Invalid traffic & fraud · also called App install fraud, mobile install fraud
Install fraud
Install fraud is faking app installs, or stealing credit for real ones, so that advertisers pay cost-per-install fees for users who do not exist or would have installed anyway.
App install campaigns often pay per install (CPI/CPA), sometimes several dollars each. That price attracts two families of fraud.
The first is fake installs: installs that never happened on a real person's phone. They come from emulator farms, device farms that install, open and delete apps, then reset the device ID to look new, and SDK spoofing, which sends fabricated install messages directly to measurement servers without any device at all.
The second is stolen attribution: the install is real, but a fraudster claims the credit, through click injection or click spamming. That form is sneakier because the users exist; the advertiser simply pays for organic growth.
Mobile measurement partners detect install fraud with click-to-install-time analysis, device-ID reset detection, checks for emulator and rooted-device traits, SDK message signing, app-store receipt validation, and post-install behaviour such as retention and in-app events. A cohort that installs but never opens the app twice is a red flag. Fraudsters increasingly fake post-install events too, so advertisers who pay on deeper events still need verification.
Think of it like this
It is like a gym paying a promoter per new member signed up, and the promoter filling the forms with made-up names, or with people who had already walked in to join.
An example
A fintech app in Indonesia pays $2.50 per install. One partner delivers 40,000 installs a month, but 60% of the devices were first seen that week, share identical hardware models and never complete sign-up. The MMP rejects them and the partner's invoice is cut.
Related terms
Click injection
Click injection is mobile ad fraud where a malicious app detects another app being installed and fires a fake ad click just before the install completes, stealing the credit.
SDK spoofing
SDK spoofing is mobile ad fraud in which fabricated install or in-app event messages, mimicking a real measurement SDK, are sent straight to attribution servers without any real device or user.
Device farm
A device farm is a physical collection of real phones or TVs, often racked on walls and controlled by scripts or workers, used to generate fake installs, ad views and engagement.
MMP (mobile measurement partner)
An MMP (mobile measurement partner) is an independent company that attributes app installs and in-app events to the ads and ad networks that drove them, and detects mobile install fraud.
App install campaign
An app install campaign is advertising designed to get people to download and install a mobile app, usually optimised and often paid per install or per post-install action.
Attribution fraud
Attribution fraud is manipulating how conversions are credited, so a fraudster claims payment for installs, sales or leads it did not actually cause, often by faking or timing clicks.
Sources: AppsFlyer glossary: SDK spoofing, AppsFlyer glossary: click injection, MRC Invalid Traffic Detection and Filtration Guidelines Addendum (2020 update)