Adversarial Fashion Makes a Statement on AI Panopticon - IEEE SpectrumIEEE.orgIEEE XploreIEEE StandardsIEEE Job SiteMore SitesSign InJoin IEEEAdversarial Fashion Confronts Surveillance NormsShareFOR THE TECHNOLOGY INSIDERSearch: Explore by topicAerospaceAIBiomedicalClimate TechComputingConsumer ElectronicsEnergyHistory of TechnologyRoboticsSemiconductorsTelecommunicationsTransportation IEEE Spectrum FOR THE TECHNOLOGY INSIDERTopicsAerospaceAIBiomedicalClimate TechComputingConsumer ElectronicsEnergyHistory of TechnologyRoboticsSemiconductorsTelecommunicationsTransportationSectionsFeaturesNewsOpinionCareersDIYEngineering ResourcesMoreNewslettersSpecial ReportsCollectionsExplainersTop Programming LanguagesRobots Guide ↗IEEE Job Site ↗For IEEE MembersCurrent IssueMagazine ArchiveThe InstituteThe Institute ArchiveFor IEEE MembersCurrent IssueMagazine ArchiveThe InstituteThe Institute ArchiveIEEE SpectrumAbout UsContact UsReprints & Permissions ↗Advertising ↗Follow IEEE SpectrumSupport IEEE SpectrumIEEE Spectrum is the flagship publication of the IEEE — the world’s largest professional organization devoted to engineering and applied sciences. Our articles, videos, and infographics inform our readers about developments in technology, engineering, and science.SubscribeAbout IEEEContact & SupportAccessibilityNondiscrimination PolicyTermsIEEE Privacy PolicyCookie PreferencesAd Privacy Options© Copyright 2026 IEEE — All rights reserved. A public charity, IEEE is the world's largest technical professional organization dedicated to advancing technology for the benefit of humanity. Enjoy more free content and benefits by creating an account
Saving articles to read later requires an IEEE Spectrum account
The Institute content is only available for members
Downloading full PDF issues is exclusive for IEEE Members
Downloading this e-book is exclusive for IEEE Members
Access to Spectrum 's Digital Edition is exclusive for IEEE Members
Following topics is a feature exclusive for IEEE Members
Adding your response to an article requires an IEEE Spectrum account
Create an account to access more content and features on IEEE Spectrum , including the ability to save articles to read later, download Spectrum Collections, and participate in conversations with readers and editors. For more exclusive content and features, consider Joining IEEE .
Join the world’s largest professional organization devoted to engineering and applied sciences and get access to all of Spectrum’s articles, archives, PDF downloads, and other benefits. Learn more about IEEE → Join the world’s largest professional organization devoted to engineering and applied sciences and get access to this e-book plus all of IEEE Spectrum’s articles, archives, PDF downloads, and other benefits. Learn more about IEEE →CREATE AN ACCOUNTSIGN INJOIN IEEESIGN INCloseAccess Thousands of Articles — Completely Free Create an account and get exclusive content and features: Save articles, download collections, and post comments — all free! For full access and benefits, subscribe to Spectrum. CREATE AN ACCOUNTSIGN INAIHistory of TechnologyNews Adversarial Fashion Confronts Surveillance Norms Adversarial attire can’t stop AI cameras, but can disrupt themRina Diane Caballar2h4 min readRina Diane Caballar is a contributing editor covering tech and its intersections with science, society, and the environment.Urban Privacy’s garments contain facial patterns that confuse facial recognition databases. Urban Privacy AI-powered cameras dot streets across the world, equipped with the power to identify faces or vehicle license plates. But a public backlash is gaining momentum.Privacy concerns abound, encompassing the lack of consent for capturing data, how that data is stored and used, and the risk of misuse. Those concerns are motivating people to fight back. The DeFlock project, for instance, maps automated license plate readers (ALPRs) to raise awareness. Some people resort to extreme measures, such as vandalizing or damaging ALPRs. Others are stitching together more creative responses, crafting “adversarial fashion” to evade surveillance cameras, like a Kickstarter project called noRecognition, presented at last month’s DEF CON hacker convention.Scrambling surveillanceIn 2025, cybersecurity expert Bill Swearingen began experimenting with a simple Python-based fuzzer, a tool that provides invalid inputs to reveal software bugs, security vulnerabilities, or unexpected behavior. The fuzzer targeted one of the most popular object detection frameworks, called YOLO. He then developed what he’d learned into a reinforcement learning algorithm that generates various adversarial patterns, which he presented at DEF CON.Each pattern is a colorful geometric abstraction he has tested against 11 object detection models—four that search faces, two that recognize faces, and five that detect people—most of which are publicly available. Successful patterns thwart the object-detection systems, lowering their confidence scores, sometimes even to the point of no detection.“Privacy is a human right, and the popularity of this just goes to show that people are interested in preserving their privacy,” Swearingen says.Cap_able and Urban Privacy are already selling physical garments. Cap_able’s patented manufacturing method weaves its bright and bold motifs into jacquard knitted fabrics. The ethically produced and sustainably made dresses, pants, and tops interfere with certain computer vision systems, particularly those backed by fast convolutional neural networks, which may lead them to classify wearers as animals or objects.“If we’re able to camouflage a person as something else, then we’re obtaining our goal,” says Cap_able founder Rachele Didero, who’s also an assistant professor at the Free University of Bozen-Bolzano in Italy. “We use this very visible and tangible item to talk about something that most of the time is intangible.”Meanwhile, Urban Privacy aims to baffle some facial recognition systems based on OpenCV algorithms with its latest Faception Reloaded collection. Black-and-white prints abstracted from a human face show up as additional faces on detectors, slowing them down. Asymmetrical cuts and wide silhouettes intend to conceal, making it harder to discern your body’s shape and gait. “The idea is to create false data,” says cofounder Daniel Preuß. Simulated patterns of the kind intended to disrupt machine vision person detectors.noRecognition“Not an invisibility cloak”Anti-surveillance fashion can trace its roots to the art pieces, DIY projects, and thought experiments that emerged in response to the onset of AI surveillance systems more than a decade ago. For instance, technologist Adam Harvey developed multiple designs in the 2010s—from hairstyles and makeup that foil face detectors to heat-reflecting attire that avert drone-enabled thermal surveillance. In 2019, artist and activist Kate Bertash created her aptly named Adversarial Fashion clothing line decked with fake license plate numbers to inject junk data into ALPR databases.The trend is now growing into a more solidified small industry. “Clothing is something you can actually buy and put on, unlike policy,” says Niloofar Mireshghallah, incoming professor of engineering and public policy at Carnegie Mellon University. “It’s a way of saying, ‘I didn’t consent to this.’”But real-world conditions might reduce the effectiveness of countersurveillance clothing, such as camera angles, lighting, and how fabric folds as you move. “One good frame is all a system needs,” Mireshghallah says.Motion and gait recognition are also influential factors. “Even if the camera thinks you’re a bear for a few frames, there’s a bear walking like you,” Mireshghallah says.The adversarial patterns must also be tuned to specific object recognition models, so they cannot resist a different model. And once surveillance system operators train a future generation of models on a given adversarial pattern and the person wearing it, which they could do manually, clothing will no longer be a sufficient defense.“It remains a fragile shield against a threat that is constantly improving from multiple angles,” says Dippu Kumar Singh, senior director of emerging data and analytics at Fujitsu North America who specializes in vision AI and AI ethics.Makers are aware of their creations’ limitations. “It’s not an invisibility cloak,” Preuß says. “Surveillance aims to capture your identity, and fashion is about expressing your identity. We’re making clothing that people can wear to make a statement about the importance of privacy in a digital world.”Active defenseEven with these hurdles, Cap_able’s Didero is determined to keep innovating. Urban Privacy will continue to release other parts of its collection, including a “shadow cap” that has an acrylic face shield layered with cutouts to blur facial contours. Swearingen plans to explore a few anomalies he has encountered, such as a pattern that shifted the bounding box and another pattern that changed a camera setting.Adversarial fashion holds promise despite its pitfalls. “At its core, this fashion is about taking back control of your face and body,” Singh says. “People are starting to realize that privacy isn’t just a right they can passively expect to be handed to them—it is something they have to actively defend.”Mireshghallah offers a more cautious approach, viewing countersurveillance fashion as a speed bump rather than an ultimate solution. The real risk, she notes, is aggregation: Models take a group of weak signals, such as a partial face, a building in the background, a time stamp, a social media post someone tagged you in, and stitch them together to make a confident guess about who you are and where you were.“None of those pieces give you away on their own, but together they do,” Mireshgallah says. “My advice is don’t just think about hiding your face from a lens. Think about what else you’re leaking that can be combined with it. That side information is often what actually identifies you— and no pattern on a shirt fixes that.”From Your Site ArticlesAI Art Generators Can Be Fooled Into Making NSFW Images ›Robots Have a Hard Time Grasping These "Adversarial Objects" ›Hacking the Brain With Adversarial Images ›Related Articles Around the WebThermally Activated Dual-Modal Adversarial Clothing against AI Surveillance Systems ›surveillanceAImachine visionobject recognitionRina Diane CaballarRina Diane Caballar is a writer covering tech and its intersections with science, society, and the environment. An IEEE Spectrum contributing editor, she's a former software engineer based in Wellington, New Zealand.The Conversation (0)SemiconductorsAINewsComputing How OpenAI Used Its Own LLMs to Design Its Jalapeño Chip 1h6 min readRoboticsSponsored Article Protecting Dynamic Industrial Robot Cable Carriers 03 Sep 20263 min readTransportationMagazineFeature Rivian’s Gambit for Full Autonomy 08 Sep 202613 min read Related Stories AIGuest Article Digital Surveillance Reshapes Fishery Enforcement in Indonesia EnergyNews Betting on AI and Robots to Automate Superconductor Discovery AINews New Platform Peers Inside AI’s Black Box |
Adversarial fashion emerges as a response to the proliferation of Artificial Intelligence surveillance systems and growing privacy concerns surrounding data capture. As AI-powered cameras are deployed globally to identify faces and license plates, public backlash regarding consent, data storage, and potential misuse has motivated individuals to develop methods of confrontation. Some initial efforts, such as the DeFlock project, have focused on mapping automated license plate readers to generate awareness, while others have employed more creative countermeasures like crafting adversarial fashion to evade surveillance.
The theoretical foundation for disrupting machine vision systems was explored through adversarial techniques. For instance, cybersecurity expert Bill Swearingen developed a Python-based fuzzer to generate invalid inputs that reveal software vulnerabilities. He extended this work into a reinforcement learning algorithm that generates adversarial patterns designed to thwart object detection systems, including popular frameworks like YOLO. These patterns are geometric abstractions tested against various object detection models, successfully reducing their confidence scores or preventing them from detecting objects entirely. This work highlights the underlying principle that privacy is a human right that necessitates active defense.
This concept has been translated into tangible products. Companies like Cap_able have patented manufacturing methods that integrate bright and bold motifs into fabrics, creating garments that interfere with computer vision systems, particularly those utilizing fast convolutional neural networks, thereby confusing them into classifying wearers as animals or objects. The founder of Cap_able suggests that using visible clothing allows individuals to make intangible statements about privacy. Similarly, Urban Privacy aims to baffle facial recognition systems based on OpenCV algorithms through collections like Faception Reloaded, using abstracted black-and-white prints that generate false facial detections and employing asymmetrical cuts to obscure body shape and gait.
The movement for anti-surveillance fashion has a history rooted in earlier thought experiments and art, with figures like Adam Harvey developing designs in the 2010s to foil face detectors and others creating clothing adorned with fake license plate numbers to inject misleading data into Automatic License Plate Recognition databases. This trend is solidifying into a nascent industry, as noted by Niloofar Mireshghallah, who views clothing as a means to assert, “I didn’t consent to this.”
However, experts caution that physical countermeasures face significant limitations in real-world settings. Factors such as camera angles, lighting conditions, and the way fabric folds during motion can negate the effectiveness of adversarial patterns. Furthermore, success depends heavily on the specific object recognition model being targeted; if surveillance operators retrain their models on an adversarial pattern, the defense becomes inadequate. Therefore, adversarial fashion is viewed not as an invisibility cloak but as a fragile shield.
The most significant risk identified is aggregation, where the combination of weak, disparate signals—such as a partial face, a background building, a timestamp, and social media tags—can be stitched together by AI models to create a confident identification of an individual, regardless of the patterns worn. Mireshghallah advises that focusing solely on hiding the face is insufficient; the real threat lies in the aggregated side information that can identify a person. Consequently, while adversarial fashion serves as an important means for individuals to assert control over their identity, it functions primarily as a speed bump, rather than an ultimate solution against evolving surveillance technologies. |