Key takeaways

  • AI-powered cameras dot streets across the world, equipped with the power to identify faces or vehicle license plates.
  • Some people resort to extreme measures, such as vandalizing or damaging ALPRs.
  • The fuzzer targeted one of the most popular object detection frameworks, called YOLO.

What happened

AI-powered cameras dot streets across the world, equipped with the power to identify faces or vehicle license plates. But a public backlash is gaining momentum. Privacy concerns abound, encompassing the lack of consent for capturing data, how that data is stored and used, and the risk of misuse. Those concerns are motivating people to fight back. The DeFlock project, for instance, maps automated license plate readers (ALPRs) to raise awareness.

noRecognition Anti-surveillance fashion can trace its roots to the art pieces, DIY projects, and thought experiments that emerged in response to the onset of AI surveillance systems more than a decade ago. For instance, technologist Adam Harvey developed multiple designs in the 2010s—from hairstyles and makeup that foil face detectors to heat-reflecting attire that avert drone-enabled thermal surveillance.

In 2019, artist and activist Kate Bertash created her aptly named Adversarial Fashion clothing line decked with fake license plate numbers to inject junk data into ALPR databases. The trend is now growing into a more solidified small industry. “Clothing is something you can actually buy and put on, unlike policy,” says Niloofar Mireshghallah, incoming professor of engineering and public policy at Carnegie Mellon University.

’” But real-world conditions might reduce the effectiveness of countersurveillance clothing, such as camera angles, lighting, and how fabric folds as you move. “One good frame is all a system needs,” Mireshghallah says. Motion and gait recognition are also influential factors. “Even if the camera thinks you’re a bear for a few frames, there’s a bear walking like you,” Mireshghallah says.

“It remains a fragile shield against a threat that is constantly improving from multiple angles,” says Dippu Kumar Singh, senior director of emerging data and analytics at Fujitsu North America who specializes in vision AI and AI ethics. Makers are aware of their creations’ limitations. “It’s not an invisibility cloak,” Preuß says. “Surveillance aims to capture your identity, and fashion is about expressing your identity.

” Even with these hurdles, Cap_able’s Didero is determined to keep innovating. Urban Privacy will continue to release other parts of its collection, including a “shadow cap” that has an acrylic face shield layered with cutouts to blur facial contours.

Why it matters

Some people resort to extreme measures, such as vandalizing or damaging ALPRs. Others are stitching together more creative responses, crafting “adversarial fashion” to evade surveillance cameras, like a Kickstarter project called noRecognition, presented at last month’s DEF CON hacker convention. In 2025, cybersecurity expert Bill Swearingen began experimenting with a simple Python-based fuzzer, a tool that provides invalid inputs to reveal software bugs, security vulnerabilities, or unexpected behavior.

The fuzzer targeted one of the most popular object detection frameworks, called YOLO. He then developed what he’d learned into a reinforcement learning algorithm that generates various adversarial patterns, which he presented at DEF CON. Each pattern is a colorful geometric abstraction he has tested against 11 object detection models—four that search faces, two that recognize faces, and five that detect people—most of which are publicly available.

Successful patterns thwart the object-detection systems, lowering their confidence scores, sometimes even to the point of no detection. “Privacy is a human right, and the popularity of this just goes to show that people are interested in preserving their privacy,” Swearingen says. Cap_able and Urban Privacy are already selling physical garments. Cap_able’s patented manufacturing method weaves its bright and bold motifs into jacquard knitted fabrics.

The ethically produced and sustainably made dresses, pants, and tops interfere with certain computer vision systems, particularly those backed by fast convolutional neural networks, which may lead them to classify wearers as animals or objects. “If we’re able to camouflage a person as something else, then we’re obtaining our goal,” says Cap_able founder Rachele Didero, who’s also an assistant professor at the Free University of Bozen-Bolzano in Italy.

” Meanwhile, Urban Privacy aims to baffle some facial recognition systems based on OpenCV algorithms with its latest Faception Reloaded collection. Black-and-white prints abstracted from a human face show up as additional faces on detectors, slowing them down. Asymmetrical cuts and wide silhouettes intend to conceal, making it harder to discern your body’s shape and gait. “The idea is to create false data,” says cofounder Daniel Preuß.

What to watch

The adversarial patterns must also be tuned to specific object recognition models, so they cannot resist a different model. And once surveillance system operators train a future generation of models on a given adversarial pattern and the person wearing it, which they could do manually, clothing will no longer be a sufficient defense.