In brief - Bill Swearingen’s noRecognition project generates patterns that stop camera software from classifying what it covers—people, faces, or cars. - The patterns defeated all 11 open-source detection algorithms he tested, including the software behind Flock license plate readers, Axon body cameras, and Clearview AI. - The first public test came Friday at Def Con in Las Vegas: a 2009 Toyota Yaris wrapped in the pattern, driven past a Flock camera. Bill Swearingen spent the past year running one experiment over and over from his home in Kansas City, where he co-founded the SecKC security meetup. About 31 million tests later, he says he can produce patterns on demand that hide whatever they cover from the detection software wired into Flock cameras—the controversial surveillance system being rolled out across America. He showed it in public for the first time Friday at Def Con, working with the YouTube channel Donut Media to cover a 2009 Toyota Yaris in one of his newest patterns and roll it past a Flock camera. “We proved it was effective,” Swearingen told TechCrunch, though he said the wheels were a challenge. Donut Media said video of the demo lands in the next few weeks. The pattern doesn’t blind the camera. Footage still records normally, and a human watching the screen sees a car. What breaks is the layer on top—the object-detection model that decides “that’s a vehicle, that’s a plate, log it.” So basically, feed an AI detector with enough visual noise engineered against its own math and it logs nothing. The car goes back to being a needle in a haystack. That’s adversarial machine learning, and it works because computer vision doesn’t see what you see. A wrap that reads as loud graphic design to a person can read as nothing at all to
The AI-Generated <b>Pattern</b> Hides You From Surveillance Cameras—Including Flock
Read the original article
decrypt.co →