Of course, but I would think that for fraud prevention à fingerprint on a seven day retention plus local IP from WebRTC will get you a long way. You really shouldn't need the whole graph BS for that purpose.
My concern would be the possibility of cheating with purpose limitations. There might be a case to prevent fraud protection companies from being involved in targeting.