Security researcher Bill Swearingen developed a reinforcement learning system called NoRecognition that generates computer printed adversarial patterns capable of hiding people, faces, and vehicles from AI powered sur... The broader 'adversarial clothing' movement — with brands like Cap able, Urban Privacy, and Voll...

Create a landscape editorial hero image for this Studio Global article: What algorithm and method did security researcher Bill Swearingen develop to create computer-printed patterns that hide people, faces, and v. Article summary: Security researcher Bill Swearingen developed a reinforcement learning system called **noRecognition** that generates adversarial, computer-printed patterns capable of hiding people, faces, and vehicles from AI-powered s. Topic tags: general, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fa
A security researcher has developed a system that generates computer-printed patterns capable of hiding people, faces, and vehicles from AI-powered surveillance cameras — and after 31 million tests, the patterns are making their way out of the lab and onto the street.
Security researcher Bill Swearingen calls the project NoRecognition. It uses a reinforcement learning approach — a genetic algorithm — that "breeds" adversarial textile patterns by testing millions of variations against AI detection models . The patterns don't block cameras from recording video, but they scramble the algorithm's ability to detect a person, face, or vehicle, preventing the system from triggering alerts
.
Swearingen's core method is a self-learning fuzzer that generates adversarial patterns and tests them against open-source object detection algorithms . Patterns that still trigger detection are modified and retested in an iterative loop. After about 31 million test iterations, the system converged on pattern variants that defeated all 11 AI surveillance models in Swearingen's test suite
.
"It's a genetic algorithm that breeds adversarial textile patterns, printed on ordinary fabric, that cause cascading failures across the full facial recognition pipeline — person detection, face detection, and identity match — with no electronics and nothing that reads as unusual to a person standing next to you," Swearingen said in a Black Hat preview .
Swearingen's project has been tested against and claims to defeat 11 different AI surveillance models, including:
Notably, Swearingen has stated his system tests against "the real models. Not academic benchmarks. The actual stuff running in Clearview AI, police body cameras, airport security" .
At the Def Con cybersecurity conference in Las Vegas on Friday, August 7, 2026, Swearingen conducted the first public real-world test of NoRecognition patterns . With help from automotive media outlet Donut Media, a 2009 Toyota Yaris was covered with the computer-generated pattern and driven past a Flock surveillance camera
.
According to Swearingen, the vehicle avoided the Flock system's automated detection — the camera did not trigger a detection alert . This marked the first time the patterns were validated against a physical camera in a live environment rather than in digital simulation
. However, independent reporters noted the demo was a single unblinded test, and broader peer-reviewed validation remains pending
.
A parallel movement called "adversarial clothing" or "adversarial fashion" has emerged as a mainstream trend alongside Swearingen's technical work .
The Guardian reported in July 2026 that designers are incorporating "adversarial patterns" — carefully arranged shapes, colors, and motifs — into garments specifically to confuse facial recognition AI . Brands like Cap_able, Urban Privacy, and Vollebak are producing clothing lines that claim to exploit weaknesses in computer vision models
.
Berlin-based artist Simon Weckert debuted a conceptual collection called "Digital Camouflage" — garments printed with generative adversarial patterns designed to prevent AI surveillance detection from any angle or fabric fold . The movement is described as "privacy could be the next big fashion trend," with wearers making a visible statement about the importance of privacy while potentially evading automated facial recognition
.
Cap_able, an Italian fashion startup, creates knitwear with adversarial patterns and constructs garments to be reversible, so the user can choose when they want to be detected by AI or not . Its patented process algorithmically develops adversarial patterns, creating what it calls "AI-camouflage"
.
The technology is not a silver bullet. Experts point to several important caveats:
NoRecognition represents one of the most rigorous attempts yet to create a practical, wearable defense against AI surveillance. With 31 million tests and a live demonstration against a Flock camera, the project has moved beyond academic proof-of-concept. But whether adversarial patterns can survive the arms race against rapidly evolving surveillance AI — and whether the broader adversarial fashion movement will deliver real privacy protection at scale — remains an open question.
As Swearingen himself put it, the core question is: "Can physical fabrics truly defeat state-of-the-art facial recognition in real-world conditions?" The answer, for now, is that they can — until the AI catches up.
Studio Global AI
Use this topic as a starting point for a fresh source-backed answer, then compare citations before you share it.
Security researcher Bill Swearingen developed a reinforcement learning system called NoRecognition that generates computer printed adversarial patterns capable of hiding people, faces, and vehicles from AI powered sur...
Security researcher Bill Swearingen developed a reinforcement learning system called NoRecognition that generates computer printed adversarial patterns capable of hiding people, faces, and vehicles from AI powered sur... The broader 'adversarial clothing' movement — with brands like Cap able, Urban Privacy, and Vollebak — is turning anti surveillance patterns into mainstream fashion, as reported by The Guardian in July 2026.
Experts caution the patterns are model specific, vulnerable to retraining by surveillance companies, and have not been independently validated in peer reviewed real world tests, creating a classic adversarial arms race.