31 million tests later, noRecognition beat Flock cameras at DefCon

Security researcher Bill Swearingen trained reinforcement-learning patterns that block ALPR and surveillance detection without hiding from video. At DefCon he wrapped a Toyota Yaris and drove past a Flock camera. Here is what builders on both sides should learn.

SaifullahSaifullah
5 min read
31 million tests later, noRecognition beat Flock cameras at DefCon

A 2009 Toyota Yaris wrapped in a weird black-and-white skin drove past a Flock camera at DefCon. The camera recorded video. The detection stack did not flag the car.

That was the first public real-world test of noRecognition, a project by Kansas City security researcher Bill Swearingen. He spent a year running roughly the same experiment over and over until his reinforcement-learning model could paint patterns that defeat common surveillance detectors on demand.

TechCrunch's Zack Whittaker reports Swearingen ran about 31 million tests before he was confident enough to demo at DefCon with help from Donut Media.

I wrote about Flock's governance failures last month. This is the technical countermove: if detection is the product, adversarial ML is the immune response.

What adversarial patterns actually do

Surveillance cameras today are not just VCRs. They run detection models that extract plates, faces, and vehicle metadata so law enforcement can search at scale.

Swearingen's patterns do not block recording. They scramble the model's ability to classify what they cover. No alert fires. No plate lands in the database. You are still on video. You are just a needle in a haystack again until someone knows where to look.

He described the goal to TechCrunch as letting people "opt out of being tracked" without claiming invisibility.

That distinction matters for policy and for engineering. This is an attack on the ML layer, not the optics.

Reinforcement learning loop where adversarial pattern generator iterates against detection algorithms until classification fails

How Swearingen trained the model

Swearingen started in a home lab, defeating one open-source detection algorithm at a time. Community members brought hardware. The project scaled into a reinforcement-learning system that essentially taught itself "how to paint."

Each failed pattern that still got detected fed back into training. Each success against one algorithm became a harder target for the next batch. Eventually he reported recipes that defeated all 11 algorithms he tested, including stacks tied to Flock ALPR, Axon body cameras, and Clearview AI.

The model now generates new patterns every minute, each batch mathematically better than the last, he told TechCrunch.

That is classic adversarial ML arms race dynamics. Fixed detectors. Moving attacks.

The DefCon field test

Friday at DefCon in Las Vegas, Swearingen covered a 2009 Toyota Yaris with one of his newest patterns and drove it past a Flock camera.

"We proved it was effective," he said. Wheels were the hard part (partial coverage leaves detectable surface area).

Donut Media filmed the test. Swearingen said the video would drop in the coming weeks.

This is early proof, not a consumer product. But it is more than a lab slide: a commercial ALPR vendor's detection stack failed on a real street with a real car.

Why surveillance vendors should care

If you ship computer vision in production, adversarial examples are not a academic curiosity. They are a maintenance bill.

LessonImplication
Detection != recordingUsers may assume "camera saw nothing" when the model just failed silently
Open-source parityAttackers can train against your public or leaked model families
Physical-world transferPatterns on vehicles and clothing work outside ImageNet
RL-scale attacks31M iterations is cheap compared to your deployment footprint

Flock's problem in Roseville was 71% misread rate on alerts. noRecognition is the opposite failure mode: intentional evasion of true positives. Both break the promise that ALPR alerts are trustworthy inputs to human escalation.

Vendors that treat model weights as static will lose. You need continuous red-teaming, ensemble defenses, and honest public messaging about what happens when detection fails (either direction).

Why civil-liberties advocates should care too

Swearingen told TechCrunch he wanted to attend a protest but felt uncomfortable about camera tracking. He acknowledged privilege as a middle-aged white guy in Kansas City, then built tooling others might use when exercising First Amendment rights.

That use case is exactly why governments deploy ALPR networks: find needles in haystacks. Adversarial patterns push everyone back into the haystack, including people you actually want to find.

There is no clean moral binary. Oppressive stalking via ALPR misuse is real (see the Washington Post's officer abuse reporting). So is chilling effects on protest. Physical-world adversarial ML just made the policy fight more technical.

What Swearingen is shipping next

noRecognition is crowdfunding merchandise: T-shirts, hoodies, eventually vehicle skins. He is keeping the strongest patterns offline so vendors cannot easily train countermeasures.

Aesthetic matters here. Earlier anti-Face-Recognition fashion often looked like glitch art cosplay. Swearingen wants patterns that work at distance and look wearable.

Every failure still improves the model, he said. The arms race continues.

Takeaways for applied AI engineers

I build voice and ops automations, not surveillance. Still, the pattern generalizes:

1. If your model gates action, assume adversarial input. Hiring filters, fraud scores, content moderation, medical triage flags. Someone will optimize against your loss function.

2. Silent failures are worse than loud ones. A camera that records but does not detect looks like success in a dashboard until a human realizes the alerts stopped firing for the wrong reason.

3. Red-team at deployment cadence, not launch cadence. Swearingen's RL loop never stops. Your quarterly pen test is already stale.

4. Governance and robustness are the same budget line. Flock's misuse scandal was access control. noRecognition is model robustness. Both erode trust in automated policing products.

If you are shipping vision or scoring models into high-stakes workflows, treat adversarial evaluation as part of the sprint, not a PhD side quest. Book a free discovery call if you want help designing human fallbacks before automation goes live.

Share this post

Related posts