DHS Launched RIVR-2 to Tackle AI-Generated Identity Fraud

The program adds deepfake detection to federal identity verification testing through 2027.

Updated on Oct. 5, 2026 in Cybersecurity

Bold flat-color editorial illustration showing a stylized geometric optical lens, representing institutional biometric security testing.
The Department of Homeland Security launched the RIVR-2 program to standardize federal testing of biometric systems against AI-generated identity fraud. AI Illustration. Upload story photo >

Live Poll

Should the federal government require independent performance testing for all digital identity verification technologies?

The Department of Homeland Security Science and Technology Directorate has launched the RIVR-2 program to improve remote identity verification. This initiative builds on findings from the previous RIVR-1 cycle, which exposed significant vulnerabilities in detecting sophisticated presentation attacks.

Why it matters

The program seeks to close security gaps where automated systems struggle to distinguish between legitimate users and AI-generated impersonations. By standardizing testing, the DHS aims to force defensive technologies to evolve faster than the threats they face.

RIVR-1 testing showed that while selfie-to-document matching reached a 99 percent median success rate, presentation attack detection systems successfully blocked only 53 percent of top-tier attacks. Nearly 25 percent of legitimate users failed to complete the full remote identity workflow.

The players

Department of Homeland Security

The federal agency tasked with securing U.S. borders and infrastructure through technology procurement and operational standards.

The details

The testing methodology utilizes sequestered datasets composed of genuine and fraudulent identity documents to evaluate vendor performance. For the new RIVR-2 biometric deepfake detection track, participants must contribute 1,000 synthetic images to the evaluation library. The process focuses on verifying whether systems can reliably authenticate identities despite the proliferation of AI-generated documents and real-time impersonation attempts.

Timeline

  1. September 21, 2026: The DHS announced the RIVR-2 program.

  2. September 30, 2026: DHS held a technical webinar detailing RIVR-1 performance results.

  3. October 16, 2026: Application deadline for IDV and SMTD tracks.

  4. November 20, 2026: Systems due for testing.

  5. 2027: Testing for PAD and BDD tracks scheduled to conclude.

The Tech Race

The RIVR-2 program marks a transition from baseline document validation toward defending against generative AI threats. It follows the RIVR-1 testing cycle, which identified critical performance disparities between document matching and attack detection.

The transition toward more rigorous identity verification will likely standardize the security requirements for remote government and commercial services. Users should expect fewer authentication failures as vendors incorporate these benchmarks into their production identity workflows.

The takeaway

The federal government is shifting its focus to combat deepfakes in identity verification as AI tools become more accessible. Watch for future RIVR-3 results, where the DHS plans to release vendor-specific performance data for the first time.

What happens next

Testing for the presentation attack detection and biometric deepfake detection tracks is scheduled to continue through 2027.

Further reading

Explore deeper into federal security standards at United States Cybersecurity.

Source note: This article includes information reported by Biometric Update.

Live Poll

Should the federal government require independent performance testing for all digital identity verification technologies?