Counterintuitive patterns created with artificial intelligence can confuse surveillance cameras and recognition systems without stopping the video recording. The development opens a new debate about privacy, but also about the limits of automated security.

Cybersecurity researcher Bill Swearingen says it took him about a year and 31 million trials to train a system that produces patterns that make it difficult to identify people and vehicles. He presented the findings at the Def Con conference in Las Vegas.
How juxtapositional patterns work
The project, called noRecognition, doesn't blind a camera or prevent it from storing an image. The adversarial patterns change how the algorithm interprets the object so that it doesn't trigger face, vehicle, or license plate recognition.
The approach is based on a reinforcement learning model. The system tests a design against detection algorithms, records whether it was detected, and then modifies the result. The process is repeated until designs fail to provide reliable detection.
According to the presentation, the researcher tested the model against 11 open-source algorithms, including software connected to Flock cameras, Axon body cameras, and Clearview AI systems. The claims are based on the author's testing and do not constitute independent verification of all systems.
See also: DroneDog robot takes on construction site security

Testing in a real environment
The first public demonstration was on a 2009 Toyota Yaris, which had one of the designs mounted on it. The goal was to prevent a Flock camera from recognizing the vehicle. Swearingen said the result was successful, although the wheels proved more difficult to deal with.
This detail is important: contrasting patterns do not provide an invisibility cloak and do not eliminate all forms of surveillance. They affect specific detection patterns, under specific lighting conditions, distances and angles. A human may see the object, while a different camera may recognize it normally.
The creator keeps the most effective designs offline so that camera manufacturers don't adapt their models. In noRecognition he describes the idea as a way to "opt out" of automatic tracking, while also considering making clothing or headgear with such designs available.
See also: Surveillance cameras targeted by a business

Privacy, security and the limits of technology
The idea is connected to a broader problem: cameras don’t just record, they classify people, vehicles, and behaviors. When the process is automated, a wrong result can lead to a false alarm, exclusion, or targeting. The contrasting patterns show that automation is not infallible.
At the same time, the same technique can be used by attackers to make it more difficult to identify suspicious vehicles or people. Therefore, publishing such results requires a balance: enough technical transparency to improve defenses, but not instructions that would allow direct reproduction of the designs.
Swearingen's research highlights that visual analytics systems need to be evaluated with controlled tests, different lighting and shooting angles, and human supervision. Organizations that use cameras should also explain what data they collect, how long they keep it, and how they correct an incorrect result.
As TechCrunch reports , noRecognition is still in its early stages and continues to produce new variations. Just because a pattern passes a test doesn't mean it will work on every camera or offer complete privacy protection.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Ring expands Search Party with artificial intelligence
The SecNews technical team believes that the most useful conclusion is not the promise of "invisibility", but the need for stricter controls. As surveillance systems gain more capabilities, they must be tested against unpredictable inputs before being used for decisions that affect people.
