Category: Cyber Security | Published: 2026-08-27
A security camera can record a person clearly while the software behind it fails to recognise that a person is there. That sounds contradictory, but it is the idea behind a growing area of computer-vision research. By designing patterns that confuse an image-recognition model, researchers are exploring how people and vehicles might remain visible to human eyes while becoming harder for automated surveillance systems to identify.
The work offers an unusual way to think about AI CCTV. These systems are often described as if they simply see what a camera sees. In reality, the camera captures an image and a separate layer of software interprets it. That interpretation can be useful, fast, and impressively accurate, but it is not infallible.
When Visibility Is Not the Same as Recognition
US cyber security researcher Bill Swearingen has spent around a year testing whether specially designed visual patterns can interfere with the object-detection models used by modern surveillance equipment. His project, noRecognition, uses AI-generated adversarial patterns to target the weaknesses of computer-vision systems.
The goal is not to make somebody disappear from a recording. A person wearing one of the patterns could still be plainly visible in the footage. A vehicle carrying a patterned covering could also be seen by someone watching the video. The intended effect is more specific: to make the automated system misclassify or overlook the object in front of it.
That matters because AI CCTV does more than save a video file. Depending on the equipment and its configuration, intelligent surveillance can identify people, recognise faces, read number plates, follow vehicles, detect objects, and raise alerts when a particular event occurs. If the recognition layer is fooled, the recording may still exist while the automatic alert never arrives.
Teaching a Model to Find the Weak Spots
Designing an effective pattern by hand would be difficult. Computer-vision models respond to combinations of shapes, contrast, colour, scale, and position that are not always obvious to a person looking at an image. A design that works against one detector may have no effect on another.
Swearingen’s approach uses reinforcement learning. The system generates a candidate pattern, tests it against a target detector, measures the result, and then uses that feedback to create another version. Patterns that perform better are retained while less successful approaches are discarded.
According to the project’s account, the process involved approximately 31 million tests. That figure illustrates the difference between a person making a piece of camouflage and an AI system searching through millions of possibilities. The model does not need to understand the pattern in the same way a human does. It only needs to discover which visual arrangements produce the desired change in the detector’s output.
This is one of the more important AI CCTV dangers for security professionals to understand. The attack does not have to involve breaking into the camera network, stealing footage, or changing a password. It can target the assumptions made by the analysis software itself.
Testing Across Different Surveillance Models
The noRecognition research has examined an 11-detector environment covering person detection, face detection, and face-recognition models. It also included a production-grade person detector taken from a deployed surveillance camera.
The results are not uniform. Effectiveness varies with the model being tested, the amount of clothing covered by the pattern, the distance from the camera, the lighting, and the angle of the subject. A design that looks promising in a digital test may perform very differently in a real street, car park, shop, or building entrance.
That limitation is important. There is a tendency to treat a successful demonstration as proof that a technique works everywhere. In practice, AI CCTV is deployed in a wide range of conditions, and camera manufacturers regularly update their models. Swearingen’s project also reports unsuccessful tests rather than showing only its strongest results, which gives a more useful picture of what the research can and cannot currently demonstrate.
Much of the strongest evidence still comes from simulations. Digital images offer controlled conditions that make testing repeatable, while real clothing and vehicles introduce folds, reflections, shadows, movement, weather, and changes in perspective. Moving from a computer model to a physical environment is a significant step.
A Real-World Demonstration
A demonstration at the DEF CON cyber security conference in Las Vegas explored that step. With help from automotive media company Donut Media, one of the patterns was applied to a 2009 Toyota Yaris and presented to a Flock surveillance camera.
The demonstration reportedly defeated the camera’s automated detection in that particular test. It did not make the car invisible, nor did it prove that every vehicle-recognition system could be bypassed in the same way. It showed something more specific and arguably more useful: a physical object can remain obvious to a person while causing a particular machine-vision system to produce the wrong result.
The project has also looked at clothing such as T-shirts and hoodies. Swearingen has chosen not to publish the most effective designs openly, partly because widely distributing them could help surveillance developers train their systems against those exact patterns. That decision reflects the difficult balance at the centre of this research. The same technique could give people more control over unwanted tracking, or help somebody evade a legitimate security measure.
AI CCTV Has Changed the Role of the Camera
Traditional CCTV was mainly a recording system. It captured what happened so that somebody could review the footage later. The practical value of a large camera network was limited by the number of people available to watch it or search through it.
Computer vision changed that model. AI CCTV can analyse huge amounts of footage continuously and decide which events deserve attention. It can search for a face, find every appearance of a vehicle, flag movement in a restricted area, or identify an object without an operator manually viewing every second of video.
That added intelligence is where much of the value comes from, but it is also where new weaknesses appear. Businesses that rely on automated camera alerts are not only protecting lenses, recorders, networks, and stored footage. They are also relying on a classifier to make a judgement about what is in the frame.
A failure at that level can be hard to notice. The video may look normal when a security team checks it after an incident. The problem is that the automated search never highlighted the relevant moment in the first place. The gap is between what was recorded and what the system decided was important.
An Arms Race Between Detection and Evasion
The likely response from surveillance manufacturers is to improve their models, add more varied training data, combine several detection methods, and test against known evasion techniques. Researchers can then use more capable AI to search for new weaknesses in those improved systems.
That creates an AI arms race within computer vision. The advantage may move back and forth as each side adapts. A pattern designed for one model may fail after an update, while a new system may introduce a different set of weaknesses. Camera operators therefore need to think about resilience rather than assuming that buying a newer model permanently solves the problem.
The privacy debate is just as complicated. People who object to pervasive automated tracking may see adversarial patterns as a way to reclaim some control over how they are analysed in public. Security teams may see the same idea as an attempt to defeat safeguards used to protect buildings, vehicles, and people.
Both concerns are valid. The question is not whether computer vision should always be trusted or always be defeated. It is how organisations use it, what people are told, what data is retained, and what other controls exist when an AI decision is wrong.
What This Means for Businesses
Businesses using AI CCTV for access control, retail monitoring, premises security, vehicle recognition, or automated alerts should treat its output as one source of information rather than an unquestionable fact.
Start by understanding what the system actually does. Is it detecting a person, recognising a known individual, reading a number plate, or simply identifying movement? Which alerts depend on a single model? How often is the software updated? What happens when lighting, weather, camera angle, or an unusual object affects the result?
Layered security is important. Combine intelligent cameras with good physical access controls, appropriate lighting, alarm systems, trained staff, and sensible review procedures. Keep audit logs so it is possible to see which events generated alerts and which were ignored. Test the system in realistic conditions, not only in the showroom or on a clear daytime recording.
There are privacy responsibilities too. Organisations should be clear about the purpose of surveillance, limit collection to what is necessary, control access to footage and analytics, and set sensible retention periods. A camera network that can identify and track people deserves the same careful governance as any other system processing personal data.
The research into adversarial patterns is a timely reminder that seeing and understanding are different things. AI CCTV can make surveillance more efficient, but its decisions still depend on software that can be tested, manipulated, updated, and occasionally mistaken. If you are reviewing the security of connected cameras, access systems, and the wider network around them, our Cyber Security services page is a good place to begin.