infected streaming boxes, exploiting CTV's high prices and harder verification.
Device spoofing
Device spoofing is faking the identity or type of device requesting an ad, such as a server posing as a smart TV or iPhone, to earn higher prices or dodge detection.
SSAI spoofing
SSAI spoofing is CTV and video fraud in which fraudsters imitate a server-side ad insertion system, sending fake ad requests that appear to come from real viewers watching real streams.
Sources: IAB Tech Lab ads.txt and app-ads.txt, MRC Invalid Traffic Detection and Filtration Guidelines Addendum (2020 update), IAB Tech Lab Open Measurement SDK