This AI-Generated Pattern Can Make You Invisible to Surveillance Cameras, Here’s How It Works

adversarial pattern surveillance camera detection

A cybersecurity researcher spent the past year running roughly 31 million tests to build something that sounds like science fiction: a computer-generated pattern that, when printed on clothing or vehicles, can stop surveillance cameras and license plate readers from detecting whatever it covers. The project, called noRecognition, was publicly demonstrated for the first time at the Def Con cybersecurity conference in Las Vegas, and it worked.

Meet the Researcher Behind It

Bill Swearingen, a cybersecurity professional based in Kansas City who co-founded the local cybersecurity meetup SecKC, built the project out of a personal concern about the sheer volume of surveillance infrastructure in everyday public spaces. He described his hometown as “swamped” with surveillance cameras, sometimes installed just a few feet apart from one another, without residents ever meaningfully opting in to being watched.

The idea crystallized after Swearingen wanted to attend a protest but felt uncomfortable doing so, worried that the dense network of surveillance cameras could be used to track and identify participants exercising their constitutional right to free expression. Assuming others likely felt the same hesitation, he decided to build a technical solution.

How the Technology Actually Works

It’s important to understand what noRecognition does and doesn’t do. Swearingen’s patterns do not block cameras from recording footage at all. Instead, they specifically target the detection algorithms that power modern surveillance systems, the software that identifies and flags people, faces, vehicles, and license plates within recorded video.

In practical terms: the camera still records video, but the AI-generated pattern scrambles the algorithm’s ability to recognize what it’s looking at, so no detection alert gets triggered. As Swearingen put it, the goal is to make a person “a needle in a haystack again” among the massive volume of footage modern surveillance systems process daily.

The Technical Process: Teaching a Model How to Paint

Swearingen’s approach evolved from a fairly modest starting point into something significantly more sophisticated. He began roughly a year ago with a proof-of-concept lab, working to defeat one open-source camera detection algorithm at a time, incrementally scaling up his testing with more computing power and support from the broader cybersecurity community who contributed hardware to the project.

That early proof of concept eventually evolved into a reinforcement learning model, essentially a self-training system that learns which visual patterns successfully evade detection and which don’t, specifically against the camera algorithms being tested. In Swearingen’s own words, he essentially taught the model “how to paint.” Every time a pattern failed, meaning an algorithm successfully detected it, the model adjusted and tried again, repeating the cycle until it found patterns capable of defeating multiple detection algorithms simultaneously.

The model eventually found reliable pattern “recipes” capable of defeating all 11 open-source detection algorithms Swearingen tested against, including the specific software that powers Flock license plate readers, Axon body-worn cameras, and Clearview AI, three of the most widely deployed surveillance and detection systems currently in use across the United States. Today, the model generates entirely new patterns every minute, with Swearingen describing each new batch as mathematically stronger than the last.

The First Real-World Test

At Def Con in Las Vegas, Swearingen ran his first live, real-world demonstration. Working with automotive media outlet Donut Media, the team covered a 2009 Toyota Yaris entirely in one of Swearingen’s newest patterns to test whether it could evade detection by a Flock license plate reader camera. According to Swearingen, the test succeeded, though the vehicle’s wheels proved to be a particularly difficult surface to fully cover and remained a partial detection challenge.

This Isn’t Entirely New, But the Approach Is More Advanced

Adversarial patterns designed to defeat facial recognition and camera detection aren’t a brand-new concept. Several art projects and clothing brands have previously released garments intended to confuse facial recognition systems, and some eyewear makers have marketed anti-facial-recognition glasses, though with limited real-world effectiveness reported so far. Swearingen’s project builds directly on this earlier body of work, but distinguishes itself through the scale and rigor of its testing, tens of millions of iterations against multiple real detection systems, rather than a single, static design.

What Happens Next

With a successful public demonstration behind him, Swearingen’s next goal is getting these patterns into the hands of people who want to use them. The noRecognition project has launched a crowdfunding campaign to help fund production of early merchandise featuring the patterns, starting with T-shirts and hoodies, with plans to eventually offer pattern-printed vehicle skins as well. Swearingen says the goal is for the designs to be genuinely wearable and aesthetically appealing, not just functional.

Notably, Swearingen is deliberately keeping his strongest-performing patterns off the internet, specifically to prevent camera and detection software makers from studying and defeating them before the technology reaches the public.

Why This Matters Beyond One Researcher’s Project

Swearingen’s work lands squarely in an active and increasingly contentious debate around algorithmic surveillance. License plate readers and facial recognition systems have already been documented causing real, serious harm, including cases where innocent people were pulled over, detained at gunpoint, or wrongfully jailed due to license plate camera errors. Against that backdrop, tools designed to let individuals opt out of algorithmic tracking in public spaces raise a genuinely difficult question: is defeating flawed detection systems a legitimate privacy right, or does it undermine legitimate law enforcement and public safety uses of the same technology? That tension is likely to intensify as adversarial pattern technology, powered by increasingly capable AI, keeps improving faster than the detection systems it’s designed to defeat.

For continuing coverage of privacy technology, surveillance policy, and the latest cybersecurity research, keep following Tech News Reports for ongoing updates.

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply

Your email address will not be published. Required fields are marked *