• 𝕸𝖔𝖘𝖘@infosec.pub
    link
    fedilink
    arrow-up
    10
    ·
    2 days ago

    Two notes. The first, I don’t like the name. These are defensive measures against adversarial systems. Calling these clothes adversarial clothing implies they’re the bad guys and the tracking system are the good guys. The second note is more of a question… where are they available?

    Edit. Misspelling

    • noughtnaut@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      1 day ago

      Last time they were in the media, I found their web site. That ugly sweater cost over a hundred Euro (don’t remember if it was two or seven, but at that point it no longer matters).

      I’m hoping for such patterns to become open source (and less hard on human eyes).

      • ArmchairAce1944@lemmy.ca
        link
        fedilink
        arrow-up
        2
        ·
        edit-2
        1 day ago

        They are hard on human eyes and also very obvious to human eyes is a major problem. I am hoping for there to be regular clothes that allow for strong facial-recognition/AI shielding that is futureproofed, but at the same wouldn’t be so obvious to regular human observers.

  • wyldrstallyns@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    15
    ·
    2 days ago

    Bullshit title: “adversarial” implies that one’s personal security is counter to gov’t interests, and that it’s the citizens’ fault for behaving so. 🤬

  • mcv@lemmy.zip
    link
    fedilink
    arrow-up
    7
    ·
    2 days ago

    Reminds of the dazzle makeup article from a decade ago. Shame that never caught on. I hope this does.

  • HAL_9_TRILLION@lemmy.dbzer0.com
    link
    fedilink
    arrow-up
    50
    ·
    3 days ago

    Oh look, capitalism trying to sell you something by calling it a solution to your problem. The problem that it created in the first place. This doesn’t seem familiar at all.

  • Septimaeus@infosec.pub
    link
    fedilink
    arrow-up
    18
    ·
    3 days ago

    Most of these countermeasures are easily thwarted by adjustments to the CV model, meaning even if they do work upon release (a big if) the countermeasure itself eventually becomes just another uniquely identifying feature.

    If we’re doing adversarial, let’s do adversarial. Like high-wattage IR lasers to permanently destroy photo receptor arrays, cheap narrowband signal jammers to push wireless chips beyond thermal limit causing early heat death, directional EMP to fry logic boards, and so forth.

  • A_norny_mousse@piefed.zip
    link
    fedilink
    English
    arrow-up
    52
    ·
    3 days ago

    But does it work?

    He emphasised that because surveillance systems are so powerful, no design can guarantee security from detection, but said “the added value of fashion is to spread awareness and help propagate public discourse”.

    Preuß said his designs used large-scale prints, asymmetrical cuts and streetwear-inspired silhouettes to confuse facial recognition algorithms. The company said its Urban Ghost coat integrates LEDs into the hood that emit infrared light to dazzle night-vision surveillance cameras.

    Preuß, who co-founded his company after reading about the whistleblower Edward Snowden’s revelations about US surveillance in the Guardian, said his designs played with the fact that “facial recognition systems freak out when they see multiple faces at once”.

    “Our patterns play with that chaos, confuse algorithms and make it way harder to pin you down,” he said.

    Bell, however, said “none of these products are tried and tested, and a lot of these surveillance technologies can deal with a little resistance … [but] even if the designs don’t necessarily work perfectly, fashion is also a visible sign of resistance.

    Still not sure.

    • fizzle@quokk.au
      link
      fedilink
      English
      arrow-up
      12
      ·
      3 days ago

      Untested means, unlikely to work at all.

      Maybe the IR LEDs at night.

    • mote@lemmy.ca
      link
      fedilink
      arrow-up
      12
      ·
      3 days ago

      My first thought when I saw this - “oh hey look, razzle dazzle clothes” which is my personal mental association of the famous scene in Stripes movie, with Dazzle Camouflage which I always thought was a neat idea.

      In late May 2026 images appeared on social media showing Russian Ural and KAMAZ trucks painted in the classic dazzle camouflage. Supposedly the unusual paint scheme is to confuse Ukrainian drones controlled by artificial intelligence and disrupt their pattern recognition, and not to trick the human eye. Ukraine has experimented with AI for targeting as seen in Operation Spiderweb, and is conducting a deep strike campaign to disrupt Russian logistics.[72][73]

      • thehermet@lemmy.ca
        link
        fedilink
        arrow-up
        2
        ·
        3 days ago

        I’d imagine it’s a bit of cat and mouse though, because if they train the drones to target that pattern they’d be sitting ducks

        • mote@lemmy.ca
          link
          fedilink
          arrow-up
          1
          ·
          2 days ago

          From my understanding (which could be incorrect, I mean I wasn’t there), the pattern applied to the hull was done differently per ship. I imagine they applied the base pattern in a random tile-like build where things can be rotated and moved around in the design before painting.

    • Batman@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      2 days ago

      just from my reading of papers, optimized patterns make use of the fact that detectors (even modern transformer based architectures) are capital S Sensitive to the sillouette of an object.

      in my other comment i linked a paper where they fool modern detectors with 80+% success rate. the clothing looks like a tiedye shirt to me. not fashionable, but not drawing attention either. if there is a way that you can make this fashionable is not a question i can answer :p

      from my reading combining detectors (ensembling) does not help. this leaves spies with a problem, how to detect these noisy people without losing performance on normal nonnoisy people. there are tricks to this, but they are limited at best, for the same reason the noise worked in the first place. here is the reason.

      assume noise makers create noise with methods A,B,C. you train on a dataset with images from the different noise makers (you don’t know which method they used). each of these noisy groups will have a distict sillouette you can detect, but together, you are building a function like:

      pineapple: fruit bannana: fruit apple: fruit

      this is a solvable problem for ml, so how do the noise makers win ultimately? randomization in the process. if each noise is distinct there is no training, you only have one image per type of fruit, you might as well use traditional CV to detect these noisy people (good luck).

      My opinion is i want a product where the customer provides a random seed which generates the process of noise generation for their shirt. the product is the transparency into how the seed effected the noise making, and an evaluation of the noise on modern off the shelf detectors.

      obviously we don’t see that here, but it seems doable, maybe a business idea for me? haha

      • A_norny_mousse@piefed.zip
        link
        fedilink
        English
        arrow-up
        2
        ·
        edit-2
        7 hours ago

        Thanks for the thoughtful reply. I like this idea esp.:

        i want a product where the customer provides a random seed which generates the process of noise generation for their shirt.

        Seems pretty doable in the age of printed t-shirt websites etc.

        Or just, you know, more diversity in clothing. I bet surveillance ml gets a massive advantage from people’s tendencies to stick to some sort of norm - aka fashion.

        In any case none of this actively opposes the huge datacenters sucking up land, water and electricity first in the US, soon all over the planet … and that’s what saddens me. I don’t know what to do about it either though.

    • thehermet@lemmy.ca
      link
      fedilink
      arrow-up
      2
      ·
      3 days ago

      Thing is, I feel like having bright dazzling lights on your hoodie just fingerprints you even more, no?

      Maybe if you use it strategically it could help, but I wouldn’t be sold on that feature

      • definitemaybe@lemmy.ca
        link
        fedilink
        arrow-up
        4
        ·
        3 days ago

        I don’t think that’s a problem, but I suppose it depends on your goals. Facial recognition in low-light conditions is already hard enough of a problem that they, presumably, are not building IR-light-clothing detection into their algorithms. And if IR-blasting clothing becomes commonplace enough that they start working on it, then it’s also no longer distinctive. So, if the goal is to defeat passive surveillance of your movements, this should be highly effective.

        If a human reviews the footage, then none of this likely matters anyway, since they’ll be able to identify other identifying features about you—but that’s a scalability problem. You’d need to have done something very “interesting” to be worth investing the time into tracking across hundreds of video feeds through a surveillance network.

        If your goal is to get away with a crime or actively resist detection while protesting, then this is (obviously) a bad idea to wear this. You should instead choose something as non-descript as possible, like all black, long sleeves, gloves, face mask, and tinted goggles. But you can’t just walk around in public like that, in general.

    • FauxLiving@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      3 days ago

      They don’t have a lot of technical details but essentially what these do is try to look maximally like ‘eyes’ or whatever other targets are used by facial recognition to some AI model.

      They have to choose which model(s) to train against and there is no guarantee that the same output would fool a differently trained model.

      The IR LED dazzlers should work against anything that is using IR as they work by overloading the sensor. The issue is that most cameras are not using IR in most conditions and will switch to visible wavelengths with enough light.

      You could technically do the same thing with visible lights, but you’re going to annoy people if you’re walking around in a hoodie ringed with 1,000 lumen LEDs.

    • SPRUNTnsfw@fedinsfw.app
      link
      fedilink
      English
      arrow-up
      12
      ·
      3 days ago

      Throw a pebble in your shoe to change your walk. Wear a smaller or bigger shoe on one foot. Wear knee and ankle braces on one leg…

      There are easy ways to change your gait for an outing.

      • Wolf314159@startrek.website
        link
        fedilink
        arrow-up
        6
        ·
        3 days ago

        As if that stops police from using it to target randos or prosecutors from using it in court. The executive branch REALLY loves its junk science.

        • Tiresia@slrpnk.net
          link
          fedilink
          arrow-up
          4
          ·
          3 days ago

          If anything, that re-enforces quick_snail’s point that all these individualistic anti-surveillance tips and tricks are pointless.

          Even if you did succesfully change your gait and wear black and use a special phone and didn’t attend the action they’re accusing you of attending, they’ll jiggle the random number generator until it says you’re guilty (p<0.05).

          There is a point in a surveillance state where it makes more sense to [REDACTED] fascists in plain view rather than waste energy trying to do anything subversively. Either follow the CIA manual on malicious compliance or blow up a pipeline, no real middle ground.

        • Auli@lemmy.ca
          link
          fedilink
          English
          arrow-up
          4
          ·
          3 days ago

          Doesn’t sound that good that changing clothes is one of the problems they are facing. What about different camera angles and heights in imaging that is an issue also.

          • quick_snail@feddit.nl
            link
            fedilink
            arrow-up
            1
            ·
            3 days ago

            Fuck. All us autistic people with the 14 pairs of the same items of clothes are gonna get screwed :(

  • Smaile@lemmy.ca
    link
    fedilink
    arrow-up
    10
    ·
    3 days ago

    wear a politician styled mask, commit a crime, system flags politician as criminal, repeat.

  • londos@lemmy.world
    link
    fedilink
    arrow-up
    7
    ·
    3 days ago

    Everyone should just agree to wear the same clothing all the time. Maybe black pants and shirt. Remove it as a differentiator.

  • Danarchy@lemmy.nz
    link
    fedilink
    arrow-up
    7
    ·
    3 days ago

    I could easily do this with one of those custom mall tshirts circa the 1990s that you could get printed to commemorate a graduation or remember a dead baby or w/e

  • Batman@lemmy.world
    link
    fedilink
    arrow-up
    2
    ·
    3 days ago

    this is the most recent arxiv paper on adversarial clothing (since a lot of people are speculating about if it’s possible): [2511.16020] Physically Realistic Sequence-Level Adversarial Clothing for Robust Human-Detection Evasion https://share.google/VMhtGB8P2kTMorGx6

    they boast an 80%+ success rate at evading the instance level (each time you walk past an ai enabled camera) detection with sequential models (more difficult to fool as they see more of your sillouette).

    not saying they are fashionable and obviously aren’t commercially available yet, but it definitely seems possible.

    my main complaint is i wish these companies could make a good baseline so we could compare their efficacy. evaluating the trade off with the level of drip.