Cybersecurity researcher Bill Swearingen publicly demonstrated Project noRecognition, a machine-learning system that generates printed wrap patterns intended to make vehicles or people harder for AI surveillance systems to detect. At DEF CON, he showed a wrapped 2009 Toyota Yaris passing a live Flock Safety camera; the camera reportedly captured video but did not log the vehicle through its automated detection pipeline. Swearingen said the system was trained with reinforcement learning across roughly 31 million tests and evaluated against 11 open-source detection algorithms, including software linked to license plate readers, body cameras, and facial recognition workflows.
The project aims to create privacy-preserving patterns that defeat automated tracking without simply obscuring a license plate, but reported results remain mixed. Security reporting said the strongest validated outcome on the project dashboard was 61.7% non-detection against a detector derived from a real deployed surveillance camera, and that result was achieved in digital simulation rather than consistent field conditions. Swearingen said real-world testing showed promise, though practical limitations remain, including weak points such as exposed wheels and the broader gap between simulated evasion and reliable operational use.

See the reporting duties and controls this puts on the clock.
5 events from the most recent confirmed update back to the earliest known activity.
Swearingen publicly demonstrated that a live Flock camera recorded video of the wrapped vehicle but reportedly failed to log it through its automated detection software. He presented noRecognition as a privacy-preserving technique intended to let people opt out of automated tracking without obscuring license plates.
At DEF CON in Las Vegas, Swearingen carried out his first real-world test by wrapping a 2009 Toyota Yaris in a noRecognition pattern and driving it past a Flock Safety camera. He said the test was effective, though the vehicle's wheels remained a weak point for evasion.
The noRecognition project dashboard cited its strongest validated result as 61.7% non-detection against a detector extracted from a real deployed surveillance camera. The article notes this result was still obtained in digital simulation rather than a real-world field test.
Swearingen said he spent about a year running roughly 31 million tests to train noRecognition to generate printed patterns that cause surveillance AI systems to miss covered vehicles or people. The system iteratively tested patterns against detection software and adjusted them when they were detected.
Bill Swearingen said he started the noRecognition project because he was concerned about being tracked by surveillance cameras while attending a protest. The effort grew from an initial experiment into a reinforcement-learning-based system for generating detection-evasion patterns.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.