A cybersecurity researcher covered a Toyota in an AI-generated pattern to confuse Flock cameras

Skye Jacobs

Posts: 2,083   +61
Staff
What just happened? Bill Swearingen's noRecognition project is testing whether computer-generated patterns can interfere with software used to identify people, vehicles, and other objects on surveillance cameras. The project received its first public test Friday at the Def Con cybersecurity conference in Las Vegas. Swearingen worked with Donut Media to cover a 2009 Toyota Yaris with one of his patterns and drive it past a Flock camera. "We proved it was effective," Swearingen, a cybersecurity professional and founder of SIXCYBER, told TechCrunch.

Donut Media plans to release video of the test in the coming weeks.

The pattern does not stop a camera from recording. Instead, it is designed to prevent the software connected to the camera from recognizing what it sees. A person or car wearing the pattern would still appear in the footage, but the detection system may not flag it as a person or vehicle.

That is the central idea behind noRecognition. Swearingen wants to make it harder for automated camera systems to track people in public spaces. He said the project is intended to give people a way to "opt out of being tracked."

"Privacy is a fundamental right," Swearingen said.

Swearingen has spent the past year building and testing the system from his home in Kansas City. He said he has run about 31 million tests so far. The work began as a small test lab aimed at defeating individual open-source object-detection algorithms. It later evolved into a reinforcement learning model that can generate and improve patterns on its own.

He described the process as teaching the model "how to paint."

The model tests a pattern against camera-detection software. If the software can still identify the object covered by the pattern, the system adjusts it and tries again. Over time, it learns which visual elements are more likely to confuse the algorithms.

Swearingen said the model has produced patterns that can defeat all 11 open-source detection algorithms he tested. Those include software used in systems associated with Flock license plate readers, Axon body cameras, and Clearview AI. He said the model now produces new patterns every minute, adding that each unsuccessful test gives it more data and allows it to generate more effective patterns over time.

The technology falls into a category often called adversarial machine learning. It relies on the fact that computer-vision systems do not interpret images the same way people do. A pattern that looks like an unusual design to a person may cause a detection model to misclassify an object or fail to identify it altogether.

The approach differs from efforts to physically block cameras. noRecognition is not designed to hide someone from view or interfere with the camera itself. Instead, it targets the software layer that processes video, reads license plates, and identifies faces or objects.

That software has become a standard feature of many camera networks. Law enforcement agencies use it to search footage and identify vehicles or people of interest. Private companies and local governments also use automated detection tools across parking lots, streets, and other public places.

These systems can process far more video than a person could review manually. But they have also drawn scrutiny over errors and the consequences of inaccurate matches. Swearingen said his concerns about the spread of surveillance cameras helped motivate the project.

He said he noticed the density of cameras in his hometown of Kansas City and began thinking about how difficult it would be to avoid automated tracking. He also said he felt uneasy about attending a protest last year because of the possibility that cameras could track participants.

Artists and clothing makers have previously tried to develop designs that confuse facial-recognition systems. Swearingen said that work helped demonstrate that such methods were possible. His project focuses on using a model to create and refine patterns at a much larger scale.

noRecognition is also running a crowdfunding campaign for clothing printed with the patterns, including T-shirts and hoodies. Swearingen said vehicle skins could follow. He said the goal is to make the patterns large and clear enough to work at a distance without making the clothing impractical to wear or the skins impractical to use.

He is keeping his strongest patterns private for now, saying he does not want camera companies to quickly develop defenses against them.

Image credit: Donut Media

Permalink to story:

 
If your local, state, or federal government respected you as a human on any level, we wouldn't be reading this. I don't believe in a political truth, or any form of civic sports, but I do believe this is what it looks like for citizens to be taken advantage of. Feel however you want about that, just don't bother telling me about it.
 
The real problem is that the government requires every single car to have have a standard, clearly visible ID code on the back (and usually front), and can have police pull you over for obstructing that government mandated ID code. Its going to be quite difficult to spoof any camera system for long, since they will have that clear, intentionally easy to read ID code to look for. Really, license plates themselves are just gross privacy violations, its obnoxious that the government was able to get people to accept them without a fight.
 
Last edited:
If your local, state, or federal government respected you as a human on any level, we wouldn't be reading this. I don't believe in a political truth, or any form of civic sports, but I do believe this is what it looks like for citizens to be taken advantage of. Feel however you want about that, just don't bother telling me about it.
If you don't want people providing opinions on your opinion, probably a better idea to keep them to yourself instead of broadcasting them on a public forum.
The real problem is that the government requires every single car to have have a standard, clearly visible ID code on the back (and usually front), and can have police pull you over for obstructing that government mandated ID code. Its going to be quite difficult to spoof any camera system for long, since they will have that clear, intentionally easy to read ID code to look for. Really, license plates themselves are just gross privacy violations, its obnoxious that the government was able to get people to accept them without a fight.
Almost like driving is a privilege, not a right, and you have no right to privacy in a public space to begin with.
 
This is ridiculous nonsense.
A "cybersecurity professional" should know that if this ever becomes a problem (which it will not, of course), the scanner algorithms can be updated to handle it in no time.

The above is not a comment on Flock cameras, I'm no fan of surveillance. The vast majority of vehicles can be reliably tracked without cameras anyway. Just the idea is technically stupid.
 
DeNuvo.
Cant wait till tomorrow when it will be hacked, bypassed, etc.
Then, here we go again.
It's not only that.
"A person or car wearing the pattern would still appear in the footage, but the detection system may not flag it as a person or vehicle."
If you masquerade your car so that it can't be flagged as vehicle, a self-driving car may not recognize it as another car it should account for when maneuvering. This puts everyone around at risk.
I really wish there were less people like this "researcher" who act first and (eventually) think later.
 
Almost like driving is a privilege, not a right, and you have no right to privacy in a public space to begin with.
Just because driving is considered a "privilege" (that whole idea itself needs a rethink, imho) does not mean we should have to purposefully make it easy for others to identify us. You can still have drivers licenses and car registration without requiring easily visible and trackable ID tags on cars. There is a gigantic difference between saying its okay to monitor what is going on in public spaces, and saying that people need to be required to make it easy to monitor them in public. Might as well just skip the ugly license plates and require everyone to have a GPS tracker in their car, if you think it is okay to force people to make themselves easier to monitor.
 
Back