Bill Swearingen explains adversarial clothing research, camera-vision confidence, and the privacy limits of biometric surveillance.
Shared Security is the the longest-running cybersecurity and privacy podcast where industry veterans Tom Eston, Scott Wright, and Kevin Tackett break down the week’s security WTF moments, privacy fails, human mistakes, and “why is this still a problem?” stories — with humor, honesty, and hard-earned real-world experience. Whether you’re a security pro, a privacy advocate, or just here to hear Kevin yell about vendor nonsense, this podcast delivers insights you’ll actually use — and laughs you probably need. Real security talk from people who’ve lived it.
Welcome to the Shared Security Podcast, the longest running cybersecurity and privacy show
for actual humans.
No jargon, no hype, just honest analysis from industry veterans who've seen everything
and survived it.
Each week we break down the stories that matter, expose the nonsense that doesn't, and give
you the tools to stay safe in a world where everything is connected and nothing
is guaranteed.
This is Shared Security.
This week on Shared Security, I'm interviewing researcher and speaker Bill Swaringen about
his Black Hat USA 2026 talk, could a pattern on your clothing fool facial recognition?
The idea seems almost science fiction.
Could something as ordinary as a clothing pattern interfere with facial recognition systems?
Well, the security and privacy questions are very real.
We'll talk about adversarial textile patterns, surveillance assumptions, how these systems
behave outside the lab, and what this research says about the future of face recognition
in public spaces.
Now Bill has spent more than two decades building and leading cybersecurity programs
for critical infrastructure, Fortune 100 teams, and high-risk clients, including
serving as CISO at CenturyLink Lutman and co-founding Trifonant Advisory Services.
He's also the researcher behind No Recognition, an AI adversarial clothing kickstarter that
has raised more than $130,000 so far.
Welcome to the show, Bill.
Well, Tom, what a great introduction.
Thanks for having me, and man, it's good seeing you again.
I miss you, homie, thanks for having me.
I know, right?
It's been a long, long time.
You're reminiscing before we started the podcast about the olden days of Shmucon and Defcon
and all the shenanigans we used to get into back when.
Super early, like Shmucon one or two type days, those were the days.
I think it was like Defcon, yes, very early Shmucon, and I think it was like Defcon,
like 15, 16, like those early days at the Riviera, like crazy.
I was kind of thinking when we had this scheduled and I was telling some of my friends, I was
like, I'm pretty sure it was Tom's talk and it was real early Defcon, something like where
me and my buddy Trent, we came up with this great plan to identify the wireless mic frequencies
that you were going to be using, and we were going to inject bodily noises like
into your talk, and we had this all planned out.
Now that would be a jerk move, right?
Let's get that clear.
Yes, I would.
Now that would be a jerk.
Back then it was totally like fair game, and if I remember right, we ended up taking
your mics completely down and I felt like such a jerk, so it was still a dick move
back thing.
Yes, I do remember that actually, that was at Shmucon I think.
So you've got this black hat talk that you just gave and I want to start with just
what was the driver to start this research, like why research adversarial clothing?
It's an interesting story I guess.
So not to get politically either which way or anything, but about a year ago I wanted
to attend a protest here in Kansas City and I'm not even going to talk about which one
or whatever, but kind of had this thought.
I had this feeling that given who I work with, what I do, the contracts that I'm
working with, maybe it would be better if my face wasn't identified or something like
that in that crowd.
As a 50-year-old white male, it was kind of like my first experience of that feeling.
As I've talked with other people, like oh, I'm so glad you guys are starting to feel
that too.
And so I kind of had this idea that I don't know, maybe could with what I'm wearing impact
detections on cameras.
And so I set out with a goal to do two things.
So one, if you and I are standing in a crowd together and you don't know me and I don't
know you, I don't want to key off to you that at a human level.
I don't want you to understand that I'm doing anything weird.
So like if we're in a mass crowd and you see somebody wearing a black hoodie with the
hoodie up and sunglasses in a bandana, and you're kind of like, well, I don't know if
I want to be standing next to that dude, right?
So at a human level, I wanted to do something that doesn't flag for humans.
But for a camera level, it causes detections not to work.
I had no idea if it would work or not.
And it's so funny when I tell this story because I think back, that was only a year
ago.
We had AI, but AI wasn't where it's at now, right?
So I had to hand write, I had to hand write a fuzzer.
It was Python.
It was the first time that I'd ever done any real like GPU work, and it was tough and
it was hard.
And it was one of those projects where you get done with work and you're tired,
but you're energized.
And then you look up and it's 4 a.m. and you're like, oh my God, I've been
writing code for, you know, 12 hours out of this 24-hour day.
And what I found real early was as wild success.
So back in the day, a year ago, I was only targeting the base computer vision models.
But the strategy that I employed was that I would take a picture of a person and I
would put them in a green garment.
Let's just picture a green t-shirt or whatever.
Yeah.
I would run that that image past the computer vision model and I would ask it,
how many people do you see in this image?
And then I would apply, I would brute force, fuzzer style, just no direction,
just fuzz and apply.
And then I would ask that vision model, how many people do you see in this
picture? And I would record any anomalies, right?
So anomalies were crazy.
Like I would find some where it would say zero people.
I'd find some that said there were 10,000 people, right?
It was kind of all over the place.
And but what I learned was that, hey, man, I'm onto something.
And so the fuzzer works.
And I know that I'm kind of working on Lego class vision models.
Let's let's go out and let's research what models do the big boys use.
And so I search for S bombs and I search for open source disclosures
and all of those kind of things trying to identify which models clear view
and Palantir and axon and Hick vision, all of those different vendors
trying to understand what the underlying model was and then have built
it's from there. So nice.
That's a great story.
And I guess it's a good way of, I mean, you're kind of bringing
back the the hacker in you, right?
Of like staying up all night, a coding project.
I know. Oh, yeah.
It's a lot of it's been wild.
So, you know, it's been one of those things.
And you don't know how other people, like when they say that they've
been working on it for a year.
Does that mean that they've been kind of working on it for a year?
But this has been my my passion, right?
So and I mean, every single day, I'm trying new things.
And the project has matured significantly since then.
And I've been very fortunate.
It's been amazing the way the hacker community has supported me.
But just trying things, I ended up writing pattern generators with stuff.
I have no idea. Is it going to work or not?
Right. So I had one pattern generator that just literally put bad words, right?
Like the real bad ones, right?
And another one that tried injection strings.
And then all of the other things that you can imagine.
So like camouflage and and all of these, you know, just other techniques.
And what I found actually when I was developing those those pattern
generators is that this was work that had already been done.
And that just absolutely blew me away.
So, wow.
Going back to the 90s, there was a there was an artist, Adam Harvey,
that had worked on makeup patterns.
So CV Dazzle and hyperface that would do something similar.
And so I kept digging in and I found, you know,
several other researchers that had tried this work before.
And so I started this research on my own and then you find, oh, my gosh,
there's this whole like treasure trove of research has already been done.
And so I feel like I'm kind of taking the torch from there
and actually targeting the harder, more modern models.
Yeah. Yeah.
So what are some surprising things that you found during your research?
Like, you know, obviously you were kind of testing these things on your own.
Like what led you to discover that this is a real thing?
Like this can actually work.
There's been some crazy, crazy findings.
So before I even get into it, you know, like one thing that I want to make sure
that, you know, whenever I'm doing these interviews is that.
For the history of computers, a parser, every single parser
that has ever been written has had difficulty differentiating
between the data that it's supposed to be parsing
and the underlying control system, right?
So from the beginning of time, if you take a look at
that's how SQL injection worked, right?
Like that's how log for shell worked.
Like the parsers have a very difficult time in understanding which data is which.
And as a hacker, our job is to get control of the input source data
that's going inside of a parser.
Think about a camera.
How do I control the data that's going into a camera?
Well, it's what it see, right?
Once I had that realization and that kind of goes back to the fuzzer.
I started working on that.
But some of the things that have fallen out and the surprising things
have been tremendous.
For example, what I learned is I had no freaking idea what I was doing.
I had no clue.
Real early, I made statements like, guys, I'm hacking facial recognition.
And and I.
Nope, I wasn't.
So it turns out that there are different types of detectors.
So in a camera and I'm talking about like a like a small,
you know, like personal, there's a flock, you know, like a small like security
camera, we're talking about very small circuit board, right?
And it has to make a decision very fast.
And so the first stage is object detection.
Do I see a person?
Do I see a car?
Do I see a motorcycle?
What do I see?
Right? Like, it's not it's not who, right?
It's what?
What do I see?
And then there is so there is a person object model.
And then there is a face object model.
So the object model, like that detects a person or a car, it says, what am I
seeing? And then when you take a look at a face model, it says, how
many faces do I see?
And then you move into facial recognition.
Who do I see?
And each one of those are separate problems and they're solved with
different patterns and different injections.
And each one of them is a different problem to solve.
Now, as I learned that, and I actually learned that from Joshua Marpette
from Paul security, he was the guy was like, Bill, you have no idea
what you're talking about.
And then he schooled me and I was like, oh, my God, thank you.
That was so good.
Like, you know, just our friend group is just so small, right?
Like, yeah, just.
And so what I learned through my just testing is that the object
detector, what am I looking at the person, the car, the motorcycle,
whatever is not connected to facial recognition flow whatsoever.
But I had this problem, Tom, I had this problem where I spent,
I don't know, a month every night, eight hours of nights trying
to figure out patterns that would beat face detector.
How many faces do you see zero, right?
But then my facial recognition harness would just crash.
And now it's so stupid looking back.
But at that point, I didn't know.
And it turns out that if there are no faces being detected,
it cannot do facial recognition.
There's a pipeline, right?
And now you're like, well, of course, you idiot, you know.
But back then it was like, I didn't know if it was my
tooling or my measuring or, you know, all those kind of things.
But they're separate problems.
So that was a big finding.
And other interesting things are, you know, kind of where my research is right now.
There there is some and I don't really want to go too much into this
because the research is still real early.
But I'm starting to find being able to take over the camera in certain ways
with just with a pattern on a t-shirt or whatever.
It's been really interesting research, quite honestly.
Yeah, it's almost like a prompt injection, right?
Like I have a reverse prompt injection we're seeing everywhere, right?
It truly is with a cord that I hold up in front of my body, right?
Like, yeah, it's wild.
Mobile apps are just part of everyday life now.
Banking, health care, shopping, entertainment, you name it.
And with that comes a lot of trust because users are putting
their personal data directly into your app.
But here's the reality.
Mobile apps are a growing target.
A recent survey found that 72% of organizations experienced
a mobile app security incident last year and 92% say threats are only increasing.
And the way attackers are going after apps is pretty sophisticated.
They're reverse engineering them, modifying them and redistributing
fake versions through phishing campaigns, side loading and even third party app stores.
So from a user's perspective, everything can look completely legitimate.
That's why taking a proactive approach to mobile app security really matters.
You want to stay ahead of these threats, not react after the damage is done.
This is where Guard Square comes in.
They provide advanced protection for both Android and iOS apps,
along with automated security testing to catch vulnerabilities early
and real time threat monitoring so you can actually see what's happening out there.
If your mobile app is critical to your business, and it probably is,
this is something worth paying attention to.
You can learn more at GuardSquare.com, that's GuardSquare.com.
I think one of the big questions that our listeners are going to have is,
can I now go out and buy this magic invisibility cloak
that will prevent any AI camera to detect who I am?
Is that a possibility or are there still challenges
depending on the cameras, depending on all these other things?
So the answer to that is no, like period, right?
And I want to be very, very clear.
So so it's been funny as this has been, you know,
people are starting to read my research and those kind of things.
I get two questions, you know, like, one,
have you talked with Ben Jordan, who is a YouTuber that's been targeting Flock?
And and two, like, are you enabling crime?
Right? Like, no.
So I want to be very, very clear, right?
So I'm only attacking the detection model, right?
If you go commit a crime at 9 p.m.
and there is a CCTV monitoring that parking lot or whatever you're doing,
the only thing that a pattern or whatever that adversarial action
you took upon that camera was only around the detection, right?
So you're still recorded, right?
You're still on camera, a person monitoring the screens, whatever.
We'll still see you, right?
All of those things still occur, right?
So just to be one, it's not an invisibility cloak.
We're only targeting the detection.
And then second, the most effective adversarial patterns
are very dependent on which detection model you're targeting, right?
So let me make sure that I say that correctly.
Right now, I'm testing 11 models.
So five person detectors, four face detectors,
two facial recognition systems.
And so let's stay with the person detector sites
on testing out five different models.
What's effective on one does not mean it's effective on five, right?
And so while I am very heavily targeting patterns that are effective
or somewhat effective across all of them,
if another model that I've never even tried is what's running on that camera,
I have no idea if that would be effective or not.
Yeah, that makes total sense.
And so you could have a piece of adversarial clothing
and, you know, depending on the camera system,
depending on all those things, like it may or may not detect you,
but it's not like one size fits all type of you wear this shirt.
It works for everything.
Like that's not the case here from the get go.
And I mean, I just want to be very clear.
I had no idea how a camera worked, right?
Like I had to go learn that.
And the way the detection models work is it's confidence, right?
So what they do is they kind of shrink down the image
and they overlay a grid over it.
And then they ask each square in that grid,
do you see something? Right?
Yes or no, it's binary.
Do you see something?
And then if yes, make a guess, right?
And so what my adversarial patterns do is just lower the confidence of that guess
lower to where.
So whatever the bar is, right?
So let's generally on a person detectors around seventy five percent
lower and below that seventy five percent.
So that that camera may still be saying, I think I still see a person,
but I'm only twenty five percent confident.
And so because it's below that that bar,
yeah, it doesn't identify you.
And you've all seen it when you see a camera,
it's got like a red or green bounding box drawn around the person that tracks them.
What I'm doing is I'm lowering that confidence rate around that decision.
So that bounding box is never drawn around you.
That makes sense.
OK, that's a good way to visually understand,
I think, what you've been researching.
And it does ring a bell with me of like,
yeah, that's the detection piece that you're going after.
So what does this mean for the vendors in this space,
police, policymakers, like all of those things?
Because we've seen everything going on with flock recently.
I mean, there's people cutting cameras down,
city council meetings are just filled with people across the whole country.
Now this is becoming a major thing.
And I think the research that you're doing just fits perfectly
into what's going on in this country right now.
What does this all mean for this movement right now?
Well, first and foremost, I hold myself to a very high ethical bar.
Right. And so I don't want anybody out committing crimes.
I have my own opinions about flock and the police state and surveillance state.
I have very strong opinions there, but we should be handling this at a policy level.
But, you know, power to the people, too.
But we should go about this the right way.
But, you know, my answer to that question gets a little bit deeper.
I think that privacy is a fundamental right.
I think that when you walk down the street and you are facially recognized
like facial recognition done to you when you walk into a grocery store
or a big box store where they're analyzing how much they think you're going to spend.
I never opted into that, right?
Like it's just we've gone too far.
I think that tech will always improve and that bleeding edge will always continue to push.
We're seeing that with a lot of things right now.
Just LLMs, AI, everything, everywhere.
But I do think it's up to the people and specifically I do think it's up to the hackers
to be that counterbalance to those things to show that, hey, like hacking's not magic, right?
And I never opted in.
So I'm going to create the opt out, right?
And I do know that when I release patterns and when I release those
kind of things that they probably will go in to their training models to tune out.
It's OK, it's going to be an arms race that, you know, like I've got better ones,
you know, they're coming to right, you know, so that's right.
Yeah, so that's kind of how I feel about that.
This podcast has been focused on privacy for years and we've always said
privacy is human rights and we are all entitled to privacy.
And when companies and these organizations and the technology feels invasive to people,
it is always interesting to me that the hacker community always steps up.
To try find ways to opt yourself out.
And I love the way that you phrased that.
One thing I did want to cover is your Kickstarter because talking about the
patterns and clothing, what was the idea for the Kickstarter?
Because you've raised a hundred and thirty five dollars on this Kickstarter.
It was one of those things that I wanted to raise somewhere around five
to six thousand dollars so that I could move my research to the next level.
Buy some more cameras.
Yeah. So the cameras that I want to target are like fifteen hundred bucks each.
And you know, I'm like, I've been fronting this myself for the year.
And just to move it to the next level, I was like, well, I'm going to
hopefully raise six K to buy some nerd stuff and and it exploded.
Right. So I did talks at both that Black Hat and Def Con this year.
And so that the Def Con talk will be posted publicly when Def Con posts us.
And I really highly encourage anybody interested in this topic
to watch it because I show how I show the math, right?
Go into how this works and all of those kind of things.
But the Kickstarter has been insane, right?
So what that proves to me is that people care about their privacy, right?
So what I'm releasing is basically three garments.
I'm releasing a T-shirt, a hoodie, and I don't know if you've ever watched
a show, Survivor, but yeah, Buff, like a tube of fabric.
You can either wear the headband or over your face.
And each one of them target different things.
So the T-shirt and the hoodie target the object model, the person object model.
So if you are wearing this T-shirt or hoodie, you are not identified as a person, right?
And what I mean by that is that little bounding box is not drawn.
They don't know what you are.
Yes. Well, and so it's so funny because on the back end, I get to see that.
Listen, I don't, you know, the model will be like, something's there.
No clue what, right?
Like no clue what.
Alien. Yeah.
Yeah.
And so there was this prior research that was done that gets brought up every once in a while.
So you can make those models detect what you want.
And so someone else did some research and said, if you're wearing this dress
or whatever they had, you were identified as a giraffe, right?
Awesome.
While the hacker in me just absolutely loves that.
But that is the wrong strategy for hiding, right?
Like if you've been alert that there is a giraffe in the crowd,
that's going to be where the people are going to look, right?
So my patterns, what they do is they drop that object detection to zero, right?
And then the buff, the one that goes over your face targets the face models.
And remember, if a face is never detected, facial recognition never happens, right?
And so, so I'm breaking the face model with the buff is what I'm doing.
And there's two versions that I have released.
There's the one that everybody gets, right?
So this will be a very effective pattern that's a little bit cheaper and everybody gets.
And that's going to be the one that I think that the camera manufacturers
will train on, right?
Sure.
Then I'm also doing runs one on one where I never show that pattern
to anybody else other than you, right?
You're the only person in the world that has seen that other than me, right?
They have seen that pattern.
And so you've never even made it into the training data set, right?
So it should be effective for much longer.
Yeah, yeah, that's awesome.
Well, I mean, not only that, but I feel like this is you're
starting a new fashion trend, right?
Yeah.
So there's been some comments about that.
So Reddit, I did like a real mini AMA type thing.
And someone was like, hey, can you make one that doesn't look like I glitched out
on drugs or whatever fashion does evolve over time, right?
So, you know, like maybe this will be the hot new trend next year.
But I show some examples of patterns on my website, but never the good ones.
But, you know, just so you can kind of get a sense of what
the pattern is going to look like.
And they're often high frequency repeating patterns that have circles and lines.
It depends on what I'm targeting, object detector.
So like the person right here, this is the hardest part.
So your shoulder, that curve, there's a lot of contrast between your
shoulder and your background, and it's an unnatural angle.
And so the patterns really target that area.
Interesting.
Yeah.
Well, we're going to have, in the show notes, we'll link to your Kickstarter.
And, you know, when this episode is released, I think there'll be some
more time on your Kickstarter as well.
So people can still sign up and contribute to the projects.
I think it's super important and to get cool, cool stuff.
What I'd really like from your audience is, hey, if you have any
comments, especially like the tough ones.
So I publish all of my stats on no recognition or flash research.
You can see what I'm grinding on right now, what my strategies are.
If you have, especially the tough feedback, I'd love to hear it.
So I've already had a few that have come in that somebody just
burning me down and I had responses for most of it.
But some of it was like, you're absolutely right, and I'm going
to change the way that I'm doing this.
So let me have it if you have, if you have comments, for sure.
Yeah.
And we'll have all of Bill's contact info and the websites and all
of that if you want to give Bill feedback.
Like I said, he appreciates the direct feedback.
Yeah, all taken.
I mean, as even when I was doing security research and all of
that, I always appreciated direct feedback, positive, negative.
Just, just bring it all to Bill.
He can handle it.
I'll take it.
Yeah, that's right.
Even if it's, even if it's Bill, you're ugly.
Like, yeah, I mean, it was cool.
I don't like your hat, Bill.
Well, thanks, man.
Well, this has been awesome.
Great to catch up with you.
And I love the research that you're doing.
I think it is so important in the privacy and security space.
And I really believe this is what hackers are supposed to do.
Like this is exactly our calling right here.
And I'm really excited about everything you've been doing.
The Kickstarter and I wish you, of course, nothing but the best.
So thanks, buddy.
I appreciate you having me on.
Thanks for your welcome.
Doing this.
All right.
Thanks, everyone, for listening.
And until next time, stay safe, stay secure and stay private.
Thank you for listening or watching.
If you liked this episode, hit subscribe, share it with your
friends and colleagues or jump into our community at sharedsecurity.net
slash supporter to keep the conversation going.
Thanks again, and we'll see you next week for another episode of Shared Security.