GIVT vs SIVT is the comparison inside the word invalid. Buyers say a campaign was filtered for IVT and mean one bucket. The Media Rating Council's Invalid Traffic Detection and Filtration Standards Addendum, in the June 2020 update, defines two. General invalid traffic is caught by routine means: lists and standardized parameter checks. Sophisticated invalid traffic is the remainder that takes advanced analytics, multi-point corroboration, or significant human intervention to identify. The addendum says accredited measurers must apply GIVT processes. It says SIVT processes are strongly encouraged, and it says they are not required.
That requirement gap is the whole comparison. Two accredited vendors can both remove known data-center traffic and declared crawlers, and only one of them may be looking for hijacked devices, hidden ads, or app spoofing. A report that says "IVT filtered" without saying which category was in scope has collapsed a mandatory list check and an optional investigation into one badge.
The addendum also says the line moves. What is SIVT today can be reclassified as GIVT later, once the industry can put it on a shared list. The categories are a method split, not a permanent taxonomy of evil. Remove the acronyms and routine list filtration still does not equal an investigation of traffic that looks legitimate.

What GIVT covers
The June 2020 addendum's examples of general invalid traffic are the checks a measurer can run from lists and parameters. Known invalid data-center traffic, with an explicit carve-out for routing artifacts of legitimate users. Bots, spiders, and crawlers, except the ones the addendum places in the sophisticated category because they masquerade as people. Non-browser user-agent headers and other unknown browsers. Pre-fetch and pre-rendered traffic where the ad was not then accessed by a valid user. Invalid placements such as 0x0 and 1x1 delivery on the client. Sessions whose device information says they cannot render an image, such as a headless browser, when the activity being counted is a rendered impression.
The addendum is careful about what this is not. Non-rendering GIVT is not a viewability test. The text says the category is agnostic of whether an ad was viewable. It also says non-rendered impressions should stay out of gross impression counts rather than being reclassified as IVT. Pre-fetch that never becomes a real render is excluded from the count. The spirit of the list is: if a standardized check can see that this was never a legitimate opportunity, drop it the same way everyone else drops it.
That sameness is why GIVT is mandatory for accredited measurement. The addendum says the point of a shared general category is to keep discrepancies between measurers small. If every audited firm strips the same data-center ranges and the same declared crawlers, the residual logs are comparable. If each firm invents its own general list, "IVT-free" means a different subtraction in every report.
What SIVT covers
Sophisticated invalid traffic, in the same section, is the traffic that survives those lists. The examples include automated browsing from a dedicated device, such as emulators and custom automation, and automated browsing from a non-dedicated device, including infected and hijacked sessions. Manipulated activity: forced windows, forced clicks, clickjacking, hijacked measurement events. Falsified events, and the addendum names viewability, clicks, location, and server-side ad insertion spoofing among them. Domain and app misrepresentation. Bots that masquerade as legitimate users and are only caught by sophisticated means. Hidden, stacked, transparent, or otherwise obfuscated ad serving. Invalid proxy traffic. Adware and malware that inject ads. Cookie stuffing.
Papyrus, the mobile scheme IAS described in August 2026, sits on this side of the line in spirit even though the MRC text does not name it. Hidden webviews, clicks passed through from a different surface, scrolls on remote instruction: that is manipulated activity and obfuscated serving, not a data-center range on a list. A GIVT filter that removes known crawlers would leave Papyrus in the log, because the devices are real phones and the user-agent can look ordinary. The damage showed up as engagement that beat the residual: nearly 25 times the click success rate, roughly 4 times the eCPM, about 13 percent higher attention.
The addendum's reporting point follows. Because SIVT methods differ by vendor, two firms can disagree on the sophisticated slice and still agree on the general slice. A buyer who switches vendors and sees the IVT rate jump may be looking at a change in SIVT coverage, not a change in the traffic. The addendum says SIVT detection can be audited, and it encourages firms that do the work to seek that accreditation. It does not pretend the sophisticated number is interchangeable the way the general lists are meant to be.
Why a clean GIVT rate can hide the problem you meant
A campaign report that says general invalid traffic was removed has done the mandatory half. Data centers, declared bots, prefetch, tiny placements. What remains can include everything the sophisticated examples name. Hijacked measurement, spoofed apps, SSAI spoofing, hidden ads. Those are the cases that still look like people in a simple filter. They are also the cases that move click rate and attention, which is what an optimizer will bid toward.
DoubleVerify's May 2026 CTV release is a reminder that the mix itself varies. In North America, bot fraud was 82 percent of the violations DV described. In APAC, data-center traffic was 98 percent. Data-center traffic is the GIVT example the MRC lists first. Bot schemes that imitate users are the sophisticated problem. A global "IVT rate" that blends those regions blends a list problem and an imitation problem. The fix for one is a range. The fix for the other is an investigation.
Pre-bid and post-bid do not line up neatly on the same split. A list of data-center IPs can run before the bid. A judgment that a real device has been hijacked, or that a webview is hidden, often needs the impression. HUMAN's own taxonomy uses the MRC split and says sophisticated traffic resembles authentic behavior, so it is not caught by the routine methods used for general traffic. That is the addendum's distinction, restated as a product. Filtering GIVT pre-bid and calling the campaign SIVT-free is how the words get swapped.
Get VAST spec updates, platform guides, and release notes in your inbox.
What to do with the two categories
Require the label. Every IVT rate in a report should say GIVT, SIVT, or both, and should say whether SIVT filtration was in scope. A vendor accredited for general filtration has done what the addendum requires. A vendor that also discloses sophisticated filtration has done the further thing. Comparing their headline rates without that sentence compares a list to an investigation.
Watch the metrics SIVT is built to fake. Clicks, viewability decisions, and attention scores can move while a GIVT report stays quiet. IAS's Papyrus figures are the pattern: interaction up, on supply that was not a declared crawler. Split those metrics from the GIVT line so a clean general rate cannot hide them.
On the tag, falsified measurement includes a verification node that never arrives. vastlint does not classify GIVT or SIVT. It checks whether impression events and AdVerifications are structurally present in VAST 2.0–4.4. A missing verification node is not sophisticated invalid traffic by itself. It is a document that cannot carry the post-bid check the sophisticated category depends on.
Examples the MRC addendum actually separates
- GIVT: known invalid data-center traffic, declared crawlers, non-browser user agents, prefetch that never renders, 0x0 and 1x1 placements.
- SIVT: hijacked devices, masquerading bots, hidden or stacked ads, app and domain spoofing, falsified viewability and clicks, SSAI spoofing.
- Required for accredited measurers: GIVT filtration.
- Encouraged, not required: SIVT filtration, which can be audited when a firm applies it.
- A category can move from sophisticated to general once it can be reduced to a shared list.
A list can make two measurers agree, and the traffic that imitates a person is exactly what the list was not built to catch.
Check the tag that a post-bid filter would have to read
Run VAST 2.0–4.4 tags against specification-derived rules so impression events and verification nodes are present. Nothing is stored.
Open the VAST validatorSources
MRC definitions, GIVT and SIVT examples, and the requirement that accredited measurers apply GIVT while SIVT is encouraged.
A hidden-webview scheme whose damage shows up in clicks and attention rather than in a data-center list.
Regional mix of bot fraud and data-center traffic in CTV violations.
Why interaction metrics are the ones sophisticated schemes are built to move.