Monday, August 10, 2026
Home TechnologynoRecognition patterns defeat license plate readers at DEF CON demonstration

noRecognition patterns defeat license plate readers at DEF CON demonstration

by Kim Stewart
0 comments
noRecognition patterns defeat license plate readers at DEF CON demonstration

noRecognition patterns defeat license-plate and facial detection in Def Con demonstration

A cybersecurity researcher’s noRecognition patterns claim to block automated detection by license-plate readers and surveillance cameras after millions of tests, shown at Def Con.

Bill Swearingen’s noRecognition patterns, developed through iterative machine learning, were demonstrated publicly at Def Con when a pattern-printed 2009 Toyota Yaris evaded automatic detection by a commonly deployed license-plate camera. The project’s creator says the patterns do not stop cameras from recording footage but scramble the detection algorithms that trigger alerts for faces, plates and vehicles. Swearingen built the system after months of laboratory work and millions of experiment iterations aimed at letting people opt out of automated surveillance.

noRecognition Debuts Anti-Surveillance Patterns at Def Con

At the Las Vegas cybersecurity conference, Swearingen covered a compact car in a noRecognition pattern and tested it against a Flock license-plate reader camera. The demonstration showed the vehicle avoided the automated detection that would normally flag a plate or vehicle in live analytics, though some physical details such as wheels still presented challenges.

Donut Media assisted with the public trial and plans to publish footage of the test in the coming weeks, according to Swearingen. He characterized the Def Con run as a first real-world validation that the patterns can degrade the performance of deployed detection systems outside the lab.

Training the model with millions of iterations

The project began as a proof-of-concept and evolved into a reinforcement learning pipeline that Swearingen describes as teaching a model “how to paint.” Over the past year the system completed roughly 31 million tests, iterating patterns that were judged by detection software and refined whenever an algorithm succeeded in identifying the target.

Each failed attempt informed the model’s next generation of patterns, accelerating improvements as computing resources and community-contributed hardware increased the project’s throughput. Swearingen says the process now generates new candidate patterns every minute, with each batch statistically outperforming the last.

Algorithms targeted and scope of testing

Swearingen reports testing the patterns against 11 open-source detection algorithms used in a range of systems, including software variants similar to those powering Flock license-plate readers, Axon body-worn camera analytics and services associated with large image databases. The patterns aim to prevent detection triggers rather than erase recorded pixels, effectively making the object a low-priority item in automated searches.

Experts have previously documented that automated plate and facial systems can produce false positives and wrongful stops, and Swearingen frames noRecognition as a response to that industrial-scale surveillance capability. He cautions, however, that success in controlled tests does not guarantee universal effectiveness against every commercial or proprietary model in circulation.

Converting adversarial images into wearable and vehicle prints

Swearingen has begun moving selected patterns from digital output to physical media, offering early merchandise such as T‑shirts and hoodies through a crowdsourcing campaign to fund higher-resolution production. The goal is to produce printed patterns and vehicle skins with sufficient detail to remain effective at distance while also being visually acceptable for everyday use.

To avoid a quick countermeasure by camera and algorithm vendors, Swearingen is withholding his most potent patterns from the public internet and says distribution will be measured. He emphasizes a trade-off between public availability for privacy-minded users and the risk that broad release will enable defenders to retrain systems to ignore the patterns.

Legal, ethical and public-safety questions

Swearingen frames his work as a tool for people who want to avoid being tracked, arguing privacy is a fundamental right and that some citizens will feel safer exercising lawful rights if automated surveillance is less effective. Civil liberties advocates may welcome tools that limit algorithmic visibility in public spaces, particularly for vulnerable or politically active communities.

At the same time, law enforcement and public-safety officials are likely to raise concerns about tools that degrade detection of suspects or vehicles in investigations. The development also opens a potential adversarial cycle where camera vendors and algorithm developers update models to counter these patterns, spurring further rounds of technical escalation.

Remaining limitations and future development

Swearingen acknowledges the project is an early-stage effort and that effectiveness varies by camera model, angle, lighting and distance. Physical realities such as reflective surfaces, moving parts and the resolution limits of printed material can reduce the reliability of a pattern’s effect in uncontrolled environments.

The model continues to generate new designs and Swearingen says every detection failure is an opportunity to improve the system. He plans additional real-world tests, broader validation against different commercial systems and a cautious rollout strategy that balances accessibility with the risk of rapid neutralization by vendors.

The noRecognition work highlights a growing technical pushback against automated public surveillance, presenting both a novel privacy tool and a set of unresolved questions about safety, legality and the future dynamics between detection systems and adversarial defenses.

You may also like

Leave a Comment

The Calgary Tribune
The voice of Alberta to the world