Three Ways to Reduce Click Fraud Impact: Igor Ivitskiy at PPC Day 2023

⏱ 9 min read
In short: At PPC Day 2023, Igor Ivitskiy explained why click fraud should be treated as a traffic-quality risk, not as a few obvious repeat clicks. The figures presented in the talk put the annual volume at $65 billion and suggested that 8 out of 10 advertisers encounter the problem without knowing it. His central idea was to match the response to the evidence: start with campaign data, move to IP control when the source can be identified, and use real-time behavioural protection when simple filters are not enough. The detailed settings remain in the full recording.

PPC Day was held online for a Ukrainian audience on January 25, 2023. The speaker was Igor Ivitskiy, a Google Ads practitioner and PhD in mathematical modelling.

The talk, “3 Secrets: How to Reduce the Impact of Click Fraud in 2023”, mapped the scale and incentives behind fraudulent clicks, distinguished several technical forms of imitation, and compared three levels of protection without pretending that one filter can solve every case.

$65 billion
annual click-fraud volume in the figures presented during the talk
Source: PPC Day 2023 talk, figures presented by Igor Ivitskiy.

Protection starts with the type of risk

Click stream filtered from bots to real conversions
Click stream filtered from bots to real conversions

Click fraud is not one behaviour. Igor described manual clicking, banks of physical devices, malware, emulators and bots. Some patterns are easy for an advertising platform to recognise, while others are designed to resemble a real person browsing, moving through a site and clicking an ad. That difference explains why a single dashboard metric cannot describe the whole problem.

The practical starting point is evidence. Changes in click-through rate, device mix, geography, repeat visits and on-site behaviour can justify a closer look, but no isolated signal proves fraud. This is the same discipline that makes keyword research for Google Ads useful: patterns matter when they are read in context rather than converted into automatic conclusions.

Google defines invalid traffic as interactions that do not come from genuine user interest and says its systems evaluate many data points to detect it. Igor’s argument adds an advertiser-side principle: when the observed risk remains material, choose a proportionate layer of control instead of applying the harshest restriction to every visitor.

1Immediate containment
Use audience-level restrictions only when the account shows an urgent pattern worth containing.
Question: what legitimate demand would this restriction also remove?
2Identified-source control
Use server evidence and IP exclusions when suspicious sources can be isolated.
Question: can the team review and refresh the evidence fast enough?
3Behavioural protection
Use real-time systems when devices, identities and browsing patterns are designed to look genuine.
Question: does the value at risk justify a specialised system?
Source: the three protection levels in Igor Ivitskiy’s PPC Day 2023 talk.

My principle for traffic protection

I do not start by blocking the largest possible audience. I start with the pattern the account can actually support, then choose the least destructive protection that can reduce its impact. Exclusions should protect the business result, just as negative keywords should be judged by economics rather than by how tidy an account looks.

This way of thinking belongs inside broader Google Ads training because traffic quality, campaign reach and conversion economics affect one another. The school’s teaching develops that analytical habit; the full talk preserves the operational detail.

Key insights

  • The risk is broader than obvious repeat clicks. Physical devices, malware and emulators can imitate elements of genuine user behaviour.
  • Incentives explain the variety. Competitors, low-quality site owners, dishonest marketers and fraudulent ad networks can benefit in different ways.
  • Emergency restrictions carry a commercial cost. Blocking repeat or short visits can stop suspicious traffic, but it can also remove real prospects.
  • IP control is precise only when the evidence stays current. Manual log review is slow, while automated rotation responds closer to real time.
  • Behavioural detection is a specialist problem. Igor’s attempt to build an in-house system showed how quickly browser, device and behaviour signals multiply.
  • Reach and exposure must be considered together. Campaign types with broad inventory can create more room for low-quality traffic, a useful caveat when evaluating broad match and reach.

Key moments from the talk

A market large enough to hide in normal reports

Igor opened with a scale argument because advertisers often treat click fraud as somebody else’s problem. “Click fraud is one of the biggest problems in the advertisers’ world,” he said before showing the figures used in the presentation. Those figures estimated fraudulent activity at 40% of internet traffic, placed annual losses at $65 billion and said the share was increasing quickly. He also stated that 8 out of 10 advertisers encounter fraud without recognising it. These were conference figures, not an audit of every listener’s account, so their proper role is to challenge complacency rather than to diagnose a campaign. A large market estimate does not tell an advertiser which clicks were false. It tells the advertiser that unexplained traffic quality deserves measurement instead of dismissal.

The next question was who benefits. A competitor may want to exhaust another advertiser’s budget. A website built mainly to monetise ad clicks has an incentive to generate more of them. A dishonest agency may degrade an account before approaching the client with a replacement offer. A fraudulent partner network may profit from traffic that appears to come through legitimate inventory. This list matters because motive shapes behaviour. A person clicking manually leaves a different trail from a device farm, malware operating in the background or an emulator trained to mimic browsing. The talk therefore moved the discussion away from one cartoon villain and towards an ecosystem of incentives. Protection becomes more credible when it asks what kind of actor could produce the observed pattern.

Why the visible invalid-click number is only a starting point

Google already filters interactions it identifies as invalid, and Igor pointed listeners to the invalid-click reporting available in the platform. Straightforward manual repetition is comparatively easy to detect. The difficult cases are the ones built to look ordinary: real phones can browse and click, infected computers can act without their owners knowing, and emulators can reproduce a visitor’s sequence of actions. A clean-looking session is therefore not proof of real intent. At the same time, unusual behaviour is not proof of fraud either. A legitimate visitor may return, leave quickly or use a device shared with others. That uncertainty is the reason to combine campaign patterns, site behaviour and server evidence before narrowing an audience.

Network context adds another layer. In the presentation, display-related inventory showed the highest exposure, with search lower and shopping lower again. Igor connected that difference to the much wider set of websites and partner networks through which display ads can appear. The strategic lesson is not to abandon broad inventory. It is to judge traffic quality by network and campaign type instead of averaging everything into one account-wide rate. A sudden shift in devices, geography or engagement can become a prompt for investigation. It should not become an automatic conviction. Good protection keeps two errors in view at once: paying for fabricated attention and blocking a genuine customer whose behaviour happens to resemble a suspicious pattern.

Three levels, chosen by evidence and cost

The first level was deliberately blunt. Igor called it “barbarian protection” because audience exclusions can stop a surge quickly but also cut away legitimate repeat visitors. He presented it as emergency containment, not as a universal account design. The second level was source-specific: review server logs, identify suspicious addresses and use Google Ads IP exclusions. Its weakness is operational latency. A human reviewing old logs reacts after the spend has happened, while a changing attack can make a static list stale. Automation can shorten that loop by evaluating visitors continuously and refreshing exclusions, but precision still depends on the quality of the signals.

The third level treated protection as a multivariable detection problem. Igor had tried to build his own system around browser fingerprints, files and behavioural differences between valid and suspicious users. The experiment exposed the true engineering burden. “Maybe it was one of the worst ideas in my life,” he said, because the number of factors called for a dedicated development function rather than a small side project. His eventual choice was a specialised real-time platform. The wider conclusion is not that every advertiser needs the same vendor. It is that build, buy and tolerate are economic decisions. The value of avoidable waste, the speed of attacks and the cost of false exclusions should determine how sophisticated the defence becomes.

The full recording of this talk is included in the bonus pack for students.

Third-party traces

Key takeaways

Click fraud ranges from obvious repeated clicks to systems that imitate real users across devices and websites.

The useful response is proportionate: verify the pattern, contain only what is necessary, and add real-time protection when the economics justify it.