First, is that we hand-approve publishers, so that we are able to tell if they are a legit project or application. We look at some social signals when they sign up to see if their traffic numbers seem realistic, and do some sanity checking.
Secondly, we do capture anonymized IP's & user agents, and create a hash of the original values. This allows us to see trends across browser types and high-level locations, which helps with fraud detection.
The other big thing is that we have feedback from our advertisers. We do pass a UTM code about what publisher traffic comes from when an ad is clicked. This allows us to figure out who is sending junk traffic to our advertisers.
We also have a few other specific technical methods that we generally don't talk about, because we don't want to give folks guidelines. But those are mostly just to stop obvious bad actors which aren't trying very hard :)
Some of these approaches work because we're still relatively small, but I think they will scale to 10-100x our size, maybe just not to Google's size. But overall, our approach to fraud is currently working based on the number of repeat advertisers we have, and the success they are seeing with our network.