Clothes That Confuse Cameras Are a Real Thing Now. Here Is What They Cannot Do.
From patterned jackets that trick face detectors to a DEF CON demo that scrambled eleven detection systems, a small industry is sewing privacy protest into everyday clothing. The catches are real.

Key points
- Cybersecurity researcher Bill Swearingen presented an AI technique at DEF CON in 2025 that generates colourful patterns capable of lowering the confidence scores of eleven different camera-based detection systems.
- Italian clothing brand Cap_able sells garments woven with bold motifs that can cause certain surveillance cameras to classify the wearer as an animal or an object rather than a person.
- Berlin-based Urban Privacy's Faception Reloaded collection uses black-and-white prints that trick some facial recognition systems into seeing extra faces, slowing detection down.
- Experts warn that a single clear camera frame is enough to identify someone, and that future AI models could be trained to ignore these patterns entirely.
- Carnegie Mellon University researcher Niloofar Mireshghallah says the bigger risk is aggregation: an AI combining a partial face, a location, a time stamp and a tagged photo to identify you even when no single signal would.
AI-powered cameras now line streets on every continent. Most can spot a face or read a number plate in milliseconds. A growing number of people want that to stop, and some of them are fighting back with their wardrobe.
The backlash is not just online petitions. Projects like DeFlock crowd-map automated licence plate readers, roadside cameras that log every passing car's registration number, so the public can see how many exist nearby. Our 3 September report "Police Are Using Flock's AI Camera Tool to Watch Anyone, Not Just Cars" showed how those systems are already being turned on individuals, not just vehicles. Others are vandalising cameras outright. A quieter, more creative resistance has taken shape in clothing designed to fool the AI doing the watching.
How does the technology behind it actually work?
The clothes exploit a weakness in object detection models, the software that scans a camera feed and draws a box around anything it recognises as a face or a body. Feed that software a pattern it was never trained to expect, and its confidence score, a number between zero and one hundred measuring how certain it is, can drop low enough that it stops flagging the person at all.
Bill Swearingen spent part of 2025 building a reinforcement learning algorithm, a type of AI that improves itself through trial and error, to generate exactly those patterns. He tested colourful geometric designs against eleven detection systems: four that search for faces, two that recognise faces, and five that detect people. Most of those systems are freely downloadable. He showed his findings at DEF CON, the annual hacker convention held in Las Vegas.
Italy's Cap_able weaves loud geometric motifs directly into knitted fabric. Founder Rachele Didero, who also teaches at a university in northern Italy, says cameras backed by fast convolutional neural networks, a common type of image-recognition AI, may log wearers as animals rather than humans. Berlin label Urban Privacy takes a different route: its Faception Reloaded line prints abstracted face shapes onto fabric, causing some systems to detect multiple faces at once and slow down.
Does it actually keep you hidden?
Not reliably, and the experts are blunt about that. "One good frame is all a system needs," says Mireshghallah, an incoming professor at Carnegie Mellon University, as first reported by IEEE Spectrum. A camera records dozens of frames per second. If the fabric bunches or the light shifts, even briefly, the system may get the clean shot it needs.
The patterns are also tuned to specific models. Switch to a different model and the camouflage stops working. Surveillance operators could train a new generation of AI on images of these garments, making the clothing useless against updated systems.
Mireshghallah's sharpest warning is about aggregation. A partial face, a building behind you, a time stamp, a photo a friend posted: none identifies you alone, but an AI can stitch them into a confident match. "No pattern on a shirt fixes that," she says.
The makers know the limits. "It's not an invisibility cloak," says Urban Privacy co-founder Daniel Preuß. The goal, he argues, is a statement as much as a shield.
What should ordinary people take from this?
Think beyond your face. The clothing is a conversation starter and a partial speed bump, not a complete answer. Watch what location data, tagged photos and your public posts say about your movements separately from each other, because those signals are often what ties an identification together. Pattern-weaving addresses none of them.



