3 Sources
[1]
Could a Shirt Fool Facial Recognition? The Answer Is Complicated - CNET
With more than a decade of experience, Nelson covers Apple and Google and writes about iPhone and Android features, privacy and security settings, and more. Read full bio A camera and its software labeled Bill Swearingen as a person. Then it suddenly wasn't sure -- all because of some weird
[2]
The AI-Generated Pattern Hides You From Surveillance Cameras -- Including Flock
The first public test came Friday at Def Con in Las Vegas: a 2009 Toyota Yaris wrapped in the pattern, driven past a Flock camera. Bill Swearingen spent the past year running one experiment over and over from his home in Kansas City, where he co-founded the SecKC security meetup. About 31 million
[3]
AI security cameras are everywhere. Can these garments scramble them all?
A former chief intelligence officer has turned fashion designer with one specific goal: creating a universal adversarial camouflage. The rise of public surveillance has also led to the rise of an adversarial counterpart: fashion designed to confuse AI security cameras. It's designed to baffle the
Share
Copy Link
Bill Swearingen unveiled noRecognition at Def Con, demonstrating AI-generated patterns that confuse computer vision models and fool facial recognition systems. After running 31.7 million tests, his adversarial patterns successfully evaded Flock cameras and 11 detection models, raising over $40,000 on Kickstarter.

Bill Swearingen, a longtime cybersecurity professional and founder of Kansas City security community SecKC, unveiled his noRecognition project at the annual hacker convention Def Con in Las Vegas on August 7
1
. During the live demonstration, Swearingen stood before a person-detection system that initially registered his presence with a confidence score above 0.751
. When he raised a flat panel covered in bizarre black-and-white adversarial patterns, the score plummeted to 0.21, causing the system to display "No person detected" in bright green letters1
. The first public field test came when Donut Media wrapped a 2009 Toyota Yaris in one of Swearingen's newest patterns and drove it past a Flock camera2
. According to Swearingen, the test proved effective at breaking the object-detection models that decide whether to log vehicle data2
.The noRecognition project targets the foundational layer of AI surveillance systems. Swearingen explained that what people call facial recognition actually involves several separate detection stages
1
. A person-detection system first asks whether a human body appears in the frame, then a face detector isolates facial features, and finally facial recognition compares that face against a database1
. By breaking the first link in this chain, the entire surveillance process may never initiate1
. These AI-generated patterns work because computer vision doesn't see images the way humans do—AI classifiers generate thousands of guesses about image content, assign confidence scores, and discard anything below a chosen threshold1
. A wrap that reads as loud graphic design to a person can register as nothing at all to a classifier2
.Swearingen didn't manually design these patterns—he built a program using reinforcement learning to create them
2
. His automated fuzzing system creates a pattern, digitally places it on a computer-generated person, and shows the altered image to multiple AI models1
. If a pattern causes significant changes like making detection boxes disappear or sharply lowering confidence scores, the fuzzer flags it for additional testing1
. The most successful designs are then altered and combined to produce new patterns through a selective breeding process1
. As of June, Swearingen's project had run 31.7 million tests1
3
. About 534,600 of those tests triggered anomaly rules, meaning detectors found fewer people or faces, invented extra ones, produced lower confidence scores, or returned wrong identities1
. Of those results, 85 met the definition of "extreme," defeating at least one person detector and one face detector simultaneously1
.Swearingen currently tests each pattern against 11 models: five that detect people, four that find faces, and two that attempt facial recognition
1
. What separates this project from previous anti-surveillance efforts is the specific target list—Swearingen tested against the actual technology stacks in wide deployment, with Flock cameras being a primary focus2
. The controversial Flock surveillance system is facing growing backlash on Capitol Hill, and internal documents show the company pitched plans to turn 350,000 Uber and Lyft dashcams into a rolling plate-scanning fleet2
. Swearingen's testing revealed that covering more body area isn't always more effective—torso patterns had the greatest effect on person detectors, while patterns closer to the head mattered more for face-detection systems1
. In one comparison, a small collar pattern worked better than a much larger print across the torso1
.Related Stories
Swearingen launched a Kickstarter campaign on August 7 to raise $5,000 for noRecognition, which has now raised more than $40,000
3
. The funds will go toward fabric, cameras, and compute resources3
. The limited-edition clothing line includes a buff that can be worn as a neck gaiter, a T-shirt, and a sweatshirt, plus stickers and patches3
. There's a 50-item run of each product, with each item featuring a pattern generated for a single person3
. Swearingen's model now generates fresh patterns every minute, and he's keeping the strongest ones offline so camera vendors can't train their systems against them2
. "Privacy is a fundamental right," Swearingen said, calling the patterns a way for people to "opt out of being tracked"2
. He revealed the idea took hold last year when he wanted to attend a protest and worried about cameras logging everyone who showed up2
.The noRecognition project arrives as automated surveillance systems face mounting scrutiny. Automated readers have already pulled over innocent drivers at gunpoint over bad matches, and immigrants and protesters continue getting swept into ICE's AI dragnet
2
. Lawmakers are pressing Meta over facial recognition in its smart glasses on a parallel track, making any legal measure to fight automatic detection technology a subject of study by privacy advocates2
. Swearingen, a former chief intelligence officer, used AI throughout the entire process—building and training models, generating and testing adversarial pattern geometry, and determining which patterns work best3
. The challenge remains finding patterns that beat multiple models simultaneously. "I have beat every model I have tested, so beating a single model is a solved problem for me," Swearingen explained. "The search now is finding that one pattern that works across many models at once"3
. As surveillance technology becomes more pervasive, questions emerge about whether people will actually wear these patterns in public and whether the resolution will work effectively at distance. Swearingen acknowledged that driving a wrapped car on public roads raises legal questions, though the patterns cover bodywork, not license plates2
. "Every failure improves my model, and so [the patterns] keep getting better and better," he said2
.Summarized by
Navi
27 Aug 2026•Entertainment and Society

17 Jul 2026•Entertainment and Society

19 Aug 2026•Technology

1
Technology

2
Technology

3
Policy and Regulation
