When I worked in adtech, I proposed a simple solution to ad fraud on our platform - assume any UA coming from an IP range owned by a cloud provider was a bot and don't show them ads, don't count their impressions. Worst case, people using a VPN hosted on EC2 might not see an ad, but I was certain they'd cope. Best case, higher quality traffic increases yields. The business team vetoed that, it would adversely impact…
But more often then not, those ads are running in an autoplay context (sticky video players in the bottom corner, large players in the footer, etc).
I built a mechanism which could tell the difference (viewport, fixed positioning, fingerprint elements on the page, provide a screenshot of the offended page with your ad on it, and various other signals).
We ran tests with advertisers, agencies, demand side platforms (dsps), server side platforms (ssps). We’d compare their existing fraud numbers (very low) with our reports (80% fraud).
Within each company, we’d have a champion saying “this is going to change everything. Quality supply, better performance metrics, etc etc”. Then we’d get introduced to a team whose compensation was driven by “percentage of spend” - every deal died at this stage.
My opinion: if your company is using online advertising tied to conversions (someone buying something, or potentially signing up for something) then you’ll be fine as long as it’s economical. But if your ads are for brand awareness, be extremely careful running on any website which isn’t in the top 10 sites on the internet.