Crypto

Flock camera AI camouflage test shows limits of surveillance evasion claims

A DEF CON test put an AI-generated wrap on a Toyota near a Flock camera, but it targeted software detection, not video recording.

Dev Ramirez

By Dev Ramirez · Crypto Correspondent

· 3 min read

Flock camera AI camouflage test shows limits of surveillance evasion claims
Photo: Decrypt

A Flock camera AI camouflage test at the DEF CON cybersecurity conference put a computer-generated pattern on a 2009 Toyota Yaris and drove it past a Flock surveillance camera. Researcher Bill Swearingen says the test showed the wrap could disrupt the system’s automated detection. For anyone following the growth of AI-powered cameras, the key detail is narrower than “invisibility”: the camera can still capture footage, while its software may fail to label what it sees.

Swearingen’s project, called noRecognition, uses what researchers call adversarial patterns. These are visual designs made to confuse machine-learning systems that classify an image as containing a vehicle, a license plate, a face, or another object. TechCrunch reported that Swearingen spent about a year on the effort and said he ran roughly 31 million tests.

According to TechCrunch, Swearingen publicly demonstrated a vehicle pattern at DEF CON in Las Vegas. Yahoo Tech and Cybernews also reported that the test used a Toyota Yaris wrapped in the design and a Flock camera.

Does AI camouflage stop a Flock camera from recording?

No. The reported purpose is to interfere with the analysis software, not to block the camera lens or erase video. Camera systems can record large volumes of footage and use automated detection to flag vehicles, license plates, faces, or activity for review. Swearingen’s claimed approach aims to make the covered object harder for that classification layer to recognize, potentially preventing an alert from being triggered.

That distinction matters. Footage may remain available for a person to review if they know where and when to look, even if the automated system does not initially identify a car or person. Cybernews also cautioned that obscuring a license plate alone may not remove a vehicle from a broader surveillance system.

What the DEF CON demonstration does and does not establish

The Las Vegas test is a reported field demonstration, not independent proof that the designs work reliably across all cameras or conditions. Yahoo Tech noted that a single drive-by at a cybersecurity conference is not peer-reviewed research. Lighting, camera placement, viewing angles, and software or firmware changes could all affect results.

Swearingen has not publicly released his strongest patterns, according to Yahoo Tech, and independent researchers had not reviewed the withheld testing data. He has claimed that the designs defeated 11 open-source detection algorithms, including software associated with Flock, Axon body cameras, and Clearview AI. That claim remains Swearingen’s, rather than an independently verified finding.

Swearingen has described noRecognition as a privacy tool for opting out of automated tracking. The project was crowdfunding printed clothing and vehicle skins, Yahoo Tech reported. The available evidence supports a claim that one vehicle demonstration disrupted automated detection, while leaving larger claims about broadly evading surveillance cameras unresolved.

This story draws on original reporting from Decrypt.

More from Crypto

All Crypto