The post has been translated automatically. Original language: Russian
19.5 million people use the Internet in Kazakhstan, and its penetration rate is 93.4%. At the same time, the mobile environment remains one of the key points of contact with the audience: there are 27.3 million mobile connections in the country.
Against the background of the growth of digital consumption, competition for user attention is also increasing. For brands, this means that digital advertising is becoming not just a channel of reach, but an important tool for attracting traffic.
But the more actively the market grows, the higher the requirements for transparency of procurement and the quality of advertising contacts. According to global statistics, 8.51% of all paid advertising clicks relate to invalid traffic. This is equivalent to about $63 billion in lost advertising budgets.
Modern fraud is no longer just about simple bots or random clicks. Fraudulent schemes are becoming more complex: they mimic the behavior of real users, generate impressions, clicks, and even basic conversions. As a result, the advertiser can see formally good metrics, but not get real audience growth.
Therefore, traffic quality control is becoming critically important for the Kazakhstan market, where digital and mobile have already become mass communication channels. The BYYD mobile platform uses an AI anti-fraud system that helps identify suspicious activity, filter invalid traffic, and increase the effectiveness of advertising investments.
We tell you how it works and provide analytics.
Intelligent advertising traffic protection system
BYYD AI Anti—fraud is a comprehensive system for protecting advertising campaigns from fraud. It is based on its own machine learning model. It processes more than 1.5 billion auction requests per day.
What does the platform do in real time?:
- Analyzes incoming traffic
- Generates a digital user profile (fingerprint)
- Decides to participate in the auction in just ~0.4 milliseconds (from the moment the bid request is received to the decision)
Currently, the architecture is deployed on a dedicated anti—fraud server - 48 CPU / 256 GB RAM. An anti-fraud service process is running on each server with a bidder (a participant in the auction for the purchase of advertising impressions), which consumes ~2 CPU.
Thus, the system scales efficiently and has virtually no effect on the performance of the main bidder (the auction participant).
System architecture
1. Real-time machine learning
The ML model (CatBoost machine learning model) processes an array of data with a wide range of traffic behavioral characteristics. The training is based on real user activity data. The dataset (data set) is formed in such a way as to include the maximum variety of patterns, both fraud—related and legitimate.
After the training is completed, the model is displayed in a working environment where it works in real time.:
- Processes every incoming request
- Calculates the necessary behavioral and technical signs
- Assigns a numeric indicator to the query — fraud score, which takes a value in the range from 0 to 1. The threshold can be adapted depending on the required balance between aggressive filtering and maintaining coverage.
Model quality metrics
To evaluate the effectiveness, key binary classification metrics are used.: precision and recall.
– Precision. It reflects the proportion of correct responses among all cases when the model classified traffic as fraud.
Formula: Precision = TP / (TP + FP), where:
- TP (True Positive) — fraud detected correctly.
- FP (False Positive) — legitimate traffic mistakenly classified as fraud
— Recall (completeness). Reflects the share of detected fraud from the total volume of actually invalid traffic.
Formula: Recall (completeness) = TP / (TP + FN), where:
- TP (True Positive) — fraud detected correctly.
- FN (False Negative) — fraud that the model did not detect.
Current performance of the model during offline validation
- Precision = 0.92
- Recall (completeness) = 0.95
This means that the system detects 95% of fraudulent traffic, while maintaining high classification accuracy and minimizing erroneous blocking of legitimate users.
2. Fingerprint: digital user profile
A unique fingerprint is generated for each user – his digital profile.
If the device ID is present, the profile is linked to it (IFA/GAID).
If missing, a unique platform ID is created based on the set of parameters. Some of them are:
- device_ip
- device_make
- device_model
- device_os
- device_osv
- device_ua_core
In this way, the system can probabilistically identify the device even in the absence of an advertising identifier.
3. Dealing with dynamic changes
In a real environment, users often:
- Changing IP (dynamic networks)
- They receive OS updates
- They change the User Agent (information about the user that the browser or application sends to the server when requesting a web page)
- They use mobile and wired Internet alternately.
If a new digital profile (fingerprint) is created, for example, due to a change in IP or UA, the display will be possible only after repeated verification — in the second and subsequent auctions with the same parameters.
This allows you to:
- It is correct to combine one user
- Minimize false positive (legitimate traffic mistakenly classified as fraud)
- Effectively combat attempts to disguise fraudulent traffic
4. Basic traffic filters
Before evaluating using machine learning, the system applies basic filtering:
- List of blocked domains
- Domains from the API of prohibited RCN resources
- IP addresses of all known cloud services
- Well-known proxies and data centers
This allows you to cut off obvious fraud even before complex analytics.
How behavioral and technical assessment is conducted: 20+ parameters
After the initial filtering, each auction request undergoes a multi-level evaluation based on more than 20 parameters.
1. The size of the device and the advertising window
The minimum height or width of the ad block must exceed the set threshold (X pixels). This filters out invisible or technical placements.
2. The presence of an operator on a cellular connection
The lack of correct operator data is a potential indicator of abnormal traffic.
3. Correctness of the User-Agent identification string of the client application
Being checked:
- Minimum length
- Matching the device model
- Matching with the OS
- Consistency of auction request data (bid request)
4. VPN and proxy traffic
Blocking is carried out by:
- Information about the network
- The name of the application
- By the application ID in the system (bundle name)
- Signatures (characteristics) of VPN services
5. Average pause between requests
The interval between the auction request (bid request) from one digital profile (fingerprint) is analyzed. Too frequent or too regular intervals are a marker of automated behavior.
6. Maximum number of requests
If the set limit is exceeded, the digital profile is blocked at the system level with the possibility of revision when the behavioral profile changes.
7. Changing the IFA/GAID
An abrupt change of the advertising identifier within one digital profile is a sign of manipulation.
8. Bursts of activity (burst detection)
The number of requests from the same profile is compared with the median for similar devices in the same application identifier (bundle name). Sudden deviations signal bot behavior.

Screenshots of statistics of real advertising campaigns
The effectiveness of the campaign in the retail segment demonstrates a high level of quality of advertising traffic.The 96% Viewable Rate is significantly higher than market benchmarks, which indicates a high visibility of advertising placements. At the same time, the share of invalid traffic was only 0.03%, and impressions outside the target geography were not recorded. This confirms the accuracy of targeting and the effectiveness of fraud prevention mechanisms.

The FMCG campaign also showed a high level of quality of advertising traffic. The viewable Rate was 94%, which indicates high visibility of placements and exceeds standard market expectations. In addition, the overall level of invalid IVT traffic was only 0.06%, which is an acceptable indicator for large-scale advertising campaigns, taking into account the size of the audience.
Additionally, there were no impressions outside the target geography — 0.00%.

The results of verification of the FMCG campaign using the DoubleVerify tracker demonstrate a high level of placement quality. 96% of the impressions were visible, and the share of impressions without complex invalid SIVT traffic exceeds 99%, which indicates the almost complete absence of fraud.
In addition, more than 99% of the impressions were delivered within the target geography and met the Brand Suitability requirements. This confirms that the campaign is set up correctly and that the ads are placed in a brand-safe environment.

Key Advantages of BYYD AI Anti Fraud
- Processing of 1+ billion requests per day
- A constantly learning model
- Real-time solution without loss of auction speed
- A stable digital profile (fingerprint) even without a device ID (Device ID)
- Behavioral analysis, not just static filters
- Flexible system of locks and permanent restrictions
BYYD AI Anti—fraud is not just a set of filters, but an intelligent dynamic traffic assessment system. It is able to identify complex fraud schemes in real time.
Thanks to a combination of machine learning model analytics, behavioral patterns and strict technical criteria, the system ensures maximum transparency and quality of advertising campaigns in Kazakhstan.
How to contact us
The BYYD platform has been engaged in mobile advertising in Kazakhstan for more than 11 years and is constantly improving its tools. Check out the cases on the website and contact us to launch an in-app campaign.
Was it helpful? Then share it with your friends and colleagues!
For consultation and cooperation:
- leave a request on the website
- write to the post office hello@byyd.me
Интернетом в Казахстане пользуются 19,5 млн человек, а уровень его проникновения составляет 93,4%. При этом мобильная среда остается одной из ключевых точек контакта с аудиторией: в стране насчитывается 27,3 млн мобильных подключений.
На фоне роста цифрового потребления увеличивается и конкуренция за внимание пользователя. Для брендов это означает, что digital-реклама становится не просто каналом охвата, а важным инструментом привлечения трафика.
Но чем активнее растет рынок, тем выше требования к прозрачности закупки и качеству рекламных контактов. По глобальной статистике, 8,51% всех платных рекламных кликов относятся к невалидному трафику. Это эквивалентно примерно $63 млрд потерь рекламных бюджетов.
Современный фрод — это уже не только простые боты или случайные клики. Мошеннические схемы становятся сложнее: имитируют поведение реальных пользователей, генерируют показы, клики и даже базовые конверсии. В результате рекламодатель может видеть формально хорошие метрики, но не получать реального роста аудитории.
Поэтому для рынка Казахстана, где digital и mobile уже стали массовыми каналами коммуникации, контроль качества трафика становится критически важным. Мобильная платформа BYYD использует AI-антифрод-систему, которая помогает выявлять подозрительную активность, фильтровать невалидный трафик и повышать эффективность рекламных инвестиций.
Рассказываем, как это работает и приводим аналитику.
Интеллектуальная система защиты рекламного трафика
BYYD AI Антифрод — это комплексная система защиты рекламных кампаний от фрода. Построена на собственной модели машинного обучения. Она обрабатывает более 1,5 миллиардов аукционных запросов (bid request) в сутки.
Что делает платформа в режиме реального времени:
- Анализирует входящий трафик
- Формирует цифровой профиль пользователя (fingerprint)
- Принимает решение об участии в аукционе всего за ~0,4 миллисекунды (с момента получения bid request до решения)
На текущий момент архитектура развернута на выделенном сервере антифрода — 48 CPU / 256 GB RAM. На каждом сервере с биддером (участником аукциона по покупке рекламных показов) запущен процесс антифрод-сервиса, потребляющий ~2 CPU.
Таким образом, система эффективно масштабируется и практически не влияет на производительность основного биддера (участника аукциона).
Архитектура системы
1. Машинное обучение в реальном времени
ML-модель (модель машинного обучения CatBoost) обрабатывает массив данных с широким спектром поведенческих характеристик трафика. Обучение проводится на реальных данных пользовательской активности. Датасет (набор данных) формируется так, чтобы включать максимальное разнообразие паттернов — как относящихся к фроду, так и легитимных.
После завершения обучения модель выводится в рабочую среду, где в режиме реального времени:
- Обрабатывает каждый входящий запрос
- Рассчитывает необходимые поведенческие и технические признаки
- Присваивает запросу числовой показатель — fraud score, который принимает значение в диапазоне от 0 до 1. Порог может быть адаптирован в зависимости от требуемого баланса между агрессивностью фильтрации и сохранением охвата
Метрики качества модели
Чтобы оценить эффективность, используются ключевые метрики бинарной классификации: precision (точность) и recall (полнота).
– Precision (точность). Отражает долю корректных срабатываний среди всех случаев, когда модель классифицировала трафик как фрод.
Формула: Precision (точность) = TP / (TP + FP), где:
- TP (True Positive) — корректно выявленный фрод
- FP (False Positive) — легитимный трафик, ошибочно классифицированный как фрод
— Recall (полнота). Отражает долю обнаруженного фрода от общего объема фактически невалидного трафика.
Формула: Recall (полнота) = TP / (TP + FN), где:
- TP (True Positive) — корректно выявленный фрод
- FN (False Negative) — фрод, который модель не обнаружила
Текущие показатели модели при оффлайн валидации
- Precision (точность) = 0.92
- Recall (полнота) = 0.95
Это означает, что система выявляет 95% фродового трафика, при этом сохраняет высокую точность классификации и минимизирует ошибочные блокировки легитимных пользователей.
2. Fingerprint: цифровой профиль пользователя
По каждому пользователю формируется уникальный fingerprint – его цифровой профиль.
Если идентификатор устройства Device ID присутствует, профиль привязывается к нему (IFA/GAID).
Если отсутствует, создаётся уникальный платформенный ID на основе совокупности параметров. Некоторые из них:
- device_ip
- device_make
- device_model
- device_os
- device_osv
- device_ua_core
Таким образом система может вероятностно идентифицировать устройство даже при отсутствии рекламного идентификатора.
3. Работа с динамичными изменениями
В реальной среде пользователи часто:
- Меняют IP (динамические сети)
- Получают обновления ОС
- Меняют User-Agent (информация о пользователе, которую отправляет браузер или приложение на сервер при запросе веб-страницы)
- Используют мобильный и проводной интернет поочередно
Если создается новый цифровой профиль (fingerprint), например, из-за смены IP или UA, показ будет возможен только после повторной проверки — во втором и последующих аукционах с теми же параметрами.
Это позволяет:
- Корректно объединять одного пользователя
- Минимизировать false positive (легитимный трафик, ошибочно классифицированный как фрод)
- Эффективно бороться с попытками маскировки фрод-трафика
4. Базовые фильтры трафика
Перед оценкой с использованием машинного обучения система применяет базовую фильтрацию:
- Список заблокированных доменов
- Домены из API запрещённых ресурсов РКН
- IP-адреса всех известных облачных сервисов
- Известные прокси и дата-центры
Это позволяет отсекать очевидный фрод ещё до сложной аналитики.
Как проводится поведенческая и техническая оценка: 20+ параметров
После первичной фильтрации каждый аукционный запрос (bid request) проходит многоуровневую оценку по более чем 20 параметрам.
1. Размер устройства и рекламного окна
Минимальная высота или ширина рекламного блока должна превышать установленный порог (X пикселей). Это отсеивает невидимые или технические размещения.
2. Наличие оператора при сотовом соединении
Отсутствие корректных данных об операторе — потенциальный индикатор аномального трафика.
3. Корректность User-Agent – идентификационной строки клиентского приложения
Проверяется:
- Минимальная длина
- Соответствие модели устройства
- Совпадение с ОС
- Согласованность данных аукционного запроса (bid request)
4. VPN и прокси-трафик
Блокировка осуществляется по:
- Информации о сети
- Названию приложения
- По идентификатору приложения в системе (bundle name)
- Сигнатурам (характеристикам) VPN-сервисов
5. Средняя пауза между запросами
Анализируется интервал между аукционным запросом (bid request) от одного цифрового профиля (fingerprint). Слишком частые или слишком регулярные интервалы — маркер автоматизированного поведения.
6. Максимальное количество запросов
При превышении установленного лимита цифровой профиль блокируется на уровне системы с возможностью пересмотра при изменении поведенческого профиля.
7. Изменение IFA/GAID
Резкая смена рекламного идентификатора внутри одного диджитал-профиля — признак манипуляции.
8. Рывки активности (burst detection)
Сравнивается количество запросов от одного профиля с медианой по аналогичным устройствам в том же идентификаторе приложения (bundle name). Резкие отклонения сигнализируют о бот-поведении.

Cкриншоты статистики реальных рекламных кампаний
Эффективность кампании в сегменте ритейла демонстрирует высокий уровень качества рекламного трафика. Показатель Viewable Rate на уровне 96% значительно превышает рыночные бенчмарки, что говорит о высокой видимости рекламных размещений. При этом доля невалидного трафика составила всего 0,03%, а показы вне целевой географии не были зафиксированы. Это подтверждает точность таргетинга и эффективность механизмов предотвращения фрода.

FMCG-кампания также показала высокий уровень качества рекламного трафика. Viewable Rate составил 94%, что говорит о высокой видимости размещений и превышает стандартные рыночные ожидания. Кроме того, общий уровень невалидного трафика IVT составил всего 0,06%, что является приемлемым показателем для масштабных рекламных кампаний с учетом размера аудитории.
Дополнительно не было зафиксировано показов вне целевой географии — 0,00%.

Результаты верификации FMCG-кампании с использованием трекера DoubleVerify демонстрируют высокий уровень качества размещений. 96% показов были видимыми, а доля показов без сложного невалидного трафика SIVT превышает 99%, что указывает на практически полное отсутствие фрода.
Кроме того, более 99% показов были доставлены в рамках целевой географии и соответствовали требованиям Brand Suitability. Это подтверждает корректную настройку кампании и размещение рекламы в brand-safe среде.

Ключевые преимущества BYYD AI Антифрод
- Обработка 1+ млрд запросов в сутки
- Постоянно дообучаемая модель
- Решение в реальном времени без потери аукционной скорости
- Устойчивый цифровой профиль (fingerprint) даже без идентификатора устройства (Device ID)
- Поведенческий анализ, а не только статические фильтры
- Гибкая система блокировок и перманентных ограничений
BYYD AI Антифрод — это не просто набор фильтров, а интеллектуальная система динамической оценки трафика. Она способна выявлять сложные схемы фрода в режиме реального времени.
Благодаря сочетанию аналитики модели машинного обучения, поведенческих паттернов и строгих технических критериев, система обеспечивает максимальную прозрачность и качество рекламных кампаний в Казахстане.
Как с нами связаться
Платформа BYYD более 11 лет занимается мобильной рекламой в Казахстане и постоянно совершенствует свои инструменты. Ознакомьтесь с кейсами на сайте и свяжитесь с нами для запуска in-app кампании.
Было полезно? Тогда поделитесь с друзьями и коллегами!
Для консультации и по вопросам сотрудничества:
- оставьте заявку на сайте
- пишите на почту hello@byyd.me