Shared Security Podcast

Bill Swearingen explains adversarial clothing research, camera-vision confidence, and the privacy limits of biometric surveillance.

Show Notes

Can a pattern on your clothing change what a camera thinks it sees? Tom talks with Black Hat USA 2026 speaker Bill Swearingen about adversarial clothing research, why person detection and facial recognition are different problems, and what model limitations mean for biometric surveillance, privacy, and accountability.

** Links mentioned on the show **

Black Hat USA 2026 briefing https://blackhat.com/us-26/briefings/schedule/#could-a-pattern-on-your-clothing-fool-facial-recognition-53532

noRecognition Kickstarter https://www.kickstarter.com/projects/norecognition/norecognition-ai-adversarial-clothing

Bill speaking at DEF CON 34 (video) https://www.youtube.com/watch?v=WyPmt8CE5L4

noRecognition research https://norecognition.org/research

Connect with Bill on LinkedIn
https://www.linkedin.com/in/billswearingen/

** Watch this episode on YouTube **

https://youtu.be/jw_WJNIYErQ

** Become a Shared Security Supporter **

Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel's membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join

** Thank you to our sponsors! **

Guardsquare

Special thanks to Guardsquare for sponsoring this episode! Guardsquare is the leader in mobile application security, with multi-layered protection for your Android and iOS apps. Learn more at https://guardsquare.com.

SLNT

Visit https://slnt.com to check out SLNT's amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code "sharedsecurity".

** Subscribe and follow the podcast **

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Follow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.social

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

What is Shared Security Podcast?

Shared Security is the the longest-running cybersecurity and privacy podcast where industry veterans Tom Eston, Scott Wright, and Kevin Tackett break down the week’s security WTF moments, privacy fails, human mistakes, and “why is this still a problem?” stories — with humor, honesty, and hard-earned real-world experience. Whether you’re a security pro, a privacy advocate, or just here to hear Kevin yell about vendor nonsense, this podcast delivers insights you’ll actually use — and laughs you probably need. Real security talk from people who’ve lived it.

Welcome to the Shared Security Podcast, the longest running cybersecurity and privacy show

for actual humans.

No jargon, no hype, just honest analysis from industry veterans who've seen everything

and survived it.

Each week we break down the stories that matter, expose the nonsense that doesn't, and give

you the tools to stay safe in a world where everything is connected and nothing

is guaranteed.

This is Shared Security.

This week on Shared Security, I'm interviewing researcher and speaker Bill Swaringen about

his Black Hat USA 2026 talk, could a pattern on your clothing fool facial recognition?

The idea seems almost science fiction.

Could something as ordinary as a clothing pattern interfere with facial recognition systems?

Well, the security and privacy questions are very real.

We'll talk about adversarial textile patterns, surveillance assumptions, how these systems

behave outside the lab, and what this research says about the future of face recognition

in public spaces.

Now Bill has spent more than two decades building and leading cybersecurity programs

for critical infrastructure, Fortune 100 teams, and high-risk clients, including

serving as CISO at CenturyLink Lutman and co-founding Trifonant Advisory Services.

He's also the researcher behind No Recognition, an AI adversarial clothing kickstarter that

has raised more than $130,000 so far.

Welcome to the show, Bill.

Well, Tom, what a great introduction.

Thanks for having me, and man, it's good seeing you again.

I miss you, homie, thanks for having me.

I know, right?

It's been a long, long time.

You're reminiscing before we started the podcast about the olden days of Shmucon and Defcon

and all the shenanigans we used to get into back when.

Super early, like Shmucon one or two type days, those were the days.

I think it was like Defcon, yes, very early Shmucon, and I think it was like Defcon,

like 15, 16, like those early days at the Riviera, like crazy.

I was kind of thinking when we had this scheduled and I was telling some of my friends, I was

like, I'm pretty sure it was Tom's talk and it was real early Defcon, something like where

me and my buddy Trent, we came up with this great plan to identify the wireless mic frequencies

that you were going to be using, and we were going to inject bodily noises like

into your talk, and we had this all planned out.

Now that would be a jerk move, right?

Let's get that clear.

Yes, I would.

Now that would be a jerk.

Back then it was totally like fair game, and if I remember right, we ended up taking

your mics completely down and I felt like such a jerk, so it was still a dick move

back thing.

Yes, I do remember that actually, that was at Shmucon I think.

So you've got this black hat talk that you just gave and I want to start with just

what was the driver to start this research, like why research adversarial clothing?

It's an interesting story I guess.

So not to get politically either which way or anything, but about a year ago I wanted

to attend a protest here in Kansas City and I'm not even going to talk about which one

or whatever, but kind of had this thought.

I had this feeling that given who I work with, what I do, the contracts that I'm

working with, maybe it would be better if my face wasn't identified or something like

that in that crowd.

As a 50-year-old white male, it was kind of like my first experience of that feeling.

As I've talked with other people, like oh, I'm so glad you guys are starting to feel

that too.

And so I kind of had this idea that I don't know, maybe could with what I'm wearing impact

detections on cameras.

And so I set out with a goal to do two things.

So one, if you and I are standing in a crowd together and you don't know me and I don't

know you, I don't want to key off to you that at a human level.

I don't want you to understand that I'm doing anything weird.

So like if we're in a mass crowd and you see somebody wearing a black hoodie with the

hoodie up and sunglasses in a bandana, and you're kind of like, well, I don't know if

I want to be standing next to that dude, right?

So at a human level, I wanted to do something that doesn't flag for humans.

But for a camera level, it causes detections not to work.

I had no idea if it would work or not.

And it's so funny when I tell this story because I think back, that was only a year

ago.

We had AI, but AI wasn't where it's at now, right?

So I had to hand write, I had to hand write a fuzzer.

It was Python.

It was the first time that I'd ever done any real like GPU work, and it was tough and

it was hard.

And it was one of those projects where you get done with work and you're tired,

but you're energized.

And then you look up and it's 4 a.m. and you're like, oh my God, I've been

writing code for, you know, 12 hours out of this 24-hour day.

And what I found real early was as wild success.

So back in the day, a year ago, I was only targeting the base computer vision models.

But the strategy that I employed was that I would take a picture of a person and I

would put them in a green garment.

Let's just picture a green t-shirt or whatever.

Yeah.

I would run that that image past the computer vision model and I would ask it,

how many people do you see in this image?

And then I would apply, I would brute force, fuzzer style, just no direction,

just fuzz and apply.

And then I would ask that vision model, how many people do you see in this

picture? And I would record any anomalies, right?

So anomalies were crazy.

Like I would find some where it would say zero people.

I'd find some that said there were 10,000 people, right?

It was kind of all over the place.

And but what I learned was that, hey, man, I'm onto something.

And so the fuzzer works.

And I know that I'm kind of working on Lego class vision models.

Let's let's go out and let's research what models do the big boys use.

And so I search for S bombs and I search for open source disclosures

and all of those kind of things trying to identify which models clear view

and Palantir and axon and Hick vision, all of those different vendors

trying to understand what the underlying model was and then have built

it's from there. So nice.

That's a great story.

And I guess it's a good way of, I mean, you're kind of bringing

back the the hacker in you, right?

Of like staying up all night, a coding project.

I know. Oh, yeah.

It's a lot of it's been wild.

So, you know, it's been one of those things.

And you don't know how other people, like when they say that they've

been working on it for a year.

Does that mean that they've been kind of working on it for a year?

But this has been my my passion, right?

So and I mean, every single day, I'm trying new things.

And the project has matured significantly since then.

And I've been very fortunate.

It's been amazing the way the hacker community has supported me.

But just trying things, I ended up writing pattern generators with stuff.

I have no idea. Is it going to work or not?

Right. So I had one pattern generator that just literally put bad words, right?

Like the real bad ones, right?

And another one that tried injection strings.

And then all of the other things that you can imagine.

So like camouflage and and all of these, you know, just other techniques.

And what I found actually when I was developing those those pattern

generators is that this was work that had already been done.

And that just absolutely blew me away.

So, wow.

Going back to the 90s, there was a there was an artist, Adam Harvey,

that had worked on makeup patterns.

So CV Dazzle and hyperface that would do something similar.

And so I kept digging in and I found, you know,

several other researchers that had tried this work before.

And so I started this research on my own and then you find, oh, my gosh,

there's this whole like treasure trove of research has already been done.

And so I feel like I'm kind of taking the torch from there

and actually targeting the harder, more modern models.

Yeah. Yeah.

So what are some surprising things that you found during your research?

Like, you know, obviously you were kind of testing these things on your own.

Like what led you to discover that this is a real thing?

Like this can actually work.

There's been some crazy, crazy findings.

So before I even get into it, you know, like one thing that I want to make sure

that, you know, whenever I'm doing these interviews is that.

For the history of computers, a parser, every single parser

that has ever been written has had difficulty differentiating

between the data that it's supposed to be parsing

and the underlying control system, right?

So from the beginning of time, if you take a look at

that's how SQL injection worked, right?

Like that's how log for shell worked.

Like the parsers have a very difficult time in understanding which data is which.

And as a hacker, our job is to get control of the input source data

that's going inside of a parser.

Think about a camera.

How do I control the data that's going into a camera?

Well, it's what it see, right?

Once I had that realization and that kind of goes back to the fuzzer.

I started working on that.

But some of the things that have fallen out and the surprising things

have been tremendous.

For example, what I learned is I had no freaking idea what I was doing.

I had no clue.

Real early, I made statements like, guys, I'm hacking facial recognition.

And and I.

Nope, I wasn't.

So it turns out that there are different types of detectors.

So in a camera and I'm talking about like a like a small,

you know, like personal, there's a flock, you know, like a small like security

camera, we're talking about very small circuit board, right?

And it has to make a decision very fast.

And so the first stage is object detection.

Do I see a person?

Do I see a car?

Do I see a motorcycle?

What do I see?

Right? Like, it's not it's not who, right?

It's what?

What do I see?

And then there is so there is a person object model.

And then there is a face object model.

So the object model, like that detects a person or a car, it says, what am I

seeing? And then when you take a look at a face model, it says, how

many faces do I see?

And then you move into facial recognition.

Who do I see?

And each one of those are separate problems and they're solved with

different patterns and different injections.

And each one of them is a different problem to solve.

Now, as I learned that, and I actually learned that from Joshua Marpette

from Paul security, he was the guy was like, Bill, you have no idea

what you're talking about.

And then he schooled me and I was like, oh, my God, thank you.

That was so good.

Like, you know, just our friend group is just so small, right?

Like, yeah, just.

And so what I learned through my just testing is that the object

detector, what am I looking at the person, the car, the motorcycle,

whatever is not connected to facial recognition flow whatsoever.

But I had this problem, Tom, I had this problem where I spent,

I don't know, a month every night, eight hours of nights trying

to figure out patterns that would beat face detector.

How many faces do you see zero, right?

But then my facial recognition harness would just crash.

And now it's so stupid looking back.

But at that point, I didn't know.

And it turns out that if there are no faces being detected,

it cannot do facial recognition.

There's a pipeline, right?

And now you're like, well, of course, you idiot, you know.

But back then it was like, I didn't know if it was my

tooling or my measuring or, you know, all those kind of things.

But they're separate problems.

So that was a big finding.

And other interesting things are, you know, kind of where my research is right now.

There there is some and I don't really want to go too much into this

because the research is still real early.

But I'm starting to find being able to take over the camera in certain ways

with just with a pattern on a t-shirt or whatever.

It's been really interesting research, quite honestly.

Yeah, it's almost like a prompt injection, right?

Like I have a reverse prompt injection we're seeing everywhere, right?

It truly is with a cord that I hold up in front of my body, right?

Like, yeah, it's wild.

Mobile apps are just part of everyday life now.

Banking, health care, shopping, entertainment, you name it.

And with that comes a lot of trust because users are putting

their personal data directly into your app.

But here's the reality.

Mobile apps are a growing target.

A recent survey found that 72% of organizations experienced

a mobile app security incident last year and 92% say threats are only increasing.

And the way attackers are going after apps is pretty sophisticated.

They're reverse engineering them, modifying them and redistributing

fake versions through phishing campaigns, side loading and even third party app stores.

So from a user's perspective, everything can look completely legitimate.

That's why taking a proactive approach to mobile app security really matters.

You want to stay ahead of these threats, not react after the damage is done.

This is where Guard Square comes in.

They provide advanced protection for both Android and iOS apps,

along with automated security testing to catch vulnerabilities early

and real time threat monitoring so you can actually see what's happening out there.

If your mobile app is critical to your business, and it probably is,

this is something worth paying attention to.

You can learn more at GuardSquare.com, that's GuardSquare.com.

I think one of the big questions that our listeners are going to have is,

can I now go out and buy this magic invisibility cloak

that will prevent any AI camera to detect who I am?

Is that a possibility or are there still challenges

depending on the cameras, depending on all these other things?

So the answer to that is no, like period, right?

And I want to be very, very clear.

So so it's been funny as this has been, you know,

people are starting to read my research and those kind of things.

I get two questions, you know, like, one,

have you talked with Ben Jordan, who is a YouTuber that's been targeting Flock?

And and two, like, are you enabling crime?

Right? Like, no.

So I want to be very, very clear, right?

So I'm only attacking the detection model, right?

If you go commit a crime at 9 p.m.

and there is a CCTV monitoring that parking lot or whatever you're doing,

the only thing that a pattern or whatever that adversarial action

you took upon that camera was only around the detection, right?

So you're still recorded, right?

You're still on camera, a person monitoring the screens, whatever.

We'll still see you, right?

All of those things still occur, right?

So just to be one, it's not an invisibility cloak.

We're only targeting the detection.

And then second, the most effective adversarial patterns

are very dependent on which detection model you're targeting, right?

So let me make sure that I say that correctly.

Right now, I'm testing 11 models.

So five person detectors, four face detectors,

two facial recognition systems.

And so let's stay with the person detector sites

on testing out five different models.

What's effective on one does not mean it's effective on five, right?

And so while I am very heavily targeting patterns that are effective

or somewhat effective across all of them,

if another model that I've never even tried is what's running on that camera,

I have no idea if that would be effective or not.

Yeah, that makes total sense.

And so you could have a piece of adversarial clothing

and, you know, depending on the camera system,

depending on all those things, like it may or may not detect you,

but it's not like one size fits all type of you wear this shirt.

It works for everything.

Like that's not the case here from the get go.

And I mean, I just want to be very clear.

I had no idea how a camera worked, right?

Like I had to go learn that.

And the way the detection models work is it's confidence, right?

So what they do is they kind of shrink down the image

and they overlay a grid over it.

And then they ask each square in that grid,

do you see something? Right?

Yes or no, it's binary.

Do you see something?

And then if yes, make a guess, right?

And so what my adversarial patterns do is just lower the confidence of that guess

lower to where.

So whatever the bar is, right?

So let's generally on a person detectors around seventy five percent

lower and below that seventy five percent.

So that that camera may still be saying, I think I still see a person,

but I'm only twenty five percent confident.

And so because it's below that that bar,

yeah, it doesn't identify you.

And you've all seen it when you see a camera,

it's got like a red or green bounding box drawn around the person that tracks them.

What I'm doing is I'm lowering that confidence rate around that decision.

So that bounding box is never drawn around you.

That makes sense.

OK, that's a good way to visually understand,

I think, what you've been researching.

And it does ring a bell with me of like,

yeah, that's the detection piece that you're going after.

So what does this mean for the vendors in this space,

police, policymakers, like all of those things?

Because we've seen everything going on with flock recently.

I mean, there's people cutting cameras down,

city council meetings are just filled with people across the whole country.

Now this is becoming a major thing.

And I think the research that you're doing just fits perfectly

into what's going on in this country right now.

What does this all mean for this movement right now?

Well, first and foremost, I hold myself to a very high ethical bar.

Right. And so I don't want anybody out committing crimes.

I have my own opinions about flock and the police state and surveillance state.

I have very strong opinions there, but we should be handling this at a policy level.

But, you know, power to the people, too.

But we should go about this the right way.

But, you know, my answer to that question gets a little bit deeper.

I think that privacy is a fundamental right.

I think that when you walk down the street and you are facially recognized

like facial recognition done to you when you walk into a grocery store

or a big box store where they're analyzing how much they think you're going to spend.

I never opted into that, right?

Like it's just we've gone too far.

I think that tech will always improve and that bleeding edge will always continue to push.

We're seeing that with a lot of things right now.

Just LLMs, AI, everything, everywhere.

But I do think it's up to the people and specifically I do think it's up to the hackers

to be that counterbalance to those things to show that, hey, like hacking's not magic, right?

And I never opted in.

So I'm going to create the opt out, right?

And I do know that when I release patterns and when I release those

kind of things that they probably will go in to their training models to tune out.

It's OK, it's going to be an arms race that, you know, like I've got better ones,

you know, they're coming to right, you know, so that's right.

Yeah, so that's kind of how I feel about that.

This podcast has been focused on privacy for years and we've always said

privacy is human rights and we are all entitled to privacy.

And when companies and these organizations and the technology feels invasive to people,

it is always interesting to me that the hacker community always steps up.

To try find ways to opt yourself out.

And I love the way that you phrased that.

One thing I did want to cover is your Kickstarter because talking about the

patterns and clothing, what was the idea for the Kickstarter?

Because you've raised a hundred and thirty five dollars on this Kickstarter.

It was one of those things that I wanted to raise somewhere around five

to six thousand dollars so that I could move my research to the next level.

Buy some more cameras.

Yeah. So the cameras that I want to target are like fifteen hundred bucks each.

And you know, I'm like, I've been fronting this myself for the year.

And just to move it to the next level, I was like, well, I'm going to

hopefully raise six K to buy some nerd stuff and and it exploded.

Right. So I did talks at both that Black Hat and Def Con this year.

And so that the Def Con talk will be posted publicly when Def Con posts us.

And I really highly encourage anybody interested in this topic

to watch it because I show how I show the math, right?

Go into how this works and all of those kind of things.

But the Kickstarter has been insane, right?

So what that proves to me is that people care about their privacy, right?

So what I'm releasing is basically three garments.

I'm releasing a T-shirt, a hoodie, and I don't know if you've ever watched

a show, Survivor, but yeah, Buff, like a tube of fabric.

You can either wear the headband or over your face.

And each one of them target different things.

So the T-shirt and the hoodie target the object model, the person object model.

So if you are wearing this T-shirt or hoodie, you are not identified as a person, right?

And what I mean by that is that little bounding box is not drawn.

They don't know what you are.

Yes. Well, and so it's so funny because on the back end, I get to see that.

Listen, I don't, you know, the model will be like, something's there.

No clue what, right?

Like no clue what.

Alien. Yeah.

Yeah.

And so there was this prior research that was done that gets brought up every once in a while.

So you can make those models detect what you want.

And so someone else did some research and said, if you're wearing this dress

or whatever they had, you were identified as a giraffe, right?

Awesome.

While the hacker in me just absolutely loves that.

But that is the wrong strategy for hiding, right?

Like if you've been alert that there is a giraffe in the crowd,

that's going to be where the people are going to look, right?

So my patterns, what they do is they drop that object detection to zero, right?

And then the buff, the one that goes over your face targets the face models.

And remember, if a face is never detected, facial recognition never happens, right?

And so, so I'm breaking the face model with the buff is what I'm doing.

And there's two versions that I have released.

There's the one that everybody gets, right?

So this will be a very effective pattern that's a little bit cheaper and everybody gets.

And that's going to be the one that I think that the camera manufacturers

will train on, right?

Sure.

Then I'm also doing runs one on one where I never show that pattern

to anybody else other than you, right?

You're the only person in the world that has seen that other than me, right?

They have seen that pattern.

And so you've never even made it into the training data set, right?

So it should be effective for much longer.

Yeah, yeah, that's awesome.

Well, I mean, not only that, but I feel like this is you're

starting a new fashion trend, right?

Yeah.

So there's been some comments about that.

So Reddit, I did like a real mini AMA type thing.

And someone was like, hey, can you make one that doesn't look like I glitched out

on drugs or whatever fashion does evolve over time, right?

So, you know, like maybe this will be the hot new trend next year.

But I show some examples of patterns on my website, but never the good ones.

But, you know, just so you can kind of get a sense of what

the pattern is going to look like.

And they're often high frequency repeating patterns that have circles and lines.

It depends on what I'm targeting, object detector.

So like the person right here, this is the hardest part.

So your shoulder, that curve, there's a lot of contrast between your

shoulder and your background, and it's an unnatural angle.

And so the patterns really target that area.

Interesting.

Yeah.

Well, we're going to have, in the show notes, we'll link to your Kickstarter.

And, you know, when this episode is released, I think there'll be some

more time on your Kickstarter as well.

So people can still sign up and contribute to the projects.

I think it's super important and to get cool, cool stuff.

What I'd really like from your audience is, hey, if you have any

comments, especially like the tough ones.

So I publish all of my stats on no recognition or flash research.

You can see what I'm grinding on right now, what my strategies are.

If you have, especially the tough feedback, I'd love to hear it.

So I've already had a few that have come in that somebody just

burning me down and I had responses for most of it.

But some of it was like, you're absolutely right, and I'm going

to change the way that I'm doing this.

So let me have it if you have, if you have comments, for sure.

Yeah.

And we'll have all of Bill's contact info and the websites and all

of that if you want to give Bill feedback.

Like I said, he appreciates the direct feedback.

Yeah, all taken.

I mean, as even when I was doing security research and all of

that, I always appreciated direct feedback, positive, negative.

Just, just bring it all to Bill.

He can handle it.

I'll take it.

Yeah, that's right.

Even if it's, even if it's Bill, you're ugly.

Like, yeah, I mean, it was cool.

I don't like your hat, Bill.

Well, thanks, man.

Well, this has been awesome.

Great to catch up with you.

And I love the research that you're doing.

I think it is so important in the privacy and security space.

And I really believe this is what hackers are supposed to do.

Like this is exactly our calling right here.

And I'm really excited about everything you've been doing.

The Kickstarter and I wish you, of course, nothing but the best.

So thanks, buddy.

I appreciate you having me on.

Thanks for your welcome.

Doing this.

All right.

Thanks, everyone, for listening.

And until next time, stay safe, stay secure and stay private.

Thank you for listening or watching.

If you liked this episode, hit subscribe, share it with your

friends and colleagues or jump into our community at sharedsecurity.net

slash supporter to keep the conversation going.

Thanks again, and we'll see you next week for another episode of Shared Security.