For one, how carefully did the user input information into fields. If you're making it up, it will be much faster and less hesitant than a legitimate entry.
That and a hundred other data points help create a ML model that reliability identifies illegitimate activity.
Even when you know the true distribution (in which case why ask for more data) you can only remove outliers. But outliers exist.
There are techniques for when someone enters many numbers but I don't know any for 1 number.