AI-powered cameras are increasingly deployed globally, capable of identifying faces and vehicle license plates. A public backlash against these surveillance technologies is developing, driven by privacy concerns regarding data capture, storage, and potential misuse. Initiatives like the DeFlock project aim to raise awareness by mapping automated license plate readers (ALPRs), while some individuals resort to vandalism of these systems. Others are creating 'adversarial fashion' to evade detection, exemplified by the Kickstarter project noRecognition, showcased at the DEF CON hacker convention.
In 2025, cybersecurity expert Bill Swearingen began using a Python-based fuzzer to identify vulnerabilities in object detection frameworks, particularly YOLO. He developed a reinforcement learning algorithm that generates adversarial patterns tested against 11 object detection models, including those for face and people detection. Successful patterns reduce detection confidence scores significantly.
"Privacy is a human right, and the popularity of this just goes to show that people are interested in preserving their privacy," Swearingen stated.
Companies like Cap_able and Urban Privacy are producing garments designed to disrupt surveillance systems. Cap_able uses a patented method to create clothing that interferes with computer vision systems, while Urban Privacy's Faception Reloaded collection features designs that confuse facial recognition algorithms. "If we’re able to camouflage a person as something else, then we’re obtaining our goal," said Cap_able founder Rachele Didero.
The trend of anti-surveillance fashion has roots in earlier artistic and technological responses to AI surveillance, with notable contributions from technologist Adam Harvey and artist Kate Bertash. The movement is evolving into a small industry, with experts noting that clothing can serve as a tangible form of protest against surveillance practices.
However, real-world factors such as camera angles and lighting may limit the effectiveness of these garments. "One good frame is all a system needs," Mireshghallah explained. Additionally, adversarial patterns must be tailored to specific recognition models, and advancements in surveillance technology could render these defenses ineffective over time.
Despite these challenges, the creators of adversarial fashion remain committed to innovation. Cap_able plans to release new items, including a 'shadow cap' designed to obscure facial features. Swearingen is also exploring new patterns that could further enhance the effectiveness of countersurveillance clothing.
Adversarial fashion is seen as a means of reclaiming control over personal privacy. "At its core, this fashion is about taking back control of your face and body," Singh noted. Mireshghallah cautions that while these garments can provide some level of protection, individuals should also consider other forms of data that could compromise their privacy. "Think about what else you’re leaking that can be combined with it," she advised.