Does this attack work with Facebook as well? I think the difference in client authentication might prevent this attack on Facebook (just ban accounts that click too many ads). But, on the other hand, Google might be able to use IP-addresses to accomplish the same.
Taking it to the next (morally questionable) level would be a virus that infects regular consumer devices, and delivers fake clicks from seemingly honest clients.