Highlights
3 years in a row named a Leader First to achieve iBeta Level 3 on iOS and Android Introducing GovFaceMatch Privacy is the architecture
01/04
01/04
Back to blog
Incode Among Top Performers in DHS S&T RIVR Track 3 Presentation Attack Detection

Incode Among Top Performers in DHS S&T RIVR Track 3 Presentation Attack Detection

As deepfakes and biometric spoofing attacks become more advanced, organizations need to know whether their identity verification systems can reliably distinguish between real users and fraudulent attempts.

In the latest U.S. Department of Homeland Security (DHS) Science and Technology Directorate (S&T) Remote Identity Validation Rally (RIVR), Incode ranked among the top performers in Track 3, which evaluates presentation attack detection and liveness.

In the passive liveness track, Incode achieved the second-lowest attack presentation classification error rate (APCER) among evaluated systems, while meeting DHS thresholds for bona fide user accuracy (BPCER) and average run time. In the active liveness track, Incode met 3 out of 4 DHS performance thresholds.

These results demonstrate Incode’s ability to detect spoofing attacks while maintaining a seamless user experience across both passive and active liveness flows. Full results are available through the Maryland Test Facility at mdtf.org/rivr/Results.

Incode across all RIVR tracks

Track 3 completes Incode’s participation across the full DHS RIVR program:

  • Track 1 (Selfie Match to Document): Met all DHS S&T goals
  • Track 2 (Document Validation): Lowest document fraud rate (DFRR) among evaluated systems
  • Track 3 (Presentation Attack Detection): Strong performance across passive and active liveness

Read more about Track 1 and Track 2.

About the DHS RIVR

The Remote Identity Validation Rally is a rigorous, independent, multi-stage evaluation led by DHS S&T to assess the accuracy, security, and robustness of remote identity verification technologies.

The program includes three tracks:

  • Track 1: Selfie Match to Document
  • Track 2: Document Validation
  • Track 3: Biometric spoof and presentation attack detection

This article focuses on Track 3 and what the results mean for organizations evaluating identity verification solutions.

To understand how these results are measured, it is helpful to look at how Track 3 evaluates spoofing attacks and liveness detection.

What Track 3 evaluates

Track 3 measures how effectively identity verification systems can detect spoofing attempts designed to impersonate a real user. These attacks include printed photos, video replays, 3D masks, and other techniques used to impersonate a real user.

Systems are evaluated using two core metrics:

  • APCER (Attack Presentation Classification Error Rate): How often a spoofing attempt is incorrectly accepted
  • BPCER (Bona Fide Presentation Classification Error Rate): How often a real user is incorrectly rejected

Together, these metrics reflect how well a system stops fraud while maintaining a smooth experience for legitimate users. Lower is better for both.

Vendors are evaluated across two formats:

  • Passive liveness (PAD-P): The system evaluates a selfie without requiring any user action
  • Active liveness (PAD-A): The user completes a guided interaction, such as head movement or on-screen prompts

Incode’s passive liveness results (PAD-P1)

In the passive liveness track, Incode is identified as PAD-P1 in the published DHS results.

Passive liveness detection is widely used in modern identity verification because it delivers strong fraud resistance with a low-friction user experience. Verification can be completed from a single selfie without requiring user prompts or challenge-based interactions.

Incode met the DHS threshold for BPCER in the passive track, and its average run time met the DHS goal for Average Run Time. Incode also achieved the second-lowest APCER among evaluated systems.

MdTF Passive PAD Results. 12 systems were evaluated across BPCER, APCER, and Average Run Time. Incode is identified as PAD-P1.

Caption: MdTF Passive PAD Results. 12 systems were evaluated across BPCER, APCER, and Average Run Time. Incode is identified as PAD-P1.

RIVR Track 3 Passive Liveness (PAD-P1) at a glance:

  • Incode is identified as PAD-P1 in the published DHS/MdTF results
  • Met the DHS threshold for BPCER and the DHS goal for Average Run Time
  • Delivered through a fully passive, single-selfie experience with no user prompts
  • Achieved the second-lowest APCER among all evaluated systems in the passive liveness track.

While passive liveness is the preferred approach for most modern identity verification experiences because it minimizes user friction, RIVR also evaluates active liveness systems that require user interaction during verification.

Incode’s active liveness results (PAD-A4)

In the active liveness track, Incode is identified as PAD-A4 in the published DHS results. While Incode’s commercial identity verification experience is built around passive liveness, the company participated in the active liveness evaluation to demonstrate support across both liveness modalities.

MdTF Active PAD Results. 6 systems were evaluated across BPCER, APCER, Satisfaction, and Average Transaction Time. Incode is identified as PAD-A4.

Caption: MdTF Active PAD Results. 6 systems were evaluated across BPCER, APCER, Satisfaction, and Average Transaction Time. Incode is identified as PAD-A4.

The RIVR evaluation reflects system performance at a specific point in time using a fixed software configuration submitted for testing. Unlike production deployments, where settings can be continuously optimized based on real-world conditions and customer requirements, the evaluation configuration remained unchanged throughout the testing period. Since the evaluation, Incode has continued to refine and optimize its liveness configuration as part of its normal product development process.

RIVR Track 3 Active Liveness (PAD-A4) at a glance:

  • Incode is identified as PAD-A4 in the published DHS/MdTF results
  • Met 3 out of 4 DHS performance thresholds
  • Demonstrates full liveness coverage across both passive and active modalities
  • Evaluation results reflect a fixed testing configuration; production deployments continue to benefit from ongoing tuning and optimization

Understanding how APCER is reported

When reviewing Track 3 results, it is important to understand how APCER is calculated and reported within the RIVR framework.

The published APCER for a given system reflects the single worst-performing attack subtype within the worst-performing attack class. It is not an average across all evaluated attacks. For example, if a system achieved 0% error on three attack subtypes but 13% on one, only the 13% figure is reflected in the published results.

This reflects a conservative, worst-case reporting methodology. For buyers evaluating vendors, it is important to look beyond the headline number and understand performance across all attack subtypes.

Incode is committed to that level of transparency. This is one of the reasons it participates in independent evaluations like RIVR across all three tracks.

Validated further: iBeta Level 3 at 0% error rate

A key differentiator of Incode is that it trains and manages its own models. This gives Incode a clear advantage by enabling faster iteration and improvement without relying on third-party model providers.

In early 2026, Incode became the first company to achieve iBeta PAD Level 3 conformance on both iOS and Android, with 0% APCER and 0% BPCER. This represents the highest level of liveness assurance testing under ISO/IEC 30107-3, simulating well-resourced attackers using hyper-realistic masks and advanced spoofing techniques.

The RIVR Track 3 evaluation reflects a point in time, based on models finalized prior to testing. Since then, Incode has continued to iterate, achieving independent validation at the highest available PAD level within approximately two to three months.

When gaps are identified, whether through independent evaluation, internal testing, or emerging threat vectors, Incode can respond, retrain, and validate quickly. That level of agility is critical in a threat landscape that evolves continuously.

Read more about our iBeta Level 3 announcement.

Why these results matter

Track 3 marks the completion of Incode’s participation in the full RIVR program. Across all three tracks, Incode has demonstrated consistent performance in independent, government-led testing. This includes meeting DHS goals in selfie matching, achieving the lowest document fraud rate among evaluated systems in document validation, and delivering one of the strongest passive liveness performances in presentation attack detection.

Equally important is what happens between evaluations. Independent testing captures a point in time. What differentiates vendors is how quickly they act on results, close gaps, and improve.

The progression from RIVR Track 3 to iBeta Level 3 certification in a matter of months reflects that commitment in practice.

Incode is designed for organizations that need:

  • Strong anti-spoofing performance validated in independent testing
  • Rapid iteration and improvement between evaluation cycles
  • End-to-end identity verification across selfie match, document validation, and liveness detection

If you would like to learn more about how Incode applies these capabilities across workforce identity, digital onboarding, and high-risk authentication flows, contact the Incode team.

Incode was named a Leader in the 2026 Gartner® Magic Quadrant™ for Identity Verification for the third consecutive year. Download the report.

Ready to see it in action?

Request a demo