Android and iOS

Calculating false-positive rates correctly

Protection investments, verification plans and supplier evaluation.

Comparison and selection1 min readEditorial methods

Not every blocked event is a false positive. Define verified legitimate use and make numerator and denominator explicit.

Evaluation approach

Do not mix user, device, session and transaction rates. State sampling and support-verification limits.

Application example

Repeated attempts from one device can raise event counts without increasing the number of affected users.

Limits and considerations

A low false-positive rate does not independently show good attack detection.

Events are not users

Use matching units in numerator and denominator. Do not automatically classify unreviewed records as confirmed false positives.

Checks and decisions

  • Choose a unit
  • Verify legitimacy
  • Measure detection separately

Sources

The primary references above provide the technical basis. Example workflows and evaluation suggestions are this publication’s explanations, not independent test results for a particular product.