How is that not fraud?
We could piece together what happened sometimes after the fact, but not reliably.
And that's just diagnosing a bug, now imagine if you were trying to find some malicious JS.
VPAID 3.0 (or is it 4.0?) has some proposals to fix this. It makes fraud analysis a first class citizen of the spec, sort of like companion ads. This allows them to be downloaded separately, as well as cached.