On Friday, at the Def Con cybersecurity conference in Las Vegas, security researcher Bill Swearingen successfully demonstrated “noRecognition”, a computer-generated pattern designed to prevent AI surveillance cameras and automatic licence plate readers from detecting people and vehicles, offering a new way to opt-out of persistent tracking.
After running more than 31 million computerised simulations over the past year, Swearingen has developed a system that generates bespoke designs on-demand. When printed onto clothing, decals, or objects, these patterns effectively block some of the most widely deployed automated surveillance systems from registering the presence of people or vehicles.
The initiative, dubbed noRecognition, aims to hand privacy back to individuals seeking to bypass the dragnet of automated algorithmic monitoring expanding across the globe.
Scrambling the algorithms of modern CCTV
Modern street cameras are no longer passive recording devices; they are heavily augmented with artificial intelligence. Today’s systems automatically track vehicle movements via licence plates and scan crowds using facial recognition software. However, these automated tools are far from flawless, often leading to wrongful detentions and disturbing errors. The underlying algorithms allow authorities to instantly sift through petabytes of video footage to isolate specific activities, turning public spaces into searchable databases.
Swearingen’s adversarial patterns do not disrupt the actual video recording. Instead, they confuse the camera’s object-recognition capabilities. Because the software fails to identify a human or a vehicle within the frame, it never triggers a detection alert. The target effectively blends back into the background noise of the footage, remaining invisible to automated filters unless a human operator manually reviews the tape.
“Privacy is a fundamental right,” Swearingen explained, framing the project as a practical tool for people wishing to opt-out of constant surveillance.
The inspiration: Reclaiming the right to protest
Based in Kansas City, where he co-founded the cybersecurity community group SecKC, Swearingen is deeply familiar with the systemic risks posed by modern surveillance networks. He noted that his own home city is densely packed with CCTV cameras, often positioned mere feet apart, capturing data on citizens who never consented to being tracked—just as they never consented to their driving licences being processed by facial recognition databases.
Acknowledging his privileged position as a middle-aged white man living in America’s heartland, Swearingen reflected on his motivation. Last year, he wanted to join a local protest but hesitated, concerned that the overwhelming network of cameras would permanently log his participation and track his movements. He realised that if he felt this anxiety, countless others—especially those from vulnerable communities—would feel even more deterred from exercising their democratic rights.

From a test lab to reinforcement learning
Efforts to bypass automated detection are not entirely new. Activists and artists have previously designed adversarial clothing lines and specialised eyewear to confuse facial recognition software, though with varying degrees of success. Swearingen’s work builds directly on these concepts, aiming for a highly systematic, industrial-scale solution.
The project began in a modest proof-of-concept lab, where Swearingen systematically targeted and bypassed open-source video detection algorithms one by one. Over twelve months, he expanded his computational resources, aided by members of the wider tech community who donated hardware to accelerate the project’s processing needs.
What started as manual testing evolved into a sophisticated reinforcement learning model. This self-training system constantly evaluates which visual elements successfully fool camera algorithms and which do not. Swearingen described the process as teaching the AI model “how to paint”.
Whenever a generated design failed to trick an algorithm, the system analysed the failure and adjusted the pattern, repeating this cycle millions of times until it could simultaneously blind multiple detection systems. The model eventually discovered optimal visual formulas capable of defeating all 11 of the open-source detection suites tested, including the algorithms that power Flock licence plate readers, Axon body cameras, and Clearview AI software. Today, the model outputs fresh, mathematically superior patterns every minute.
Putting the anti-AI pattern to the test
The real-world viability of these patterns was put to the test in Las Vegas. Partnering with automotive media outlet Donut Media, Swearingen wrapped a 2009 Toyota Yaris in one of his latest adversarial designs to see if it could evade detection by a commercial Flock camera system.
The test was a success, proving the vehicle could bypass automated detection, though Swearingen noted that the car’s exposed wheels presented a unique tracking challenge. Donut Media is scheduled to release a video documenting the full demonstration in the coming weeks.
With a successful live test completed, the focus is now on distribution. To fund the production of wearable items featuring the designs, the noRecognition project has launched a crowdfunding campaign. The initial product line will include high-quality T-shirts and hoodies, with plans to offer vehicle wraps in the future. Swearingen emphasises that the patterns are designed to be aesthetically appealing while maintaining the high resolution and contrast necessary to fool cameras from a distance.
To prevent surveillance manufacturers from updating their software to recognise and bypass his designs, Swearingen is keeping his most potent patterns offline. Meanwhile, his automated models continue to run, constantly generating new, more effective variations. “Every failure improves my model, and so the patterns keep getting better and better,” he said.

