Community Trust ScoreVerified
Bill Swearingen ran 31 million tests from his home in Kansas City. The result: a pattern that makes vehicles basically invisible to Flock surveillance cameras — without touching the lens, without blocking a single frame of footage.
The project, called noRecognition, targets the object-detection software layer sitting behind the camera. Flock cameras keep recording normally. The AI just can’t identify what it’s looking at. Swearingen does that through adversarial machine learning — patterns that generate visual noise calibrated specifically to confuse recognition algorithms. His reinforcement learning model generates new patterns every minute, constantly adjusting to stay ahead of whatever the camera software expects to see. He described the training process as teaching the model “how to paint.” The most effective patterns, though, he keeps offline. Deliberately. He doesn’t want camera vendors to get their hands on them and patch around the vulnerability.
Pretty smart, honestly.
The Def Con Demo
Swearingen didn’t just theorize. He went to Def Con and showed the thing working in the real world, alongside Donut Media. They wrapped a 2009 Toyota Yaris in one of his latest patterns and drove it past a Flock camera. The camera recorded the pass. The detection software didn’t register a vehicle. Test passed. Swearingen did flag that applying the pattern to the wheels was particularly hard — the geometry there is tricky — but the overall result held up. Donut Media plans to release footage of the demonstration, though no exact date was given for when that drops.
Flock has been controversial for a while now. The company’s surveillance cameras are expanding fast across the United States, and the pushback from privacy advocates has grown alongside that expansion. One proposal that drew especially sharp criticism: turning Uber and Lyft dashcams into mobile plate-scanning units. That idea alone set off a new wave of concern about how far automated vehicle tracking could reach into everyday life.
And the consequences of getting it wrong aren’t abstract. Incidents where automated license plate readers misidentified vehicles have led to innocent people being detained at gunpoint. For immigrants and protesters especially, the stakes of being swept up in AI-powered surveillance networks are severe. Privacy advocates have been watching all of it closely, looking for legal angles to push back.
Privacy Angle and Legal Gray Areas
Swearingen co-founded the SecKC security meetup, and he’s pretty open about what’s driving him here. He sees noRecognition as a tool for people to “opt out of being tracked.” His concern about surveillance during protests is part of what pushed him to build this in the first place. He’s not hiding the motivation.
The legal picture, though, is murky. Plate obstruction laws vary by state, and it’s unclear how different jurisdictions would treat a vehicle wrapped in an adversarial pattern. Swearingen’s designs cover only the car body — not the license plates themselves — which probably matters legally. But probably isn’t certainly, and no one has fully mapped out the state-by-state exposure yet. That ambiguity isn’t going away soon.
noRecognition is also raising money. Swearingen launched a crowdfunding campaign to produce T-shirts, hoodies, and eventually vehicle skins featuring the patterns. So there’s a consumer product angle here too, not just a security research project sitting in a lab.
Swearingen’s work fits into a longer tradition of people finding creative ways to disrupt surveillance systems. Earlier tactics were pretty low-tech — placing traffic cones on autonomous vehicles to freeze them, for instance. noRecognition is something different. It’s a machine learning system fighting another machine learning system, pattern versus pattern, updated every minute. That’s a different category of resistance entirely.
Flock’s Broader Footprint
Flock isn’t the only surveillance technology facing scrutiny right now. Lawmakers have been pushing harder on facial recognition broadly, including Meta’s use of it in smart glasses. The political environment around automated surveillance is shifting, and Swearingen’s timing — going public at Def Con with a working demo — lands right in the middle of that conversation.
He says he’ll keep improving the model. Patterns get more effective over time as the reinforcement learning system keeps training. Whether that outpaces whatever countermeasures camera vendors eventually build is unclear. No details on that yet.
The 2009 Toyota Yaris drove past a Flock camera. The software saw nothing.
Frequently Asked Questions
How does Bill Swearingen’s noRecognition pattern evade Flock cameras?
The patterns use adversarial machine learning to generate visual noise that confuses Flock’s object-detection software, while the camera itself continues recording footage normally.
What did Swearingen demonstrate at Def Con?
He and Donut Media drove a 2009 Toyota Yaris wrapped in one of his patterns past a Flock camera, successfully evading vehicle detection during the live test.
