Clothing that defeats AI surveillance hits Kickstarter
Def Con week ended with a working answer to the question that has hovered over AI surveillance for years: yes, a pattern printed on fabric can stop cameras from detecting you — and now you can buy it.
A Kansas City security researcher says he has produced computer-generated patterns that stop AI surveillance cameras from detecting people, faces, and vehicles — and he demonstrated them at Def Con before putting the patterns on Kickstarter. Bill Swearingen, co-founder of the SecKC cybersecurity meetup, spent a year running what he says were 31.7 million tests for his noRecognition project. His system is a reinforcement learning model that he describes as having taught itself "how to paint": every time a pattern failed and a detection algorithm caught it, the model tried again, refining the next batch until the patterns defeated all 11 open-source detection systems he tested — including the software that powers Flock license plate readers, Axon body cameras, and Clearview AI. The patterns don't block cameras from recording; they scramble detection so no alert fires, and the person or vehicle the pattern covers drops out of the algorithmic haystack.
On Friday, at Def Con in Las Vegas, Swearingen ran his first real-world test with help from the YouTube channel Donut Media: a 2009 Toyota Yaris wrapped in one of his newest patterns, driven past a Flock camera. "We proved it was effective," he said, though the wheels were a challenge; the footage is expected in the next few weeks. He had already shown the work at Black Hat earlier in the week, where PCMag described the patterns as poisoning facial recognition with no masks or electronics required.
The Kickstarter campaign opened Thursday, selling tees, hoodies, and neck gaiters printed with the patterns, plus 50 "one of one" pieces generated for a single buyer and never released again. What sets this apart from the anti-surveillance clothing that came before it is the testing regime: the project publishes its method, scoring every pattern against 11 production computer vision models — including the vehicle and person detector running on tens of thousands of American streets — requiring each to beat a plain panel of the same size, holding out 30 test wearers who were never used to build it, and publishing the results that went against it. Swearingen says he keeps his strongest patterns off the internet so camera makers can't train against them.
This is adversarial machine learning leaving the paper and arriving as a consumer product validated against the actual surveillance stack deployed across U.S. cities — the first credible "opt-out" for algorithmic tracking, as Swearingen frames it. The honest caveats: a shirt pattern won't save you from a camera aimed at your face from every angle, the Yaris's wheels still got caught, and the moment public patterns ship in volume, vendors can retrain on them. But the generator keeps improving with every failure, and the method is cheap to reproduce. The deeper question is whether the fix belongs in individuals' hands at all — or whether a working evasion tool should push cities and vendors to justify detection-driven policing in the first place.
What to watch: the Donut Media footage of the Yaris run, and how quickly Flock and its peers respond to a pattern that beats their cameras on camera.
Would you wear a pattern designed to hide you from AI cameras — and should evading surveillance be an individual choice? Tell us in the comments.
Sources: TechCrunch · PCMag · noRecognition · Kickstarter