AI-Generated Patterns Can Confuse Surveillance Cameras

AI-Generated Patterns Can Confuse Surveillance Cameras

A cybersecurity researcher has demonstrated how AI-generated visual patterns can interfere with computer-vision systems used by surveillance cameras. Bill Swearingen, founder of SIXCYBER, developed the noRecognition project to explore whether specially generated designs could prevent automated systems from correctly identifying people, vehicles, and other objects. At the DEF CON cybersecurity conference in Las Vegas, a 2009 Toyota Yaris covered with one of the patterns was driven past a Flock camera, and Swearingen said the test successfully disrupted the system's ability to recognize the vehicle.

The system does not physically block or damage the camera. Instead, it targets the software that interprets the camera's images. Swearingen has used reinforcement learning to generate patterns, repeatedly testing them against object-detection algorithms and modifying unsuccessful designs. He says the system has conducted around 31 million tests and has produced patterns capable of defeating all 11 open-source detection algorithms he tested, including software associated with Flock license-plate readers, Axon body cameras, and Clearview AI.

This technique is an example of adversarial machine learning, in which carefully designed inputs cause an AI vision system to make mistakes that a human observer would not necessarily make. A pattern can appear simply unusual or artistic to a person while causing an AI model to misclassify an object or fail to recognize it. Unlike traditional methods of avoiding surveillance, such as physically covering a camera, the noRecognition approach attempts to exploit weaknesses in the algorithm itself.

The project raises an important debate about privacy versus the reliability of automated surveillance. Swearingen describes the technology as a way for people to opt out of automated tracking in public spaces, while the same research demonstrates that computer-vision systems can potentially be manipulated. The project therefore highlights an emerging security problem: as AI becomes more deeply embedded in surveillance infrastructure, researchers can use AI itself to find ways around those systems. This creates a continuing technological contest between better detection algorithms and increasingly sophisticated adversarial techniques.

About the author

TOOLHUNT

Effortlessly find the right tools for the job.

TOOLHUNT

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to TOOLHUNT.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.