LIVE
All stories ›
AI IN LIFENEWS
Tools & AppsBusiness & DealsAI ModelsSocietyChips & ComputeResearchSafety & SecurityRegulation & PolicyRobotics OpenAIAnthropicGoogle & DeepMindAlibaba / QwenxAIMetaByteDance
HomeResearch › RESEARCH
RESEARCH

Anti-Surveillance Clothing Meets Its Real-World Limits

Garments printed to confuse face detectors are now sold as fashion, yet the people building them agree the effect is fragile outside the lab.

Anti-Surveillance Clothing Meets Its Real-World Limits
Symbolic illustration: patterned fabric runs through a knitting machine in a workshop while a camera aims at the garment and a nearby monitor shows abstract detection boxes.

In short

Adversarial fashion can briefly confuse detection systems, but its own makers describe it as a statement rather than a cloak, because one clean frame is enough for a camera.

At a glance

  • noRecognition, by Bill Swearingen, was shown at DEF CON 34 and is running as a Kickstarter project.
  • Swearingen used reinforcement learning to generate patterns, tested against 11 detection models.
  • The set covered 4 face-search models, 2 face-recognition models and 5 people-detection models.
  • Earlier work: Adam Harvey in the 2010s and Kate Bertash's Adversarial Fashion line in 2019.

Anti-surveillance clothing has moved from conference demos to online storefronts, and the people selling it are unusually blunt about what it cannot do. In a report published by IEEE Spectrum on September 14, 2026, designers and researchers describe the garments as protest wear whose technical effect breaks down quickly on the street.

The pitch

Security researcher Bill Swearingen started experimenting in 2025 and showed his noRecognition project at DEF CON 34, funded through Kickstarter. He built a reinforcement learning routine to generate patterns and ran them against 11 object-detection models: 4 that search for faces, 2 that recognize them, and 5 that detect people.

Two sellers take different routes. Cap_able, founded by Rachele Didero, knits its motifs into dresses, pants and tops on a jacquard machine, aiming to have a detector read a person as something else entirely. Urban Privacy, cofounded by Daniel Preuß, offers the Faception Reloaded collection and a shadow cap, using black-and-white face abstractions that hand a detector extra faces, plus asymmetrical cuts meant to blur body shape and gait.

Where it fails

Niloofar Mireshghallah of Carnegie Mellon University puts the practical ceiling plainly: “one good frame is all a system needs.” Her second point is the harder one, since a camera that briefly classifies someone as an animal has still logged something moving along a very human route.

Dippu Kumar Singh of Fujitsu North America calls the approach a fragile shield against a threat improving from several directions at once. The listed weaknesses are specific: patterns are tuned to particular models, angle and lighting and moving fabric degrade them, gait recognition works without a face, and the next training round can absorb the patterns outright.

What is actually driving it

The demand comes from the cameras, not the clothes. Consent, data retention and misuse are the recurring complaints in the report, and the DeFlock project maps automated license plate readers so residents can see where they stand. Preuß frames his own product accordingly: not an invisibility cloak, but something to wear as a statement.

What the report does not supply is a measured success rate, and it gives no prices, unit sales or funding totals either. We have not verified the garments' performance independently.

◈ AI-GENERATED REPORT · SOURCES LINKED

FAQ

Does anti-surveillance clothing actually beat facial recognition?

Only partly, and only in narrow conditions. Patterns are tuned to specific models, camera angle, lighting and fabric movement degrade them, and a single usable frame is enough for the system.

Who makes adversarial fashion?

The report names noRecognition by Bill Swearingen, Cap_able by Rachele Didero, and Urban Privacy, cofounded by Daniel Preuß. Earlier work came from Adam Harvey in the 2010s and Kate Bertash in 2019.

What is DeFlock?

A project that maps automated license plate readers so people can see where the cameras are. It documents surveillance infrastructure rather than interfering with detection.

Sources

More reports