TechNewsReel
Live

AI-Generated Patterns Can Hide Vehicles and People From Surveillance

Researcher Bill Swearingen developed a machine-learning model that creates adversarial patterns capable of defeating widely used AI detection algorithms.

TechNewsReel Newsroom · August 9, 2026

Security researcher Bill Swearingen has developed a reinforcement learning model that generates adversarial patterns capable of hiding people, faces, and vehicles from AI surveillance detection. The project, known as noRecognition, represents a technical shift in privacy tools by using machine learning to systematically evade the algorithms used by law enforcement and private security firms.

To refine the effectiveness of these patterns, Swearingen’s model underwent approximately 31 million tests. The resulting patterns do not block the physical recording of video, but they prevent AI systems from triggering detection alerts. In a real-world demonstration at the Def Con conference in Las Vegas, a 2009 Toyota Yaris—wrapped in the adversarial pattern with assistance from Donut Media—successfully evaded detection by a Flock license plate reader. According to the research, the model has successfully defeated 11 open-source detection algorithms, including those utilized by Clearview AI, Axon, and Flock.

The Surveillance Context

The emergence of noRecognition comes as AI-powered surveillance, including facial recognition and automated license plate readers (ALPRs), becomes increasingly prevalent across the United States. These tools are widely deployed by law enforcement agencies to track movement and identify individuals in real time. Swearingen, a cybersecurity professional and co-founder of SecKC, developed the tool to provide citizens with a way to "opt-out" of algorithmic tracking. He argues that such tools are necessary to protect the right to free expression, particularly during public protests, stating that "privacy is a fundamental right."

Implications for the AI Arms Race

This development marks a significant escalation in the ongoing "arms race" between surveillance technology and privacy-preserving tools. Previous attempts to thwart AI detection often relied on art-based adversarial clothing, which frequently had limited or inconsistent efficacy. By contrast, the noRecognition approach uses a systematic, data-driven method to defeat specific commercial and government software. This suggests a scalable path for individuals to maintain anonymity in public spaces, as the patterns are designed to target the mathematical vulnerabilities of the detection models themselves. Swearingen noted that the iterative nature of the project allows for constant refinement, stating, "Every failure improves my model, and so [the patterns] keep getting better and better."

What's Next

As these adversarial patterns become more sophisticated, surveillance providers like Axon and Flock may be forced to update their detection models to recognize and counteract these specific visual disruptions. The effectiveness of noRecognition in diverse lighting conditions and across different camera angles remains a key area for further observation. While the Def Con demonstration proved the concept against specific hardware, the broader impact will depend on whether these patterns can be easily reproduced and deployed by the general public to evade state-level surveillance infrastructure.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.