Seatext library / BotRefund evidence
How to Read CPU Concurrency Data in Bot Detection Reports
To interpret CPU concurrency data, look at trends and compare the number with other signals instead of treating a single value as proof. A mismatch is only one piece of evidence, and accuracy comes...
✓ Built for advertisers who need clear, refund-ready traffic evidence.
What is CPU concurrency in bot detection?
To interpret CPU concurrency data, look at trends and compare the number with other signals instead of treating a single value as proof. A mismatch is only one piece of evidence, and accuracy comes from corroboration across browser, network, device, and behavior data.
CPU concurrency is a browser property (typically navigator.hardwareConcurrency) that reports the number of logical processor cores available to the device. Bot detection platforms capture this value to build a hardware fingerprint, then compare it with other device and behavior signals.
In a bot detection report, CPU concurrency appears as a number (like 2, 4, 8, or 16) along with a verdict or anomaly flag when it doesn't match the rest of the fingerprint.
Step 1: Read the raw number but treat it as evidence, not proof
Start by noting the reported concurrency value. A real browser on a typical laptop or phone will show a value that matches the device profile — for example, 8 cores on a modern desktop. An automated browser or virtual machine might report an impossible or inconsistent value, such as 100 cores on a mobile device.
But a single mismatch is not a bot verdict. As BotRefund explains, "A single anomaly is not a bot verdict." So write down the value, but don't jump to a conclusion.
Consider the context. A low-end smartphone might report 2 or 4 cores. A high-end desktop might report 16 or 32. If the value seems out of place, that is a clue, not a conclusion.
Step 2: Compare CPU concurrency with other device signals
Check whether the concurrency value fits with the rest of the hardware fingerprint: GPU model, installed fonts, operating system, screen resolution, audio capabilities, and performance timing. A real browser reports hardware, graphics, fonts, and operating-system details that naturally fit together for that device.
For example, if the report says the visitor has a high-end gaming GPU but also reports only 2 CPU cores, that inconsistency is worth investigating. The CPU concurrency check specifically looks for a mismatch that a real browsing session does not normally create.
Look for pairs that should correlate. A 4K screen with a low-end CPU is possible but unusual. A modern OS with an ancient CPU is also suspicious. Use your judgment, but always verify with other signals.
Step 3: Look for cross-signal corroboration, not single flags
The most misleading mistake is to treat CPU concurrency in isolation. Strong bot detection relies on corroboration. BotRefund states that its platform "cross-checks it against independent browser, network, device, and behavior data."
Ask: do other signals tell the same story? For example, if CPU concurrency is odd but click behavior, input speed, mouse movement, and session duration are all human-like, the overall evidence may point to a legitimate anomaly. Conversely, if CPU concurrency is unusual and the session also shows superhuman input speed or linear mouse paths, the combined pattern is much more suspicious.
Think of it like a puzzle. One piece that doesn't fit might be a mistake. Several pieces that don't fit together likely indicate fraud.
Step 4: Account for legitimate exceptions before judging
Privacy tools, travel, corporate networks, and unusual devices can produce unexpected behavior for genuine people. A virtual machine running a real user's browser session can report a weird CPU concurrency value. Similarly, a corporate remote desktop may show a hardware profile that doesn't match the user's physical device.
Before flagging a session as bot traffic, check if the visitor came through a VPN, a cloud host, or a managed corporate environment. These contexts can explain a single anomaly.
Consider the user's journey. A person on a corporate VPN might appear to have a different IP and hardware profile. That alone is not a reason to block them. Look for other signals like form input speed or mouse movement to confirm they are human.
Step 5: Track trends across sessions and over time
The real value of CPU concurrency data appears in aggregates. Instead of analyzing one event, look at a stream of sessions. Ask questions like:
- Do many sessions from the same IP or device family show identical, unrealistic concurrency values?
- Is there a sudden spike in sessions with unusual concurrency around the same time as a campaign change?
- Do sessions with anomalous concurrency also share other suspicious signals (e.g., no scrolling, fast form fills)?
Trends matter more than any individual reading. A single weird number is often noise; a pattern is a signal.
For example, if a new ad campaign attracts 100 visits with 128 CPU cores each, that is suspicious. But if one visitor has 12 cores on a MacBook, that is probably normal.
Step 6: Verify your interpretation with your bot protection platform
If your bot detection report highlights CPU concurrency as part of a bot score, don't manually override it based on the number alone. Verify by checking the full signal breakdown inside your platform. Look for the list of independent checks and whether the system cross-referenced the concurrency value with other data.
BotRefund sends CPU concurrency into its prediction AI, which evaluates the complete picture across browser, network, device, and behavior evidence. That's the correct way to interpret such data: as one input to a weighted decision, not as a smoking gun.
Use the report as a guide. If the platform gives a confidence score, see how much weight it assigns to CPU concurrency. Some signals are stronger than others.
Key facts: CPU concurrency check
| Attribute | Detail |
|---|---|
| Signal name | CPU Concurrency Lie |
| Scope | One of 106 independent checks |
| What it looks for | Mismatch between reported hardware and actual device profile |
| Primary role | Adds objective evidence about the visit |
| Context | Cross-checked against browser, network, device, and behavior data |
| Verdict rule | Not a standalone bot verdict; combines with AI prediction |
| Accuracy context | Reported 99% accuracy when used as part of the full model |
Limitations and when this data misleads
CPU concurrency data is far from perfect. It can be spoofed by advanced bots using anti-detect frameworks. Many automation tools now claim consistent hardware values that match a target profile. And legitimate users on unusual devices or with privacy extensions may trigger false flags.
The biggest limitation is that the value alone has almost no predictive power. Only when combined with behavioral signals, network data, and other device fingerprints does it become useful. If your report shows a single high CPU concurrency number without any other anomalies, it likely means nothing. Overreacting to such a number can block real users and hurt your conversions.
Another limitation is that some browsers report concurrency incorrectly. For example, Safari on older Macs might report fewer cores than actual. Always cross-check with other properties.
Practical scenarios and decision criteria
Here are three real-world examples to help you apply the interpretation steps.
Scenario A: High concurrency on mobile. A report shows 16 cores on a phone. Phones typically have 4, 6, or 8 cores. This is suspicious, but check the model. Some high-end tablets have 12 or more. Check if the OS and screen match a device with that many cores.
Scenario B: Low concurrency on a desktop. A desktop with a 4K monitor and a high-end GPU reports 2 cores. That is odd. But a virtual machine might have 2 cores assigned. If the user is on a corporate remote desktop, that explains it. Look at network IP and behavior.
Scenario C: Pattern across sessions. You see 50 sessions with exactly 8 cores, all from the same IP range, all with no mouse movement. That is a clear bot pattern. Even if each session looks plausible, the uniformity and lack of behavior confirm automation.
Use these criteria to decide: Does the value fit the device? Does it fit with other hardware? Does the user's behavior support a human? Do other sessions from the same source show similar patterns?
FAQ
Why is CPU concurrency used in bot detection?
It helps create a hardware fingerprint that distinguishes a real browser from an automated emulator. Real devices have consistent hardware profiles, while bots or virtual machines often report mismatches.
What does a typical CPU concurrency value look like?
Most consumer devices report between 2 and 16 logical cores depending on the processor. Desktops and high-end laptops often report 8 or more. Your report should show a value consistent with the device's other hardware attributes.
Can CPU concurrency be spoofed by bots?
Yes. Advanced bot frameworks can set the property to any value they want. This is why a single reading is meaningless; the context and corroboration matter.
What should I do if I see an unusual CPU concurrency value in my report?
Treat it as a lead, not a conclusion. Check other device signals and behavior data, and see if the same pattern repeats. If your bot detection platform flags it as part of a larger pattern, then you can act.
How often does CPU concurrency cause false positives?
It can cause false positives when virtual machines, corporate networks, or privacy tools create legitimate mismatches. That's why platforms like BotRefund cross-check the signal against independent evidence before making a decision.
Is CPU concurrency enough to prove a visit is from a bot?
No. It is one of many signals. The accuracy comes from corroboration, not one browser tell. A verdict should always be based on the complete pattern.
Further reading and comparison sources
These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.
- performance.now, hardwareConcurrency, and Timing Fingerprints
- Bot detection 101: How to detect bots In 2025? - The Castle blog
- How to Identify Bot Traffic in Google Analytics: The 2026 Precision ...
Visit the website for more information.
Learn more — Continue to the relevant page on the client website.
Further reading and comparison sources
These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.
Learn more
Visit the website for more information.