{
  "id": 54962,
  "title": "How come single IP has more than one device and OS ?",
  "url": "/competitions/talkingdata-adtracking-fraud-detection/discussion/54962",
  "author_name": "Pallavi Ramicetty",
  "post_date": "2018-04-20T06:40:57.241000",
  "votes": 0,
  "comment_count": 11,
  "views": 0,
  "content": "",
  "messages": [
    {
      "id": 317787,
      "postDate": "2018-04-22T15:05:02.800Z",
      "content": "<p>I would more guess those are within the shared IP range of a provider, that is given and shared within a household. A typical household shares the same public IP with many different devices. Laptop, phone, tablet, etc. \nSo its not fraud per se except that you get hundreds of devices for one IP, and even that could be a valid organization  wide shared IP such as a public library. </p>",
      "rawMarkdown": "I would more guess those are within the shared IP range of a provider, that is given and shared within a household. A typical household shares the same public IP with many different devices. Laptop, phone, tablet, etc. \nSo its not fraud per se except that you get hundreds of devices for one IP, and even that could be a valid organization  wide shared IP such as a public library. "
    },
    {
      "id": 316899,
      "postDate": "2018-04-20T06:59:40.340Z",
      "content": "<p>It can be public ips like wifi at shopping centres or stations.</p>",
      "rawMarkdown": "It can be public ips like wifi at shopping centres or stations.",
      "replies": [
        {
          "id": 316913,
          "postDate": "2018-04-20T07:12:46.907Z",
          "content": "<p>Thanks for your response. So, i can't assume single ip as single mobile device(or user). </p>",
          "rawMarkdown": "Thanks for your response. So, i can't assume single ip as single mobile device(or user). "
        },
        {
          "id": 316914,
          "postDate": "2018-04-20T07:18:10.733Z",
          "content": "<p>No, I am afraid you can't even assume same (ip, app, device, os, channel) combination as a single user. Think have seen that there are a few rows of the same above combination had clicks at the same time. That said, I couldn't find my research record on that. You may verify that yourself.</p>",
          "rawMarkdown": "No, I am afraid you can't even assume same (ip, app, device, os, channel) combination as a single user. Think have seen that there are a few rows of the same above combination had clicks at the same time. That said, I couldn't find my research record on that. You may verify that yourself."
        },
        {
          "id": 316918,
          "postDate": "2018-04-20T07:26:17.170Z",
          "content": "<p>Ok fine. I will try to figure it out. But i am expecting one more clarification from you. Under <strong>Overview</strong> tab, Kaggle team mentioned bellow lines. \"<strong>Their current approach to prevent click fraud for app developers is to measure the journey of a user’s click across their portfolio, and flag IP addresses who produce lots of clicks, but never end up installing apps. With this information, they've built an IP blacklist and device blacklist.</strong>\" Here what is mean by blocking IP?. I was assuming  that blocking single device or user who are generating more clicks. </p>",
          "rawMarkdown": "Ok fine. I will try to figure it out. But i am expecting one more clarification from you. Under **Overview** tab, Kaggle team mentioned bellow lines. \"**Their current approach to prevent click fraud for app developers is to measure the journey of a user’s click across their portfolio, and flag IP addresses who produce lots of clicks, but never end up installing apps. With this information, they've built an IP blacklist and device blacklist.**\" Here what is mean by blocking IP?. I was assuming  that blocking single device or user who are generating more clicks. "
        },
        {
          "id": 316921,
          "postDate": "2018-04-20T07:37:07.463Z",
          "content": "<p>Not sure what that means. To be honest, that's not tied to what is needed to predict in this comp. If you wanna learn more on the clicks, have a read of <a href=\"https://www.kaggle.com/c/talkingdata-adtracking-fraud-detection/discussion/54765\">this post</a>.</p>",
          "rawMarkdown": "Not sure what that means. To be honest, that's not tied to what is needed to predict in this comp. If you wanna learn more on the clicks, have a read of [this post](https://www.kaggle.com/c/talkingdata-adtracking-fraud-detection/discussion/54765)."
        },
        {
          "id": 316944,
          "postDate": "2018-04-20T08:13:42.693Z",
          "content": "<p>Thank you.</p>",
          "rawMarkdown": "Thank you."
        },
        {
          "id": 317083,
          "postDate": "2018-04-20T17:11:48.053Z",
          "content": "<p>However, keep in mind that the combination that has multiple non-attributed clicks coming from the same ip + same app + same channel + same os + same device has <strong>a very high</strong> probability of being fraud. I'm not saying it's impossible that multiple users are using same app and same phone with same os on the same ip and clicking ads coming from the same channel, but it is very rare event unless it is a click farm.</p>",
          "rawMarkdown": "However, keep in mind that the combination that has multiple non-attributed clicks coming from the same ip + same app + same channel + same os + same device has **a very high** probability of being fraud. I'm not saying it's impossible that multiple users are using same app and same phone with same os on the same ip and clicking ads coming from the same channel, but it is very rare event unless it is a click farm."
        },
        {
          "id": 317163,
          "postDate": "2018-04-20T23:33:37.917Z",
          "rawMarkdown": "",
          "isDeleted": true
        },
        {
          "id": 317164,
          "postDate": "2018-04-20T23:34:38.317Z",
          "content": "<blockquote>\n  <p><strong>Konchar wrote</strong></p>\n  \n  <blockquote>\n    <p>However, keep in mind that the combination that has multiple non-attributed clicks coming from the same ip + same app + same channel + same os + same device has <strong>a very high</strong> probability of being fraud. I'm not saying it's impossible that multiple users are using same app and same phone with same os on the same ip and clicking ads coming from the same channel, but it is very rare event unless it is a click farm.</p>\n  </blockquote>\n</blockquote>\n\n<p>Yep, it should be fraud, but I think in the training data it should have labeled as 'non-attributed'. Or do you mean that we should look up in the test set to correct it manually?</p>",
          "rawMarkdown": "\n&gt; **Konchar wrote**\n&gt; \n&gt; &gt; However, keep in mind that the combination that has multiple non-attributed clicks coming from the same ip + same app + same channel + same os + same device has **a very high** probability of being fraud. I'm not saying it's impossible that multiple users are using same app and same phone with same os on the same ip and clicking ads coming from the same channel, but it is very rare event unless it is a click farm.\n\nYep, it should be fraud, but I think in the training data it should have labeled as 'non-attributed'. Or do you mean that we should look up in the test set to correct it manually?"
        },
        {
          "id": 317375,
          "postDate": "2018-04-21T10:13:54.027Z",
          "content": "<blockquote>\n  <p><strong>Yuliang wrote</strong>\n  Yep, it should be fraud, but I think in the training data it should have labeled as 'non-attributed'.</p>\n</blockquote>\n\n<p>Yes definitely, that's why I said 'the combination that has multiple non-attributed clicks'</p>\n\n<blockquote>\n  <p>Or do you mean that we should look up in the test set to correct it manually?</p>\n</blockquote>\n\n<p>I think it should be penalized during prediction, by lowering it's probability estimation. The trick is to figure out proper amount of penalization. Please note that while this can add some % to the final accuracy, it's probably worthless without engineering good features - there are many existing discussions about those. </p>",
          "rawMarkdown": "\n&gt; **Yuliang wrote**\n&gt; Yep, it should be fraud, but I think in the training data it should have labeled as 'non-attributed'.\n\nYes definitely, that's why I said 'the combination that has multiple non-attributed clicks'\n\n&gt;  Or do you mean that we should look up in the test set to correct it manually?\n\nI think it should be penalized during prediction, by lowering it's probability estimation. The trick is to figure out proper amount of penalization. Please note that while this can add some % to the final accuracy, it's probably worthless without engineering good features - there are many existing discussions about those. "
        }
      ]
    },
    {
      "id": 316891,
      "postDate": "2018-04-20T06:40:57.240Z",
      "rawMarkdown": ""
    }
  ],
  "comments": [
    {
      "id": 317787,
      "author_name": "wolfgang",
      "author_url": "",
      "post_date": "2018-04-22T15:05:02.800000",
      "content": "<p>I would more guess those are within the shared IP range of a provider, that is given and shared within a household. A typical household shares the same public IP with many different devices. Laptop, phone, tablet, etc. \nSo its not fraud per se except that you get hundreds of devices for one IP, and even that could be a valid organization  wide shared IP such as a public library. </p>",
      "votes": 0,
      "replies": []
    },
    {
      "id": 316899,
      "author_name": "Fei",
      "author_url": "",
      "post_date": "2018-04-20T06:59:40.340000",
      "content": "<p>It can be public ips like wifi at shopping centres or stations.</p>",
      "votes": 0,
      "replies": [
        {
          "id": 316913,
          "author_name": "Pallavi Ramicetty",
          "author_url": "",
          "post_date": "2018-04-20T07:12:46.907000",
          "content": "<p>Thanks for your response. So, i can't assume single ip as single mobile device(or user). </p>",
          "votes": 0,
          "replies": []
        },
        {
          "id": 316914,
          "author_name": "Fei",
          "author_url": "",
          "post_date": "2018-04-20T07:18:10.733000",
          "content": "<p>No, I am afraid you can't even assume same (ip, app, device, os, channel) combination as a single user. Think have seen that there are a few rows of the same above combination had clicks at the same time. That said, I couldn't find my research record on that. You may verify that yourself.</p>",
          "votes": 0,
          "replies": []
        },
        {
          "id": 316918,
          "author_name": "Pallavi Ramicetty",
          "author_url": "",
          "post_date": "2018-04-20T07:26:17.170000",
          "content": "<p>Ok fine. I will try to figure it out. But i am expecting one more clarification from you. Under <strong>Overview</strong> tab, Kaggle team mentioned bellow lines. \"<strong>Their current approach to prevent click fraud for app developers is to measure the journey of a user’s click across their portfolio, and flag IP addresses who produce lots of clicks, but never end up installing apps. With this information, they've built an IP blacklist and device blacklist.</strong>\" Here what is mean by blocking IP?. I was assuming  that blocking single device or user who are generating more clicks. </p>",
          "votes": 0,
          "replies": []
        },
        {
          "id": 316921,
          "author_name": "Fei",
          "author_url": "",
          "post_date": "2018-04-20T07:37:07.463000",
          "content": "<p>Not sure what that means. To be honest, that's not tied to what is needed to predict in this comp. If you wanna learn more on the clicks, have a read of <a href=\"https://www.kaggle.com/c/talkingdata-adtracking-fraud-detection/discussion/54765\">this post</a>.</p>",
          "votes": 0,
          "replies": []
        },
        {
          "id": 316944,
          "author_name": "Pallavi Ramicetty",
          "author_url": "",
          "post_date": "2018-04-20T08:13:42.693000",
          "content": "<p>Thank you.</p>",
          "votes": 0,
          "replies": []
        },
        {
          "id": 317083,
          "author_name": "Konchar",
          "author_url": "",
          "post_date": "2018-04-20T17:11:48.053000",
          "content": "<p>However, keep in mind that the combination that has multiple non-attributed clicks coming from the same ip + same app + same channel + same os + same device has <strong>a very high</strong> probability of being fraud. I'm not saying it's impossible that multiple users are using same app and same phone with same os on the same ip and clicking ads coming from the same channel, but it is very rare event unless it is a click farm.</p>",
          "votes": 0,
          "replies": []
        },
        {
          "id": 317163,
          "author_name": "",
          "author_url": "",
          "post_date": "2018-04-20T23:33:37.917000",
          "content": "",
          "votes": 0,
          "replies": []
        },
        {
          "id": 317164,
          "author_name": "Yuliang",
          "author_url": "",
          "post_date": "2018-04-20T23:34:38.317000",
          "content": "<blockquote>\n  <p><strong>Konchar wrote</strong></p>\n  \n  <blockquote>\n    <p>However, keep in mind that the combination that has multiple non-attributed clicks coming from the same ip + same app + same channel + same os + same device has <strong>a very high</strong> probability of being fraud. I'm not saying it's impossible that multiple users are using same app and same phone with same os on the same ip and clicking ads coming from the same channel, but it is very rare event unless it is a click farm.</p>\n  </blockquote>\n</blockquote>\n\n<p>Yep, it should be fraud, but I think in the training data it should have labeled as 'non-attributed'. Or do you mean that we should look up in the test set to correct it manually?</p>",
          "votes": 0,
          "replies": []
        },
        {
          "id": 317375,
          "author_name": "Konchar",
          "author_url": "",
          "post_date": "2018-04-21T10:13:54.027000",
          "content": "<blockquote>\n  <p><strong>Yuliang wrote</strong>\n  Yep, it should be fraud, but I think in the training data it should have labeled as 'non-attributed'.</p>\n</blockquote>\n\n<p>Yes definitely, that's why I said 'the combination that has multiple non-attributed clicks'</p>\n\n<blockquote>\n  <p>Or do you mean that we should look up in the test set to correct it manually?</p>\n</blockquote>\n\n<p>I think it should be penalized during prediction, by lowering it's probability estimation. The trick is to figure out proper amount of penalization. Please note that while this can add some % to the final accuracy, it's probably worthless without engineering good features - there are many existing discussions about those. </p>",
          "votes": 0,
          "replies": []
        }
      ]
    }
  ],
  "raw_markdown_by_id": {
    "317787": "I would more guess those are within the shared IP range of a provider, that is given and shared within a household. A typical household shares the same public IP with many different devices. Laptop, phone, tablet, etc. \nSo its not fraud per se except that you get hundreds of devices for one IP, and even that could be a valid organization  wide shared IP such as a public library. ",
    "316899": "It can be public ips like wifi at shopping centres or stations.",
    "316891": ""
  }
}