# TalkingData AdTracking Fraud Detection Challenge

Fraud risk is everywhere, but for companies that advertise online, click fraud can happen at an overwhelming volume, resulting in misleading click data and wasted money. Ad channels can drive up costs by simply clicking on the ad at a large scale. With over 1 billion smart mobile devices in active use every month, China is the largest mobile market in the world and therefore suffers from huge volumes of fradulent traffic.

TalkingData, China’s largest independent big data service platform, covers over 70% of active mobile devices nationwide. They handle 3 billion clicks per day, of which 90% are potentially fraudulent. Their current approach to prevent click fraud for app developers is to measure the journey of a user’s click across their portfolio, and flag IP addresses who produce lots of clicks, but never end up installing apps. With this information, they've built an IP blacklist and device blacklist.

While successful, they want to always be one step ahead of fraudsters and have turned to the Kaggle community for help in further developing their solution. In their 2nd competition with Kaggle, you’re challenged to build an algorithm that predicts whether a user will download an app after clicking a mobile app ad. To support your modeling, they have provided a generous dataset covering approximately 200 million clicks over 4 days!

# Setup

In [1]:
# To suppress some warnings below. Nothing important, just to make some outputs cleaner.
import warnings
warnings.simplefilter(action='ignore', category=FutureWarning)
warnings.simplefilter(action='ignore', category=DeprecationWarning)

In [2]:
# To automatically reload modules defined in external files.
%reload_ext autoreload
%autoreload 2

# To display plots directly in the notebook:
%matplotlib inline

In [3]:
import numpy as np
import pandas as pd
import matplotlib.pyplot as plt

In [4]:
import matplotlib
import sklearn

In [5]:
# To make the notebook reproducible
seed = 42
np.random.seed(seed)

# Get the data

In [22]:
train = pd.read_csv('datasets/train.csv', nrows=100000)

In [23]:
train.shape

(100000, 8)

In [38]:
train.head(100)

Unnamed: 0,ip,app,device,os,channel,click_time,attributed_time,is_attributed
0,83230,3,1,13,379,2017-11-06 14:32:21,NaT,0
1,17357,3,1,19,379,2017-11-06 14:33:34,NaT,0
2,35810,3,1,13,379,2017-11-06 14:34:12,NaT,0
3,45745,14,1,13,478,2017-11-06 14:34:52,NaT,0
4,161007,3,1,13,379,2017-11-06 14:35:08,NaT,0
5,18787,3,1,16,379,2017-11-06 14:36:26,NaT,0
6,103022,3,1,23,379,2017-11-06 14:37:44,NaT,0
7,114221,3,1,19,379,2017-11-06 14:37:59,NaT,0
8,165970,3,1,13,379,2017-11-06 14:38:10,NaT,0
9,74544,64,1,22,459,2017-11-06 14:38:23,NaT,0


# Data Fields

Each row of the training data contains a click record, with the following features.

- `ip`: ip address of click.
- `app`: app id for marketing.
- `device`: device type id of user mobile phone (e.g., iphone 6 plus, iphone 7, huawei mate 7, etc.)
- `os`: os version id of user mobile phone
- `channel`: channel id of mobile ad publisher
- `click_time`: timestamp of click (UTC)
- `attributed_time`: if user download the app for after clicking an ad, this is the time of the app download
- `is_attributed`: the target that is to be predicted, indicating the app was downloaded

Note that ip, app, device, os, and channel are encoded.

The test data is similar, with the following differences:

- `click_id`: reference for making predictions
- `is_attributed`: not included

In [25]:
variables = ['ip', 'app', 'device', 'os', 'channel']
for v in variables:
    train[v] = train[v].astype('category')

In [26]:
#set click_time and attributed_time as timeseries
train['click_time'] = pd.to_datetime(train['click_time'])
train['attributed_time'] = pd.to_datetime(train['attributed_time'])

#set as_attributed in train as a categorical
train['is_attributed']=train['is_attributed'].astype('category')

In [27]:
train.describe()

Unnamed: 0,ip,app,device,os,channel,click_time,attributed_time,is_attributed
count,100000.0,100000.0,100000.0,100000.0,100000.0,100000,169,100000.0
unique,15369.0,118.0,59.0,95.0,133.0,528,161,2.0
top,73487.0,9.0,1.0,19.0,145.0,2017-11-06 16:00:45,2017-11-06 16:01:13,0.0
freq,610.0,13280.0,94397.0,23957.0,10582.0,1187,3,99831.0
first,,,,,,2017-11-06 14:32:21,2017-11-06 16:00:47,
last,,,,,,2017-11-06 16:01:48,2017-11-07 15:53:02,


In [32]:
import ipaddress

In [33]:
ipaddress.ip_address(45745).__str__()

'0.0.178.177'

In [34]:
import socket, struct

In [37]:
socket.inet_ntoa(struct.pack('!L', 161007))

'0.2.116.239'