AI-Generated Adversarial Patterns Can Prevent Some Surveillance Cameras From Detecting People and Vehicles

By
KOMCHAD
KOMCHAD นำเสนอข่าวไอที AI สมาร์ตโฟน Gadget คอมพิวเตอร์ ความปลอดภัยไซเบอร์ และนวัตกรรมล่าสุดในภาษาไทย

Cybersecurity researcher Bill Swearingen says he has developed computer-generated patterns capable of preventing some widely deployed surveillance systems from automatically detecting people, vehicles, and other objects.

The project, called **noRecognition**, does not stop a camera from recording video. Instead, its adversarial patterns interfere with the computer-vision algorithms used to identify what appears in that footage, potentially preventing automated systems from generating detection alerts.

Swearingen says the result comes after roughly **31 million tests** conducted over the past year. His system now uses reinforcement learning to continually create patterns optimized against multiple detection algorithms, and he publicly demonstrated the approach on a vehicle at the DEF CON cybersecurity conference in Las Vegas.

noRecognition Targets Algorithmic Detection Rather Than the Camera

Modern surveillance systems increasingly rely on computer vision to analyze large volumes of recorded footage.

These systems can identify vehicles, read license plates, detect people, and in some cases perform facial recognition. The automation allows operators and law-enforcement agencies to search enormous amounts of footage without manually watching every recording.

Swearingen’s approach targets this automated detection layer.

The camera can still capture the scene, but the adversarial pattern is designed to confuse the detection model so the object covered by the pattern is not classified or flagged correctly.

Swearingen described the project as a way for people to opt out of automated tracking, telling TechCrunch that **”Privacy is a fundamental right.”**

Around 31 Million Tests Led to the Current Patterns

Swearingen began the project with a proof-of-concept laboratory designed to test whether patterns could defeat individual open-source camera-detection algorithms.

Over time, he expanded the testing process with additional computing resources and support from members of the wider cybersecurity community.

The project eventually evolved into a reinforcement-learning system.

Each time a pattern failed and an algorithm successfully detected the target, the model generated another candidate and tested again. Swearingen described the process as teaching the model **”how to paint.”**

The iterative process continued millions of times.

According to Swearingen, his model ultimately generated patterns capable of defeating all **11 open-source detection algorithms** included in his testing.

The technologies tested included software associated with systems used by **Flock Safety license plate readers, Axon body-worn cameras, and Clearview AI**.

The Model Can Generate New Patterns Every Minute

The system is not limited to a single static design.

Swearingen says the reinforcement-learning model can now generate new patterns every minute, with each new batch mathematically optimized based on what the model has learned from previous successes and failures.

This continual adaptation matters because surveillance vendors can also update their detection algorithms.

Keeping the strongest patterns private could therefore make it harder for camera companies to train their systems specifically to recognize and defeat them.

Swearingen said he is not publishing his strongest designs online for that reason.

DEF CON Test Used a 2009 Toyota Yaris

The project moved beyond laboratory testing during a public demonstration at the DEF CON cybersecurity conference in Las Vegas.

With assistance from **Donut Media**, Swearingen covered a **2009 Toyota Yaris** with one of the latest noRecognition patterns and tested whether a Flock camera would automatically detect the vehicle.

Swearingen said the demonstration proved effective, although the wheels remained a challenge for the pattern.

Donut Media is expected to publish video of the demonstration in the coming weeks.

The test represents early real-world evidence that adversarial patterns developed against computer-vision systems can influence surveillance detection outside a controlled laboratory.

Adversarial Clothing Could Become a Consumer Privacy Tool

Swearingen is now exploring ways to make the technology available beyond research demonstrations.

The noRecognition project has launched a crowdfunding campaign intended to support early merchandise featuring the adversarial designs, including T-shirts and hoodies.

Vehicle skins incorporating the patterns could also be developed later.

For practical use, the designs need to retain enough resolution to affect detection systems from a distance while still looking like wearable or visually acceptable products.

Swearingen says the objective is not simply to create random visual noise, but patterns that can function as privacy tools while remaining aesthetically usable.

The Idea Builds on Earlier Anti-Facial Recognition Experiments

Attempts to confuse facial-recognition and surveillance systems are not new.

Artists, researchers, fashion designers, and eyewear companies have experimented with clothing, makeup, glasses, and visual patterns intended to interfere with computer vision.

Results have varied, and many approaches that work in laboratories become less reliable when used against different cameras, lighting conditions, distances, or updated algorithms.

Swearingen’s project differs by using reinforcement learning and large-scale automated testing to continually search for patterns effective against multiple algorithms rather than manually designing one pattern for one system.

Surveillance AI Creates a New Privacy Arms Race

The project illustrates a broader technical tension emerging as cameras become increasingly dependent on AI.

Computer vision has made surveillance systems dramatically more scalable because software can automatically locate objects or people of interest across enormous collections of video.

Adversarial AI creates the opposite possibility: using machine learning to discover visual inputs that exploit weaknesses in those same detection systems.

Swearingen’s model is continuing to generate and test new patterns as surveillance algorithms evolve.

As he told TechCrunch, every failed pattern provides additional information to the model, allowing subsequent generations of designs to improve.

Share This Article
Follow:
KOMCHAD นำเสนอข่าวไอที AI สมาร์ตโฟน Gadget คอมพิวเตอร์ ความปลอดภัยไซเบอร์ และนวัตกรรมล่าสุดในภาษาไทย
Leave a Comment