Security1 distinct publisher2 min readPublished
NYU and Radboud researchers spent a year turning Google's Ads Transparency Center into a detector for deceptive software ads, and found that the report button removes a creative while leaving the domain behind it serving.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Reporting works at the creative, and the operators work at the domain. The paper traced ad landing pages to domains that several protective DNS services had already flagged, one of them tied to the TamperedChef malware campaign [10]. The team reported a single ad pointing at that domain and it came down; 41 more ads pointing at the same domain kept running [11]. That is 42 creatives aimed at one known-bad destination, and the abuse channel reached one of them [1].
The bill is the part defenders can act on. Roongta itemised it: $96 for a 4-core DigitalOcean VM, plus GPU time on an L40S at $1.57 an hour [14], with the LLM annotation finishing in under 12 hours [15]. Twelve hours of L40S is $18.84, so the full run lands under roughly $115 [2]. Across 188,000 creatives that is about six hundredths of a cent per ad [3].
The flag rate itself is low. 238 plus 3,346 plus 258 is 3,842 ads, near 2 percent of the corpus [4]. Duration carries more weight than the count. The most-viewed false-claims ad had been live more than two years and collected 14.5 million impressions on its own [6], and one French creative carrying no advertiser information beyond a Continue button and a QR code took 1.6 million impressions [7]. The scareware copy is templated and easy to fingerprint, down to lines like "Your phone has been severely damaged by 33 types of viruses" [17], which is why a similarity search plus an open-weight model panel was enough to find them [3].
For a defender the usable output is the landing-domain list, not the report queue. The archive is public, extraction costs a day of GPU rental, and the domains can go into a resolver blocklist without Google's participation. The researchers say the pipeline is not tied to Google's archive [16], so the same method applies to any platform publishing one under the transparency rules Google built the Ads Transparency Center to satisfy [2].
Ranked by verification strength, evidence, and original report placement.
Ritik Roongta of NYU said the team has been extensively trying to reach Google's trust and safety team to find a better way to report these ads and malicious URLs to help with blanket blocking, and has received no response so far.
Roongta broke down the cost of running AdLens as a 4-core DigitalOcean VM at $96, plus GPU inference charged hourly, with the L40S GPU used for the study costing $1.57 per hour.
The team could complete the LLM annotation in less than 12 hours.
Researchers from NYU and Radboud University spent a year building AdLens, a tool to find deceptive software ads inside Google's public ad archive.
Google's Ads Transparency Center is a public database Google built to satisfy transparency rules such as the EU's Digital Services Act.
The researchers pulled 188,000 software-related ad creatives from the Ads Transparency Center and ran them through a two-stage system: a cheap similarity search to flag likely offenders, then a panel of open-source language models to confirm.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 1, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
product
Poland asks Brussels for a €250M Meta fine it has no power to levy1 distinct publisher
product
France's under-15 ban failed on the age check, not the age limit1 distinct publisher
science
3.2 million replies, 88 candidates, and the gender gap that prevalence metrics erase1 distinct publisher
security
Washington names industrial-scale distillation, then hands the detection bill to abuse teams1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Specific counts, one voice behind them
The numbers are precise and mutually consistent — 188,000 creatives in, 3,842 flagged, 14.5 million impressions on the single worst offender — and the impression figures ultimately come from Google's own public archive, which is what keeps this credible. But the study behind them is never named or linked in our coverage, nobody has audited the language-model panel that produced the verdicts, and the enforcement failures are documented entirely from the reporting party's side.
The ads are deployed; the tool is not
Two things are in use here and they point opposite ways. The deceptive advertising is thoroughly operational — a billion impressions across one advertiser's catalogue, a false-claims ad running for over two years, forty-one creatives still serving a known-bad domain. AdLens has exactly one operator, the lab that built it. The $115 bill and the modular design make the newsroom-or-regulator scenario plausible, but nothing in this reporting says the code is available or that anyone outside the team has run it.
Restrained reporting, forward-leaning arithmetic
Help Net Security declines the easy accusation — Google is described as unresponsive, not complicit — and it gives equal billing to the inconvenient fact that domain blocking is hard because the URLs rotate registrars. The lean comes from the money and the verdict: a '$115 pipeline' assumes a best-case sub-twelve-hour GPU run and a VM price whose billing period is never stated, and 'it works' is asserted for a detector nobody outside the lab has checked.
One interested party present, one absent
The researchers benefit from a tool that sounds cheap and a platform that sounds deaf, and both of those characterisations come from them. Google, whose enforcement is the actual subject, appears only as the sender of report-status messages; there is no sign it was asked to explain why an acknowledged violation stays live. The credential-risk report download closing the piece is trade-publishing economics rather than a thumb on this particular story.
Core finding hard to fake, figures still one-sided
Because the flagged ads sat in a public archive with public impression ranges, the central claim — remove the creative and the domain keeps serving — is checkable by anyone who wants to and awkward to fabricate. What we cannot yet stand behind are the exact counts and the cost line, which come from one unlinked paper via one interview, with the platform silent throughout. Read the numbers as the researchers' figures, not settled ones.