At the DEF CON security conference in Las Vegas earlier this month, a 2009 Toyota Yaris wrapped in a digitally designed camouflage pattern drove past a Flock automated license plate reader. The camera recorded video of the vehicle. Its detection software logged nothing. The car effectively vanished from the algorithmic view of one of the most controversial and rapidly expanding surveillance networks in the United States. This was not a glitch or a hardware failure. It was the public debut of noRecognition, a reinforcement learning model developed over the past year by cybersecurity expert Bill Swearingen, founder of SIXCYBER, which has run an extraordinary 31 million tests to produce patterns specifically engineered to defeat the object detection algorithms embedded in modern surveillance cameras.
What Is noRecognition and How Does It Generate Adversarial Patterns?
noRecognition is not a physical shield or an electronic jammer. It is a computational system that uses reinforcement learning to generate two-dimensional visual patterns. When applied to the exterior of a vehicle, these patterns interfere with the computer vision software that cameras use to identify objects, read license plates, and trigger alerts. The key distinction is that the patterns do not prevent the camera from recording footage. A human watching the video replay would still see the car clearly. What fails is the automated software layer that interprets the video stream — the layer responsible for detecting a vehicle as a vehicle, logging its plate, and potentially flagging it against a law enforcement database.
Swearingen’s methodology was methodical and brute-force in scale. He set up a testing loop that generated a pattern, presented it to a detection algorithm, and measured whether the software identified the object. If the pattern was detected, the system adjusted the design and tested again. This process repeated across 31 million iterations until the system converged on patterns that consistently evaded detection. The resulting patterns are not random noise or simple geometric shapes. They are highly optimized adversarial examples — inputs intentionally designed to cause a machine learning model to make a mistake — applied to the physical world in the form of a vehicle wrap.
The system has been tested against 11 open-source detection algorithms, including the software that powers Flock license plate readers, Axon body-worn cameras, and cameras running Clearview AI’s facial recognition system. According to Swearingen, noRecognition beats all of them. The patterns are generated continuously, with new designs emerging every minute that are effective against the current versions of these detection systems.
The Flock Camera Network: Scale, Controversy, and a Live Test
Flock Safety has become one of the most dominant players in the American surveillance landscape. The company sells automated license plate recognition (ALPR) cameras to police departments, neighborhood associations, and private businesses. These cameras photograph every passing vehicle and cross-reference the license plates in real-time against law enforcement databases for warrants, stolen vehicle reports, and other investigative flags. The network has expanded at remarkable speed. Earlier this year, it was revealed that Flock had proposed integrating 350,000 Uber and Lyft dashcams into its scanning network, a move that would effectively turn ride-share vehicles into roving surveillance nodes covering vast swaths of the country.
The growth has been met with significant backlash from privacy advocates and civil liberties organizations. Concerns center on the scope of data collection, the lack of warrant requirements for many deployments, and the potential for inaccuracies. There have been documented cases where Flock cameras produced incorrect plate matches, leading to innocent drivers being pulled over at gunpoint by police responding to an alert. The system’s speed and automation mean that errors can escalate rapidly with serious real-world consequences.
It was within this context that Swearingen chose to test his noRecognition pattern against a live Flock camera. He wrapped the 2009 Toyota Yaris and drove it past the camera during a demonstration at DEF CON. The result was a successful evasion: the camera recorded the vehicle’s presence in the video feed, but its detection software did not identify the car, did not log the plate, and did not trigger any alert. Swearingen noted a specific challenge: the vehicle’s wheels. The patterns are applied to the bodywork of the car, but the wheels, which are in constant motion and have a different shape and material, proved harder to cover effectively.
Why Covering the Bodywork and Not the License Plate Matters
A critical detail in the noRecognition approach is that the patterns are applied to the body of the car but explicitly not to the license plate itself. Obscuring a license plate is illegal under the laws of every U.S. state. Swearingen designed the system to comply with that legal boundary. The goal is not to hide the plate from human view or from camera recording. The goal is to prevent the automated detection software from identifying the vehicle as a vehicle in the first place. If the software cannot detect a car, it never reaches the step of reading the plate or cross-referencing it against a database.
This distinction raises an important question: could covering a car’s bodywork in a pattern specifically designed to fool surveillance software itself become an offense? As of now, there is no established legal precedent. The patterns are printed wraps, akin to custom paint jobs or vehicle graphics. They do not physically block the plate. They do not emit signals. They are a purely visual surface treatment that exploits the vulnerabilities of specific machine learning models. Whether law enforcement or legislators will treat this as a form of evasion, akin to using a plate cover or a similar device, remains an open and unresolved issue.
How Adversarial Patterns Exploit Machine Vision Vulnerabilities
To understand why noRecognition works, it is necessary to understand how modern surveillance cameras process visual data. A camera like the Flock ALPR unit does not simply take a picture and send it to a human reviewer. It runs the video feed through a series of computer vision models trained to detect specific objects — vehicles, faces, license plates. These models are deep neural networks that have been trained on millions of labeled images. They learn to recognize patterns of pixels that correspond to “car,” “truck,” “SUV,” and so on.
Adversarial attacks exploit the fact that these models do not see images the way humans do. Small, carefully calculated perturbations in pixel values that are imperceptible to the human eye can cause a model to misclassify an object or fail to detect it entirely. In the case of noRecognition, the perturbations are not pixel-level tweaks applied to a digital image. They are large-scale geometric patterns printed onto a physical surface. The patterns are designed to disrupt the feature detectors within the neural network that are responsible for identifying vehicle shapes, edges, and contours.
The 31 million test iterations served to refine these patterns against specific detection algorithms. Swearingen’s system effectively learned which visual features cause each algorithm to fail. The result is a set of patterns that are robust enough to work in real-world conditions — daylight, shadow, different angles — but that are also specific enough that they do not degrade the human-readable appearance of the vehicle beyond recognition.
What Is a Reinforcement Learning Model and Why Does It Matter for Privacy Technology?
Reinforcement learning is a type of machine learning where an agent learns to make decisions by performing actions in an environment and receiving feedback in the form of rewards or penalties. In the noRecognition system, the agent is the pattern generator. The environment is the simulated camera detection pipeline. The action is generating a new pattern. The reward is successfully evading detection. Over 31 million iterations, the agent learned which pattern characteristics yield the highest evasion rate.
This approach is significant because it means the system can adapt. New versions of detection algorithms can be met with new patterns generated by the same reinforcement learning framework. Swearingen has stated that he is deliberately keeping the strongest patterns offline, not publishing them publicly, to prevent camera manufacturers and software developers from training their models specifically against them. This is a cat-and-mouse dynamic familiar to cybersecurity: a vulnerability is discovered, a patch is developed, a new vulnerability is found. Here, the patching cycle is inverted — the evasion tool is the one that can update, while the detection systems must try to keep up.
The practical implication is that noRecognition is not a one-time fix. It is an ongoing capability. As Flock, Axon, or Clearview AI update their detection algorithms, Swearingen’s system can generate new patterns that defeat those updates. The asymmetry favors the privacy tool, at least in the short term, because it is easier to generate a pattern that fools a specific model than it is to harden that model against all possible adversarial patterns.
The Motivation: Opting Out of Automated Tracking at Protests and Beyond
Swearingen has stated that the project began after he wanted to attend a protest and felt uncomfortable about being tracked by surveillance cameras. His stated goal is framed in terms of fundamental rights. “Privacy is a fundamental right,” he said, and he believes that noRecognition offers a way for people to “opt out of being tracked.” This framing places the technology within the broader context of resistance to mass surveillance, particularly in the United States where police departments have rapidly adopted automated monitoring systems with relatively little legislative oversight.
The specific use case of protests is instructive. Law enforcement agencies increasingly use Flock and similar systems to identify vehicles attending demonstrations, track their movements, and build patterns of association. A vehicle that cannot be algorithmically detected cannot be algorithmically tracked. The driver remains anonymous to the system, even as the camera records their passage. This creates a gap in the surveillance chain that no amount of database cross-referencing can fill.
However, the technology is not limited to protest contexts. Any driver who wishes to avoid being logged by an ALPR network could theoretically use such a pattern. The question of legality and social acceptability remains unresolved, but the technical capability exists and is being actively refined.
A Featured Snippet: Can a Printed Pattern Really Fool a Flock Camera?
Can a printed pattern really fool a Flock camera? Yes. In a live test at the DEF CON conference, a 2009 Toyota Yaris wrapped in a noRecognition pattern was driven past a Flock camera. The camera recorded video of the vehicle, but its detection software did not identify the car, did not log the license plate, and did not trigger any alert. The system has been tested against 11 open-source detection algorithms, including the software behind Flock cameras, and has proven effective against all of them.
The Arms Race Between Surveillance and Evasion
The emergence of noRecognition signals a new phase in the ongoing tension between surveillance technology and privacy tools. Historically, ALPR systems have enjoyed a significant advantage: they are deployed at scale, they operate passively, and the targets of surveillance rarely have any way of knowing they have been logged. The only traditional countermeasures — obscuring or removing a license plate — are illegal and easily spotted by a human officer.
NoRecognition changes that calculus. It offers a legal, deniable method of concealment that targets the software, not the hardware. It cannot be detected by a human observer because the patterns are visible but not suspicious in and of themselves. They look like custom vehicle wraps, which are common and legal. The evasion is invisible to the human eye, occurring only in the algorithmic processing layer.
The response from Flock and other companies will be telling. They can attempt to retrain their models to recognize noRecognition patterns and classify them as vehicles despite the adversarial interference. But Swearingen’s system can generate new patterns continuously, and the strongest ones are kept private. This creates an information asymmetry. Flock would need access to the patterns to train against them, and that access is being deliberately withheld. The alternative — redesigning detection algorithms to be fundamentally more robust to adversarial inputs — is a harder problem and one that the computer vision community has not yet solved.
The Future of Visual Privacy and the Cost of Being Seen
What makes noRecognition noteworthy is not merely that it works, but that it represents a shift in the balance of power between the surveilled and the surveillor. For years, privacy advocates have argued that the only effective defense against automated surveillance is legislative restriction or technical regulation of the cameras themselves. Neither has materialized at scale in the United States. Flock cameras continue to multiply. noRecognition offers a bottom-up alternative: a tool that individuals can use, at their own discretion, to remove themselves from the algorithmic grid.
The broader implications extend beyond license plate readers. The same principles could be applied to facial recognition systems, drone surveillance, and any other computer-vision-based tracking technology. Swearingen’s tests already include Axon body cameras and Clearview AI’s facial recognition. The patterns are designed to defeat vehicle detection, but the methodology — reinforcement learning over millions of adversarial examples — is transferable.
Whether noRecognition remains a niche tool for privacy-conscious drivers or becomes a more widespread phenomenon depends on several factors: legal rulings, public awareness, the cost of producing custom wraps, and the response from surveillance companies. What is clear is that the technical foundation has been laid. The era of passive, inescapable algorithmic surveillance may be coming to an end, not because the cameras are being removed, but because the patterns on our cars can now see us through.