noRecognition’s Adversarial Patterns Defeated a Real Flock Camera at DEF CON
At DEF CON, a security researcher's AI-generated adversarial patterns stopped a real Flock Safety camera from recognizing a test vehicle, the result of a year of automated testing against...
A Kansas City security researcher used the DEF CON hacking conference in Las Vegas to show that computer-generated adversarial patterns can stop a live surveillance camera from recognizing what it is looking at. On Friday, August 7, Bill Swearingen wrapped a 2009 Toyota Yaris in one of his patterns and tested whether a real Flock Safety license plate camera would still detect it, according to TechCrunch. “We proved it was effective,” Swearingen told the outlet, though he said the car’s wheels remained a challenge.
Table Of Content
A Year of Automated Testing Behind One Public Demo
The DEF CON test was the first real-world trial for a project Swearingen calls noRecognition, the product of roughly a year of automated experimentation. TechCrunch reports Swearingen has run some 31 million tests to find patterns that, once applied to clothing or objects, stop detection software from flagging whatever they cover. On the project’s own research page, Swearingen writes that after deduplication those runs produced 5.7 million labeled examples, each recording which pattern, applied to which target, defeated which specific detection model.
The patterns do not stop a camera from recording video. Instead, TechCrunch reports they scramble a detection algorithm’s ability to classify what is under the pattern, so no face, plate, or object alert ever fires, which TechCrunch describes as turning a tracked person or vehicle back into a needle in a haystack until someone already knows where to look.
How the Patterns Are Built
Swearingen told TechCrunch he essentially taught his model “how to paint.” Each candidate pattern is scored against detection software, and every failure feeds back into the next generation of patterns until the system converges on designs that beat multiple algorithms at once. According to his research page, the first version of that scoring system was a gradient-boosted model, XGBoost, which reached a mean AUC-ROC of 0.77 on the deduplicated data, enough to confirm the signal was learnable at all. That baseline model could separate patterns that worked from patterns that did not, but Swearingen says it was far less useful at ranking his best “elite” patterns against one another, scoring a correlation of just 0.06 when tested on 511 of them. He then built a transformer to rank recipes more precisely, and on top of that added a reinforcement learning system that his research page says is what actually proposes new patterns, tested against what he calls “the Gauntlet,” a bank of 10 production-grade AI surveillance models. That reinforcement learning system is the one generating new patterns, which, per TechCrunch, now happens roughly once a minute.
TechCrunch reports the resulting patterns have defeated all 11 open-source detection algorithms Swearingen tested against, including software that powers Flock license plate readers, Axon body-worn cameras, and cameras running Clearview AI. The DEF CON test, run with help from the automotive media outlet Donut Media, was the first time one of the patterns was tried against a camera actually deployed in the field rather than only in simulation.
A Researcher With Federal and Corporate Security Experience
Swearingen’s GitHub page for the project and his research site describe him as a former chief information security officer at a major telecommunications company and a red team leader for NSA contractors, as well as a co-founder of SecKC, a Kansas City cybersecurity meetup his own materials describe as the largest of its kind held monthly anywhere. He has also spoken at DEF CON and Black Hat in prior years.
Swearingen told TechCrunch his motivation is personal rather than academic. He recalled wanting to attend a protest but hesitating over how many cameras lined the route, and worried other people might skip exercising their right to free expression for the same reason. “Privacy is a fundamental right,” he said, describing noRecognition as a way for people to “opt-out of being tracked.” On his research page, Swearingen writes that he built the project against a backdrop he describes as more than 117 million Americans indexed in police facial recognition networks, a figure drawn from his own project materials rather than an outside audit.
Not the First Attempt, But a Bigger One
TechCrunch notes that clothing brands and art projects aimed at defeating facial recognition already exist, and that some eyewear-based approaches in the same vein have had little real-world effect. Swearingen says noRecognition builds on that earlier work. What sets it apart, on the evidence reported so far, is scale, 31 million automated tests, and the fact that a pattern has now been demonstrated against camera hardware actually deployed in the field rather than only against algorithms running in a lab.
What’s Next
Video of the DEF CON vehicle test is expected within a few weeks, Donut Media told TechCrunch. Swearingen said the next step is getting finished patterns into the hands of people who want to use them; the noRecognition project is already running a crowdfunding campaign for early merchandise such as T-shirts and hoodies printed with the patterns, with vehicle-sized pattern skins described as a possible future product. The project’s pattern-generation code is also published on GitHub, where outside researchers can inspect and test the pipeline for themselves.








No Comment! Be the first one.