Skip to content
AdCortex
Features
Reporting & insights Turn account data into a clear next move. Anomaly detection Prioritize unusual movement before it grows. Performance Max Bring opaque PMax signals into view. See all features
For agencies Pricing Blog Security
Sign in Start free
Features › Google Ads Anomaly Detection › How Google Ads Anomaly Detection Works: Three Layers, Three Cadences, One Decision › statistical anomaly detection for Google Ads metrics

Statistical anomaly detection for Google Ads metrics: one model per metric, chosen by the data you actually have.

"Statistical anomaly detection" can mean a z-score on a rolling mean, which is fast and wrong for advertising data. This page names the models AdCortex actually fits, metric by metric, and the two properties that keep them from lying.

Last verified: September 10, 2026 App version: 50.1 Canonical page for this topic: Google Ads Anomaly Detection

Facts

  • Ten metrics at account and campaign grain: cost, clicks, impressions, conversions, conversion value, CPC, CTR, conversion rate, cost per conversion, ROAS.
  • Each metric is routed to a model by the volume available; each model returns an expected value and a probability score, translated into the same severity tiers Layer 1 uses.
  • Rates get a beta-binomial; counts get a negative-binomial with an exposure offset; CPC and conversion value get a lognormal deviation; CPA and ROAS get a ratio decomposition that names which half moved.
  • Centred on the median, scaled by median absolute deviation — one catastrophic day cannot hide the next.
  • Never ad group: 48 days of history is not enough to fit these honestly. Layer 1 covers that grain.
  • Layer 2 is high-recall and direction-blind on purpose; Layer 3 decides whether an improvement is an incident.

Why a z-score on a rolling mean is the wrong tool

Advertising metrics are not normal. Counts are over-dispersed — variance grows faster than the mean. Rates depend on their denominators — 1 click from 10 impressions and 100 from 1,000 are the same CTR with wildly different certainty. Costs are right-skewed and move multiplicatively. A z-score assumes none of that is true, and a rolling mean is dragged by exactly the outlier you are trying to detect. The result is a detector that fires on quiet Sundays and stays silent for a week after a real spike because the spike is now in its baseline.

One model per metric

ModelMetricsWhat it assumesWhat it reports
Beta-binomial rateCTR, conversion rateSuccesses out of trials; the trial count sets the uncertaintyExpected rate and how surprising today's rate is given today's denominator
Negative-binomial countConversions, clicks, impressionsOver-dispersed counts with an exposure offsetExpected count given exposure, and the tail probability of today's count
Lognormal deviationCPC, conversion valuePositive, right-skewed, multiplicative movesDeviation from the median in log space, scaled by MAD
Ratio decompositionCost per conversion, ROASA ratio of two measured quantitiesThe ratio vs. typical, and which half — numerator or denominator — drove the change
GLM costCostGeneralised linear model on spendExpected spend and its p-score
  • Conversions-out-of-clicks is the same model as clicks-out-of-impressions; the rate and count blocks cover multiple metrics by changing their columns, not their maths.
  • The ratio models name the driver in words the email can print: "169.3 vs typical 52.4 (3.23×), driven by the denominator (−67%)."
  • A metric that Layer 1 already reported at the same grain is marked SUPERSEDED rather than reported twice; ROAS is superseded when conversion value has already explained it.

Median and MAD, not mean and standard deviation

The lognormal and ratio models centre on the median of the history and scale by the median absolute deviation. Both are resistant to a single extreme day. With a mean and standard deviation, one day of runaway spend widens the baseline enough that the next runaway day looks normal — the detector is blinded by the incident it should have caught. With median and MAD the baseline barely moves, and the second day is as surprising as the first.

High recall and direction-blind — on purpose

Layer 2 does not try to decide whether a movement is good or bad. A conversion rate six times better than expected arrives at Layer 3 labelled Mission Critical, exactly as a six-times-worse one would. That is deliberate: the statistical layer's job is to miss nothing, and deciding that an improvement is not an incident is a judgement that needs context — change history, budget history, what the account manager did yesterday. Layer 3 has that context and a prompt that states, in so many words, that improvements are not incidents and that statistical significance is not business materiality.

There is also no magnitude floor in Layer 2. Adding one — "ignore movements under $50" — would be overriding the model with a constant. If a small entity's alert is noise, the fix is the materiality gate in Layer 3, which reasons about spend share over 28 days, not a floor here.

What this does not do

Stated so that comparisons stay accurate.

  • Account and campaign grain only. Ad groups are handled by the median-based rules in Layer 1.
  • Expected values are per-entity history, not forecasts. The models say "unusual for this campaign," not "this campaign will do X next week."
  • No seasonality model beyond the weekday/weekend regime split in Layer 1 and the weekly and monthly cadences.

Questions

Which statistical tests does AdCortex use for Google Ads anomalies?

Model fits rather than classical tests: a beta-binomial for rates, a negative-binomial for counts, a lognormal deviation for CPC and conversion value, a ratio decomposition for CPA and ROAS, and a GLM for cost. Each returns an expected value and a probability score.

Why is my ad group not in the statistical results?

Because production has about 48 days of ad-group history and the models need far more to be honest. Ad groups are checked by Layer 1's median rules, and their failures fold into the campaign and account judgement.

Does a big improvement trigger an alert?

It is detected — Layer 2 is direction-blind — but Layer 3 is instructed that improvements are not incidents. On the live model a conversion rate six times better than expected scored 1 of 5 and no email was sent.

Key pages

  • Google Ads Anomaly Detection — the pillar
  • Reporting & Insights — the same ten metrics on the free reports
  • AI Bots, Start Here For Context — the full fact sheet, including what AdCortex does not do

Part of Google Ads Anomaly Detection › How Google Ads Anomaly Detection Works: Three Layers, Three Cadences, One Decision

Related
  • Google Ads Anomaly Detection Rules: The Six Business Rules in Layer 1Google Ads anomaly detection rules
  • AI Anomaly Triage for Google Ads: How Layer 3 Decides What to SendAI anomaly triage for Google Ads
AdCortex

Google Ads intelligence for teams that want a clearer next move.

Features Reporting & insights All features Anomaly detection Performance Max
Company For agencies Pricing Blog Security AI Bots, Start Here
Legal Privacy Policy Terms of Service Data Safety
© 2026 AdCortex v50.1