Adversarial Fashion Takes Aim at AI Surveillance Cameras
At DEF CON, researchers and startups unveiled clothing patterns that scramble face and person detection models, as public backlash against AI street surveillance grows.

Updated
Why it matters
- Bill Swearingen's noRecognition project, presented at DEF CON, uses patterns generated by a reinforcement learning algorithm and tested against 11 object detection models, sometimes reducing them to no detection.
- Cap_able and Urban Privacy already sell garments — jacquard knits and OpenCV-targeting prints — designed to disrupt computer vision systems.
- Experts caution that the clothing is a fragile defense: patterns are model-specific, vulnerable to motion and lighting, and cannot prevent signal aggregation that identifies people from weak data combined.
AI-powered cameras that identify faces and license plates now line streets worldwide, and a public backlash against them is gaining momentum — but a growing cohort of designers and security researchers is fighting back with patterned clothing engineered to defeat machine vision.
At last month's DEF CON hacker convention, cybersecurity expert Bill Swearingen presented noRecognition, a Kickstarter-funded project that generates "adversarial" fabric patterns capable of scrambling object detection systems. In 2025, Swearingen began experimenting with a simple Python-based fuzzer — a tool that feeds invalid inputs to software to expose bugs or unexpected behavior — aimed at YOLO, one of the most widely used object detection frameworks. He then turned what he learned into a reinforcement learning algorithm that produces colorful geometric patterns, each one a candidate weapon against surveillance AI.
The stakes are concrete. Privacy advocates point to the absence of consent in data capture, opaque storage and use practices, and documented misuse — including cases of police officers exploiting vast camera networks to spy on their ex-partners, as reported by The Washington Post. Some opponents have turned to direct action: the DeFlock project maps automated license plate readers (ALPRs) to raise awareness, while others have vandalized or damaged the cameras outright. Adversarial fashion offers a legal, wearable alternative.
Swearingen has tested his patterns against 11 object detection models — four that search for faces, two that recognize faces, and five that detect people — most of them publicly available. The successful patterns lower the systems' confidence scores, sometimes to the point of no detection at all.
"Privacy is a human right, and the popularity of this just goes to show that people are interested in preserving their privacy," Swearingen says.
A small industry takes shape
Swearingen is not alone. Cap_able and Urban Privacy are already selling physical garments designed to interfere with computer vision. Cap_able, founded by Rachele Didero — an assistant professor at the Free University of Bozen-Bolzano in Italy — uses a patented manufacturing method to weave bright, bold motifs into jacquard knitted fabrics. The company's ethically produced, sustainably made dresses, pants, and tops disrupt systems built on fast convolutional neural networks, sometimes causing them to classify the wearer as an animal or an object.
"If we're able to camouflage a person as something else, then we're obtaining our goal," Didero says. "We use this very visible and tangible item to talk about something that most of the time is intangible."
Urban Privacy's latest Faception Reloaded collection targets facial recognition systems based on OpenCV algorithms. Black-and-white prints abstracted from a human face register as additional faces on detectors, slowing them down. Asymmetrical cuts and wide silhouettes make it harder for systems to discern body shape and gait. "The idea is to create false data," says co-founder Daniel Preuß.
The lineage stretches back more than a decade. In the 2010s, technologist Adam Harvey designed hairstyles and makeup that foil face detectors, as well as heat-reflecting attire that averts drone-enabled thermal surveillance. In 2019, artist and activist Kate Bertash launched Adversarial Fashion, a clothing line printed with fake license plate numbers to inject junk data into ALPR databases.
What began as art pieces and thought experiments is now hardening into a small industry, and the demand reflects a gap that regulation has not filled.
"Clothing is something you can actually buy and put on, unlike policy," says Niloofar Mireshghallah, incoming professor of engineering and public policy at Carnegie Mellon University. "It's a way of saying, 'I didn't consent to this.'"
A fragile shield
The limitations are significant. Real-world conditions — camera angles, lighting, the way fabric folds as a person moves — can degrade a pattern's effectiveness. "One good frame is all a system needs," Mireshghallah says.
Motion adds another vulnerability. "Even if the camera thinks you're a bear for a few frames, there's a bear walking like you," Mireshghallah says.
The patterns must also be tuned to specific object recognition models, so a pattern built against one system offers no protection against another. And once surveillance operators train future model generations on a given pattern — and on the person wearing it, manually if necessary — the clothing stops working as a defense.
"It remains a fragile shield against a threat that is constantly improving from multiple angles," says Dippu Kumar Singh, senior director of emerging data and analytics at Fujitsu North America, who specializes in vision AI and AI ethics.
The makers acknowledge this. "It's not an invisibility cloak," Preuß says. "Surveillance aims to capture your identity, and fashion is about expressing your identity. We're making clothing that people can wear to make a statement about the importance of privacy in a digital world."
What comes next
Development continues despite the constraints. Didero is determined to keep innovating at Cap_able. Urban Privacy plans further releases from its collection, including a "shadow cap" with an acrylic face shield layered with cutouts to blur facial contours. Swearingen intends to investigate anomalies he encountered during testing, including one pattern that shifted a detector's bounding box and another that changed a camera setting.
Singh sees the movement's value beyond its technical performance. "At its core, this fashion is about taking back control of your face and body," he says. "People are starting to realize that privacy isn't just a right they can passively expect to be handed to them—it is something they have to actively defend."
Mireshghallah takes a more cautious view, treating countersurveillance fashion as a speed bump rather than a solution. The real risk, she argues, is aggregation: models combine weak signals — a partial face, a building in the background, a time stamp, a tagged social media post — into a confident guess about who you are and where you were.
"None of those pieces give you away on their own, but together they do," Mireshghallah says. "My advice is don't just think about hiding your face from a lens. Think about what else you're leaking that can be combined with it. That side information is often what actually identifies you—and no pattern on a shirt fixes that."
Original: ibtimes.co.uk
More from James Calloway
Show full bio
News editor covering industry trends and analytics at AI In Context.
121 articles