Device Attestation Comes to OM SDK: A New Fraud Signal for CTV and App Sellers
IAB Tech Lab added device attestation to the Open Measurement SDK to fight device spoofing, starting with Apple devices and Fire TV. Here is what it does and what app and CTV sellers should do.
What was announced
On October 23, IAB Tech Lab announced device attestation support in the Open Measurement SDK (OM SDK), the industry-standard library that apps and CTV applications use to let third-party verification vendors measure ads. The new capability lets buyers independently verify that an impression comes from a genuine device, using privacy-preserving attestations from device manufacturers. At launch it is supported on Apple devices and Fire TV.
The work came out of the Open Measurement Commit Group, with participants including AdsWizz, Amazon Ads, DoubleVerify, Google, HUMAN and Integral Ad Science. In the announcement, Amazon DSP's Neal Richter described device spoofing as a significant threat and said that receiving secure signals of authenticity directly from devices such as Fire TV lets buyers be confident they are getting inventory from real devices.
The problem it addresses
Device spoofing is exactly what it sounds like: fraudulent traffic that claims to come from a premium device or app it does not come from. It has been especially damaging in CTV, where CPMs are high and many ads are stitched into streams on the server side. In server-side ad insertion, the ad request often comes from a server rather than the device itself, so the device details in the request are passed along rather than observed directly. That creates room for bad actors to fabricate requests that look like they come from popular streaming devices and apps.
Existing defenses, such as app-ads.txt, sellers.json and supply chain objects, tell buyers who is authorized to sell an app's inventory and through which path. They do not prove that a given request came from a real device running that app. Attestation adds that missing piece: a signal rooted in the device platform itself.
Why it matters to sellers, not just buyers
It is easy to read fraud tools as something buyers use against sellers. In practice, honest sellers are the biggest beneficiaries. Every dollar spent on spoofed CTV or app inventory is a dollar that did not go to a real publisher, and every fraud scheme that comes to light pushes buyers to discount entire categories of supply. The IAB Tech Lab announcement makes this point directly: for sellers and app developers, attestation protects monetization by signaling authentic supply paths.
Over time, it is reasonable to expect buyers to prefer, and eventually pay more for, impressions that carry verified signals of authenticity. Sellers who can supply them early will be in a better position when that preference hardens into buying requirements.
Where gaming and app publishers fit
Mobile gaming apps and other in-app publishers face their own version of the problem. App inventory has long been targeted by spoofing that impersonates popular titles, and buyers have responded with tighter allow lists and verification requirements. For game developers monetizing through in-app bidding and mediation, attestation on supported platforms is another way to separate legitimate inventory from impersonators, particularly on iOS, where support is available from the start.
What app and CTV sellers should do
- Check your OM SDK version. Device attestation requires an OM SDK integration that supports it. If your app or your ad SDK partners bundle an older version, plan an update and confirm with them when support will ship.
- Ask your partners how the signal flows. Attestation is only useful if it reaches buyers and their verification vendors. Ask your SSPs, mediation partners and verification vendors how they surface and use the signal, and whether it shows up in their reporting.
- Tighten the basics. Attestation complements, rather than replaces, the supply chain standards. Keep app-ads.txt accurate on the developer domain listed in each app store, confirm your sellers.json entries with each SSP, and make sure supply chain objects are complete.
- For CTV and FAST, review SSAI partners. If a server-side ad insertion vendor makes ad requests on your behalf, confirm they pass device and app information accurately and support the relevant verification signals. Your inventory's reputation depends on their implementation.
- Watch coverage expand. Launch support covers Apple devices and Fire TV. Track which other platforms add support, and prioritize integration on the devices that make up most of your audience.
A note on timing
Standards take time to reach production. SDK updates need to be built, tested and released in apps, then adopted by users who update those apps. CTV applications on some platforms update on slower cycles. Plan attestation work into your normal release schedule rather than treating it as an emergency, but do put it on the roadmap now so it is not the last item added when buyers start asking for it.
What it does not do
Attestation confirms that a real, supported device is involved. It does not by itself prove that a person watched the ad, that the ad was viewable, or that the content was appropriate for the brand. It also does not cover devices that have not implemented support. Buyers will still rely on the full set of verification tools, and sellers should not present attestation as a guarantee of quality. Treat it as one strong signal among several.
The takeaway
Device attestation in OM SDK is a practical step against one of the most costly forms of fraud in CTV and app advertising, and it gives honest sellers a way to prove their inventory is real. The work for publishers is mostly integration and coordination: current SDKs, partners that pass the signal through, and clean supply chain files. HBDR helps app and CTV publishers review their supply paths and partner integrations so that signals like this reach the buyers who value them.
Related Articles
July's Privacy Law Changes: A Checklist for Health and Finance Publishers
Connecticut, Arkansas and Virginia changes took effect July 1, and IAB Tech Lab just proposed GPP updates. What health, finance and other sensitive-content publishers should check.
Privacy Sandbox Is Winding Down in Chrome. Time to Clean Up Your Wrapper
Chrome 150 is now rejecting Protected Audience calls as Google retires most Privacy Sandbox APIs. Here is what to remove from your ad stack and what stays the same.
July 1 Privacy Deadlines: Connecticut and Arkansas Tighten Teen Ad Rules
On July 1, Connecticut's amended privacy law and Arkansas's children's and teens' privacy law take effect, both restricting targeted ads to minors. What publishers should change first.