adversarial patterns block surveillance cameras by targeting weaknesses in the artificial intelligence systems that analyze camera images. New research in 2026 has pushed the technology beyond simple computer simulations, with researchers testing wearable designs, visible-thermal attacks and more natural-looking clothing patterns against modern person-detection systems.
The subject has gained fresh attention in the United States following cybersecurity researcher Bill Swearingen’s presentation at Black Hat USA 2026. His session, “Could a Pattern on Your Clothing Fool Facial Recognition?”, focused on whether specially designed clothing can interfere with automated surveillance technologies. Black Hat listed the presentation under its Privacy and Human Factors tracks.
At the same time, academic researchers have continued developing physical adversarial clothing. Recent 2026 work has examined full-body camouflage, thermal sensing and clothing designed to remain effective as a person changes position, distance and viewing angle.
These developments do not mean that a patterned shirt makes someone invisible to every security camera. The current research supports a narrower conclusion: carefully engineered visual patterns can cause certain AI detection models to make mistakes under tested conditions.
What Are Adversarial Patterns?
Adversarial patterns are specially designed visual designs that take advantage of weaknesses in machine-learning models.
A human may see a collection of shapes, colors or camouflage elements. An AI system may process those same details very differently.
Computer-vision systems break images into mathematical features. They use those features to decide whether an image contains a person, vehicle, face or other object.
Researchers can deliberately modify a visual pattern so those calculations become less reliable.
This approach differs from simply covering a camera lens or hiding behind an object. The camera can continue recording the scene. The goal is to interfere with the automated system interpreting what it sees.
That distinction matters because modern surveillance often involves several separate AI functions.
A camera system may first detect a person. Another process may locate a face. A separate recognition model may then compare the face with stored information.
Interfering with one stage does not automatically defeat the others.
Why Clothing Has Become a Major Research Area
Clothing offers researchers a practical surface for testing physical adversarial designs.
Unlike a small digital patch, a garment can cover a substantial portion of the body. Researchers can also print patterns over shirts, dresses or other wearable materials.
Earlier research established that physical adversarial textures can affect person detectors. Later studies began addressing one of the biggest weaknesses of these designs: changes in camera angle.
A pattern that works from directly in front of a camera may behave differently when a person turns sideways.
Lighting creates another challenge.
Sunlight, shadows, indoor lighting and camera exposure can all change how a pattern appears in an image.
Modern research therefore attempts to build those variations into the testing process.
The Latest AdvTiles Research
One of the newest developments is AdvTiles, a research framework introduced in an August 7, 2026 preprint.
The study focuses on physical adversarial camouflage clothing designed to interfere with person detectors. Researchers divided the clothing design into smaller learnable tiles rather than treating the entire garment as one large texture.
This approach gives the system more control over individual sections of the design.
The researchers also used 3D Gaussian Splatting to simulate different viewpoints, distances, lighting conditions and backgrounds during optimization.
That matters because a person rarely remains perfectly still in front of a surveillance camera.
Someone may walk toward a camera, move across its field of view or turn around. Clothing also bends and wrinkles during movement.
The researchers reported an average attack success rate of 86.2% across multiple detectors. They also manufactured the optimized designs as wearable clothing and conducted physical testing under different distances, angles and backgrounds.
The result represents an important step in physical computer-vision research.
However, the finding applies to the tested systems and conditions. It does not establish that one design defeats every surveillance camera.
Thermal Cameras Are Part of the Research
Visible-light cameras are not the only systems researchers are studying.
Thermal imaging provides another way to detect people. Instead of relying primarily on visible colors and textures, thermal systems use infrared radiation associated with temperature.
That creates a different technical challenge.
A pattern designed only for an ordinary camera may have little effect on a thermal detector.
Researchers have therefore started developing clothing that addresses both visible and thermal sensing.
A CVPR 2026 study examined thermally activated adversarial clothing for AI surveillance systems. The design combined thermochromic materials with flexible heating components.
The researchers created a garment in which heating could change the appearance of the material. Their system was designed to produce patterns relevant to both visible-spectrum and infrared detection.
The study reported physical testing and an attack success rate above 80% across the tested surveillance environments.
The significance lies in the dual-sensor approach.
A surveillance system that combines visible and thermal information can use more than one source of evidence. Researchers attempting to disrupt such systems must therefore consider both channels.
Another Study Targets Visible-Thermal Detectors
A separate 2026 study examined adversarial clothing against visible-thermal, or RGB-T, object detectors.
The researchers developed a non-overlapping RGB-T pattern that uses different materials for visible and thermal information.
The design was tested against multiple detector architectures.
Researchers reported strong attack performance in both digital and physical testing. They also investigated transferability against RGB-T detectors that were not used directly during the original optimization.
This research demonstrates why surveillance technology cannot be treated as one uniform category.
A conventional RGB camera, thermal camera and multimodal system process information differently.
An adversarial design that affects one system may perform differently against another.
Bill Swearingen’s NoRecognition Project
The current U.S. discussion also includes the NoRecognition project associated with cybersecurity researcher Bill Swearingen.
The project focuses on AI-generated patterns for clothing that can interfere with person detection, face detection and facial-recognition systems.
Swearingen presented his research at Black Hat USA 2026. The official conference schedule lists the presentation under Privacy and Human Factors and identifies the session as a 40-minute briefing.
The project is particularly relevant because it treats pattern creation as an automated optimization problem.
Instead of relying on a designer to manually create a graphic, software can generate candidate patterns and evaluate how those designs affect selected detection models.
The process can then continue with new patterns.
This makes it possible to test a much larger number of potential designs than would be practical through manual experimentation.
Read More – Karmelo Anthony Video Footage: What Surveillance and Bodycam Clips Revealed in Court
Person Detection Is Different From Facial Recognition
One of the most important points in current research is the difference between detection and recognition.
Person detection asks whether a person appears in an image.
Face detection asks whether a face is present.
Facial recognition attempts to determine who that face belongs to.
These are separate technical tasks.
A pattern that reduces the confidence of a person detector may prevent later processing from occurring. However, that does not prove that the same design defeats facial recognition when a face is clearly detected.
The distinction also applies to surveillance networks.
A camera may continue recording a person even if its automated system fails to classify that individual correctly.
A human reviewing the video may still be able to see the person.
For that reason, claims about becoming “invisible” to surveillance should be treated carefully.
Why One Camera Can Behave Differently From Another
Surveillance cameras can differ substantially in their hardware and software.
Important variables include:
- Camera resolution
- Lens characteristics
- Viewing angle
- Lighting
- Image compression
- Detection model
- Detection threshold
- Image preprocessing
- Camera distance
- Environmental conditions
Two cameras positioned in the same area can therefore respond differently to the same clothing.
The AI model itself is particularly important.
Adversarial patterns are often optimized against specific model behavior. Changing the model can change the outcome.
This is one reason researchers increasingly test their designs against several detector architectures.
Physical Testing Is More Difficult Than Digital Testing
Digital experiments provide researchers with precise control.
They can change a pattern, adjust its position and test the result against a known model.
Physical experiments introduce many more variables.
Printed clothing has fabric texture. Colors can change during printing. The material can fold or stretch. A moving person can create motion blur.
Outdoor cameras also deal with changing sunlight, shadows and weather.
Distance can affect the number of pixels representing the pattern.
All of these factors can reduce the consistency of an adversarial design.
Recent research addresses some of these issues by simulating different viewing angles, distances, lighting conditions and backgrounds before producing physical garments.
That makes the latest work more relevant to real-world conditions than a single static image test.
Earlier Research Laid the Foundation
The current developments build on years of adversarial machine-learning research.
Researchers previously demonstrated that specially designed textures could interfere with deep-learning person detectors in physical environments.
A 2022 study on adversarial textures examined clothing printed with patterns intended to work across different camera angles. Researchers created physical garments and tested them in real environments with different distances, poses and scenes.
Other work examined infrared detection.
Research published through CVPR investigated clothing designed to interfere with infrared detectors at multiple angles. Physical experiments tested different distances, poses and environments.
The 2026 studies build on that foundation by combining stronger optimization methods with more advanced materials and multimodal sensing.
Natural-Looking Clothing Remains a Challenge
Effectiveness is only one part of the problem.
A highly unusual garment may interfere with an AI model but attract immediate attention from people.
That creates a practical challenge for researchers seeking clothing that can be worn in ordinary public environments.
AdvTiles specifically addresses the balance between visual naturalness and attack performance.
Its tile-based method allows individual sections of the design to be optimized while maintaining an overall camouflage appearance.
The researchers reported that their manufactured garments retained effectiveness during tests involving different physical conditions.
This focus represents a broader shift in the field.
Researchers are not simply asking whether a pattern can fool an algorithm in one image. They are investigating whether a design can remain effective while behaving like real clothing.
Surveillance Defenses Are Developing Too
The research does not move in only one direction.
As adversarial attacks become more sophisticated, researchers are also developing methods to make computer-vision systems more resistant.
One 2026 study examined defenses against patch-based and texture-based adversarial attacks.
The researchers used spectral decomposition and adversarial training to improve resistance to deliberately designed visual attacks.
Testing included adaptive attacks created against the defense itself.
That work highlights an important feature of adversarial machine learning: each successful attack can encourage the development of a corresponding defense.
A detector can be retrained.
Image processing can be changed.
Additional sensors can be introduced.
Multiple models can also be used together.
These defensive techniques make universal results difficult to establish.
What the Current Evidence Actually Shows
The latest research supports several clear conclusions.
First, physical adversarial clothing is a genuine research area.
Second, researchers have demonstrated that specially designed patterns can interfere with some AI-based person detectors.
Third, 2026 research has moved further into physical clothing, thermal sensing and multimodal detection.
Fourth, newer techniques attempt to maintain performance across different viewing conditions.
Fifth, results remain dependent on the systems and conditions being tested.
There is currently no factual basis for claiming that one clothing pattern can defeat every surveillance camera used in the United States.
The research instead shows that AI surveillance systems can have weaknesses that researchers can identify and test.
Why the Technology Matters in the United States
The issue has particular relevance in the U.S. as computer vision becomes more common in public and private environments.
Automated cameras can support security operations, traffic monitoring, access control and other applications.
Facial-recognition technology adds another layer by attempting to associate captured faces with identities.
Adversarial research examines the other side of that technology.
Instead of asking how cameras can identify people more effectively, researchers ask how visual systems can be made to misinterpret what they see.
That creates an ongoing technical competition.
Surveillance developers seek more reliable detection.
Researchers studying adversarial machine learning seek ways to expose weaknesses.
Defensive researchers then work to reduce those weaknesses.
The Bottom Line
The latest evidence shows that adversarial patterns can interfere with AI-based surveillance under specific tested conditions. Research in 2026 has demonstrated physical clothing attacks, visible-thermal techniques and new methods for creating more natural-looking camouflage.
The technology remains highly dependent on the camera, detection model and surrounding conditions. A design that affects one detector does not automatically defeat another, and disrupting automated detection does not erase the underlying video recording.
For U.S. readers, the most important development is the growing sophistication of the research. Scientists and cybersecurity researchers are moving from simple visual tricks toward physical garments, multimodal attacks and designs tested under changing real-world conditions.
At the same time, defenses are improving. That means the future of adversarial clothing will depend on how well these patterns transfer across different surveillance systems and how effectively camera operators adapt their detection models.
As researchers continue testing where AI surveillance succeeds and fails, adversarial clothing is becoming an important part of the wider debate over automated identification and privacy.
