ShieldLabs
Anonymous Signals

Detect anti-detect browser usage on every visit

ShieldLabs' anti-detect browser detection signal identifies browser profile spoofing used for multi-accounting and abuse, on every visit, in real time

Anti-detect browser detection illustration

How ShieldLabs helps

Visitor identification

Identification of visitors using anti-detect browsers

Anonymization detection

Detect VPN and proxy alongside anti-detect browser signals

Pattern detection

Identify multi-accounting and fraud networks using anti-detect browsers

Protect your product from the real cost

Anti-detect browsers let a single user run dozens of isolated browser profiles simultaneously, each appearing as a different, legitimate user to standard detection. They replace every signal websites rely on: browser version, device type, location, and connection. The result is fraud that looks exactly like organic traffic

api.shieldlabs.ai/v1/visits/latest
{
  "request_id": "0c284695-cf0b-4755-8beb-0a2e9536595e",
  "device_id": "6a45967d-1371-9652-ba99-b01ea3992208",
  "visitor_id": "aa8c616a-8a25-4a5e-bee2-a9a08e5128a4",
  "session_id": "aa8c616a-8a25-4a5e-b4e2-a9a08e5128a4",
  "cookie_id": "aa8c616a-8a25-4a5e-j4e2-a9a08e5128a4",
  "traffic_source": {
    "channel": "Google Ads",
    "reason": "gclid_present",
    "referrer_domain": "google.com",
    "landing_url": "https://site.com/pricing?utm_source=google&utm_medium=cpc&utm_campaign=brand_ru&utm_content=banner_1&utm_term=shieldlabs"
  },
  "ip": "62.197.149.124",
  "country": "Lithuania",
  "connection_type": "vpn",
  "antidetect_browser": true,
  "os": "Windows",
  "browser": "Chrome",
  "device_type": "desktop",
  "user_hid": "guest",
  "score": 90,
  "signals": [
    { "name": "antidetect", "risk": 60 },
    { "name": "os_mismatch", "risk": 60 },
    { "name": "proxy", "risk": 10 },
    { "name": "timezone_mismatch", "risk": 10 }
  ],
  "webrtc_ip": "62.197.149.124",
  "webrtc_country": "Lithuania",
  "javascript_enabled": true,
  "timestamp": "2026-04-23T12:37:04Z"
}

Get started with anti-detect browser detection

Anti-detect browser detection provides a single response with:

  1. 1

    Identification

    Every visitor gets a stable identity that persists across session resets, IP rotation, and cookie clears

  2. 2

    Anonymization signals

    VPN and proxy detected alongside anti-detect browser usage

  3. 3

    Risk Score

    All active signals combined into a single 0–100 score for the visitor profile

  4. 4

    Traffic source

    Acquisition channel, referrer domain, landing URL, and full UTM parameters attributed to every visit

Analyze abuse in your traffic

Analyze visits by traffic source and UTM parameters to see where anti-detect browser usage concentrates across your acquisition channels

Traffic Sources

Channel breakdown by request volume, traffic share, and traffic risk.

ChannelRequests / ShareTraffic Risk
Google Ads
12,480
32.4%
18Low
Meta
8,210
21.3%
42Medium
TikTok
4,520
11.7%
71High
Organic Search
5,670
14.7%
8Clean

Request Signals

Anti-detect Browser
1 350 visits · 5.4%
High risk

Patterns Summary

Suspicious
3 250
Dangerous
1 170

Patterns

See which visitors are using anti-detect browsers in fraudulent activity across your product, with risk level and scale for each pattern from individual suspicious accounts to coordinated networks

Many Accounts on One Device

Multi-accountingAccount farmsAnti-fraud bypass
UserHID
1,243
Suspicious870
Dangerous373
DeviceID
2,105
Suspicious1,490
Dangerous615

Changing IDs on One Account

Anti-detect browser usageScripted activityAnti-fraud bypass
UserHID
678
Suspicious430
Dangerous248
DeviceID
910
Suspicious610
Dangerous300

Many Devices on One Account

Account sharingAccount resaleAccount takeover
UserHID
530
Suspicious380
Dangerous150
DeviceID
870
Suspicious590
Dangerous280

See anti-detect browser activity on your traffic

Analyze traffic and stop abuse

Frequently asked questions