The Anti-Surveillance Wardrobe

As facial recognition spreads, adversarial fashion is using deceptive patterns and infrared materials to confuse AI-powered surveillance cameras.

These Clothes Were Designed to Trick AI Surveillance Cameras

Author: Jelinda Montes

As fears of surveillance rise thanks to security cameras in every public (or private) space, an unexpected form of resistance is popping up: adversarial fashion. This unique type of fashion is created with the intention of obscuring people from AI facial recognition software.  

These “adversarial” pieces of clothing and accessories employ special patterns and materials made to confuse AI facial recognition software. Sometimes they include unique patterns that can cause AI to misidentify people as animals or objects. Other anti-surveillance clothing technology uses infrared reflective gear that blocks faces out entirely on camera, as if a bright light was shining on them. 

There’s a range of brands selling adversarial clothes at wildly different price points. On the more practical and accessible end, Anti-AI Clothing sells masks and gaiters under $20 and T-shirts for around $30. Looking to the other end of the spectrum, Italian-based company Cap_able sells a $780 reversible dress, one side of which reads as a person to AI while the other reads as a zebra. 

While at the Fashion Institute of Technology in 2019, Cap_able’s founder and CEO Rachele Didero began developing adversarial apparel after noticing just how many biometric cameras were in New York City. 

“The problem with [surveillance] technology is that citizens don’t have the possibility in the physical world to opt out,” she told the Mozilla Foundation. “In the digital space, we can say yes or no to cookies. In the physical world, we don’t have this option. We wanted to create this physical protection that would allow the citizens to give their consent, or not.”

Some skeptics of adversarial design say that algorithms are much more likely to advance beyond this AI camouflage faster than new protections can be produced. One brand that errs on the more accessible end of this niche, Urban Privacy, has a disclaimer at the bottom of the $45 Faceception Reloaded Tee: “Effectiveness varies depending on the algorithm and conditions. Not all systems are affected equally. Tested with iPhone 8 and OpenCV Face Cascade. Results may change as recognition technology evolves.” 

Nevertheless, many developers of this clothing argue the message it gets across is just as important as its actual utility against facial recognition.

The market for video surveillance enhanced by AI is worth over $4 billion in 2026, and is only expected to grow. By 2032, the market is expected to surpass $10 billion. Extremely popular personal security camera company Ring recently came under fire for a lost-dog program that many critics felt could be used to track people across private Ring cameras just as easily as pets. This slippery slope concern isn’t entirely unfounded, considering Flock Safety, a private automatic license plate reader company that has partnered with many law enforcement operations across the country, has reportedly enabled stalking and misuse

Facial recognition programs function through computer vision and deep learning systems that take images and videos and analyze them through huge data networks that enable complex pattern recognition. Face recognition specifically captures unique data points such as the distance between eyes and jawline contours and compares it to stored data. In general, facial recognition systems are worse at deciphering Black and Asian faces, leading to false recognition and, sometimes, false arrests

Adversarial clothing stops the AI-detection process at its first step by making it impossible to detect a face, either through infrared light blocking or by introducing symbols and patterns that interfere with the facial detection process. The AI systems break these unique face markers into digital signatures, so patterns work by using pixels that alter the computer’s ability to interpret these signatures. 

“So-called ‘adversarial clothing’ wins on many levels. As well as the practicality of protection, it’s fashionable and fun, it makes a powerful, public statement that many are in agreement with, it spreads even more awareness about the importance of privacy, and it helps encourage public debate,” Nick Tidball, the co-founder of clothing brand Vollebak, told The Guardian

Though Vollebak doesn’t make any anti-facial-recognition clothing, the U.K.-based fashion technology startup sells apparel with unique materials at premium prices, including a $4,295 leather jacket that blocks radio waves and a $1,895 copper “Full Metal Jacket” windbreaker. 

“If such clothing genuinely proved effective, it could get political very quickly,” Tidball said to The Guardian. “Then this type of clothing could find itself banned.”

Credits: TCA, LLC.

Discover more from thinkly gold

Subscribe now to keep reading and get access to the full archive.

Continue reading