How AI Can Make Cameras Look Away

How AI Can Make Cameras Look Away

Artificial intelligence has given surveillance cameras the ability to recognise and track what they see, yet researchers are now demonstrating how AI can also be turned against those systems, creating patterns that leave people and vehicles perfectly visible to humans while potentially making them much harder for automated surveillance to detect.

What Has Been Developed?

US cyber security researcher Bill Swearingen has spent around a year investigating whether specially designed visual patterns can interfere with the computer vision increasingly built into modern surveillance systems.

The result is noRecognition, a project using AI-generated “adversarial patterns” designed specifically to confuse object-detection algorithms.

This is very different from hiding from a conventional camera. For example, someone wearing one of the patterns could still appear clearly in the recorded footage, while a vehicle covered with one could remain equally visible. The aim, however, is to make the software analysing those images fail to recognise what it is seeing, potentially preventing the automated detection or alert that would normally follow.

Swearingen’s aim is to give individuals greater control over whether automated surveillance systems can identify and track them as they move through public spaces. His research therefore focuses on disrupting the algorithmic analysis taking place behind the camera rather than preventing the camera itself from recording. As the noRecognition website puts it: “Privacy is not a luxury. It is a fundamental right.”

Teaching AI To Confuse AI

Creating patterns capable of doing that reliably has required an enormous amount of experimentation.

For example, Swearingen reportedly began by testing designs against individual open-source computer-vision systems before developing a reinforcement-learning model capable of improving them automatically. When a pattern failed to fool a detector, the model could learn from the result, alter its approach and try again.

Around 31 million tests later, the system can generate new patterns continuously, with successive designs intended to become increasingly effective against the detection software being targeted.

Tested Against Different Surveillance Systems

Swearingen’s published research covers an 11-detector test environment involving person detection, face detection and recognition models, including a production-grade person detector extracted from a deployed surveillance camera. Results vary considerably between models, garment coverage and test conditions, with many of the strongest findings still based on digital simulations rather than physical clothing facing real cameras.

Importantly, noRecognition also says it records results where the patterns fail, describing its approach simply as: “We publish the results that went against us too.”

That distinction is quite important because something capable of confusing an algorithm using digital imagery may not necessarily work when printed onto fabric and exposed to different distances, lighting conditions, body shapes and camera angles.

Putting The Idea On The Road

A recent demonstration at the DEF CON cyber security conference in Las Vegas provided an important step towards testing whether the principle could work outside a computer simulation.

With help from automotive media company Donut Media, one of Swearingen’s patterns was applied to a 2009 Toyota Yaris before the vehicle was presented to a Flock surveillance camera.

The demonstration reportedly succeeded in defeating automated detection, although Swearingen acknowledged that the vehicle’s wheels presented a particular challenge. It provided early evidence that adversarial patterns can potentially move beyond carefully controlled digital experiments into real-world surveillance environments.

The project is also exploring pattern-covered T-shirts, hoodies and other clothing. Swearingen is deliberately keeping his most effective designs away from the public internet, partly because making them widely available could give surveillance technology developers the data needed to train their own systems against them.

CCTV Isn’t Just Watching Anymore

The wider significance of this research comes from how dramatically surveillance cameras themselves have changed.

Traditional CCTV largely captured images for later examination, which meant the usefulness of a large camera network was limited partly by the number of people available to watch or search its footage.

By removing much of that limitation, computer vision allows AI to analyse enormous volumes of imagery automatically, identifying people and vehicles, reading number plates, detecting particular objects and making recorded footage searchable without somebody manually watching every minute.

Rather than simply recording what happened, modern surveillance cameras are increasingly supported by software that decides what is happening, what deserves attention and what information should be extracted from the scene.

By targeting precisely that additional layer of intelligence, adversarial patterns could cause a detection system to fail to classify a person even though the camera has successfully recorded them, meaning the footage still exists but the automated system designed to find that individual may never flag it.

An AI Arms Race?

That creates a potentially important new contest within computer vision. Camera manufacturers can improve their detection models and train them against known attempts at evasion. Researchers can then use increasingly powerful AI to search for new patterns that exploit different weaknesses, potentially creating a continuing cycle of detection and counter-detection.

Swearingen’s project appears to show how quickly that process can become automated. For example, rather than a human designer manually creating each new camouflage pattern, AI can repeatedly test possibilities and retain those that perform best.

The technology also raises an important question about the balance between privacy and security. A technology capable of reducing automated tracking could appeal to people concerned about pervasive surveillance, yet similar techniques could potentially be exploited by someone deliberately attempting to evade legitimate security or law-enforcement systems.

What Does This Mean For Your Business?

For businesses, the research highlights an emerging weakness that becomes more relevant as organisations increasingly rely on intelligent cameras for security, access control, retail monitoring, vehicle recognition and automated alerts. Computer vision can dramatically increase the usefulness of surveillance, although businesses should avoid treating an AI detection as an infallible substitute for conventional security controls.

The development also shows how familiar cyber security concepts are moving into the physical world. Protecting a surveillance system increasingly means considering not only whether somebody can hack its network or access its recordings, but whether the intelligence interpreting those recordings can itself be deliberately manipulated.

Perhaps most importantly, this research demonstrates an unusual consequence of the rapid development of AI. The same broad technology that has taught cameras to understand the world around them can now be used to discover exactly what those cameras struggle to understand, potentially creating an ongoing contest between AI-powered surveillance and AI-powered methods designed to defeat it.