Adversarial Patterns Could Help People Evade AI Surveillance Cameras

Cybersecurity researcher Bill Swearingen says his noRecognition project creates patterns that can prevent some surveillance cameras and license plate readers from automatically detecting people and vehicles.

Aug 10, 2026 - 02:28
 1
Adversarial Patterns Could Help People Evade AI Surveillance Cameras
IMAGE CREDITS: BILL SWEARINGEN

Cybersecurity researcher Bill Swearingen says he has developed computer-generated patterns capable of preventing some widely used surveillance systems from automatically detecting people, vehicles and other objects.

Swearingen spent roughly a year repeatedly testing patterns against camera detection algorithms. After around 31 million tests, he says his project, called noRecognition, can now generate designs on demand that interfere with the computer vision systems used by some surveillance cameras and license plate readers.

The patterns do not stop cameras from recording footage. Instead, they are designed to confuse the algorithms that analyse video and automatically identify objects, faces or vehicles. If the detection system fails to recognise what it is seeing, it may not generate the alerts normally used to flag activity for further review.

Swearingen describes the technology as a way for people to opt out of automated tracking in public spaces.

“Privacy is a fundamental right,” Swearingen said, arguing that people should have more control over whether automated surveillance systems track them.

Surveillance cameras are becoming more powerful

Modern surveillance networks increasingly combine cameras with artificial intelligence capable of analysing enormous quantities of video. These systems can identify license plates, detect people and vehicles, and in some cases use facial recognition to identify individuals.

That automation allows organisations and law enforcement agencies to search through footage much faster than human operators could. Rather than manually watching thousands of hours of video, algorithms can identify potentially relevant activity and generate alerts.

Swearingen’s approach attempts to disrupt that automated layer. The underlying footage still exists, but if the algorithm does not recognise the person or vehicle, finding it later becomes considerably more difficult without knowing where to look.

The project grew partly from Swearingen’s concerns about the increasing number of surveillance cameras around Kansas City, where he lives and co-founded the cybersecurity community SecKC.

He said people generally never explicitly agreed to being continuously tracked by these systems. His concerns became more personal when he considered attending a protest but worried that cameras could be used to identify and follow people exercising their rights to public expression.

Teaching an AI model to create patterns

Efforts to interfere with facial recognition and computer vision systems are not new. Artists, researchers and clothing companies have previously experimented with apparel, glasses and visual designs intended to confuse recognition algorithms, with varying levels of success.

Swearingen built on that earlier research by creating a proof-of-concept laboratory where he could systematically test patterns against open-source camera detection algorithms.

Over time, the project developed into a reinforcement learning system capable of learning which visual patterns succeeded and which failed. Swearingen described the process in simple terms as teaching the model “how to paint.”

Whenever a pattern failed and an algorithm successfully detected the covered object, the system generated another version and tried again. The process repeated millions of times as the model searched for designs capable of defeating several detection systems simultaneously.

Swearingen says the model eventually produced patterns that defeated all 11 open-source detection algorithms included in his testing. Those included software associated with systems used by Flock license plate readers, Axon body-worn cameras and cameras running Clearview AI technology.

The system now produces new patterns roughly every minute, with each generation informed by the successes and failures of previous designs.

Real-world test at Def Con

Swearingen publicly demonstrated the technology at the Def Con cybersecurity conference in Las Vegas on Friday. With assistance from Doughnut Media, the team covered a 2009 Toyota Yaris with one of the latest noRecognition patterns and tested whether a Flock camera could automatically detect the vehicle.

Swearingen said the demonstration showed that the pattern was effective, although the vehicle’s wheels remained challenging for the system to conceal from automatic detection. Doughnut Media plans to release video of the demonstration in the coming weeks.

The test provides early evidence that adversarial patterns developed through repeated computer simulation can also work against surveillance detection systems in real-world environments.

noRecognition plans clothing and vehicle designs

Swearingen now wants to make some of the patterns available to people who want to reduce automated tracking. The noRecognition project has launched a crowdfunding campaign intended to support early merchandise featuring the designs, including T-shirts and hoodies.

Pattern-covered vehicle skins could eventually follow. Swearingen said the designs need to maintain sufficiently high resolution to remain effective from a distance while still looking like something people would actually want to wear or place on their vehicles.

He is keeping his strongest patterns off the public internet for now because publishing them could allow surveillance technology companies to retrain their systems to recognise and defeat the designs.

Meanwhile, his models continue generating and testing new versions. Because unsuccessful designs provide additional training data, Swearingen believes the system can continue improving as it encounters more failures.

“Every failure improves my model,” he said, adding that the patterns continue getting better as the testing process runs.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Angry Angry 0
Sad Sad 0
Wow Wow 0
Shivangi Yadav Shivangi Yadav reports on startups, technology policy, and other significant technology-focused developments in India for TechAmerica.Ai. She previously worked as a research intern at ORF.