HUMAN vs Fraudlogix is the search a platform runs when it wants something in front of the bid and finds two firms that publish completely different kinds of numbers. HUMAN (formerly White Ops) documents MediaGuard, a pre-bid service that takes an OpenRTB request and returns an IVT prediction, and its July 7, 2026 NewsJunkie disclosure says the operation reached hundreds of millions to nearly two billion invalid CTV bid requests per day per seller at its peak. Fraudlogix's State of Ad Fraud 2026 report puts invalid traffic at 20.64 percent of 105.7 billion impressions collected in 2025, and its Q1 2026 report puts it at 18.12 percent of a 26.3 billion impression sample. Its product page offers a pre-bid blocklist of more than 30 million IP addresses, updated hourly. vastlint does not rank HUMAN against Fraudlogix. It checks whether a VAST 2.0–4.4 tag still carries the verification node and trackers that a post-bid tag needs, and it does not classify invalid traffic.
HUMAN does not publish a market-wide invalid traffic rate in the documents read for this page, and Fraudlogix does not publish named-scheme takedowns in its reports. One firm's public record is a per-request answer plus counts for specific operations. The other's is a share of a sample plus the size of a list. Setting 20.64 percent beside two billion bid requests a day compares a fraction with a volume.
The units also reflect what each firm sells. A MediaGuard client sends a request and gets back a yes or no. A Fraudlogix client can download the IP list and check it on its own servers. Both are pre-bid tools for platforms, and both pair with a post-bid tag that runs where the ad renders, but they answer the bid question in different shapes.
What the HUMAN figures measure
HUMAN's MediaGuard overview describes a predictive model based on reputation data that reads the OpenRTB bid object and returns whether the request is likely invalid. The documented example drops requests that come back with IVT=true. MediaGuard can also return opt-in policy decisions, which HUMAN says are not IVT. HUMAN's package plans describe Ad Fraud Defense as real-time analysis of each bid request in 12 milliseconds or less across mobile, desktop, CTV, and audio. The unit is one decision on one request. It does not add up to a published share of the market.
The model learns from what it lets through. HUMAN's closing-the-loop page says FraudSensor data retrains MediaGuard every four hours, and that 0.5 percent of SIVT-flagged traffic and 0.05 percent of GIVT-flagged traffic is passed through so the post-bid tag can confirm the call. The MRC's April 11, 2025 statement on pre-bid IVT says HUMAN provides suggestions on whether a request is IVT, only to DSPs and SSPs, and does not itself filter requests or block serving. A platform that wires in MediaGuard still decides what to do with the answer.
The scheme figures are counts of specific operations. HUMAN's March 5, 2025 BADBOX 2.0 release describes more than one million infected consumer devices across 222 countries and territories, and 24 evil-twin apps that produced up to 5 billion fraudulent bid requests a week at peak. Its Satori team's March 26, 2025 post counts nearly 500,000 devices beaconing to sinkholed domains, and about 3.5 million unique IP addresses doing so across BADBOX 2.0, Vo1d, and Vo1d 2. The FBI's June 5, 2025 public service announcement on BADBOX 2.0 says the botnet consists of millions of infected devices and sells access to compromised home networks as residential proxies. The NewsJunkie disclosure describes a single Jacksonville local news app that generated about 42.2 billion bid requests in two months with 185 reviews, and supply paths with more than 100 times the median CTV seller's concentration of unverified IP addresses. Each count describes one operation, not the share of anyone's traffic that was invalid.
The MRC's digital accreditation list shows HUMAN accredited for pre-bid IVT detection and for SIVT detection and filtration across desktop, mobile web, mobile in-app, and CTV, with a note that the SIVT accreditation applies to backend detection and IVT predictions. The MRC statement says HUMAN's pre-bid metrics classify requests as GIVT or SIVT. Those categories follow HUMAN's published IVT taxonomy, which is where its treatment of proxies is written down.
What the Fraudlogix figures measure
The State of Ad Fraud 2026 report covers 105.7 billion impressions collected through Fraudlogix's sensor network from January 1 through December 31, 2025, of which 21.81 billion, or 20.64 percent, showed risk signals. The report says the dataset was compiled specifically for this analysis and does not represent the entirety of traffic monitored. Device rows are desktop at 27.03 percent, mobile at 19.30 percent, and tablet at 16.34 percent, and the United States is 23.69 percent of 37.6 billion. The Q1 2026 report puts 4.77 billion of 26.3 billion impressions at risk, an 18.12 percent rate across 246 countries and territories, and calls the set a representative sample compiled for the analysis. Neither report has a CTV row.
The definition sorts traffic into valid, with no risk signals detected, and invalid, showing risk signals. The listed signals are proxy and VPN detection, Tor exit node identification, known botnet signatures, abnormal behavior, device spoofing indicators, and IP addresses with fraud histories. Fraudlogix's methodology page says more than 40 anomalies are weighted by type and severity, and its IVT product page says multiple indicators are required before traffic is flagged as high risk. The reports do not split the rate into general and sophisticated invalid traffic, and Fraudlogix does not appear on the MRC's list of accredited digital services.
The pre-bid product is a list rather than a query. Fraudlogix's IVT page describes more than 30 million IP addresses updated hourly, with about 6 percent changing each day, three risk levels (Medium, High, Extreme), and reason codes in seven categories, delivered for download so a platform can store it on its own servers. Its 2026 buyer's guide adds an IP Risk Score API that it says returns assessments in under 50 milliseconds. The post-bid product is a JavaScript pixel added to ad tags, with daily CSV reports.
The roughly $37 billion headline in the annual report multiplies an estimated $180 billion of 2025 US programmatic spend by the 20.64 percent sample rate, and Fraudlogix's own note says actual impact depends on verification practices, refund policies, and pricing basis. Fraudlogix's comparison page on HUMAN, written by one of the two parties, says HUMAN does not offer pre-bid IP blocking or an IP risk scoring API as standalone products. HUMAN's own documentation describes a pre-bid prediction service rather than a downloadable list, which is a difference in delivery that the comparison page frames as a gap.
Why a prediction, a takedown count, and a sampled rate have no shared scale
A MediaGuard answer is per request and is not published in aggregate. A NewsJunkie or BADBOX 2.0 count is the size of one operation, measured in bid requests, devices, or IP addresses. A Fraudlogix rate is a fraction of a sample drawn from its clients' pixel deployments. None of the three can be converted into another without a denominator that neither firm publishes, so there is no arithmetic that turns two billion bid requests a day into a percentage comparable with 20.64.
The proxy rule is the sharpest difference in definition. HUMAN's IVT taxonomy puts data-center traffic in GIVT when no VPN or proxy is detected and says it is not the byproduct of a legitimate user browsing through a VPN or proxy. Its NewsJunkie disclosure says residential proxy use is not invalid in and of itself, and that a heavy concentration on one seller is the signal. Fraudlogix lists proxy and VPN detection among the risk signals that make traffic invalid, while requiring more than one indicator before a high-risk flag. The MRC's 2020 IVT addendum treats proxy traffic as SIVT when the proxy exists to manipulate counts or pass on invalid traffic. A VPN user would therefore be counted differently depending on which definition applies, and neither firm publishes how many impressions sit on that line.
BADBOX 2.0 shows why both firms watch proxies anyway. The FBI's announcement says infected devices were enrolled into residential proxy services, and HUMAN's Satori post names IpMoYu as one such service. An IP-based list can flag addresses that keep showing bad behavior, and a request-level model can weigh the same address against the app, the seller, and the device claims on the request. In the NewsJunkie disclosure, HUMAN's Lindsay Kaye says no single signal revealed the fraud. Neither the list size nor the scheme count tells a buyer how much of a specific campaign either method would have removed.
Which question each firm's number answers
Not published means the documents cited here do not contain the figure, not that the firm could not produce it for a client.
| Question a buyer asks | HUMAN public answer | Fraudlogix public answer |
|---|---|---|
| Should this bid request be dropped? | MediaGuard returns IVT true or false per OpenRTB request, to DSPs and SSPs | Check the IP against a 30 million address list with Medium, High, or Extreme risk |
| What share of impressions was invalid? | Not published in the documents read | 20.64 percent of 105.7 billion in 2025; 18.12 percent of 26.3 billion in Q1 2026 |
| Which operation was behind it? | Named schemes such as BADBOX 2.0 and NewsJunkie, with device and request counts | Not published; reports give rates by network, browser, and country |
| Is a VPN or proxy user invalid? | Not in itself, per the taxonomy and the NewsJunkie disclosure | Proxy and VPN detection is a risk signal, with multiple indicators needed for high risk |
| Is the method MRC accredited? | Yes, for pre-bid IVT detection and SIVT across desktop, mobile web, in-app, and CTV | Not on the MRC accredited list, and the reports do not claim it |
| What share of US CTV was invalid? | Not published in the documents read | Not published; the reports have no CTV row |
| How does the post-bid tag reach video? | FraudSensor tag served with the impression, carrying the MediaGuard lookup ID | A JavaScript pixel in the ad tag; no VAST placement published in the pages read |
Where the post-bid tag has to survive in the VAST response
Both pre-bid products lean on a post-bid tag. HUMAN's FraudSensor overview says the tag loads a short code snippet on the device where each impression occurs, and the closing-the-loop page says the detection tag served with the impression carries a pv parameter set to the MediaGuard lookupId and a to parameter that reports the prediction state as a value from 0 to 4, where 3 means success. Fraudlogix describes a JavaScript pixel placed in the ad creative or ad tag. For video, whether either script runs depends on the VAST document: an Impression element holds a URI the player requests, and a script runs only where the player loads an executable resource such as an OMID JavaScriptResource inside a Verification.
The verification envelope is specific. In VAST 4.1 and later, AdVerifications sits under InLine or Wrapper, each Verification carries a required vendor attribute, a JavaScriptResource or ExecutableResource, optional VerificationParameters, and a TrackingEvents block where verificationNotExecuted reports a failed load through the [REASON] macro. IAB Tech Lab's OMID API document says VAST 2.0, 3.0, and 4.0 load the same schema through an Extension of type AdVerifications. The OM SDK web video onboarding guide says VPAID is not recommended as a delivery mechanism for measurement code. HUMAN's malvertising integration, a separate ad-quality product rather than IVT, replaces the original VAST URL with a HUMAN-wrapped URL that fetches and unwraps the original, which adds one more hop where a node can be dropped.
Much of CTV never runs the script. The NewsJunkie disclosure says a substantial share of CTV inventory is delivered with no JavaScript, which is why its two techniques, SSAI device spoofing and residential-proxy spoofing, had to be caught from request signals. IAB Tech Lab's CTV programmatic guide says macros such as [DEVICEUA], [SERVERUA], and [PAGEURL] are filled by the party making the VAST request, which under server-side ad insertion is the stitching server acting for the player. A tag whose macros arrive unexpanded, or whose AdVerifications node was stripped at a wrapper, gives either firm's post-bid sensor nothing to read. Walled-garden placements on YouTube, Meta, and TikTok do not take a buyer's VAST tag, so this check does not apply there.
What to do with the shortlist
Write the unit beside every number before comparing: a per-request prediction, a holdout share, a scheme count in bid requests or devices, a sampled risk-signal rate, a list size, or a dollar extrapolation. Once the units are written, HUMAN vs Fraudlogix stops looking like a contest over who found more fraud. It becomes a choice between a queried model with an MRC-accredited pre-bid method and a downloadable IP list with a sampled rate behind it, and a platform can run both.
If the choice needs evidence, test both on the same supply for the same weeks. Ask HUMAN for the share of requests MediaGuard flagged on that supply and the FraudSensor confirmation rate on the pass-through. Ask Fraudlogix which reason codes fired, and how many requests were flagged on proxy or VPN evidence without a second indicator. Run the post-bid tags on the same impressions so the comparison shares a denominator, which neither firm's public material provides.
Before a post-bid tag can confirm anything on video, it has to be in the delivered document. vastlint is independent of HUMAN and of Fraudlogix. It checks VAST 2.0–4.4 structure, including Impression elements, AdVerifications placement, the vendor attribute, resource types, apiFramework, and the [REASON] macro on verificationNotExecuted. It does not classify invalid traffic, it does not know whether a vendor host is up, and it does not rank these firms.
What to separate before using this comparison
- HUMAN's MediaGuard figure is one IVT prediction per OpenRTB request, sent to DSPs and SSPs, and HUMAN does not publish it as an aggregate rate.
- The 0.5 percent and 0.05 percent figures are shares of flagged SIVT and GIVT that HUMAN passes through for retraining, not invalid traffic rates.
- NewsJunkie's nearly two billion invalid bid requests a day is a per-seller peak for one CTV operation, not a share of CTV.
- Fraudlogix's 20.64 percent is a share of a 105.7 billion impression sample compiled for its 2025 report, with no CTV row.
- Fraudlogix counts proxy and VPN detection as a risk signal, while HUMAN's taxonomy says proxy use is not invalid in itself.
- Fraudlogix's 30 million figure is the size of an hourly IP list, and HUMAN's 12 milliseconds is a per-request response time.
Questions buyers ask about HUMAN and Fraudlogix
- Does HUMAN publish an ad fraud rate? Not in the documents read for this page; HUMAN publishes per-request predictions, accreditation scope, and counts for named schemes such as BADBOX 2.0 and NewsJunkie.
- Is Fraudlogix MRC accredited? Fraudlogix does not appear on the MRC's list of accredited digital services, while HUMAN is listed for pre-bid IVT detection and SIVT detection across desktop, mobile web, in-app, and CTV.
- Can advertisers use HUMAN's pre-bid product directly? The MRC's April 2025 statement says HUMAN's pre-bid suggestions go only to DSPs and SSPs, which then decide whether to filter.
- Does Fraudlogix treat VPN users as invalid traffic? Its reports list proxy and VPN detection as a risk signal, and its product page says multiple indicators are required before traffic is flagged as high risk.
- Does either firm publish a CTV invalid traffic rate? Neither does in the pages read; HUMAN publishes CTV scheme counts and Fraudlogix's reports break out desktop, mobile, and tablet only.
Check the tag the post-bid sensor depends on
Paste a VAST 2.0–4.4 tag to see whether AdVerifications, the vendor attribute, OMID resources, and Impression trackers are present and consistent. Nothing is stored.
Sources
Pre-bid IVT prediction from the OpenRTB bid object, the IVT=true example, and opt-in policy decisions.
Retraining every four hours, the 0.5 and 0.05 percent pass-through, and the pv and to parameters.
The post-bid tag that loads on the device where each impression occurs.
GIVT and SIVT categories, including the data-center carve-out for legitimate VPN and proxy users.
The HUMAN-wrapped VAST URL used by the ad-quality product.
Ad Fraud Defense at 12 milliseconds or less per bid request, and Ad Fraud Sensor surfaces.
July 7, 2026. Up to nearly two billion invalid CTV bid requests per day per seller, the residential proxy qualifier, and the no-JavaScript CTV note.
The 42.2 billion bid request Jacksonville app and the 100x concentration of unverified IPs.
March 5, 2025. More than one million infected devices in 222 countries and territories and 5 billion fraudulent bid requests a week at peak.
Nearly 500,000 devices beaconing to sinkholes, about 3.5 million IPs, and the IpMoYu proxy service.
June 5, 2025. FBI announcement that BADBOX 2.0 consists of millions of infected devices used as residential proxies.
April 11, 2025. HUMAN's pre-bid suggestions go to DSPs and SSPs, and HUMAN does not itself filter requests.
HUMAN's accredited pre-bid and SIVT metrics; Fraudlogix is not listed.
June 2020. GIVT and SIVT definitions, including invalid proxy traffic.
20.64 percent of 105.7 billion impressions collected in 2025, the risk-signal definition, and the $37 billion calculation.
18.12 percent of a 26.3 billion impression sample, January to March 2026.
More than 30 million IPs updated hourly, risk levels, reason codes, the JavaScript pixel, and the multiple-indicator rule.
More than 40 weighted anomalies and the universal pixel in the ad creative or ad tag.
Updated January 8, 2026. The IP Risk Score API at under 50 milliseconds.
Fraudlogix's own comparison of the two firms' pre-bid delivery.
VPAID is not recommended for delivering measurement code.
AdVerifications in VAST 4.1 and the Extension path for VAST 2.0, 3.0, and 4.0.
Which party fills device and page macros under server-side ad insertion.
How a pre-bid decision and a post-bid tag split the work.
What MediaGuard and FraudSensor cover and what a buyer would replace.
The envelope check for vendor, resource, and verificationNotExecuted.
