Seatext library / BotRefund evidence
How BotRefund Evaluates Visit Patterns: The 106-Check Process Explained
BotRefund evaluates visit patterns by running 106 independent checks across browser, network, device, and behavioral signals. Each check produces one piece of evidence — not a verdict. An AI model then weighs the complete...
✓ Built for advertisers who need clear, refund-ready traffic evidence.
BotRefund does not rely on a single signal to decide whether a visit is human or automated. Instead, it runs 106 independent checks that each capture one objective fact about the session — things like mouse tremor, click timing, iframe behavior, and network characteristics. No single check triggers a block. The system cross-references every signal against the others, then feeds the full pattern into a prediction model that outputs a probability score. That corroboration approach is what drives the 99% accuracy claim.
The 106 independent checks: what they cover
BotRefund groups its checks into four evidence categories. Each category contains dozens of specific tests that run silently during the visit.
- Browser evidence — rendering quirks, JavaScript engine behavior, extension fingerprints, and iframe handling (including the Blocked Challenge Iframe test).
- Network evidence — IP reputation, VPN/proxy detection, connection timing, and routing anomalies.
- Device evidence — hardware concurrency, screen properties, battery API, sensor availability, and rendering performance.
- Behavioral evidence — mouse movement quality, click timing, scroll patterns, form interaction speed, and session duration distributions.
The Blocked Challenge Iframe check, documented as one of the 106, looks for a mismatch that real browsing sessions do not normally create. Scripts can send clicks and scrolls, but they struggle to reproduce the varied timing, movement, and hesitation of real people.
Behavioral signals: the human imperfections bots miss
Real visitors produce imperfect, varied behavior: pauses, hesitation, natural movement, and interactions shaped by reading and decision-making. BotRefund measures several concrete behavioral dimensions:
- Pointer behavior — robotic linear mouse movements, absence of humanlike mouse tremor, and grid-aligned movement patterns that snap to precise lines instead of natural curves.
- Speed behavior — superhuman input speed (under 1 millisecond) that identifies interactions faster than a person could realistically perform.
- Engagement behavior — absence of clicks or scrolling, highlighting sessions that stay too static to match a real browsing journey.
- Session behavior — unnatural session durations that are too short, too long, or too uniform to be human.
- Trap behavior — honeypot trap interactions that watch for bots responding to hidden or intentionally deceptive page elements.
- Click behavior — ghost click detection that catches click activity happening without the natural sequence of human intent.
Each of these signals adds one objective fact. Privacy tools, travel, corporate networks, and unusual devices can produce unexpected behavior for genuine people, so BotRefund keeps every signal as evidence — not a verdict — and cross-checks it against the other categories.
Technical signals: browser, network, and device fingerprints
Beyond behavior, the system collects technical evidence that automation frameworks struggle to forge consistently:
- Browser checks examine canvas rendering, WebGL parameters, audio context, font enumeration, and the presence of automation markers like
navigator.webdriver. - Network checks identify VPN exit nodes, residential proxy networks, data center IP ranges, and connection latency patterns that don't match the claimed geography.
- Device checks verify hardware concurrency, device memory, screen resolution versus viewport, touch support consistency, and battery status API responses.
These technical signals are independent of user behavior. A sophisticated bot might mimic human mouse movement but still fail the device fingerprint check because its hardware profile doesn't match the user agent it claims.
Cross-verification: why one anomaly is not a bot verdict
The system operates on a three-step logic documented in the source material:
- Independent evidence — each check adds one objective fact about the visit.
- Cross-checked context — BotRefund tests whether other signals support the same story.
- AI prediction — the model weighs the complete pattern instead of trusting a raw rule.
For example, a visitor using a privacy-focused browser might trigger the Blocked Challenge Iframe check. But if their mouse tremor, click timing, network reputation, and device fingerprint all align with human patterns, the AI weighs the full picture and classifies the visit as human. This prevents false positives from privacy tools, corporate proxies, or unusual but legitimate devices.
The AI prediction model: weighing the complete pattern
After all 106 checks run, the signals feed into a prediction model that evaluates the complete picture across browser, network, device, and behavior evidence. The model does not apply a fixed threshold on any single check. Instead, it learns which combinations of signals reliably separate human from automated traffic.
The 99% accuracy claim comes from this corroboration approach. A single browser tell — like a missing API or an unusual user agent — is unreliable on its own. But when dozens of independent signals point the same direction, the classification becomes highly confident. The model also adapts as new bot frameworks emerge, because it learns from the pattern relationships rather than hard-coded rules.
Limitations and when the model needs human review
No automated system is perfect. The source material acknowledges that privacy tools, travel, corporate networks, and unusual devices can produce unexpected behavior for genuine people. In edge cases — such as a user on a corporate VPN with a locked-down browser accessing the site from a new device — multiple technical signals may look anomalous while behavioral signals remain human. The system flags these for review rather than auto-blocking.
Additionally, the model depends on the quality of the training data. New bot frameworks that successfully mimic both technical fingerprints and behavioral patterns could temporarily evade detection until the model retrains on fresh examples. BotRefund addresses this by continuously updating its signal library and retraining the prediction model.
Practical scenarios: what this looks like in production
Scenario 1: Click farm on Meta Audience Network. A publisher runs bots that click ads in third-party apps. The bots use real mobile devices (bypassing IP filters) but show superhuman input speed, no mouse tremor, and uniform session durations. Behavioral signals flag the visits; technical signals confirm real devices. The AI classifies as bot.
Scenario 2: Competitor click script on Google Ads. A script rotates residential proxies and uses Puppeteer with stealth plugins. It mimics human mouse curves and click timing. However, the Blocked Challenge Iframe check catches an iframe mismatch, the device fingerprint shows headless Chrome artifacts, and network checks detect proxy exit nodes. Multiple independent signals converge on bot classification.
Scenario 3: Privacy-conscious human user. A user browses with hardened Firefox, uBlock Origin, and a VPN. The Blocked Challenge Iframe check triggers. Network check shows VPN. But mouse tremor, click hesitation, scroll variance, and session duration all fall within human ranges. The AI weighs the full pattern and classifies as human.
Key facts
| Fact | Detail | Source |
|---|---|---|
| Total independent checks | 106 | S1 |
| Evidence categories | Browser, network, device, behavior | S1 |
| Classification method | AI prediction model weighing complete pattern | S1 |
| Claimed accuracy | 99% | S1 |
| Single-check verdicts | No — each signal is evidence, not a verdict | S1 |
| Cross-verification steps | Independent evidence → cross-checked context → AI prediction | S1 |
| Behavioral signals measured | Mouse tremor, click timing, scroll patterns, form speed, session duration, honeypot interaction, ghost clicks | S2 |
| Technical signals measured | Browser fingerprint, VPN/proxy detection, device hardware profile, automation markers | S2 |
| False positive mitigation | Privacy tools, corporate networks, unusual devices kept as evidence not verdicts | S1 |
Terminology
- Blocked Challenge Iframe — a specific check that looks for iframe behavior mismatches typical of automation frameworks.
- Ghost click — a click event that fires without the preceding human intent signals (hover, pause, natural approach).
- Honeypot trap — a hidden page element that real users never interact with; bots often click or fill it.
- Mouse tremor — the microscopic jitter in human pointer movement caused by physiological factors.
- Superhuman input speed — interactions completing in under 1 millisecond, faster than human neuromuscular limits.
- Grid-aligned movement — pointer paths that snap to exact pixel coordinates or straight lines, typical of scripted movement.
- GCLID/FBCLID — Google Click ID / Facebook Click ID, used to tie ad clicks to specific sessions for refund evidence.
Frequently asked questions
How many checks does BotRefund run per visit?
106 independent checks across browser, network, device, and behavioral categories.
Does a single failed check mean the visit is blocked?
No. Each check produces one piece of evidence. The AI model weighs the complete pattern. Privacy tools, VPNs, and unusual devices can trigger individual checks without resulting in a bot classification.
What behavioral signals are most reliable for detecting bots?
Superhuman input speed (under 1ms), absence of mouse tremor, grid-aligned movement, and uniform session durations are among the hardest for automation to fake consistently.
Can sophisticated bots that mimic human behavior evade detection?
Bots that perfectly mimic both technical fingerprints and behavioral patterns could temporarily evade detection. BotRefund counters this by continuously updating its 106-check library and retraining the prediction model on new attack patterns.
How does BotRefund use visit pattern data for ad refunds?
When the system classifies a paid click as invalid, it captures the GCLID (Google) or FBCLID (Meta) linked to behavioral evidence. This creates audit-ready reports for billing disputes with Google Ads and Meta.
What happens to visits flagged as uncertain?
Edge cases — such as corporate VPN users with hardened browsers — are flagged for review rather than auto-blocked, preventing false positives on legitimate traffic.
Does the system work on both Google Ads and Meta traffic?
Yes. The same 106-check evaluation runs on all paid traffic sources. Refund evidence generation is tailored to each platform's click ID format (GCLID for Google, FBCLID for Meta).
Further reading and comparison sources
These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.
Learn more
Visit the website for more information.