New algorithm hides people and vehicles from surveillance cameras
An algorithm built on adversarial patches can make cameras miss people, faces and vehicles, sharpening the race between surveillance systems and privacy tools.

A security researcher has designed an algorithm that generates computer-made patterns capable of hiding people, faces and vehicles from surveillance cameras, pushing the struggle between detection systems and privacy tools into sharper focus. The method relies on adversarial machine learning, where small visual changes can cause a computer-vision system to misclassify what it sees.
The idea has been building for years. In 2019, Simen Thys, Wiebe Van Ranst and Toon Goedemé of KU Leuven’s EAVISE group published Fooling automated surveillance cameras: adversarial patches to attack person detection, showing that adversarial patches could make automated cameras miss people. Adam Harvey’s CV Dazzle project, first created in 2010 as part of his master’s thesis at New York University’s Interactive Telecommunications Program, took a different route, using anti-facial-recognition camouflage to break neural-network face detection rather than simply covering the face.
The timing matters because surveillance is increasingly automated and built on vast image libraries. The University of Chicago’s 2023 SoK: Anti-Facial Recognition Technology paper said Clearview AI had scraped freely available pictures from Facebook, YouTube and other websites to build a database of more than 3 billion photos. Clearview AI also told investors in 2022 that it was seeking to reach 100 billion images in its index of faces. Clearview has said its platform helps with investigations and public safety, while the scale of the database has drawn sustained privacy concerns.

Those concerns reached court in May 2020, when the ACLU, ACLU of Illinois and Edelson PC filed ACLU v. Clearview AI, alleging violations of Illinois residents’ privacy rights under the Illinois Biometric Information Privacy Act. The ACLU later said a settlement permanently banned Clearview nationwide from making its faceprint database available to most businesses and other private actors. The case underscored the central policy conflict in biometric surveillance: law enforcement and security users want fast identification, while civil libertarians warn that scraping and indexing faces can turn ordinary public life into a searchable biometric record.
The same technology is now moving into consumer-facing privacy tools. In July 2024, Rachele Didero described Cap_able clothing at a MIT talk, saying it uses adversarial patterns to protect identity without covering the face. That shift matters because it shows the same visual tricks that can evade a camera in a lab can be packaged for everyday use, making it easier for people to move through camera-filled spaces without being automatically identified.
This article was produced by Prism’s automated news system from verified source data, official records, and press releases, then run through automated quality and moderation checks before publishing. The system is built and supervised by the people who set the standards it runs under. Read our full AI policy.
Did this article answer your question?


