A Researcher Used AI Camouflage to Fool Flock Cameras

SIXCYBER’s noRecognition wrap, tested against 11 algorithms after a year of 31 million AI iterations, targets Flock, Axon, and Clearview

Al Landes Avatar
Al Landes Avatar

By

Image: yarislawas instagram

Key Takeaways

Key Takeaways

  • SIXCYBER’s noRecognition project defeated 11 open-source detection algorithms using AI-generated adversarial patterns.
  • Patterns disrupt neural network classification layers, leaving surveillance footage intact but machine recognition broken.
  • noRecognition expands beyond vehicles, offering crowdfunded anti-surveillance clothing and car wraps to consumers.

A 2009 Toyota Yaris — not exactly the vehicle you’d pick for a high-stakes tech demo — rolled past a Flock surveillance camera in a Las Vegas parking lot last week covered in what looked like a migraine rendered in vinyl. The bizarre pattern wasn’t decoration. Bill Swearingen, founder of cybersecurity firm SIXCYBER, says his noRecognition project spent a year and roughly 31 million iterative tests generating adversarial designs that make object-detection software choke. “We proved it was effective,” Swearingen told TechCrunch after the DEF CON demonstration.

How a Pattern Beats a Camera Without Blocking It

The footage still exists — the software just can’t figure out what it’s looking at.

The camera still records. The video file still exists on a server somewhere. What breaks is the classification layer — the algorithm that decides “that’s a car” or “that’s a license plate.” Swearingen’s patterns exploit structural weaknesses in how neural networks process visual information. Think of it as an optical illusion engineered for silicon, not the human eye. No spray paint. No physical obstruction. Just geometry tuned to make machine learning models fail silently.

Swearingen claims the patterns defeat all 11 open-source detection algorithms he tested, including software associated with:

  • Flock license plate readers
  • Axon body cameras
  • Clearview AI

“Privacy is a fundamental right,” he said, framing the project as giving people a way to opt out of automated tracking.

Image: Bill Swearingen

One Demo Does Not Make a Clinical Trial

A DEF CON parking lot and the real world are very different places.

A single drive-by at a hacker conference is not peer-reviewed research. Swearingen says he’s keeping his strongest patterns private to slow countermeasures — a move that reads as either responsible disclosure or convenient unprovability, depending on your read. Real-world variables — lighting shifts, camera angles, firmware updates — could narrow the gap between demo and disappointment. Independent researchers have not yet reviewed the withheld pattern data, so the claims remain unverified beyond Swearingen’s own testing environment.

From Car Wrap to Your Wardrobe

Anti-surveillance fashion gets a machine-learning upgrade.

The project isn’t staying in the parking lot. noRecognition is crowdfunding printed clothing — hoodies, T-shirts — and vehicle skins. This echoes the CV Dazzle face-paint experiments from a decade ago, when artist Adam Harvey used disruptive makeup patterns to confuse early facial recognition systems. The difference now is scale: millions of automated iterations instead of an artist’s intuition. Think of it as the Balenciaga of not being catalogued.

The arms race ahead is predictable. Surveillance vendors update their models; Swearingen updates his patterns. That cycle is as old as locksmithing. What’s new is that anyone with a printer and a crowdfunding page might soon be able to opt out of being catalogued every time they leave the house.

Share this

At Gadget Review, our guides, reviews, and news are driven by thorough human expertise and use our Trust Rating system and the True Score. AI assists in refining our editorial process, ensuring that every article is engaging, clear and succinct. See how we write our content here →