The Camouflage Hoodie: What People Buy When Privacy Law Fails

The Kickstarter had a day left to run, closing on 5 September 2026, and by 4 September had taken $194,103. The goal was $5,000. One thousand one hundred and thirty-eight people had pledged money for a T-shirt, a hoodie and a neck gaiter printed with patterns that a computer bred, over roughly thirty-one million attempts, to make the machines that watch pavements fail to notice a human body is standing there.
The man behind it is Bill Swearingen, a Kansas City security professional who spent decades on red teams and as a chief information security officer before turning his attention to the cameras. He unveiled the project, called noRecognition, at DEF CON 34 in Las Vegas in early August 2026, and presented the underlying research at Black Hat USA the same week. On 31 August he sat down with Tom Eston for the Shared Security Podcast to explain what the patterns do, what they do not do, and why person detection and facial recognition are not the same problem.
The opening slide of his DEF CON deck reads: “Today, over 100 cameras logged your beautiful face. You didn't opt in. You can't opt out.”
That sentence is the entire commercial proposition, and it is the thing worth sitting with. Not the algorithm. Not the fabric. The fact that more than eleven hundred people, in a month, decided the most practical response to being biometrically catalogued in public was to buy a garment.
There is a version of this story that is a gadget story. Clever hacker beats the cameras, here is where to buy the shirt. TechCrunch reported the project in August, noting Swearingen's claim to have run more than 31 million tests against eleven detection systems. Dark Reading described how he pulled models out of actual camera hardware and worked through a series of dead ends, including shirts printed with text and shirts printed with dozens of human faces, before landing on dense geometric noise.
The more interesting story is what it means that the shirt exists at all, and what happens to the person wearing it when the pattern does not work.
A camera is just a parser
Swearingen's framing of the attack is the most useful thing in the deck, and it is worth restating precisely because it strips away the mystique.
“A camera is just a parser,” one slide reads. “It parses pixels into objects. Nothing more. Every parser in the history of computing has been exploitable when an attacker controls the input.”
The analogy he reaches for is SQL injection, which works because a database parser cannot reliably distinguish data from instructions. If you control what appears in front of the lens, you control the input. The question is whether you can control the output.
Consider what one of these parsers does. Swearingen pulled apart the model file shipped on Flock Safety cameras, the number plate reading hardware now deployed across thousands of American communities. The file, flock_yoloV5.tflite, produces an output tensor of shape 1 by 6300 by 13. One image per pass. Six thousand three hundred candidate boxes drawn from grids at three scales. Thirteen numbers per candidate: four box coordinates, one objectness score, and eight class scores covering person, car, truck, bus, trailer, motorcycle, bicycle and licence plate.
The plate reader was never bolted on afterwards. It is a class in the same output channel as “person”.
Of those thirteen numbers, one decides whether you exist. Objectness answers a single question: is there a thing here at all? The final score is objectness multiplied by the probability the thing is a person, and a box is drawn only if that product clears 0.75.
The adversarial pattern goes after that one scalar. The backbone of the network is an edge and texture detector trained on natural photographs, tuned for skin, cloth folds, hair and shadow. A dense, high-frequency, periodic print matches none of those filters. In the grid cells the garment covers, objectness collapses. Swearingen's measured example on a held-out identity: 0.91 clean, 0.28 with the pattern. Same body, same camera, same model, only the texture changed. Under the keep line, no box is drawn, so non-maximum suppression never runs, tracking never runs, and nothing is uploaded.
That is an elegant result, and a very specific one. It works on the family of detectors that stake everything on one objectness scalar. Swearingen is candid about where it stops. On single-shot detectors with 1,917 anchors, each running class against background, the garment reaches the torso boxes but the whole-body and background boxes still see you, and one surviving box keeps you detected. His slide title for this is blunt: “WHY SSD WALLS”.
Three machines, three different failures
The single most important correction in the whole project is one that costs nothing and almost nobody makes.
Person detection, face detection and facial recognition are three different capabilities answering three different questions. How many people are there. How many faces are there. Do we know this face. The first produces a count. The second produces a crop. Only the third produces an identity, and only the third can put your name on a watchlist hit.
They also have opposite economics. A person detector runs a low threshold, because in most deployments the cost of missing someone exceeds the cost of a spurious box. A face recogniser runs a high threshold, because a false match asserts that a specific human being is a specific other human being, and that error has a name and an address. Defeating one tells you nothing reliable about the others.
Almost every headline about anti-surveillance clothing collapses these three into “facial recognition”. So does almost every product description. The distinction matters to the buyer, because the noRecognition garments are tuned differently for different jobs. The gaiter targets face detection. The tee and hoodie target person detection. No single pattern wins everywhere.
The testing apparatus reflects that. Swearingen built what he calls a fuzzer: a system that generates candidate patterns, overlays them on standardised persona images and pushes them through an ensemble of models, logging anything that produces a failure or a dramatic confidence drop. The pattern library reached 61 distinct generators at version 0.9.8, from fractal noise to what he calls surgical attacks that locate facial landmarks and then place high-contrast patches on the nose or cheek, apply noise only to eyes and mouth, or stamp dozens of decoy eyes into the frame to overwhelm the bounding-box logic.
When a pattern produces an anomaly, its recipe is saved and used as a parent. The system mutates it, adding, removing or swapping layers, and splices successful recipes together. That is the genetic algorithm at the heart of the project. Patterns are bred, not designed.
The gauntlet each candidate runs started at ten models and grew to eleven when a fifth person detector was added in July 2026. Five person detectors, four face detectors, two recognition models. Across 31.7 million patterns tested, the system logged 534,600 anomalies, about 1.7 per cent. Of those, 480,700 fooled more than one model. Eighty-five qualified as extreme, which is 0.016 per cent of the anomalies and about one in every 373,000 patterns tested.
That last number is the honest shape of the research. Overwhelmingly, this does not work. Occasionally it works spectacularly.
What ninety-six point six six per cent actually measures
The figure that travels furthest in coverage of adversarial clothing comes from a 2021 paper by Alon Zolfi, Shai Avidan, Yuval Elovici and Asaf Shabtai, researchers at Ben-Gurion University of the Negev and Tel Aviv University. Their abstract reports that in real-world experiments, the face recognition system “was only able to identify 3.34% of the participants wearing the mask (compared to a minimum of 83.34% with other evaluated masks).”
Subtract, and you get 96.66 per cent, a striking number routinely repurposed as evidence that clothing defeats facial recognition.
Read the paper and three qualifications arrive at once. First, the object is a face mask, the surgical kind, worn over the nose and mouth. It is not a shirt. It occupies the most information-dense region of the face, which is why it works and why it does not generalise to a torso print. Second, the comparison is against other masks, not a bare face. The claim is that this printed mask is dramatically better at defeating recognition than an ordinary one, which is narrower and more interesting. Third, the evaluation was a CCTV use case run by the researchers. Photons went through a real lens, which is more than most of this literature can say, but it is not a measurement against a deployed commercial identification service on a street.
The other two papers in the current wave of coverage are similarly precise and similarly narrow. Zhanhao Hu and colleagues, in work accepted to CVPR 2023, used Voronoi diagrams and Gumbel-softmax optimisation with 3D mesh-based augmentation to produce clothing textures that look like ordinary camouflage, printed them on fabric, tailored them into garments and reported high attack success rates against multiple detectors at multiple viewing angles. Person detectors. Not recognition. The survey by Jiakai Wang and colleagues, cataloguing more than a hundred studies, is organised around the observation that physical adversarial examples acquire awkward properties through manufacturing and re-sampling that digital ones never face.
That gap has been measured. Jakob Shack, Katarina Petrovic and Olga Saukh, in a 2024 study bluntly titled “Breaking the Illusion”, varied patch size, position, rotation, brightness, hue and blur across digital and physical conditions. Geometric transformations behaved consistently across both worlds. Colour transformations did not. Even after aligning digital transformation parameters with measured real-world ones, they found discrepancies of up to 64 per cent in patch performance.
Sixty-four per cent is not a rounding error. It is the difference between a defence and a decoration.
The fabric has not been tested yet
Here is the part of the story that almost none of the coverage foregrounds, and which Swearingen himself put on a slide in front of a DEF CON audience.
Under the heading “WHERE THE PROOF STANDS”, the deck reads: “Digital, and held to a stricter bar than the field.” It describes sealed sweeps where training, selection and reporting are kept separate, more than 500 held-out personas unseen at training time across multiple view buckets, and a control most of this field skips entirely: every pattern must beat a solid black panel of the same geometry, or the result is discarded. Otherwise you are not measuring an adversarial effect, you are measuring the fact that you covered someone with a large opaque rectangle.
Then, immediately beneath: “LIVE FABRIC TESTING. Just begun. Printed fabric trials are under way. Nothing physical is claimed yet: the digital results above do not transfer until fabric passes the same occlusion-subtracted bar.”
Nothing physical is claimed yet.
That is the researcher, at the moment of maximum publicity, telling the room that the thing being crowdfunded has not yet been demonstrated on cloth. The Kickstarter is explicit that this is what the money is for: test fabrics, substrates, weaves and inks, a dye-sublimation printer so an iteration takes hours instead of weeks, and more fielded camera hardware so results are measured through real lenses rather than on a bench.
There has been one public demonstration outside the digital sweeps. At DEF CON on 7 August 2026 Swearingen held a flat rigid panel printed with the pattern in front of a live person-detection feed, running a model taken from a fielded Flock unit, and the confidence score fell. With the automotive outlet Donut Media he also had a 2009 Toyota Yaris wrapped in a generated pattern driven past a Flock camera, which by his account failed to register it. Reporters noted what the deck had already conceded: a single unblinded test, with broader peer-reviewed validation still pending. A rigid printed panel is not cloth on a moving body, and a car wrap is not a hoodie. The sentence about nothing physical being claimed refers to the garments, which are the things people are buying.
This is admirably honest. It is also a strange thing to sell more than a thousand people a garment on the back of. The buyer is funding the validation of the product they are buying. Both are true at once, and the gap between them is where most of the difficulty in this story lives.
Everyone who tried this before
Swearingen does not pretend to have invented the genre, and his deck contains a slide crediting the lineage that is more generous than most academic related-work sections.
Adam Harvey created CV Dazzle in 2010 as his master's thesis at NYU's Interactive Telecommunications Program: makeup and hair styling designed to break face detection while remaining perfectly legible to humans. It became the defining image of anti-surveillance aesthetics, reproduced in a thousand articles about the coming panopticon.
Harvey's own website is now the most rigorous debunking of Harvey's own work. The original looks targeted the Viola-Jones algorithm and its haar cascade classifiers, which he describes as unofficially deprecated since around 2016. He advises against using those patterns against newer systems. Convolutional networks, he notes, would require a different strategy entirely. He is careful to insist that CV Dazzle is a technique and not a specific pattern, that it must be customised to a particular algorithm and environment, and that lighting alone changes the outcome. Fifteen years on, the artist who made the most famous anti-facial-recognition object in the world says plainly that the object no longer works.
In 2017 Harvey collaborated with the interaction design studio Hyphen-Labs on HyperFace, a textile printed with decoy face patterns designed to saturate detectors with false candidates. Where CV Dazzle attacked the figure, HyperFace attacked the ground. It debuted at Sundance as part of Hyphen-Labs' NeuroSpeculative AfroFeminism project, which put the question of who gets watched, and how badly the machines perform on them, at the centre rather than the margin.
In 2019 Kate Rose launched Adversarial Fashion, garments printed to inject false plate reads into number plate recognition systems. In 2023 the Italian label Cap_able released its Manifesto knitwear, which Swearingen's slide records as claiming 60 per cent evasion against a single detector. Reflectacles sells infrared-blocking eyewear aimed at cameras and depth sensors.
And then the slide that should be pinned above every product page in the category, headed “THE MEASUREMENT GAP”: claims are typically measured against a single object detector, in sample, without a control. Of thirty published methods, according to the independent review he cites, twelve were ever tested against a real system.
Twelve out of thirty. The field's central problem is not that the attacks are impossible. It is that almost nobody checks properly.
Today's evasion is tomorrow's training data
Assume the fabric trials succeed. Assume a hoodie ships that reliably drops objectness below the keep line on a fielded camera in ordinary daylight. How long does that last?
Adversarial examples are not a permanent property of the physical world. They are a property of a specific model with specific weights. The moment a pattern is public, printed, photographed and posted, it becomes training data. Adversarial training, in which the defender fine-tunes on the attack, is the oldest and most boring countermeasure in machine learning, and it works well enough against fixed, published, printed patterns that any vendor with an engineering team and a quarterly release cycle should be expected to deploy it.
Swearingen understands this perfectly. It is why the strongest patterns are withheld from public release, according to TechCrunch's reporting: publishing them hands camera manufacturers the countermeasure. But that creates its own bind. A pattern that is secret cannot be independently verified. A pattern that is verified is on its way to being neutralised. There is no configuration of this problem in which the buyer gets both public proof and lasting protection.
The asymmetry is the point. Eleven hundred people bought a garment they will own for years. The other side ships a model update. One side of this exchange has a supply chain, a printing process and a wardrobe. The other has a continuous integration pipeline. When a single new detector entered Swearingen's gauntlet in July 2026, every persona had to be rescored against eleven models rather than ten, and research throughput fell in proportion. The defender's cost of adding a model is trivial. The attacker's cost of covering it is linear and painful.
The garment is a static artefact deployed against a moving target. Even in the best case, what you are buying is a pattern with an expiry date that nobody can tell you.
The pipeline does not care what you wear
Even a perfectly effective adversarial hoodie defeats exactly one modality. The surveillance stack has many.
Cloth-changing person re-identification is an entire research subfield built on the premise that people change their clothes, and it works precisely by extracting features that are independent of what you are wearing: body shape, gait, skeletal proportion. Gait is attractive to researchers exactly because it is harder to change than a jacket. Recent systems are evaluated on datasets deliberately constructed around substantial variation in clothing, carried objects and viewing angle. A garment that removes your bounding box from one camera does nothing about the walk that identifies you on the next.
Then there is everything that is not vision at all. Your phone announces itself. Your car is read by the same Flock model whose licence plate class sits in the same tensor as the person class, across a network the American Civil Liberties Union puts at more than 120,000 readers in at least 6,000 communities. Swearingen's slides cite 140,000 monthly police users. Your contactless payment timestamps you. Your travel card timestamps you. Your face is already in a driving licence database that police search.
Being unseen by one camera for one frame is not the same as being unidentified. Identification in 2026 is a joining operation across many weak signals, and the hoodie removes one of them, some of the time, at some angles, in some light.
This is the strongest argument against treating adversarial clothing as a defence, and it does not depend on the technology failing. It works even if the technology is perfect.
The problem with looking like you have something to hide
There is a second cost, and it is not technical.
A garment covered in dense, high-frequency geometric noise is not inconspicuous. It is one of the most conspicuous things a person can wear. The whole design constraint of CV Dazzle, which Harvey articulated fifteen years ago, is that it defeats machines while remaining perfectly legible to humans. That legibility cuts both ways. To a camera you may be an absence. To the officer watching the monitor, and to the operator who notices that the tracking box keeps dropping in the same place, you are the most interesting person on the street.
This is the signalling problem, and it inverts the entire purpose. Evasion that announces itself is not privacy. It is a flag.
The legal position sharpens it. In the United States, according to the International Center for Not-for-Profit Law, 23 states and the District of Columbia have statutes limiting face coverings in public, many written in the twentieth century and repeatedly used against protesters. The politics have become strange. California's Senate Bill 627, the No Secret Police Act, took effect on 1 January 2026 and banned most face coverings by federal immigration agents and local police. In February 2026 US District Judge Christina Snyder preliminarily enjoined the mask ban, holding that California does have the general power to stop federal officers covering their faces, but that SB 627 had exercised it discriminatorily, because it imposed no equivalent requirement on the state's own officers. The companion No Vigilantes Act, which requires non-uniformed officers to display an agency name and badge number, survived that round, the district court finding those identification requirements neutral and generally applicable. On 22 April 2026 the Ninth Circuit blocked that provision too, ruling 3-0 that it attempts to regulate the United States directly and so likely violates the Supremacy Clause: a state law directly regulating the conduct of the United States is void, in the panel's words, irrespective of whether the regulated activities are essential to federal functions. Both provisions are now enjoined pending further litigation, which makes this a suspension rather than a settled outcome. So the legislative moment that seeks to unmask the officer coexists with statutes that criminalise the masked citizen, and it is the unmasking laws that are blocked while the anti-mask statutes stand.
In England and Wales, Section 60AA of the Criminal Justice and Public Order Act 1994 lets an officer of inspector rank or above authorise, within a locality and for up to 24 hours, a power for any constable in uniform to require removal of any item the constable reasonably believes is being worn wholly or mainly to conceal identity. Refusal carries up to a month's imprisonment or a fine. Netpol's briefing on the power notes that the default position is that police cannot demand you remove a covering, and that items worn for warmth, health, religious observance or political symbolism may fall outside it.
A hoodie is a garment. It is not a mask. But the statutory test turns on the officer's reasonable belief about your purpose, and you have just told a crowdfunding platform, in public, that your purpose is concealing your identity from recognition systems. The receipt is the evidence.
The law that was meant to do this job
The reason the Kickstarter is interesting is not that the hoodie works. It is that more than a thousand people concluded, correctly, that nothing else was going to.
On paper the regulation exists. The EU AI Act's Article 5(1)(h) prohibits real-time remote biometric identification in publicly accessible spaces for law enforcement, enforceable since 2 February 2025. Read the exceptions and the shape changes: targeted searches for victims of abduction, trafficking or sexual exploitation and for missing persons; prevention of a specific, substantial and imminent threat to life or of a terrorist attack; and identification of a person suspected of a scheduled offence punishable by at least four years' custody. Each deployment requires prior authorisation from a judicial or independent administrative authority, a fundamental rights impact assessment and registration in an EU database. It is a real constraint with a wide gate.
In the United Kingdom, which is outside that regime, the direction is the opposite. The Metropolitan Police ran a six-month pilot of fixed live facial recognition cameras on lampposts at either end of Croydon high street from October 2025 to March 2026. The force reported 173 arrests across 24 operations, an arrest every 35 minutes of operation, more than 470,000 people passing the cameras and a single registered false positive, alongside a claimed 10.5 per cent fall in crime in the pilot area. Commissioner Sir Mark Rowley has announced static cameras across the West End and Soho by the end of 2026. In January 2026 the Home Office announced an increase in facial recognition vans from ten to fifty, available to all forces in England and Wales. Big Brother Watch's response was that police have used the technology for a decade absent a democratic or legal basis, and that instead of pausing pending consultation the government funded an expansion. A legal framework was confirmed for the Police Reform Bill in the May 2026 King's Speech, which is to say the deployment came first and the law is arriving afterwards.
Meanwhile the enforcement record on the private side is a case study in what a fine is worth to a company that declines to pay it. Five European supervisory authorities found Clearview AI's processing of EU residents' biometric data unlawful between 2022 and 2024, issuing more than €110 million in penalties. France's CNIL levied €20 million in October 2022 and a further €5.2 million in May 2023. The Dutch Data Protection Authority added €30.5 million in September 2024. Clearview has paid essentially none of it, and in October 2025 the campaign group noyb escalated by filing a criminal complaint with Austrian prosecutors against the company and its executives.
Set that against a crowdfunding page. One system produced €110 million in unenforceable paper. The other produced 1,138 hoodies. Only one of them gave anybody something to put on.
Privacy at seventy-five dollars a garment
A hoodie costs $75. That is not much for a hoodie and it is a great deal for a fundamental right.
The distributional logic here is worth stating plainly, because it is the ugliest part. The people most exposed to biometric surveillance are, on the available evidence, the least able to buy their way out of it. NIST's landmark demographic study of face recognition algorithms found that false positive rates across demographics often vary by factors of ten to beyond a hundred, and that rates were highest for West and East African and East Asian faces and lowest for Eastern European ones. The Greater London Authority has reported that over half of the Met's facial recognition deployments in a recent year took place in areas with a higher proportion of Black residents.
So the machine is disproportionately deployed where certain people live, and it is disproportionately wrong about certain faces. The response on offer is a consumer good priced in dollars, sold on an American crowdfunding platform in limited runs, with the colour-matched pieces marketed as one-off and never released to anyone else.
Privacy as a subscription. Privacy as a size medium. Privacy for people who read TechCrunch.
This pattern is not specific to clothing. It is the same logic that turned ad-blocking into a paid app and identity theft protection into an upsell attached to the breach that caused it. A structural harm is created at scale by institutions, and the remedy is retailed back to individuals one unit at a time. The market response is not a scandal. It is often the only response available. But it should be recognised for what it is: the privatisation of a collective problem, monetised at the point of the person least able to solve it.
And the thing about individualised resistance is that it does not aggregate. Eleven hundred people in adversarial hoodies do not add up to a policy. They add up to eleven hundred people who are slightly harder to detect and considerably easier to notice.
The case that this is a talisman
The sceptical position deserves its strongest form, so here it is.
Adversarial clothing is closer to an amulet than to armour. It is a physical object that offers protection through a mechanism its wearer cannot verify, against a threat its wearer cannot observe, with a failure mode that produces no feedback. You will never know whether the hoodie worked. There is no notification. There is no log you can read. The camera does not tell you it lost you, and it does not tell you it found you either. That epistemic condition is precisely the one under which talismans thrive.
And unlike an amulet, this one has a plausible cost. If the garment induces real confidence, it changes behaviour. Someone attends a protest they would otherwise have avoided. Someone declines a mundane precaution because they believe the technical one is handling it. If the pattern fails, and the literature says physical patterns fail far more than the demo reels suggest, the wearer has been made worse off by the purchase. False confidence is not neutral. It is a negative.
The steelman gets stronger when you notice how little of the sales pipeline transmits the caveats. Swearingen's own slide says nothing physical is claimed yet. That sentence appears in a research deck seen by a conference audience. It is not what a backer sees, and it is not what survives the trip through aggregators, newsletters and posts about the hacker who beat the cameras. The honest version of this research is fragile in exactly the way the marketable version is robust.
What blunts the argument is that the person making the strongest claims also keeps the strictest controls. Occlusion subtraction against a solid black panel. Sealed sweeps with training, selection and reporting kept apart. More than 500 held-out personas. A test standard containing the phrase “or the result is discarded”. In a field where twelve of thirty published methods were ever tested against a real system, this is unusually disciplined work. It is also work being sold before it is finished, and both facts belong in the same paragraph.
What the hoodie is honestly for
Return to the question underneath all of this. What does it mean that the most practical response to pervasive facial recognition is to change what you wear?
It means the ordinary person has correctly diagnosed their position and has almost no instruments with which to act on it. You cannot negotiate with a lamppost. You cannot opt out of a watchlist you were never told you were on. You cannot appeal a system whose accuracy statistics are published by the organisation that operates it. You cannot collect on a €110 million fine that nobody intends to pay. The set of actions available to a single human being facing a biometric state is close to empty, and into that emptiness a garment has arrived. It is not irrational to reach for it. It is what reaching looks like when there is nothing else within reach.
And what does the Kickstarter tell us about the everyday experience of being watched by machines that can identify you from a single frame?
That the experience has become mundane enough to have a price. Anti-surveillance fashion used to be art. CV Dazzle was a thesis. HyperFace was at Sundance. Adversarial Fashion was a statement piece. In 2026 it is a fulfilment schedule, a size chart and a dye-sublimation printer, backed by the 1,138 people who had pledged by 4 September 2026, with a day of the campaign still to run, and who mostly do not think of themselves as activists. The surveillance became ordinary, so the resistance became merchandise. Those two facts are the same fact.
The hoodie is not a solution. On the evidence available, it is not yet even a demonstrated defence, and its own creator says so on a slide. Against gait recognition, cloth-changing re-identification, plate readers, phone signals and payment records, it addresses a single modality in a stack that has many, and it announces itself while doing it.
But calling it merely a symptom is too easy, and a little smug, because the people who say it usually have nothing better to offer. A symptom is passive. This is not. It is a legible object a person can put on their body, which makes an invisible infrastructure briefly visible and turns a diffuse unease into something with a shape and a price. That has a value not measured in objectness scores. Photographs of people in patterned gaiters will do more to tell the public that lampposts in Croydon run one-to-many face matching than any consultation response ever will.
So the honest answer is that the hoodie is a receipt. It is documentary evidence that eleven hundred people looked at the regulatory position in 2026, understood it accurately, and concluded that their best available move was a consumer purchase with an unverified mechanism and an unknown expiry date.
Whether the pattern defeats the camera is, in the end, the less interesting question. It probably will, for a while, against some models, in some conditions, until the next release. The question that stays is why the parser is there at all, why nobody asked, and why the only person who has to change their behaviour is the one walking past.
Sources and References
- Tom Eston, Shared Security Podcast, “Could a Pattern on Your Clothing Fool Facial Recognition? Interview with Bill Swearingen”, 31 August 2026. https://securityboulevard.com/2026/08/could-a-pattern-on-your-clothing-fool-facial-recognition-interview-with-bill-swearingen/
- Bill Swearingen, “noRecognition: Could a Pattern on Your Clothing Fool Facial Recognition?“, DEF CON 34 presentation slides, August 2026. https://media.defcon.org/DEF%20CON%2034/DEF%20CON%2034%20presentations/DEF%20CON%2034%20presentations/DEF%20CON%2034%20-%20Bill%20Swearingen%20-%20noRecognition%20Could%20a%20pattern%20on%20your%20clothing%20fool%20Facial%20Facial%20Recognition%20-%20hevnsnt.pdf
- Bill Swearingen (hevnsnt), noRecognition project repository and technical documentation, GitHub, updated August 2026. https://github.com/hevnsnt/norecognition
- Zack Whittaker, TechCrunch, “This 'adversarial' pattern can prevent surveillance cameras from detecting you”, 9 August 2026. https://techcrunch.com/2026/08/09/this-adversarial-pattern-can-prevent-surveillance-cameras-from-detecting-you/
- Dark Reading, “Can Clothes Make You Invisible to Facial Recognition?”, August 2026. https://www.darkreading.com/cyber-risk/clothes-invisible-facial-recognition
- Kickstarter, “noRecognition: AI Adversarial Clothing by Bill Swearingen”, campaign running 6 August to 5 September 2026.
- Kicktraq, campaign tracking data for “noRecognition: AI Adversarial Clothing”, accessed 4 September 2026. http://kicktraq.com/projects/norecognition/norecognition-ai-adversarial-clothing/
- Alon Zolfi, Shai Avidan, Yuval Elovici and Asaf Shabtai, “Adversarial Mask: Real-World Universal Adversarial Attack on Face Recognition Models”, arXiv:2111.10759, 21 November 2021, revised 7 September 2022. https://arxiv.org/abs/2111.10759
- Zhanhao Hu, Wenda Chu, Xiaopei Zhu, Hui Zhang, Bo Zhang and Xiaolin Hu, “Physically Realizable Natural-Looking Clothing Textures Evade Person Detectors via 3D Modeling”, arXiv:2307.01778, 4 July 2023, revised 8 November 2024, accepted to CVPR 2023. https://arxiv.org/abs/2307.01778
- Jiakai Wang, Xianglong Liu, Jin Hu, Donghua Wang, Siyang Wu, Tingsong Jiang, Yuanfang Guo, Aishan Liu and Jiantao Zhou, “Adversarial Examples in the Physical World: A Survey”, arXiv:2311.01473, 1 November 2023, revised 22 August 2024. https://arxiv.org/abs/2311.01473
- Jakob Shack, Katarina Petrovic and Olga Saukh, “Breaking the Illusion: Real-world Challenges for Adversarial Patches in Object Detection”, arXiv:2410.19863, 23 October 2024. https://arxiv.org/abs/2410.19863
- IEEE, “An In-Depth Exploration of Person Re-Identification and Gait Recognition in Cloth-Changing Conditions”, conference publication, 2023. https://ieeexplore.ieee.org/document/10204291/
- Adam Harvey, “CV Dazzle”, adam.harvey.studio, project begun 2010, page updated with newer looks. https://adam.harvey.studio/cvdazzle/
- Adam Harvey, “HyperFace”, adam.harvey.studio, developed with Hyphen-Labs, 2017. https://adam.harvey.studio/hyperface/
- Patrick Grother, Mei Ngan and Kayee Hanaoka, National Institute of Standards and Technology, NISTIR 8280, “Face Recognition Vendor Test (FRVT) Part 3: Demographic Effects”, December 2019. https://nvlpubs.nist.gov/nistpubs/ir/2019/nist.ir.8280.pdf
- Metropolitan Police, “Met makes one arrest every 35 minutes during live facial recognition pilot”, May 2026. https://news.met.police.uk/news/met-makes-one-arrest-every-35-minutes-during-live-facial-recognition-pilot-509256
- Computer Weekly, “Met pushes ahead with major facial-recognition expansion”, 2026. https://www.computerweekly.com/news/366645018/Met-pushes-ahead-with-major-facial-recognition-expansion
- Big Brother Watch, “Unprecedented Expansion of Facial Recognition Is 'Worrying for Democracy'”, January 2026. https://bigbrotherwatch.org.uk/press-releases/unprecedented-facial-recognition-rollout/
- Greater London Authority, “Over half of all facial recognition deployments last year took place in areas with a higher proportion of Black residents”. https://www.london.gov.uk/over-half-all-facial-recognition-deployments-last-year-took-place-areas-higher-proportion-black
- European Union, Artificial Intelligence Act, Article 5, Prohibited AI Practices, applicable from 2 February 2025. https://artificialintelligenceact.eu/article/5/
- European Data Protection Board, “Dutch Supervisory Authority imposes a fine on Clearview because of illegal data collection for facial recognition”, 3 September 2024. https://www.edpb.europa.eu/news/dutch-supervisory-authority-imposes-a-fine-on-clearview-because-of-illegal-data-collection-for_en
- CNIL, “Facial recognition: 20 million euros penalty against CLEARVIEW AI”, 20 October 2022. https://www.cnil.fr/en/facial-recognition-20-million-euros-penalty-against-clearview-ai
- International Center for Not-for-Profit Law, “Anti-Mask Laws in the United States”. https://www.icnl.org/our-work/us-program/assembly/anti-mask-laws-in-the-united-states
- CalMatters, “9th Circuit blocks California limits on anonymous immigration agents”, 22 April 2026. https://calmatters.org/justice/2026/04/immigration-mask-ban-9th-circuit/
- Netpol, “Section 60AA Briefing”, 27 February 2026. https://netpol.org/2026/02/27/section-60aa-briefing/

Tim Green UK-based Systems Theorist & Independent Technology Writer
Tim explores the intersections of artificial intelligence, decentralised cognition, and posthuman ethics. His work, published at smarterarticles.co.uk, challenges dominant narratives of technological progress while proposing interdisciplinary frameworks for collective intelligence and digital stewardship.
His writing has been featured on Ground News and shared by independent researchers across both academic and technological communities.
ORCID: 0009-0002-0156-9795 Email: tim@smarterarticles.co.uk
Listen to the free weekly SmarterArticles Podcast








