noRecognition tests patterns that disrupt surveillance detection

Bill Swearingen says his noRecognition project has generated computer-designed patterns that defeated all 11 open-source detection algorithms in his tests after roughly 31 million trials. At the Def Con cybersecurity conference in Las Vegas, he demonstrated a 2009 Toyota Yaris covered in one of the patterns and said it successfully avoided detection by a Flock camera.
The patterns are intended for clothing, objects and vehicles. They do not prevent a camera from recording video. Instead, they are designed to interfere with the automated recognition layer, so a system may fail to identify the person, object or vehicle that the pattern covers and may not generate a detection alert.
A model trained to create adversarial patterns
Swearingen developed the project over the past year, initially testing whether patterns could defeat individual open-source video-camera detection algorithms. As he added computing power, the proof of concept became a reinforcement-learning model that learns from failed attempts and produces new variations.
He described the process as teaching the model how to paint. When a tested pattern was detected, the model tried another approach until it could defeat several algorithms simultaneously. Swearingen said the system now creates new patterns every minute and that each batch is mathematically better than the last.
The tests included software that powers Flock license plate readers, Axon body-worn cameras and cameras running Clearview AI. Swearingen said the patterns ultimately found configurations capable of defeating each of the 11 algorithms he evaluated. The Def Con vehicle demonstration was his first public real-world test, although he noted that covering the wheels presented a challenge.
Detection can fail while video remains available
The distinction between recording and detection is central to the project. Modern surveillance deployments can sift large volumes of footage for specified activity, including vehicles and faces. noRecognition seeks to return a covered subject to the wider mass of recorded footage unless an investigator already knows where to look.
Swearingen has framed the work as a privacy tool for people who do not wish to be automatically tracked in public. He cited concerns about extensive camera coverage and the ability of people to exercise free expression without feeling exposed to automated surveillance. He also said the strongest patterns will not be published online, in part to prevent camera makers from adapting their systems to them.
What organisations should take from the test
The project is still at an early stage. Swearingen plans to make patterns available through merchandise, including T-shirts and hoodies, and has raised the prospect of vehicle skins. He says the intended designs need sufficient resolution to work at distance while remaining visually usable.
For organisations operating cameras, the demonstration is a practical reason to test the limits of automated detection rather than equating an absent alert with an absent subject. Video retention, human review and clearly defined operating procedures remain important when algorithmic recognition does not flag what a camera has recorded.

