An install is the easiest conversion to fake in all of digital advertising: it needs no card, no form and no intent — just a device (or something that looks like one) and an attribution to steal. This final lesson is about separating users from smoke.
The metrics that tell users from numbers
None of these live in Google Ads: they come from your own measurement (Firebase or an attribution provider). They are the ones that truly judge a campaign:
- Open rate after install: what share ever opens the app at all. A source whose installs never open isn't expensive: it is fake.
- Day-1 and day-7 retention, by campaign, country and creative. It is the most reliable smoke detector there is.
- Reaching the key event: sign-up, tutorial, first purchase.
- Revenue per install (or per user) over the following weeks: the translation of all the above into money.
With these metrics by segment you can do what Google Ads doesn't do on its own: compare sources by quality, not by price.
The fraud techniques that exist
Install fraud usually doesn't happen inside Google's advertising, but in the attribution chain — which is why detecting it is your measurement's responsibility. The four known families:
| Technique | What it does | Tell-tale signal |
|---|---|---|
| Click injection | Detects an install starting and fires a click to steal the attribution | Click→install time of seconds |
| Click spamming | Floods the system with fake clicks hoping some match real installs | Huge click counts, absurd conversion rate, very long times |
| SDK spoofing | Sends fake install events with no real install | Installs with no later activity; impossible device patterns |
| Device farms and emulators | Genuinely install and open, in bulk | Near-zero retention, concentrated device models/IPs, clone-like behaviour |
The signals that give them away, in short: the distribution of time between click and install (legitimate takes a while; injected takes seconds), zero retention with normal-looking installs, and no subsequent activity in segments that install a lot.
What defences exist
- An attribution provider with anti-fraud is the main defence: it filters and rejects fraudulent installs before they contaminate your reports and your optimisation.
- Optimising for deep events (not for installs) is a defence in itself: faking an install is cheap; faking recurring purchases with revenue is not.
- Per-segment vigilance: reviewing retention and activity by campaign, country and network, and acting on what doesn't hold up.
- Within Google's ecosystem, invalid traffic is filtered systematically and not charged when detected; but attribution fraud happening outside its network is nobody else's job to spot.
And scripts? What isn't solved today
It is worth being honest about the tools, ours included: Ninja Shield protects the opposite direction from this module. It excludes low-quality apps from the inventory where an advertiser's ads are shown (Display, Performance Max, Demand Gen): it protects you from apps, not an app.
For install campaigns, a Google Ads script hits a real limit: app campaigns don't expose placements, so there is nothing specific to exclude. What could be built — and is noted on our roadmap — is a quality-vigilance layer: crossing what Google Ads does let you read (campaign, country, network, spend, installs) with the retention and activity data from your own measurement, to flag segments with a fraud pattern and act with what the platform allows (excluding geographies, pausing, adjusting targets). In the meantime, that vigilance is done by hand — and this lesson is the manual for doing it.
💡 Ninja trick: build a weekly table with one row per campaign×country and three columns: installs, day-1 retention and revenue per install. The rows with many installs and retention near zero are your suspect list. You need no more technology to find 80% of the problem.
⚠️ Pitfall: celebrating a drop in cost per install without looking at retention. Almost every spectacular CPI drop that doesn't come from a creative or listing improvement comes from worse traffic.
What you should remember
- Judge by retention, activity and revenue, not by CPI.
- Four known frauds; their signals are time-to-install, zero retention and no activity.
- Defences: a provider with anti-fraud, optimising for deep events and per-segment vigilance.
- Today that vigilance is manual: the campaign×country×retention table is the most profitable tool you can build this week.
End of the module. If you came from the Intermediate level, you have walked the full path: how they work, how they are measured, how they are structured, how bidding works, which creatives are needed, how the listing matters, how users are won back, how to operate and how to defend yourself.