IANAL. This is my understanding.
For US citizens entering the US: If you're concerned about protecting your data from this threat, you should use GrapheneOS (or less good would be a latest iPhone in lockdown mode and BFU) and not talk to the police. The 5th amendment does not seem to have an exception at the border, so you can't legally be compelled to hand over your password by border agents (there's not strong case law here). They can lie, they can detain you, search you, they can seize your stuff. You shouldn't be the one arguing with them, you should be silent (besides identification) and ask for an attorney (you don't have a right to an attorney at a routine search). As a US citizen, you can refuse and still enter.
GrapheneOS has demonstrated to be robust against physical access even in AFU [1]. It's still a good idea to shut down / restart because BFU is much more secure. To maintain convenience while avoiding reliance on the rate limiting of the secure element, you can use a long random passphrase as your primary unlock (you enter it every time the device is in BFU) and a fingerprint with a second factor pin as the secondary unlock.
Even if you factory reset your phone and backed up data (to an E2EE cloud provider, over Tor and memorized the credentials), you should still not disclose your password because it could allow evidence to be planted or your device to be compromised. Nothing you say to the border agents can help you in court, it can only be used against you.
The duress pin is generally not how you should handle a situation like this. You do not need the duress pin to prevent access, its purpose is if you're being physically coerced as well as to give the attacker the dillema of whether to enter a coerced password (it even gives this benefit for people that don't use the duress password).
Sure, if police are behaving illegally and the information that would be disclosed is worth the possible punishment, then that's a personal decision.
[1] Based on leaked Cellebrite documentation, GrapheneOS was the best performing device against AFU attacks. It also has a customizable reboot timer to bring the device back to BFU after a set time of not unlocking. The options are between 10 minutes and 72 hours of unlocking and 18 hours is the default iirc. Apple and Google added this to their phones after GrapheneOS without the option to customize. Theirs are set at 72 hours.
I just read an article today claiming that some police contractor had bypadded the BFU protection on iphones. They were managing to keep the phone in AFU state... somehow. worth a read.
There was a case where someone was charged with erasing evidence using this method. While its unlikely they would be convicted, its still not something you wanna go through as they can put you through the ringer and fuck up your plans at a great monetary cost to you.
The thing is, they do these searches not because they are "evil" - definitely not morally upstanding people, but at the end of the day, its still a job and they are following some guidance. When they encounter an uncooperative person, a) it makes their monotonous job more exciting, and b) an uncooperative person is more likely to be guilty, which means more excitement.
As such, if you care about privacy, just get a degoogled phone, and use the web interface for all the communication stuff that you need, including phone. Then just clear browser data and cache before you land. If you get one that supports usb OTG or screen mirroring, you can also get a lapdock and use that as your laptop.
Then, if they detain you and ask for your devices, you can just give them everything and let them have at it. Because you are cooperative, and the phone did not reset with the pin like the Graphene OS one, they are way more likely to let you go
I think it's prudent for everyone to turn off your phone or put it into Lockdown mode (which I think is the same as Before First Unlock) while going through security checkpoints. This applies to anyone in the world.