Skip to content

The pattern that blinds surveillance cameras: 31 million tests to beat eleven algorithms at once

1 min read
Share
The pattern that blinds surveillance cameras: 31 million tests to beat eleven algorithms at once

One researcher spent a year and ran over 31 million tests to arrive at something that sounds made up: a pattern that confuses surveillance cameras to the point where they stop recognising a person, a vehicle or a face beneath it. Bill Swearingen called the project noRecognition, and at the Def Con security conference in Las Vegas he demonstrated it on his own car - a 2009 Toyota Yaris.

It matters to understand what the pattern actually does, because it is not an invisibility cloak. The camera keeps recording. What stops working is the algorithm that is supposed to draw a conclusion from the footage - that the thing over there is a car, that this is a licence plate, that that shape is a human face. Swearingen describes it with an image that carries the whole point: a person becomes a „needle in a haystack" again.

How he arrived at the pattern is what makes this story different from the classic privacy tricks. This is not somebody who found a flaw and exploited it. Swearingen used reinforcement learning - he let a model generate patterns, test them against open source recognition algorithms, see what got through and what did not, and did that millions of times until it was trained. In the end a single pattern was working simultaneously against eleven different algorithms, among them the software behind Flock's licence plate readers, Axon's body cameras and Clearview AI's systems. Those are, to be precise, some of the most widely deployed automatic recognition systems in use today.

The Las Vegas demonstration worked - Flock's cameras did not recognise the vehicle. Swearingen admits the wheels were a problem during testing, which is the sentence that convinces you the man actually did this rather than just recounting it.

What follows is more interesting than the technology itself. Swearingen deliberately does not publish his most advanced patterns. The reason is practical, not mysterious: the moment camera manufacturers see them, they will start teaching their systems to recognise them. So the weaker version goes public, while the model that keeps retraining produces stronger ones. It is a race in which every published success is also a manual for the other side - the same mechanism that has kept cybersecurity moving for thirty years.

The project meanwhile has a commercial side too: a crowdfunding campaign selling clothing with the patterns, with vehicle stickers planned. „Privacy is a basic right," Swearingen says, explaining that it is about a person's ability to „opt out of being tracked".

That sentence is exactly where the story touches us as well. Automatic recognition of licence plates and faces has long stopped being something that exists only in American cities - cameras are cheap, the software is bought off the shelf, and the question of who watches the footage and how long they keep it rarely gets a clear answer from any operator. Swearingen's answer is technical: if a system was installed without your consent, make yourself illegible to it. Whether that is a solution or merely a better position in an endless race is another question.