The camera does not see you the way another person does.
It sees landmarks.
Eyes. Nose. Jaw. Distance between features. Clothing. Color. Body shape. Movement. Tattoos. Accessories. License plates. Vehicle shape.
The modern surveillance system does not necessarily need to know your name when it first sees you. It just needs enough machine-readable information to decide that the person in Camera A is probably the same person who appeared in Camera B.
That changes the privacy equation.
For generations, being anonymous in public mostly meant blending into a crowd. Today, anonymity increasingly means giving computer vision less useful information to work with.
And that has created an entire field of anti-surveillance experimentation: masks, unusual makeup, CV Dazzle, adversarial clothing, infrared materials, reflective accessories and patterns specifically designed to make artificial intelligence see something different from what the human standing next to you sees.
Some of it genuinely works.
Some of it works only against particular systems.
Some of it is basically cyberpunk fashion with a good marketing department.
Here is what we actually know.
First: Flock Cameras and Facial Recognition Are Not the Same Thing
This distinction matters.
Flock Safety’s familiar roadside cameras are primarily automated license plate readers, or ALPRs. Flock says its standard LPR cameras do not perform facial recognition. They identify vehicles through license plates and characteristics such as make, model, color and distinguishing features.
So if you drive past a Flock ALPR while wearing the world’s most sophisticated anti-facial-recognition makeup, the camera may not care.
Your car is your face.
But Flock’s ecosystem has expanded beyond traditional plate readers.
Its FreeForm system can search enabled video using ordinary-language descriptions based on visible characteristics such as clothing and accessories. Flock says the system does not identify people biometrically, but investigators can nevertheless search video based on what someone looks like.
That creates several separate surveillance problems:
- Facial recognition: Who is this face?
- Person detection: Is there a human in this image?
- Person re-identification: Is this the same person who appeared on another camera?
- Appearance search: Find the person wearing a blue jacket and backpack.
- ALPR surveillance: Where has this vehicle been?
There is no single trick that defeats all five.
But there are ways to give each system less useful data.
The Basic Philosophy: Remove Signal or Add Noise
Almost every anti-surveillance technique falls into one of two categories.
Remove signal.
Cover the information the system wants.
A mask removes the mouth, nose and jaw. Sunglasses remove portions of the eye area. A hat changes what can be seen from an elevated camera. Covering a tattoo removes an unusually strong identifier.
Or:
Add noise.
Give computer vision visual information that causes it to interpret the image incorrectly.
That is where things get interesting.
Researchers have demonstrated makeup, glasses, printed clothing, adversarial patches and even materials invisible to human eyes that can cause AI systems to miss or misidentify what is directly in front of them.
This is essentially camouflage for machines.
1. CV Dazzle: Face Paint Designed for Algorithms
The most famous example is CV Dazzle, a project created by artist and researcher Adam Harvey.
Instead of painting the face to look natural, CV Dazzle does almost the opposite.
Traditional facial-recognition systems attempt to locate relatively predictable facial landmarks: eyes, eyebrows, nose, mouth, jaw and the geometric relationships among them.
CV Dazzle deliberately disrupts those relationships.
Think:
- strong asymmetry;
- contrasting shapes crossing the nose;
- one eyebrow visually erased or exaggerated;
- geometric blocks around one eye;
- dark and light regions that change perceived facial geometry;
- hair crossing areas a detector expects to be clear;
- artificial lines suggesting false facial boundaries.
The goal is not necessarily to make a human unable to recognize you.
The goal is to make the machine struggle to find a normal face in the first place.
Modern reporting on renewed CV Dazzle experimentation has described techniques including fake eye shapes, asymmetric makeup, strong contrast and hair positioned across important facial regions.
A basic CV Dazzle concept
Picture a normal face.
Now break the symmetry.
Instead of conventional eyeliner around both eyes, put a heavy geometric shape around one.
Run another contrasting shape diagonally across the bridge of the nose.
Alter the apparent eyebrow line.
Extend a block of color from the forehead into one eye region.
The machine is expecting:
eye — nose — eye
You are trying to give it:
shape — edge — maybe-eye — color boundary — nose? — another edge
That’s the theory.
Does CV Dazzle still work?
Sometimes.
But the original CV Dazzle experiments emerged when face detection was considerably less sophisticated than today’s deep-learning systems.
Modern facial-recognition models are much better at dealing with imperfect images, unusual lighting and partial obstruction.
However, adversarial makeup itself is very much alive as a research field.
A CVPR 2024 paper called DiffAM used modern diffusion models to generate visually plausible makeup specifically designed to protect facial privacy against face-recognition systems. Researchers reported improved attack performance even under black-box conditions where the exact recognition system was unknown.
So CV Dazzle is not magic.
But the underlying idea was absolutely real.
And researchers are still developing it.
Verdict: Real concept. Modern effectiveness depends heavily on the recognition system.
2. The Low-Tech Option: Physically Cover the Face
There is an amusing irony in spending millions of dollars researching adversarial neural-network attacks when humanity already invented fabric.
A physical covering does something extremely useful:
It removes pixels.
The computer cannot analyze facial geometry that the camera never captured.
NIST testing has repeatedly found that masks interfere with facial-recognition performance, although algorithms became substantially better at handling masked faces after the COVID-19 pandemic. Greater facial coverage generally creates more difficulty than minimal coverage.
Modern recognition systems can still work from the remaining visible face.
Which means a mask is better understood as signal reduction, not invisibility.
Mask + glasses + hat
If facial privacy is the objective, layers matter.
A mask removes much of the lower face.
Large glasses obscure part of the eye region.
A brimmed hat changes illumination and can interfere with clean views of the forehead and upper face, particularly from cameras mounted above eye level.
None is guaranteed.
Together, however, they leave substantially less conventional facial geometry exposed than an uncovered face.
There is nothing particularly futuristic about it.
Sometimes the best anti-AI technology is a baseball cap.
Verdict: Probably the most practical everyday approach.
3. Adversarial Makeup Has Become Much More Sophisticated
CV Dazzle was the punk-rock prototype.
Modern adversarial makeup is the laboratory version.
Researchers now use machine learning itself to determine which subtle modifications most strongly change the mathematical representation of a face inside another neural network.
In other words:
AI designs the makeup that confuses AI.
A 2022 CVPR project generated adversarial makeup intended to preserve a natural cosmetic appearance while changing the identity representation produced by face-recognition models.
DiffAM pushed the idea further in 2024 by using diffusion models and ensemble techniques to improve transferability to systems that were not directly available to the attacker.
This is important because it addresses the central weakness of homemade anti-recognition tricks.
You usually do not know which algorithm is watching you.
A pattern that completely confuses one model can be meaningless to another.
Research increasingly focuses on making adversarial appearance changes survive that uncertainty.
Verdict: One of the most promising areas of facial-privacy research, but consumer-ready universal makeup does not exist yet.
4. Infrared: The Camera Can See Colors You Cannot
Now we enter proper cyberpunk territory.
Human vision occupies only a small portion of the electromagnetic spectrum.
Many cameras can detect near-infrared light that your eyes cannot see.
That creates the possibility of having one appearance to humans and another appearance to cameras.
Researchers demonstrated this concept years ago using infrared illumination positioned around the face. To a nearby human, the face looked ordinary. To a susceptible camera, infrared light altered important facial regions enough to disrupt recognition.
The research has become considerably more sophisticated.
A 2025 study developed patches using infrared-absorbing ink. The material was designed to remain inconspicuous in visible light while generating adversarial patterns when photographed using near-infrared imaging. Researchers reported an average physical attack success rate of 82.46% against the models they tested.
Read that again.
The researchers were essentially creating face markings the computer could see but humans could not.
That is no longer science fiction.
It is published computer-vision research.
Should you buy “infrared facial-recognition glasses” online?
Be skeptical.
Different cameras have different infrared filters, wavelengths, illumination systems, exposure controls and recognition models.
Something that produces a dramatic effect on one security camera might produce nothing on another.
And active infrared light sources worn close to the eyes raise obvious safety concerns.
The science is real.
The claim that one random pair of Amazon glasses makes you universally camera-proof is not.
Verdict: Scientifically legitimate, technically fascinating and very system-dependent.
5. Adversarial Clothing: Make the AI Forget You Are a Person
Facial recognition is only part of surveillance.
Before software recognizes your face, another algorithm may first need to answer a simpler question:
Is there a person in this frame?
That creates another target.
Researchers have repeatedly demonstrated clothing covered in specially generated patterns that cause person-detection algorithms to overlook the wearer.
A 2022 CVPR study called Adversarial Texture printed adversarial patterns onto real shirts, skirts and dresses and demonstrated that people wearing them could fool person detectors under physical-world conditions and multiple viewing angles.
A 2024 CVPR project developed more natural-looking dynamic adversarial patches and reported physical-world success against tested smart-camera detectors.
The research is moving quickly.
In August 2026, researchers published AdvTiles, which creates natural-looking camouflage patterns optimized across different camera angles, lighting conditions and scales. The authors reported an average attack success rate of 86.2% across the detectors they evaluated.
The resulting clothing does not necessarily look like a QR code glued to your chest.
Increasingly, it looks like… clothing.
Why weird patterns can confuse AI
Neural networks do not recognize “personhood” philosophically.
They identify statistical patterns.
Researchers can therefore optimize an image so that the features activating the model’s person category become weaker.
A human looks at the result and sees:
person wearing ugly shirt
The detector may see:
background noise
That gap between human perception and machine perception is the fundamental weakness adversarial fashion exploits.
Verdict: Absolutely real in laboratories and controlled physical tests. Reliability against unknown real-world systems remains inconsistent.
6. The New Frontier: Clothing That Fights Visible and Thermal Cameras
Thermal cameras create another problem.
Paint does not necessarily help if the system is looking at heat instead of visible color.
Researchers are already working on that too.
At CVPR 2026, researchers demonstrated thermally activated adversarial clothing designed to affect both visible-light and infrared surveillance systems.
At room temperature, the garment appeared to be an ordinary black shirt. Heating elements activated thermochromic material, revealing an adversarial pattern. Researchers reported attack success above 80% across their tested surveillance environments.
Another CVPR 2026 project developed physical clothing targeting combined visible-and-thermal detectors using different materials for the visible and thermal portions of the adversarial pattern.
So yes:
Researchers are now literally building clothes whose appearance changes depending on whether a human being or an AI surveillance sensor is looking at them.
We have arrived.
Verdict: Real cutting-edge research. Not an everyday consumer solution yet.
7. Plain Clothing Can Be Privacy Technology Too
There is another strategy that requires absolutely no adversarial AI research.
Become visually boring.
Flock’s current FreeForm documentation says enabled video can be searched using observable characteristics such as clothing and visible accessories.
Imagine an investigator searching for:
man wearing purple cowboy hat, orange backpack and white jacket
Now compare:
person wearing dark jeans and gray hoodie
The second description is far less discriminating.
If privacy matters, unusually distinctive characteristics can work like temporary identification numbers.
That includes:
- recognizable tattoos;
- unusual bags;
- rare jackets;
- political or organizational logos;
- distinctive hats;
- highly unusual shoes;
- brightly colored accessories.
This does not make ordinary clothing an invisibility cloak.
It makes you less uniquely searchable.
That distinction matters in an era when video databases can be searched by description.
Verdict: Extremely practical.
8. Tattoos Are Basically Human QR Codes
A face is not the only persistent visual identifier.
A large tattoo may remain unchanged for years.
If it is unique enough, hiding your face while leaving the tattoo exposed can defeat the point.
That becomes even more relevant as video-search systems become better at natural-language queries and visual matching.
The privacy solution is not complicated.
When anonymity matters, cover unusually distinctive features.
Sleeves exist.
Verdict: Obvious but frequently overlooked.
9. Your Walk Can Identify You
Things get stranger.
Researchers have spent years developing gait recognition: identifying people based on the way their body moves while walking.
The field remains active. CVPR 2026 research demonstrated gait-recognition systems using event cameras capable of extracting motion and body-shape information even under difficult lighting conditions.
Other current research combines detailed kinematic motion with broader body-shape features for recognition.
This means the future surveillance stack does not necessarily stop at:
I can’t see his face.
It can continue:
What is his body shape?
How does he walk?
Is this the same movement signature we saw two blocks away?
There is no sensible recommendation that everyone deliberately walk strangely.
The important point is conceptual.
Covering your face does not make the rest of your body cease to exist as data.
10. Changing Clothes Can Break an Important Link
Modern surveillance research includes person re-identification, usually called Re-ID.
The goal is straightforward:
Camera A sees someone.
Camera B sees someone later.
Are they the same person?
Clothing is one of the strongest available clues.
Research specifically examining clothing changes found that changing clothing makes conventional person-reidentification significantly more difficult, because many systems rely heavily on appearance information.
Modern systems increasingly try to overcome that limitation using body shape, gait and other persistent characteristics.
But clothing remains extremely important.
Which leads to an interesting privacy principle:
Your outfit can become a temporary tracking identifier.
11. Reflective Materials: Potentially Useful, Frequently Oversold
You’ve probably seen videos where reflective jackets or glasses explode into giant white blobs on security cameras.
That phenomenon can be real.
It also depends heavily on how the particular camera illuminates and exposes the scene.
Retroreflective materials send light strongly back toward its source. Under cameras using near-camera illumination, they can sometimes create intense glare or overexposed regions.
But modern cameras can automatically change exposure, use different wavelengths or simply photograph you under ambient light.
So reflective materials belong in the category:
Interesting additional interference, not universal invisibility technology.
The deeper research into infrared-absorbing inks demonstrates why spectrum-specific materials are promising, but it also demonstrates why generic claims about “anti-camera fabric” deserve skepticism.
Verdict: Possible advantage against particular cameras. Never assume universality.
12. What About Fake Faces and False Eyes?
This is another clever idea.
Computer vision often begins by locating candidate facial features before attempting identification.
That means adding false facial information can sometimes interfere with detection.
Artists experimenting with CV Dazzle have used false eyes and unusual feature placement specifically for this reason.
The same principle appears throughout adversarial-computer-vision research:
You do not necessarily need to hide information.
Sometimes you can overwhelm the model with the wrong information.
Imagine a jacket covered in dozens of face-like arrangements.
A human sees a pattern.
An algorithm may have to decide whether it is looking at zero faces, one face or twenty.
Modern systems are much better at resolving this than older detectors, so fake eyes should not be treated as a guaranteed countermeasure.
But the underlying idea — attacking classification with misleading features — is central to adversarial AI research.
13. The Ultimate Anti-Surveillance Look May Be Extremely Normal
There are actually two opposite privacy strategies.
Strategy A: Adversarial
Look unusual to humans so you look confusing to machines.
CV Dazzle.
Geometric makeup.
Adversarial prints.
Infrared materials.
Machine-generated camouflage.
Strategy B: Anonymous
Look completely ordinary to humans so even if the machine sees you perfectly, you are difficult to distinguish from everyone else.
Common clothes.
Common colors.
No visible tattoo.
No unique backpack.
No giant logo.
Face partially covered where lawful.
Nothing memorable.
The first strategy tries to defeat the machine.
The second tries to starve it of uniqueness.
For everyday privacy, the second strategy may often be more practical.
The ideal combination may eventually be clothing that looks extremely ordinary to humans while containing subtle adversarial characteristics optimized for cameras.
That is exactly where the research appears to be heading.
14. Flock Cameras Are Different: The Car Is the Identifier
Now for the frustrating part.
None of your clever face paint matters much to a standard Flock license-plate reader.
The system is looking at your vehicle.
ALPR databases convert ordinary driving into searchable location records, potentially allowing vehicle observations across different places and times to be queried later. The Electronic Frontier Foundation has documented widespread privacy concerns surrounding Flock’s network and law-enforcement use of it.
A license plate is unusually powerful because the government requires it to be:
- externally visible;
- unique;
- persistent;
- attached to your vehicle.
It is essentially a government-issued machine-readable username for your car.
Do not assume plate-blocking gadgets are legal
Plate covers, sprays and devices marketed as camera blockers occupy a very different legal category from clothing or face paint.
States generally require plates to remain visible, and some specifically prohibit products intended to defeat automated plate reading.
So the clever answer to Flock is generally not:
Make the plate unreadable.
It is understanding that the plate is only one layer.
Flock also advertises vehicle searches involving characteristics beyond the plate itself.
Make the vehicle less distinctive
Privacy-conscious drivers may want to think about optional characteristics such as:
- unusual bumper stickers;
- rare decals;
- distinctive wheel covers;
- roof accessories;
- highly recognizable exterior modifications.
A generic vehicle gives computer vision fewer secondary identifiers.
That will not hide the plate.
It simply prevents you from voluntarily adding another half-dozen visual fingerprints.
15. Want to Know Where the Cameras Are? People Are Mapping Them
There is now an entire grassroots movement dedicated to documenting ALPR installations.
EFF has highlighted DeFlock, a crowdsourced project that maps publicly visible automated license-plate-reader cameras and provides information about surveillance deployments. Flock previously sent the project’s creator a cease-and-desist demand, which he rejected with legal support.
That development says something important about the surveillance era.
Citizens are watching the watchers.
Whatever someone chooses to do with that knowledge, simply understanding where surveillance infrastructure exists can help people make informed decisions about their own privacy and their local government’s policies.
16. Don’t Forget the Tracking Device You Voluntarily Carry Everywhere
There is an elephant in the room.
The phone.
You can wear adversarial facial makeup worthy of Blade Runner and still carry a device broadcasting information through cellular networks, Wi-Fi, Bluetooth and apps.
Camera privacy and digital privacy are separate problems.
Protecting one while ignoring the other is like installing blackout curtains while livestreaming your bedroom.
If location privacy genuinely matters, camera countermeasures should be considered only one layer of a broader privacy strategy.
So What Actually Works?
Here is the practical ranking.
| Technique | Practical value | Reality |
|---|---|---|
| Physical face covering | ★★★★★ | Removes facial information directly |
| Mask + glasses + hat | ★★★★★ | Simple layered occlusion |
| Covering distinctive tattoos | ★★★★★ | Removes persistent identifiers |
| Plain, common clothing | ★★★★☆ | Reduces descriptive searchability |
| Avoiding distinctive accessories | ★★★★☆ | Useful against appearance search |
| CV Dazzle makeup | ★★★☆☆ | Can disrupt some systems; model-dependent |
| Modern adversarial makeup | ★★★★☆ research | Promising but not universal |
| Adversarial clothing | ★★★★☆ research | Proven experimentally against person detectors |
| Reflective materials | ★★☆☆☆ | Highly camera-dependent |
| Infrared-absorbing materials | ★★★★☆ research | Strong experimental results |
| Active infrared glasses | ★★☆☆☆ | Experimental, system-specific and potential eye-safety issue |
| Thermal adversarial clothing | ★★★★★ research | Cutting-edge; not normal consumer technology |
| Random “anti-camera” products online | ? | Demand evidence before believing the marketing |
A Practical Privacy-Conscious Outfit
If your goal is not cinematic invisibility but simply making automated identification harder, the everyday version is remarkably simple:
Face:
A legitimate face covering that conceals substantial facial geometry.
Eyes:
Large conventional sunglasses where appropriate.
Upper face:
A brimmed hat.
Clothing:
Common colors and common designs rather than highly unique patterns.
Identifiers:
Cover distinctive tattoos and avoid unnecessary unique accessories when anonymity matters.
That approach does not exploit a specific algorithm.
It simply provides less information.
The experimental version
For people interested in pushing the technology:
- asymmetric CV Dazzle makeup;
- adversarial makeup patterns;
- printed adversarial clothing;
- infrared-sensitive or infrared-absorbing materials;
- reflective accessories;
- future dual-spectrum clothing capable of changing its visual signature to cameras.
That is the frontier.
And unlike the endless stream of products marketed as “military grade” or “camera blocking,” several of these ideas have actually been demonstrated in peer-reviewed computer-vision research.
One Legal Reality Worth Knowing
Privacy does not automatically become suspicious because it is deliberate.
People routinely alter their public appearance using masks, makeup, hats, wigs, glasses and clothing.
However, anti-mask laws still exist in some states, and their wording and enforcement vary considerably. The ACLU has documented renewed controversy over these statutes as facial-recognition surveillance has expanded.
That is worth checking locally.
But it should not obscure the larger principle:
Being in public does not create an obligation to optimize yourself for machine identification.
You do not have to wear memorable clothing.
You do not have to expose a tattoo.
You do not have to style your face for the convenience of a recognition algorithm.
Privacy can be intentional.
The Surveillance Arms Race Has Already Started
The most fascinating thing about anti-surveillance technology is how closely it resembles an evolutionary arms race.
Computer vision improves.
Researchers discover a weakness.
Someone designs an adversarial pattern.
The detector is retrained.
Researchers attack the improved detector.
Systems add infrared.
Researchers design infrared countermeasures.
Systems begin using multiple sensors.
Researchers develop clothing targeting multiple sensor types simultaneously.
That cycle is happening right now in academic computer-vision research.
And it creates a future that would have sounded ridiculous twenty years ago:
Clothing designed for two audiences simultaneously.
One appearance for humans.
Another appearance for machines.
Makeup generated by AI to fool another AI.
Fabric that changes its machine-readable characteristics when heated.
Patterns that convince a computer that the person standing directly in front of it is not a person at all.
The surveillance state is becoming algorithmic.
It should surprise absolutely no one that privacy is becoming algorithmic too.
Frequently Asked Questions
Can makeup actually block facial recognition?
Certain makeup patterns can interfere with facial-recognition systems. CV Dazzle demonstrated the basic concept, while newer peer-reviewed research uses machine learning to generate adversarial makeup specifically optimized against modern recognition models. Results vary significantly between systems.
What is CV Dazzle?
CV Dazzle is an anti-surveillance concept pioneered by Adam Harvey that uses asymmetric hair and makeup patterns to interfere with the facial landmarks computer vision expects to find.
Can sunglasses stop facial recognition?
Ordinary sunglasses obscure useful facial information but should not be assumed to defeat modern facial recognition by themselves. Systems increasingly work with partially occluded faces.
Does a face mask stop facial recognition?
Masks can significantly reduce recognition performance, but modern algorithms have become much better at recognizing partially covered faces. Greater coverage generally removes more useful facial information.
Do infrared glasses work against security cameras?
Infrared-based interference has been demonstrated experimentally, and newer research has developed infrared-absorbing adversarial materials. Effectiveness depends heavily on the camera and recognition system involved.
Is anti-facial-recognition clothing real?
Yes. Multiple peer-reviewed studies have physically manufactured garments containing adversarial patterns that reduce person-detection accuracy. Current research is attempting to make these patterns more natural-looking, robust and effective against multiple sensing technologies.
Can Flock cameras recognize your face?
Flock says its standard license-plate readers do not use facial recognition. Its FreeForm video-search system can nevertheless search enabled video using visible characteristics such as clothing and accessories.
Can you hide from a Flock camera by covering your face?
Not if you are driving past a standard Flock ALPR in your own vehicle. The plate and vehicle are the primary identifiers.
Can cameras identify you without seeing your face?
Potentially. Modern surveillance research includes person re-identification, body characteristics, clothing analysis and gait recognition in addition to traditional facial recognition.
References and Further Reading
Flock Safety and Automated License Plate Readers
Flock Safety — License Plate Readers (LPR) — Flock’s own current product documentation. Useful as a primary source for what the company says its cameras can capture and search, including vehicle signatures and vehicle information beyond a readable plate. Because Flock is the vendor, its claims about privacy, safety, or social benefit should not be treated as independent evidence.
Flock Safety — FreeForm Search — Primary documentation for Flock’s natural-language video and LPR search system. Flock states that FreeForm can search enabled video using descriptions such as clothing and visible accessories while saying that the system does not use facial or biometric person recognition.
Electronic Frontier Foundation — Automatic License Plate Readers — Concise civil-liberties overview of how ALPR systems convert individual plate observations into searchable vehicle-location histories. EFF is a digital-rights advocacy organization, so its policy conclusions should be understood as advocacy; the document is useful for understanding the surveillance architecture and privacy concerns surrounding large ALPR networks.
Electronic Frontier Foundation — EFF’s Investigations Expose Flock Safety’s Surveillance Abuses: 2025 in Review — Summarizes EFF investigations into actual searches conducted through Flock’s network, including documented uses involving protesters, reproductive-health investigations, and cross-jurisdictional searches. Particularly useful for understanding why the privacy debate extends beyond the theoretical capabilities of ALPR technology.
Electronic Frontier Foundation — Anti-Surveillance Mapmaker Refuses Flock Safety’s Cease-and-Desist Demand — Background on DeFlock, the crowdsourced effort to document publicly visible ALPR installations, and the dispute that followed Flock Safety’s attempt to stop use of the company’s name and imagery.
Facial Recognition, Masks, and Physical Occlusion
National Institute of Standards and Technology — Face Recognition Vendor Test (FRVT) — NIST’s continuing independent evaluation program for facial-recognition algorithms. Its mask testing provides authoritative evidence that facial occlusion can reduce recognition performance while also showing that newer algorithms have become substantially better at recognizing partially covered faces.
NIST — Ongoing Face Recognition Vendor Test Part 6A: Face Recognition Accuracy With Masks Using Pre-COVID-19 Algorithms — The underlying federal technical report quantifying how face masks affected facial-recognition accuracy. Useful for separating the defensible claim that masks remove useful biometric information from the much stronger and unsupported claim that a mask universally defeats recognition.
CV Dazzle and Adversarial Makeup
Adam Harvey — CV Dazzle — The original source for one of the most influential anti-computer-vision camouflage concepts. Harvey explains how asymmetric makeup and hairstyles were designed to disrupt the facial structures expected by early face-detection algorithms — and explicitly notes that the original patterns targeted now-obsolete technology and should not be assumed to defeat current systems.
Sun et al., CVPR 2024 — “DiffAM: Diffusion-Based Adversarial Makeup Transfer for Facial Privacy Protection” — Peer-reviewed research demonstrating that the basic idea behind anti-recognition makeup did not disappear with older face detectors. DiffAM uses modern diffusion models to generate more natural-looking adversarial makeup and tests transferability against facial-recognition models not directly used to generate the attack.
Adversarial Clothing and Person Detection
Hu et al., CVPR 2022 — “Adversarial Texture for Fooling Person Detectors in the Physical World” — Peer-reviewed physical-world experiments in which adversarial textures were printed onto real clothing and tested against AI person detectors from different viewing angles. This is strong evidence that “anti-surveillance clothing” is a legitimate computer-vision research field rather than purely a fashion concept.
Guesmi et al., CVPR 2024 — “DAP: A Dynamic Adversarial Patch for Evading Person Detectors” — Research aimed at producing more naturalistic adversarial patches that remain effective despite physical deformation such as clothing folds and changes in a wearer’s pose. Physical-world testing also illustrates the major limitation of these techniques: success against one detector does not establish universal effectiveness.
Infrared and Human-Invisible Countermeasures
Xie et al., 2025 — “Human-Imperceptible Physical Adversarial Attack for NIR Face Recognition Models” — Research into transparent infrared-absorbing material designed to appear inconspicuous in visible light while producing adversarial patterns for near-infrared facial-recognition cameras. The authors reported an average physical attack success rate of 82.46% across the models they tested. This is a preprint rather than evidence that an off-the-shelf consumer product will work against arbitrary cameras.
Visible, Infrared, and Thermal Surveillance
Long et al., CVPR 2026 — “Thermally Activated Dual-Modal Adversarial Clothing Against AI Surveillance Systems” — Cutting-edge peer-reviewed research on clothing using thermochromic materials and heating elements to generate adversarial patterns against both visible-light and infrared surveillance. The researchers reported physical attack success above 80% in their tested environments.
Zhu et al., CVPR 2026 — “Physical Adversarial Clothing Evades Visible-Thermal Detectors via Non-Overlapping RGB-T Pattern” — Research targeting systems that fuse conventional RGB cameras with thermal imaging, demonstrating how the anti-surveillance arms race is already expanding beyond ordinary visible-light cameras.
Gait and Identification Beyond the Face
Xu et al., CVPR 2026 — “EventGait: Towards Robust Gait Recognition With Event Streams” — Current peer-reviewed research showing how movement and body-shape information can support gait recognition even under difficult lighting conditions. It is an important reminder that defeating facial recognition does not necessarily prevent other forms of machine-assisted identification.
Privacy Rights and the Law
Carpenter v. United States — U.S. Supreme Court — A foundational Supreme Court decision for modern location privacy. Carpenter does not hold that public surveillance cameras or ALPRs are automatically unconstitutional, but it rejects the simplistic idea that people necessarily surrender every privacy interest in their movements merely because individual pieces of location information are exposed outside the home.
American Civil Liberties Union — “America’s Mask Bans in the Age of Face Recognition Surveillance” — Civil-liberties analysis of the tension between historical anti-mask laws, anonymous public activity, and modern facial-recognition systems. Useful for understanding the legal-policy debate, but it is advocacy analysis rather than a substitute for checking the statutes and case law of a particular jurisdiction.
American Civil Liberties Union — “States Dust Off Obscure Anti-Mask Laws to Target Pro-Palestine Protesters” — More recent discussion of how anti-mask statutes are actually being invoked in the United States, illustrating why claims about a universal right — or universal prohibition — on covering one’s face in public are both too broad.
Editorial note: Facial-recognition systems, Flock products, ALPR sharing policies, adversarial computer-vision techniques, and state or local mask laws are changing rapidly. Research showing that a technique defeats a particular model or sensor should not be interpreted as proof that it will defeat other systems. Legal rules should likewise be checked against current law in the reader’s jurisdiction.



