Seatext library / BotRefund evidence
The Truth About CPU Concurrency in Bot Detection
CPU concurrency is a weak signal that is often overhyped. A mismatch in reported CPU cores can hint at a virtual machine or spoofed profile, but it is not proof of a bot. Effective...
✓ Built for advertisers who need clear, refund-ready traffic evidence.
CPU concurrency is a weak, often-overhyped signal in bot detection. It can hint that a visitor is a virtual machine or a spoofed profile, but it is not proof of a bot. Effective detection works by combining many independent signals, not by trusting one browser tell.
Most bot detection tools treat CPU concurrency as one piece of evidence. The truth is that a mismatch in reported CPU cores rarely means a bot on its own. Real detection systems cross-check it against dozens of other hardware, browser, network, and behavior signals. This article explains what CPU concurrency is, why it is overhyped, and how professional detection systems actually use it.
What is CPU concurrency in bot detection?
CPU concurrency refers to the number of logical processors a device reports through the hardwareConcurrency browser API. This API exposes the number of CPU cores available to the browser. A real device has a consistent story: the number of CPU cores matches the rest of the hardware profile. An automated browser or virtual machine may claim a different CPU count than its actual hardware supports.
Bot detection services look for this mismatch. As the BotRefund CPU Concurrency Lie page explains, the check looks for a mismatch that a real browsing session does not normally create. Virtual machines and spoofed profiles can claim one device while their graphics, fonts, audio, or processor behavior tells another story.
For example, a typical laptop might report 8 cores. A headless browser running on a server with 32 cores might report 32, but the graphics card, screen resolution, and other hardware details often come from a generic baseline. That inconsistency is a clue. However, it is not proof. Many legitimate setups create mismatches. A virtual machine used by a developer, a cloud desktop, or a privacy-focused browser that randomizes hardware details can all show unusual CPU concurrency.
Why a single hardware signal is not enough
A single anomaly is not a bot verdict. Privacy tools, travel, corporate networks, and unusual devices can produce unexpected behavior for genuine people. For example, a user on a corporate VPN might have a different CPU profile than expected, or a privacy-focused browser might mask hardware details.
Consider a real scenario: an employee working from a virtual desktop infrastructure (VDI) accesses the same website as a home user. The VDI reports a CPU count that matches the host server, but the graphics and display might be virtualized. This creates a mismatch. A naive bot detector that only checks CPU concurrency would flag this legitimate employee as a bot. That is a false positive, and it harms the business by blocking real users and wasting ad spend on verification.
Another example: a privacy browser like Tor or Brave with fingerprinting protection may deliberately alter the reported CPU count. The user is human, but the signal looks suspicious. Similarly, a user in a hotel or airport using a VPN might have a mismatched CPU count because the VPN routes through a data center. These are not bots, yet they trigger a mismatch.
Relying on CPU concurrency alone would flag many real users as bots. That is why professional detection treats it as evidence, not a verdict. It must be cross-checked against independent browser, network, device, and behavior data.
How professional detection handles CPU concurrency
BotRefund treats CPU concurrency as one of 106 independent checks. It adds one objective fact about the visit. Then it tests whether other signals support the same story. Finally, an AI prediction model weighs the complete pattern instead of trusting a raw rule.
The key idea is corroboration. Accuracy comes from corroboration, not one browser tell. By seeing how all signals fit together, a system can identify a visit as bot or human with 99% accuracy.
Here is a step-by-step walkthrough of how a bot detection system evaluates a session:
- Collect signals. The system captures a wide range of data points: CPU concurrency, GPU details, fonts, screen resolution, timezone, language, network ports, mouse movements, scroll patterns, session timings, and more.
- Run independent checks. Each signal is compared against expected human behavior. For example, the CPU Concurrency Lie check looks for a mismatch between the reported CPU count and other hardware data. Another check might flag impossible tab speed if a session switches tabs in under 100 milliseconds.
- Assign evidence scores. Each check produces a suspicion score. A mismatch may add a few points, but it does not alone decide the verdict.
- Cross-reference signals. The system looks for corroboration. If the CPU mismatch is accompanied by a suspicious port or a non-human mouse path, that raises the overall risk. If the mismatch appears alongside normal human behavior, it is likely a false positive.
- Weigh the pattern. An AI model combines all evidence into a final probability score. The model learns from millions of known bot and human sessions.
- Decide and act. If the probability exceeds a threshold, the session is classified as a bot. The action may be blocking, challenging, or suppressing conversions for ad platforms.
This multi-step process avoids jumping to conclusions. Each independent check adds a vote, and the system requires a strong consensus before labeling a visitor a bot.
Key facts about CPU concurrency detection
| Fact | Detail |
|---|---|
| Number of independent checks | 106, including CPU concurrency lie |
| Role of the signal | Evidence, not a verdict |
| What it looks for | Mismatch between reported CPU concurrency and other hardware/browser signals |
| How it is used | Cross-checked against independent browser, network, device, and behavior data |
| Final decision | AI prediction model weighs the complete pattern |
| Claimed accuracy | 99% when combined with all signals |
The table above summarizes the core facts. Notice that CPU concurrency is just one data point. Serious detection systems use dozens or even hundreds of checks to build a reliable picture.
Common myths about CPU concurrency
Myth 1: A mismatched CPU count means a bot. False. A mismatch only raises suspicion. It needs support from other signals. For example, a user on a virtual machine for work may have a mismatched CPU count but still behave like a human. The BotRefund documentation states that a single anomaly is not a bot verdict. It must be cross-checked against independent data.
Myth 2: More CPU cores means more human. Real users can have any core count. Bots can spoof any number. A bot browser can easily report 16 cores even if the underlying server has 4. The CPU concurrency value is just a JavaScript property; it can be overridden or manipulated. Thus, the absolute value has no predictive power.
Myth 3: CPU concurrency alone can stop ad fraud. No. Ad fraud detection needs behavioral, network, and device signals to be reliable. According to BotRefund, bot clicks steal up to 20% of Google and Meta ad budgets. Recovering that waste requires a comprehensive system that can prove bot clicks with video evidence and cross-checked signals. A single hardware signal cannot provide such proof.
The overhyped idea that one signal can identify a bot is dangerous. It leads to false positives and wasted ad spend on real users. Instead, professional tools like BotRefund rely on hundreds of independent checks and an AI model that weighs the full evidence.
How to choose a bot detection tool that understands the truth
When evaluating a bot detection solution, ask these questions:
- Does it use a single signal or a wide set of independent checks?
- How does it handle false positives from privacy tools and corporate networks?
- Does it cross-check signals or act on any single anomaly?
- What is the claimed accuracy based on—corroboration or one tell?
- Can it provide proof for ad platform refunds?
Look for a tool that explains how it weighs evidence. The best tools treat each signal as one vote, not the whole jury.
Also, consider the tool's ability to integrate with your ad platforms. BotRefund, for example, provides audit trails that are accepted by Google and Meta ad reps. The FinTrust case study shows how a neobank recovered $140,000 in ad spend and increased conversion rate by 18% after using behavioral auditing. That level of detail requires more than a CPU check.
A reliable tool should also offer a free audit or trial. BotRefund provides a free bot audit in about one minute. Use that to see how the tool handles real traffic on your site.
Limitations and exceptions
The CPU concurrency signal is not useful in isolation. It fails for users on VPNs, privacy browsers, or unusual devices that legitimately produce mismatches. Even when a mismatch appears, it is only a hint.
Here are common situations that cause false positives:
- VPN users: A VPN routes traffic through a server in another location. That server might have a different CPU topology, but the browser still reports the local CPU count. This is not a mismatch by itself, but if combined with other network anomalies, it can raise suspicion.
- Privacy browsers: Browsers like Tor, Brave, or Firefox with strict fingerprinting protection may randomize or round the reported CPU count. This makes the signal unreliable for those users.
- Virtual machines: Developers, QA testers, and businesses often use VMs. A VM may report a CPU count based on the host's physical cores, but other hardware details like GPU might be virtualized. This creates a mismatch that is entirely legitimate.
Bot detection systems should always err toward evidence-based decisions. If you see a marketing claim that a single signal like CPU concurrency is enough to catch bots, be skeptical. That is not how reliable detection works.
How advertisers should interpret bot detection reports
Advertisers often receive reports from bot detection tools. These reports list flagged sessions, reasons, and sometimes video proof. Understanding these reports is critical to making informed decisions.
First, look at the confidence score. A good report will show the probability that a session is a bot. A score above 99% is strong. Anything lower should be reviewed manually.
Second, check the corroborating signals. A single mismatch should not be the sole basis for a refund claim. The report should show multiple independent checks that agree. For example, a bot session might show a CPU mismatch, impossible tab speed, and a robotic mouse path. That combination is convincing.
Third, understand the refund process. According to BotRefund, they prove bot clicks, negotiate with Google and Meta, and get your money back. Their audit trails are accepted by ad reps. This means the report must be detailed and verifiable.
Fourth, use the report to optimize your campaigns. The FinTrust case study shows that suppressing bot conversions improved their ad targeting. By filtering out invalid traffic, they trained Facebook and Google's algorithms only on verified human actions, which increased conversion rates.
Finally, integrate bot detection with your analytics. Set up alerts for suspicious spikes in traffic. A good tool will provide real-time data and historical trends.
Frequently asked questions
Is CPU concurrency a reliable bot signal?
No. It is weak on its own. It becomes useful only when cross-checked with other signals. The BotRefund documentation explicitly says that a single anomaly is not a bot verdict.
What causes a real user to show a CPU concurrency mismatch?
Corporate networks, VPNs, virtual machines used by legitimate users, and privacy extensions can alter how a browser reports hardware details. For example, a privacy browser may hide or randomize the CPU core count to protect user fingerprint.
How many signals do serious detection systems use?
BotRefund uses 106 independent checks. The exact number varies by vendor, but the principle is that more corroborating signals reduce false positives. A higher number of checks often leads to more accurate verdicts, but the quality of each check matters too.
Can CPU concurrency detection improve ad spend efficiency?
Yes, but only as part of a full system. Bot clicks can steal up to 20% of ad budget, so a tool that cross-checks many signals can help recover that waste. The FinTrust case study shows a $140,000 refund and an 18% conversion rate increase after implementing behavioral auditing.
What should I look for in a bot detection service?
Look for transparency about how signals are weighed, a low false-positive rate, and proof that the system uses corroboration rather than single-tell rules. Also, check if the tool provides evidence that ad platforms accept for refunds. The best tools offer a free audit and clear documentation.
Further reading and comparison sources
These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.
- Anti-Bot Evasion. Web scraping today is much more than… | by ...
- Bot Detection Guide 2025: How to Identify & Block Bots
- performance.now, hardwareConcurrency, and Timing Fingerprints
Further reading and comparison sources
These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.
Learn more
Visit the website for more information.