Cloaking is a hard problem. People have a massive monetary incentive to improve cloaking tools, meaning that basically every technique you can think of to detect malicious behavior dynamically has a finite timeframe to where it is no longer useful.
Ad networks almost certainly have a system to detect cloaking. It is almost certainly not detecting all malicious scripts.
Ad networks almost certainly have a system to detect cloaking. It is almost certainly not detecting all malicious scripts.