cd /news/computer-vision/can-adversarial-fashion-actually-tri… · home topics computer-vision article
[ARTICLE · art-129242] src=promptcube3.com ↗ pub= topic=computer-vision verified=true sentiment=· neutral

Can adversarial fashion actually trick AI cameras?

Adversarial fashion uses specific patterns and silhouettes to lower the confidence scores of object detection models or force them to misclassify humans as animals or objects, according to reporting on the practice. In 2025, Bill Swearingen used a Python-based fuzzer to find vulnerabilities in the YOLO object detection framework, then scaled it into a reinforcement learning algorithm whose geometric patterns he tested against 11 object detection models — five detecting people, four searching for faces, and two recognizing faces — dropping confidence scores low enough that systems failed to detect a human presence. Companies including Cap_able, which uses a patented jacquard knitting method targeting fast convolutional neural networks, and Urban Privacy, whose Faception Reloaded collection uses black-and-white abstracted-face prints to trick OpenCV-based facial recognition, are now commercializing the approach.

read3 min views2 publishedSep 14, 2026
Can adversarial fashion actually trick AI cameras?
Image: Promptcube3 (auto-discovered)

Adversarial fashion uses specific patterns and silhouettes to lower the confidence scores of object detection models or force them to misclassify humans as animals or objects. While some people fight surveillance by mapping automated license plate readers (ALPRs) through projects like DeFlock or even vandalizing hardware, others are using reinforcement learning to create wearable "noise" that confuses computer vision.

How these patterns break object detection #

The technical side of this comes from exploiting how models process visual data. In 2025, Bill Swearingen used a Python-based fuzzer to find vulnerabilities in the YOLO object detection framework. He later scaled this into a reinforcement learning algorithm to generate geometric patterns designed to thwart AI.

Swearingen tested these patterns against 11 different object detection models, including five that detect people, four that search for faces, and two that recognize faces. The result is a set of colorful abstractions that can drop a model's confidence score so low that the system fails to detect a human presence entirely.

Which brands are applying this to clothing? #

Several companies are moving these patterns from digital simulations to physical garments:

  • Cap_able: They use a patented jacquard knitting method to weave bold motifs into sustainable fabrics. These designs specifically target fast convolutional neural networks, which can lead the AI to misclassify the wearer as an object or an animal.
  • Urban Privacy: Their Faception Reloaded collection uses black-and-white prints based on abstracted human faces. These are designed to trick OpenCV-based facial recognition by appearing as "extra" faces, which slows down the detection process. They also use asymmetrical cuts and wide silhouettes to mask a person's gait and body shape.

The evolution from DIY projects to industry #

This isn't entirely new, but it's becoming more commercialized. Back in the 2010s, Adam Harvey created makeup and hairstyles to foil face detectors and developed heat-reflecting clothing to hide from thermal drones. In 2019, Kate Bertash launched a line featuring fake license plate numbers specifically to inject junk data into ALPR databases.

We've moved from these experimental art pieces to a small industry where people can buy their way into privacy. As Niloofar Mireshghallah from Carnegie Mellon University points out, wearing a garment is a tangible way to signal a lack of consent for data capture, whereas waiting for policy changes is a much slower process.

The "noRecognition" project, which appeared at the recent DEF CON hacker convention, shows that the community is still pushing the boundaries of how to create "false data" in the physical world. It's not an invisibility cloak, but it's a way to degrade the quality of the data these cameras collect.

Next Stop treating LLMs like magic and start treating them like software →

All Replies (2) #

I want to try this tonight. I used an infrared-reflective fabric once and it barely tripped the 400 series sensors.

This burned me during a project with YOLOv8. My custom patterns barely worked against the newer 1080p feeds.

── more in #computer-vision 4 stories · sorted by recency
── more on @bill swearingen 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/can-adversarial-fash…] indexed:0 read:3min 2026-09-14 ·