AI Pattern Can Fool Cameras, Hiding People From Flock

Researchers produced a repeating visual pattern that reduced person detection by surveillance systems in lab and field tests, including commercial crowd-monitoring software Flock.

In a recent paper, a team of computer vision researchers described an AI-designed repeating high-contrast visual pattern that reduced person detection by common surveillance systems, including commercial crowd-monitoring software Flock. The pattern was tested on live cameras and in simulations.

The team created the pattern using an adversarial learning process that optimizes a neural network against multiple object-detection models and viewing conditions. When printed on shirts, signs or backpacks and recorded from typical public-camera positions, the pattern caused detectors to miss people, assign much lower confidence scores, or produce incorrect classifications.

Experiments included controlled lab trials, limited field recordings and simulated camera noise and compression meant to mimic footage streamed to remote monitoring services. The researchers varied camera resolution, lighting and tilt to approximate real-world conditions and to test the pattern’s robustness at different angles and distances.

According to the paper, the pattern creates local features that detectors treat as background or non-human texture, disrupting the models’ associations between edges, limb joints and human silhouettes. The design was optimized to survive basic transformations such as scale and rotation, so small movements or stepping back did not always restore detection.

The authors reported limits to the approach: high-resolution camera feeds, thermal imaging, depth sensors and systems that fuse multiple sensing modalities often identified people despite the pattern. The pattern is visually conspicuous in many settings, and printed copies can degrade in real-world conditions, which reduces effectiveness.

The report recommends that providers add adversarial training and sensor fusion and that operators test camera networks under adversarial scenarios. The researchers wrote that sharing methods with vendors could speed development of patches and more robust models.

Security practitioners and privacy advocates responding to the paper flagged two points: adversarial patterns can reduce detection in some scenarios, and operators can update models or add sensors to counter specific attacks. The research frames the work as a security audit of image-only surveillance tools and documents conditions where current systems remain vulnerable.

The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.

Articles by this author