Security1 publisher3 min readPublished
A year of pattern testing says the weak link in ALPR is the model, not the camera
Bill Swearingen ran roughly 31 million tests to produce printable patterns that make detectors ignore what they cover. His best validated result is 61.7 percent non-detection, in simulation.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Kansas City-based cybersecurity researcher Bill Swearingen spent the past year printing patterns, watching cameras fail to detect them, and repeating, running roughly 31 million tests.
- TechCrunch reports that after roughly 31 million tests, Swearingen can generate patterns on demand that block licence plate readers and surveillance cameras from recognising whatever the pattern covers, whether a person or a vehicle.
- The camera still records everything; what breaks is the detection layer sitting on top of the footage, the software that flags licence plates, tracks faces, or spots activity of interest across thousands of hours of video.
- The project is called noRecognition.
- Swearingen is a co-founder of the SecKC meetup.
Compiled by The WatchSomething wrong?How this is made
Why it matters
A Kansas City researcher spent the past year printing patterns, watching cameras fail to flag them and repeating the process about 31 million times, and TechCrunch reports he can now generate patterns on demand that stop licence plate readers and surveillance cameras from recognising whatever the pattern covers, person or vehicle [1][2]. For anyone operating a camera estate, the failure mode is the awkward part: the recording stays intact and the analytics layer on top of it simply declines to raise a hit [3].
The project is called noRecognition [4]. Bill Swearingen, co-founder of the SecKC meetup, says he started it out of concern about the number of cameras in his town and the possibility of being tracked at a protest [5][6]. What began as manual experimentation became a reinforcement learning loop: every time a pattern was detected, the system adjusted and tried again, eventually learning to defeat several detection algorithms at once rather than one at a time [7][8]. At 31 million tests over a year, that is an average of roughly 85,000 trials a day, which is the real story here [9]. Detection models are cheap to query and cheap to fail against, so an attacker gets as many attempts as compute allows.
The project's own research dashboard is more restrained than the headline. It states the objective as "one pattern that defeats every detector" and concedes that goal is only partially met [10][11]. The strongest validated result against a detector extracted from a real deployed surveillance camera is 61.7 percent non-detection across held-out test subjects [12]. That leaves 38.3 percent of subjects still detected [13], and the dashboard labels most of its headline figures as digital and simulated, tested against a virtual camera and a printed-ink model rather than a real garment photographed in the field [14].
The physical test came at DEF CON in Las Vegas, where Swearingen, with help from Donut Media, wrapped a 2009 Toyota Yaris in one of his newest patterns and ran it against a Flock camera, the sort widely deployed for automated licence plate reading across the US [15][16]. "We proved it was effective," he said, though the wheels were a challenge, curved surfaces being less cooperative with flat printed patterns than a car door [17][18]. Donut Media said video of the demonstration would be out within a few weeks [19].
Swearingen is not publishing his best patterns, on the grounds that camera makers would find and block them, and is instead crowdfunding printed T-shirts and hoodies with vehicle wraps possibly to follow [20][21]. That commercial posture is worth reading twice, because it means defenders cannot test against the strongest known samples.
Watch for the DEF CON video, which is the first evidence anyone outside the project will get about how a real wrap behaved against a real Flock unit [19]. Watch also for whether the fabric results survive weather and varied camera geometry, which the researcher's own framing concedes is unresolved [22]. Until then, the operational read is unglamorous: a detector output is advisory, not authoritative, and a quiet night on an analytics-driven alerting stack is not the same as an uneventful one.