The AI-Generated Pattern Hides You From Surveillance Cameras—Including Flock Bill Swearingen's noRecognition project generates adversarial patterns that defeated all 11 open-source detection algorithms he tested, including software behind Flock license plate readers, Axon body cameras, and Clearview AI, based on about 31 million tests. The first public test at Def Con on Friday involved a 2009 Toyota Yaris wrapped in the pattern driven past a Flock camera, which Swearingen said proved effective. Swearingen, co-founder of the SecKC security meetup, built the patterns with a reinforcement learning model and keeps the strongest ones offline to prevent camera vendors from training against them. In brief - Bill Swearingen’s noRecognition project generates patterns that stop camera software from classifying what it covers—people, faces, or cars. - The patterns defeated all 11 open-source detection algorithms he tested, including the software behind Flock license plate readers, Axon body cameras, and Clearview AI. - The first public test came Friday at Def Con in Las Vegas: a 2009 Toyota Yaris wrapped in the pattern, driven past a Flock camera. Bill Swearingen spent the past year running one experiment over and over from his home in Kansas City, where he co-founded the SecKC https://www.seckc.org/ security meetup. About 31 million tests later, he says he can produce patterns on demand that hide whatever they cover from the detection software wired into Flock cameras—the controversial surveillance system being rolled out across America. He showed it in public for the first time Friday at Def Con, working with the YouTube channel Donut Media https://www.youtube.com/@donut to cover a 2009 Toyota Yaris in one of his newest patterns and roll it past a Flock camera. “We proved it was effective,” Swearingen told TechCrunch https://techcrunch.com/2026/08/09/this-adversarial-pattern-can-prevent-surveillance-cameras-from-detecting-you/ , though he said the wheels were a challenge. Donut Media said video of the demo lands in the next few weeks. The pattern doesn’t blind the camera. Footage still records normally, and a human watching the screen sees a car. What breaks is the layer on top—the object-detection model that decides “that’s a vehicle, that’s a plate, log it.” So basically, feed an AI detector with enough visual noise engineered against its own math and it logs nothing. The car goes back to being a needle in a haystack. That’s adversarial machine learning, and it works because computer vision doesn’t see what you see. A wrap that reads as loud graphic design to a person can read as nothing at all to a classifier. Swearingen built it with a reinforcement learning model that grades its own homework. Pattern gets detected, model adjusts, tries again—what he described as teaching the model “how to paint.” It now spits out fresh patterns every minute, and he’s keeping the strongest ones offline so camera vendors can’t train against them. “Privacy is a fundamental right,” he said, calling the patterns a way for people to “opt out of being tracked.” He said the idea took hold last year when he wanted to attend a protest and worried about the cameras logging everyone who showed up. The long tail of hiding from machines People have been improvising against detection systems for years, usually with hardware store solutions. San Francisco activists put traffic cones on the hoods https://www.theguardian.com/technology/2023/jul/07/san-francisco-autonomous-cars-protest-cone of Waymo and Cruise robotaxis to freeze them in place, an exploit that needed no code at all. During last year’s Los Angeles immigration raids, protesters went further and torched several Waymos https://decrypt.co/324336/robotic-waymo-cars-torched-ice-protest-los-angeles . Masks, hoods, and brimmed caps remain the default on protest lines. Adversarial clothing labels https://www.theguardian.com/fashion/2026/jul/17/adversarial-clothing-are-garments-designed-to-confuse-facial-recognition-systems-about-to-go-mainstream have been selling face-confusing prints for years, and anti-recognition eyeglasses https://www.404media.co/zennis-anti-facial-recognition-glasses-are-eyewear-for-our-paranoid-age/ have arrived with thin evidence they do much. What separates Swearingen’s project, which he calls noRecognition, is the target list. Swearingen tested against the specific stacks in wide deployment, and Flock is the one drawing heat. The company is facing a growing backlash on Capitol Hill https://decrypt.co/374603/flock-cameras-backlash-privacy-concerns-capitol-hill , and internal documents show it pitched a plan to turn 350,000 Uber and Lyft dashcams https://decrypt.co/375149/flock-cameras-uber-drivers-nationwide-plate-scanning-fleet into a rolling plate-scanning fleet. Automated readers have already pulled over innocent drivers at gunpoint https://ij.org/dozens-of-innocent-motorists-have-been-pulled-over-detained-at-gunpoint-or-jailed-due-to-ai-license-plate-camera-errors/ over bad matches, and immigrants and protesters keep getting swept into ICE’s AI dragnet https://decrypt.co/325003/how-immigrants-and-protesters-are-being-caught-in-ices-ai-dragnet . Lawmakers are pressing Meta over facial recognition in its smart glasses https://decrypt.co/361477/democrats-press-meta-facial-recognition-plans-smart-glasses on a parallel track, so any legal measure to fight against automatic detection technology is being studied by privacy enthusiasts. Swearingen’s noRecognition project is running a crowdfunding campaign https://www.kickstarter.com/projects/norecognition/norecognition-ai-adversarial-clothing to fund early merchandise—T-shirts and hoodies now, vehicle skins later. Swearingen said the goal is resolution high enough to work at a distance and design good enough that people will actually wear it. Driving a wrapped car on public roads is its own legal question, and plate obstruction statutes vary by state. The patterns cover bodywork, not plates. “Every failure improves my model, and so the patterns keep getting better and better,” Swearingen said.