
A patterned 2009 Toyota Yaris drove past a Flock surveillance camera at DEF CON on Friday and, according to researcher Bill Swearingen, avoided the system's automated detection. TechCrunch describes it as noRecognition's first public physical-camera test. The result is narrower than a car or person becoming invisible: the camera still recorded footage, while the demonstration video and logs are not public. TechCrunch is the only detailed public account we found.
The distinction matters because the project's own research dashboard labels its published benchmarks digital and simulated. They test rendered patterns against detector software, including weights extracted from a deployed camera, but they are not measurements of printed fabric or a vehicle under uncontrolled outdoor conditions. The Las Vegas drive-by is therefore an intriguing lead, not yet a reproducible result. The evidence has to be read detector by detector and condition by condition.
- The field resultA Toyota Yaris wrapped in a generated pattern reportedly passed one Flock camera without triggering the expected automated detection.
- The evidence gapNo public demo video, alert log, control run or repeated physical-test dataset is available yet.
- The benchmarkThe project's strongest published percentages are held-out digital simulations, not printed-fabric or real-camera measurements.
- The next standardRepeated independent trials across cameras, light, distance, angles and controls are needed before the pattern can support a dependable privacy claim.
What happened in Las Vegas
Swearingen presented the work at Black Hat on August 6 in a briefing titled “Could a Pattern on Your Clothing Fool Facial Recognition?”. TechCrunch reports that the first public physical test followed on Friday at DEF CON. With help from Donut Media, the team covered the Yaris in a newly generated pattern and drove it past a Flock camera. Swearingen said the attempt was effective, although the wheels complicated the design. Donut Media expects to publish video in the coming weeks.
That account establishes three things: a particular pattern was printed, a particular vehicle encountered a particular camera, and the researcher says the expected alert did not appear. It does not tell readers how many passes were attempted, how the camera was configured, whether a plain control vehicle was run on the same route, or whether the result survived changes in distance, direction, speed and light. There is no raw footage, event log or independent observer's dataset to examine.
Nor did the camera stop recording. The reported effect concerns the automated layer that identifies an object and raises an alert. A missed machine detection can make footage harder to find in a large archive, but a person reviewing the correct time and camera could still see the vehicle. That is why “camouflage” is a better description than “invisibility,” and why the distinction between a camera, a detector and an alerting system should stay explicit.
The published numbers come from simulation
noRecognition says its evaluation spans 11 detectors. One of them, identified as f-YOLOv5, uses weights extracted from a production person detector in a deployed surveillance camera. Testing the literal weights avoids one common weakness in adversarial research: optimizing against a substitute model that behaves differently from the target. The project reports 61.7% non-detection, or 148 misses in 240 held-out trials, for a full-garment digital pattern against that model at its chosen detection threshold.
A second YOLOv5 setup reached 90% held-out non-detection in the project's digital tests. A ResNet34-SSD target, called P4, had resisted earlier methods but later reached 62.5%, or 20 misses in 32 held-out trials, when the pattern occupied a wide portion of the image. The dashboard says thinner coverings remain constrained by a measured coverage floor of roughly 5% to 6% of the frame. Those details are more informative than a single success percentage because they show the attack's dependence on architecture and visual footprint.
They also cut against the broadest interpretation of the project. Its stated goal is one pattern that defeats every detector, yet the dashboard says a single flat-ink tile that beats all 11 simultaneously has not been demonstrated. P4 was a documented wall until July, and its current 62.5% result depends on a wide footprint. The official language is notably more cautious than a claim that one recipe can defeat the entire surveillance stack.
The hard part is transferring from pixels to streets
Adversarial patterns exploit how a model converts pixels into features and confidence scores. In a digital test, researchers can control the image transformation, detector weights, threshold, scale and crop. Printing introduces a chain of new variables: the printer's color gamut, ink reflectance, material texture, folds, seams and the way a pattern bends around a moving body or vehicle. A camera adds lens distortion, exposure, compression, rain, glare and motion blur. Distance can reduce a carefully designed patch to a handful of altered pixels.
This gap is familiar in adversarial-machine-learning research. A 2019 paper on patches designed to attack person detection showed that physical transfer is possible, but it also treated robustness across transformations as the central engineering problem. A pattern that succeeds in one view can fail after a small change in angle or scale. A result against known, white-box weights can also collapse when a vendor changes preprocessing or retrains the detector.
noRecognition deserves credit for reporting held-out trials, using same-coverage controls and publishing negative results. Those choices reduce some easy ways to exaggerate performance. They do not replace a physical test matrix. The public dashboard explicitly says physical fabric and real-camera validation is a later phase, while the strongest pattern images are withheld to slow vendor countermeasures. That may be a reasonable operational choice, but it makes independent reproduction impossible today.
There is another mismatch to resolve. The fresh report describes a vehicle test against a Flock camera, while the headline project is usually discussed as clothing that could defeat person or face recognition. Object detection, face detection, identity matching and license-plate recognition are different stages with different inputs and failure modes. Evidence that one vehicle was not automatically flagged does not establish that a printed shirt will suppress a person box, much less prevent a face match.
What convincing evidence would look like
A serious field evaluation would begin with a fixed protocol published before the results. It would name the camera hardware, firmware, detection threshold and alert rule; pre-register the patterns and controls; and run repeated passes across several cameras without tuning after each failure. The control should cover the same area with equally complex but non-adversarial artwork so that ordinary occlusion is not mistaken for an algorithmic effect.
The test set should vary daylight, night lighting, rain, viewing angle, distance, speed and camera compression. For clothing, it should include different bodies, sizes, poses and fabric motion. Researchers should report every pass, not only the best clip, and publish the denominator behind each success rate. Independent evaluators should hold back at least one detector and one physical environment until the final test.
Raw alert logs and synchronized video would let others separate a missed object box from a missed plate read or a downstream search failure. Confidence intervals would make small samples legible. A 20-of-32 result is suggestive, for example, but its uncertainty is materially wider than a rate built from hundreds of independent physical trials. The Friday demonstration may eventually supply some of this evidence; until the video and protocol appear, it cannot carry that weight.
The final test is durability. A vendor that sees a recurring visual signature can add it to training data, adjust preprocessing or ensemble multiple detector families. The project responds by generating new patterns, which points toward an arms race rather than a permanent cloak. Success should therefore be measured not only on launch day but after the target system has had a chance to adapt.
A privacy tool with a product incentive
The motivation is easy to understand. Automated license-plate readers turn ordinary video into searchable location records and alerts. The Electronic Frontier Foundation's ALPR overview explains how those systems capture plates with time and location metadata, then retain or distribute the resulting records. If a pattern reliably prevents the detection stage from firing, it can restore some of the search cost that automation removed.
TECHi has seen versions of this idea before. In 2013, an artist's anti-drone hoodie used reflective material to disrupt thermal surveillance. More recent disputes over facial recognition used for fraud prevention and the privacy implications of camera-equipped smart glasses show why people want a physical way to decline machine classification.
But noRecognition is also moving toward merchandise. Its Kickstarter campaign pitches shirts and hoodies using the patterns. That creates a higher evidence bar. A research prototype can be valuable because it exposes a model's weakness; a product implies that buyers can depend on that effect. Failure would be silent, and a wearer would have no reliable way to know which model watched them or whether the pattern still worked.
The finding matters even if the garment is not ready
The strongest conclusion available today is modest but important: the project's digital tests show that one production person-detector model is vulnerable under specified simulated conditions, while a separate physical vehicle test reportedly avoided Flock detection. Those are two different pieces of evidence. They justify independent testing, not a promise of reliable privacy in public spaces.
The project also exposes a governance problem. People subject to automated surveillance rarely know which detector is operating, what threshold it uses, how long events are retained or how errors are reviewed. A countermeasure inherits that opacity. Even a rigorously tested garment cannot guarantee protection against an undisclosed model, a software update or a second camera using a different architecture.
For now, the honest headline is the evidence gap. The public benchmarks are digital; the universal pattern remains unproven; the only reported physical result is a single vehicle demonstration whose video and quantitative results are still pending. If those materials arrive and repeated controlled tests hold up, noRecognition will have moved adversarial camouflage from a model demo toward a practical privacy technology. Until then, it has shown a promising crack in the detector, not a cloak.
FAQ
Frequently asked questions
What is noRecognition's AI camouflage?
It is a research project that uses computer-generated visual patterns intended to lower the confidence of person, face or vehicle detectors. The camera can still record footage; the proposed effect is a missed automated detection or alert.
Did the DEF CON test make a car invisible?
No. TechCrunch reports that a patterned Toyota Yaris did not trigger the expected detection from one Flock camera. The camera still recorded video, and the demonstration video, control runs and quantitative field results are not public yet.
Has noRecognition clothing been proven on real surveillance cameras?
Not by the evidence currently published. The project's dashboard labels its reported benchmark percentages digital and simulated. One physical vehicle test has been reported, but that does not establish how a printed garment performs across cameras and conditions.
Why can an adversarial pattern fail outside a lab?
Printing, fabric folds, lighting, distance, viewing angle, motion blur, compression and software updates all change the pixels a detector receives. A pattern optimized for known model weights may not transfer to another detector or remain effective after retraining.
About the Author
Zoha Imdad Ali covers crypto markets, protocol-level developments, and the Web3 projects that survive their own airdrops. She watches on-chain analytics from Glassnode and Nansen, spot ETF flows from Farside, and the governance votes that actually shift protocol economics. Her reporting separates speculation from substance: distinguishing narrative-driven pumps from accumulation patterns, and treating token launches with the skepticism the category has earned.



