Tools to evade AI-powered surveillance: Are they effective?
You might cover or obscure your face, but that can get you in trouble with the cops.

Image by Bill Swearingen/Cybernews.
- Privacy activists are developing tools to evade facial recognition as police surveillance networks expand across the United States.
- Bill Swearingen says his noRecognition pattern blocked Flock cameras after 31 million tests and a Def Con demonstration.
- Masks, infrared eyewear, makeup, and adversarial clothing can disrupt some systems, but each has limits and legal risks.
- New systems using gait and body-shape analysis may identify people even when faces are hidden or unclear.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
With concern over ever-smarter yet often poorly regulated facial recognition software growing worldwide, a clan of privacy activists and researchers is building tools that can fool such invasive surveillance-enabling technology.
Roughly 1 in every 3 American adults is indexed in police facial recognition networks.
“Most never consented, were never informed, and have no way to opt out,” says Bill Swearingen, a cyber professional from Kansas City.
“Their faces were scraped from driver's license photos, mugshot databases, and public records, then fed into AI systems that can identify them in real time from any camera feed.”
Since AI is error-prone, the systems produce much higher match rates for darker-skinned individuals.
Check if your data has been leaked
This, of course, means that people who, at least in the US, already face the most aggressive policing, are “also the people most likely to be wrongly identified by the technology justifying that policing,” Swearingen points out.
31 million tests and a pattern
Indeed, the world already looks pretty dystopian. The cameras built by ambitious cop-friendly companies like Flock Safety are everywhere now (and the CEO wants more), and the databases are vast: we didn’t opt-in, and we cannot officially opt out – all while the police track us 24/7.
But there are ways to at least try to evade the modern big brother. They’re mostly analog and range from wearing simple Covid masks, ideally paired with sunglasses, to applying smart makeup or even stuffing your cheeks with halved ping-pong balls.
Ok, that last one doesn’t work, but you get the idea of how wild this space is. Swearingen has himself been testing and building a unique computer-generated pattern that could be applied to clothing and objects.
It took 31 million tests, the cyber pro says, but he’s finally developed a pattern that prevents, for example, Flock license plate readers and smart surveillance cameras from detecting whatever or whoever the pattern covers.
The concept of Swearingen’s project, called noRecognition, is as follows: “Generate a visual pattern, apply it to simulated clothing, run it through production-grade AI surveillance models, and record whether the person was detected.”
He already successfully demonstrated the pattern printed on a 2009 Toyota Yaris at the Def Con cybersecurity conference in Las Vegas last week. Since a Flock camera didn’t detect it, the test became public proof that it’s indeed possible to avoid algorithmic detection.
What’s also interesting, Swearingen is using AI to beat AI. His proof of concept is essentially a reinforcement learning model that trains itself on which adversarial patterns work and which don’t, and improves each time they fail to fool the algorithm.
No wonder Swearingen isn’t showing off his most effective patterns on the web. He wants to prevent the facial recognition camera makers from beating them.
Is blinding facial recognition systems an answer?
Swearingen’s method looks pretty complex, of course. There indeed are more similar solutions where you still need to tinker with certain objects to avoid the smart gaze of the facial recognition camera.
Specialized infrared (IR) setups – such as hidden IR LEDs mounted on a cap or frames – can in theory blind certain facial recognition systems by casting invisible light patterns or washing out the camera’s sensor.
In other words, those LEDs shine invisible light onto the face, creating hot spots or false shadows that scramble machine-learning facial embeddings.
Reflectacles, for instance, are specialized privacy eyewear and sunglasses, engineered to block or reflect IR light and visible light to thwart facial recognition systems, 3D dot-matrix face-mapping, and surveillance cameras.
“You may be new to facial recognition ideas, or in general, TECH HELL, but welcome to the terrible existence. I’m doing my best to help. We all should,” Scott Urban, creator of Reflectacles, says on the product’s website.
It’s sold out, by the way, but new stock is apparently coming. The technology is already used by Zenni Optical, an online eyewear retailer, which introduced Zenni ID Guard last year to help customers disrupt unwanted tracking.
Some, though, are doubting the effectiveness of IR-based privacy products. First, high-grade security and law enforcement cameras usually utilize physical IR cut filters or advanced sensor algorithms that neutralize ambient or amateur IR interference.
Besides, facial recognition systems are called systems for a reason. They don’t just measure your features: they also associate your cell phone identifiers with your likeness. A unique person can and will be associated with a unique individual who’s always wearing glasses.
Standing out or blending in
That’s why a simple face mask is a good idea. The COVID-19 pandemic is long over, but there’s a reason protesters across the United States keep covering their faces with masks or balaclavas – that’s, of course, to confuse facial recognition systems (and to avoid tear gas).
The general idea is that anything that confuses a facial recognition app on your smartphone will also confuse facial recognition systems in public.
The problem is that, in some areas, laws making it illegal to wear a mask or hide your face are already being revived. At least 8 US states feature general prohibitions against wearing masks or disguises in public spaces.
As someone on Reddit once pointed out, “there are cops with bodycams everywhere who will harass and hassle you if you refuse to show your face to them when confronted” – despite civil liberties groups saying that such bans infringe on free speech and peaceful assembly.
In short, a mask – or anti-surveillance makeup known as the “anti-face” – makes you stand out, and that’s unfortunate if you just want to blend in. But subtle adversarial clothing is hurtling into fashion, and it looks fine.
Full-face hyper-realistic silicone masks are another rather interesting idea. They get better every year and can replicate 3D facial geometry and skin texture.
However, modern AI counter-measures look for micro-expressions, natural blinking, eye movement, and thermal mapping to spot fake or swapped identities. Plus, motion and gait analysis has improved a lot over the past few years – and that’s a killer, unless you're willing to walk with stones in your shoes.
Dance like everyone is watching
Researchers recently developed a biometric recognition system called FarSight, designed to identify people at long distances using not only facial recognition, but also gait and body-shape analysis captured from drones and elevated surveillance video.
FarSight, of course, points toward a broader form of surveillance in which people may be identifiable even when their faces are partially obscured, low-resolution, or unavailable.
The unpredictability of fast-moving technological advances is precisely the point, says Emily Wenger, an assistant professor of Electrical and Computer Engineering at Duke University, where she runs the ARGUS Lab and focuses on topics such as AI, security, and society.
For an anti-facial recognition tool to be effective, it has to be resilient to the future and facial recognition techniques not yet employed,said Emily Wenger, an assistant professor of Electrical and Computer Engineering at Duke University.
Still, trying new creative ways to fool the system – unless you’re actually a criminal planning some dirty deeds – is perfectly fine. Does anyone really want to have their face constantly scanned on the street?
Then again, just dance like everyone is watching – because they are. And don’t stuff your cheeks with halved ping-pong balls: this will do little against modern AI-driven computer vision.