Project noRecognition Uses Reinforcement Learning to Blind AI Surveillance
Researcher Bill Swearingen developed adversarial patterns that trick automated detection layers into ignoring vehicles and people.
Cybersecurity researcher Bill Swearingen has developed "noRecognition," a project that uses reinforcement learning to create adversarial visual patterns capable of fooling AI surveillance systems. The research demonstrates that automated detection layers can be tricked into ignoring subjects entirely, rather than simply obscuring them.
To develop the patterns, Swearingen utilized a reinforcement learning model trained over approximately 31 million simulated tests. The goal was to generate specific visual disruptions that target the detection layer of surveillance software—the initial stage where AI identifies a face, license plate, or "activity of interest." In digital simulations, the project achieved a peak non-detection rate of 61.7% against a detector from a real deployed camera. Swearingen later moved the project from simulation to the physical world at DEF CON, where he wrapped a 2009 Toyota Yaris in these patterns to test them against a Flock Safety automated license plate reader. "We proved it was effective," Swearingen stated.
The Logic of Adversarial Stealth
The project was born from Swearingen's concerns regarding the proliferation of surveillance cameras in Kansas City, specifically the potential for these systems to be used to track individuals during public protests. Unlike traditional stealth or camouflage, which attempts to hide a subject from the camera lens or a human observer, noRecognition targets the machine's perception. The patterns do not make the subject invisible to the camera; instead, they cause the AI software to fail to recognize the subject as an object of interest, effectively rendering the person or vehicle invisible to the automated alert system.
Implications for Automated Tracking
This research exposes a fundamental vulnerability in the AI layers that power modern security infrastructure. If these adversarial patterns can be scaled into mass-produced vehicle wraps or wearable clothing, they could significantly undermine the reliability of automated tracking systems. The project specifically aims to create a universal pattern capable of defeating multiple detection algorithms simultaneously, including those deployed by industry leaders such as Flock, Axon, and Clearview. For law enforcement and private security firms relying on these tools for real-time monitoring, the ability to bypass detection via a printed pattern represents a critical failure point in the trust model of AI surveillance.
The Path to Universal Patterns
While the DEF CON test provided a successful proof of concept, the project continues to evolve toward a more versatile application. The current objective is the development of a single, universal pattern that can disrupt a wide array of different detection algorithms across various hardware platforms. As surveillance AI becomes more integrated into urban environments, the battle between detection layers and adversarial patterns is likely to intensify, forcing security vendors to rethink how their models identify targets in an environment where the targets can actively manipulate the AI's perception.