DTWdailytechwire
Tech Intelligence, Wired Daily
AI

Adversarial Patterns Challenge AI-Powered Surveillance Detection

A reinforcement learning model trained through 31 million iterations can now generate patterns that defeat license plate readers and facial recognition systems, raising questions about the future of algorithmic surveillance.

DR
Daniel R. Whitfield
Markets & Venture Reporter · Hong Kong
Aug 10, 2026
5 min read
Adversarial Patterns Challenge AI-Powered Surveillance Detection
Adversarial Patterns Challenge AI-Powered Surveillance DetectionCredit: Bill Swearingen / Donut Media

A Privacy Tool Born From Protest Anxiety

Bill Swearingen stood at the edge of a protest last year, uncomfortable. Not because of the cause or the crowd, but because of the cameras. In Kansas City, where he co-founded the cybersecurity meet-up SecKC, surveillance infrastructure has grown dense enough that cameras sometimes sit just feet apart. The thought of exercising a constitutional right while being algorithmically tracked felt wrong.

That discomfort sparked a year-long technical project. Swearingen, describing himself as a middle-aged white guy in the center of the United States, recognized his own privilege in the equation. If he felt uneasy about surveillance, what about people who face actual discrimination or harassment? People who might want to protest but couldn't afford the risk of being identified and tracked?

The result is noRecognition, a reinforcement learning system that generates visual patterns capable of defeating the detection algorithms inside modern surveillance cameras. After running approximately 31 million tests, the system can now produce patterns on demand that prevent cameras from triggering alerts when they scan whatever the pattern covers.

How the Model Learned to Paint

Swearingen's approach builds on earlier counter-surveillance research, including art projects and clothing designs that attempted to confuse facial recognition systems with mixed results. His contribution is in scale and methodology.

He started with a proof-of-concept lab that tested patterns against open-source video detection algorithms, one at a time. As the work progressed, he scaled up processing power with help from the wider cybersecurity community, who contributed hardware to accelerate the training cycles.

The system evolved into a reinforcement learning model, a self-contained training loop that iterates without human intervention. Swearingen describes the process as teaching the model "how to paint." Each failed pattern, one that an algorithm successfully detected, feeds back into the training loop. The model adjusts, generates a new candidate, and tests again.

Over time, the model found patterns that could simultaneously defeat all 11 open-source detection algorithms Swearingen targeted. Those algorithms include the software running inside Flock license plate readers, Axon body-worn cameras, and systems powered by Clearview AI's facial recognition technology.

Now, the model generates new pattern batches every minute. Each iteration, according to Swearingen, is mathematically superior to the last. The system continues to refine its output even after achieving perfect scores against its test suite.

Real-World Validation in Las Vegas

At the Def Con cybersecurity conference in Las Vegas on Friday, Swearingen ran his first public field test. Working with Donut Media, the team wrapped a 2009 Toyota Yaris in one of the newly generated patterns and drove it past a Flock camera to see if the detection system would register the vehicle.

The test succeeded. The camera failed to trigger an alert. Swearingen noted that the wheels presented a challenge, likely due to their curved surfaces and the difficulty of applying flat patterns to rotating objects. A full video of the demonstration is expected to be released in the coming weeks, according to Donut Media.

The successful demo offers early proof that adversarial patterns can work outside controlled lab environments. Surveillance cameras still record footage, but without detection triggers, the recordings become effectively unsearchable. A person or vehicle covered in the pattern returns to being a needle in a haystack until someone manually reviews the footage and knows where to look.

The Mechanics of Algorithmic Blindness

The patterns do not jam cameras or interfere with recording. Instead, they exploit the way detection algorithms parse visual information. Modern surveillance systems rely on neural networks trained to recognize specific features: the shape of a face, the rectangular outline of a license plate, the silhouette of a human body.

Adversarial patterns introduce visual noise that disrupts this recognition process. The camera sees and records everything, but the algorithm interprets the scene incorrectly. It might classify a person as background texture or fail to identify a vehicle as a vehicle at all.

This approach has precedent in machine learning research. Adversarial examples, inputs designed to fool neural networks, have been studied extensively in academic settings. What Swearingen has done is industrialize the process, creating a system that can generate effective adversarial patterns at scale and adapt them to specific real-world surveillance technologies.

The implications extend beyond individual privacy. If adversarial patterns become widely available, they could undermine the economic and operational model of surveillance-as-a-service companies that rely on automated detection to deliver value to law enforcement and private clients.

Patterns as Protest Infrastructure

Swearingen frames his work in terms of opting out. He argues that people never consented to pervasive surveillance, just as they never consented to having their driver's license photos used for facial recognition databases. The patterns offer a technical mechanism to withdraw from a system that treats public visibility as automatic consent to tracking.

The project has launched a crowdsourcing campaign to fund early merchandise, including T-shirts and hoodies printed with the patterns. Swearingen says the goal is to produce high-resolution prints that remain effective at a distance while also being aesthetically wearable. Vehicle wraps and skins are potential future products.

He is withholding his most effective patterns from public release to prevent surveillance companies from training their algorithms to defeat them. The arms race dynamic is built into the project's design. As companies adapt, Swearingen's model will continue generating new patterns, iterating faster than manual countermeasures can be deployed.

The project raises questions about who gets to be invisible in public space. Swearingen acknowledged his own position of relative safety when considering protest attendance. For others, marginalized communities, activists, or people targeted by state or non-state actors, the stakes are higher. Adversarial patterns could function as protest infrastructure, a layer of technical protection for people exercising rights that should not require protection in the first place.

The Limits and Future of Counter-Surveillance

The Def Con demo also exposed practical constraints. Wheels were difficult to cover effectively, suggesting that complex geometries or moving parts may require different pattern strategies. The patterns work against the 11 algorithms Swearingen tested, but surveillance ecosystems are fragmented. Proprietary systems, especially those developed by large government contractors or tech companies, may use detection methods not represented in open-source models.

There is also the question of legal and social acceptance. Wearing adversarial patterns is not illegal, but it could attract attention or suspicion in contexts where blending in is the safer strategy. The patterns are a form of visible resistance, which may not align with every threat model.

Still, the project represents a shift in the counter-surveillance landscape. Earlier efforts relied on physical obfuscation, like masks or reflective materials, or on fashion that happened to confuse early facial recognition systems. Swearingen's approach is algorithmic and adaptive, designed to evolve alongside the surveillance technologies it opposes.

At DailyTechWire, we've tracked the proliferation of AI-powered surveillance across Asia and the West, from license plate networks in American suburbs to facial recognition gates in Southeast Asian transit hubs. The technology has outpaced public debate about consent, accuracy, and accountability. Projects like noRecognition won't resolve those debates, but they do redistribute some technical power back to individuals who want to move through public space without being logged, analyzed, and stored.

Read next
AI

When Testing Becomes the Threat: AI Models Break Free From Cyber Evaluations

Arjun S. Mehta · 8 min
AI

GPT-Live Changes the Rhythm of AI Conversations

Arjun S. Mehta · 5 min
AI

Anthropic Chooses Automation Over Human Oversight in Claude Code Rollout

Arjun S. Mehta · 4 min
Spot something wrong? Email corrections@dailytechwire.com. We log every correction publicly.