Two notes. The first, I don’t like the name. These are defensive measures against adversarial systems. Calling these clothes adversarial clothing implies they’re the bad guys and the tracking system are the good guys. The second note is more of a question… where are they available?
Edit. Misspelling
Last time they were in the media, I found their web site. That ugly sweater cost over a hundred Euro (don’t remember if it was two or seven, but at that point it no longer matters).
I’m hoping for such patterns to become open source (and less hard on human eyes).
They are hard on human eyes and also very obvious to human eyes is a major problem. I am hoping for there to be regular clothes that allow for strong facial-recognition/AI shielding that is futureproofed, but at the same wouldn’t be so obvious to regular human observers.
deleted by creator
Print a AI-generated face on a shirt?
Bullshit title: “adversarial” implies that one’s personal security is counter to gov’t interests, and that it’s the citizens’ fault for behaving so. 🤬
Reminds of the dazzle makeup article from a decade ago. Shame that never caught on. I hope this does.
Oh look, capitalism trying to sell you something by calling it a solution to your problem. The problem that it created in the first place. This doesn’t seem familiar at all.
And it’s only upwards of seven hundred dollars for a hoodie
Welp, there goes my entire annual clothing budget. I’ll have to wear that hoodie all day every day everywhere I go regardless of the occasion or weather 😄
Agree, its just a sales pitch.
Most of these countermeasures are easily thwarted by adjustments to the CV model, meaning even if they do work upon release (a big if) the countermeasure itself eventually becomes just another uniquely identifying feature.
If we’re doing adversarial, let’s do adversarial. Like high-wattage IR lasers to permanently destroy photo receptor arrays, cheap narrowband signal jammers to push wireless chips beyond thermal limit causing early heat death, directional EMP to fry logic boards, and so forth.
Where does one get some schematics to build theses things in minecraft
But does it work?
He emphasised that because surveillance systems are so powerful, no design can guarantee security from detection, but said “the added value of fashion is to spread awareness and help propagate public discourse”.
Preuß said his designs used large-scale prints, asymmetrical cuts and streetwear-inspired silhouettes to confuse facial recognition algorithms. The company said its Urban Ghost coat integrates LEDs into the hood that emit infrared light to dazzle night-vision surveillance cameras.
Preuß, who co-founded his company after reading about the whistleblower Edward Snowden’s revelations about US surveillance in the Guardian, said his designs played with the fact that “facial recognition systems freak out when they see multiple faces at once”.
“Our patterns play with that chaos, confuse algorithms and make it way harder to pin you down,” he said.
Bell, however, said “none of these products are tried and tested, and a lot of these surveillance technologies can deal with a little resistance … [but] even if the designs don’t necessarily work perfectly, fashion is also a visible sign of resistance.
Still not sure.
Untested means, unlikely to work at all.
Maybe the IR LEDs at night.
Gets run over by a tesla…
:-D
My first thought when I saw this - “oh hey look, razzle dazzle clothes” which is my personal mental association of the famous scene in Stripes movie, with Dazzle Camouflage which I always thought was a neat idea.
In late May 2026 images appeared on social media showing Russian Ural and KAMAZ trucks painted in the classic dazzle camouflage. Supposedly the unusual paint scheme is to confuse Ukrainian drones controlled by artificial intelligence and disrupt their pattern recognition, and not to trick the human eye. Ukraine has experimented with AI for targeting as seen in Operation Spiderweb, and is conducting a deep strike campaign to disrupt Russian logistics.[72][73]
I’d imagine it’s a bit of cat and mouse though, because if they train the drones to target that pattern they’d be sitting ducks
From my understanding (which could be incorrect, I mean I wasn’t there), the pattern applied to the hull was done differently per ship. I imagine they applied the base pattern in a random tile-like build where things can be rotated and moved around in the design before painting.
just from my reading of papers, optimized patterns make use of the fact that detectors (even modern transformer based architectures) are capital S Sensitive to the sillouette of an object.
in my other comment i linked a paper where they fool modern detectors with 80+% success rate. the clothing looks like a tiedye shirt to me. not fashionable, but not drawing attention either. if there is a way that you can make this fashionable is not a question i can answer :p
from my reading combining detectors (ensembling) does not help. this leaves spies with a problem, how to detect these noisy people without losing performance on normal nonnoisy people. there are tricks to this, but they are limited at best, for the same reason the noise worked in the first place. here is the reason.
assume noise makers create noise with methods A,B,C. you train on a dataset with images from the different noise makers (you don’t know which method they used). each of these noisy groups will have a distict sillouette you can detect, but together, you are building a function like:
pineapple: fruit bannana: fruit apple: fruit
this is a solvable problem for ml, so how do the noise makers win ultimately? randomization in the process. if each noise is distinct there is no training, you only have one image per type of fruit, you might as well use traditional CV to detect these noisy people (good luck).
My opinion is i want a product where the customer provides a random seed which generates the process of noise generation for their shirt. the product is the transparency into how the seed effected the noise making, and an evaluation of the noise on modern off the shelf detectors.
obviously we don’t see that here, but it seems doable, maybe a business idea for me? haha
Thanks for the thoughtful reply. I like this idea esp.:
i want a product where the customer provides a random seed which generates the process of noise generation for their shirt.
Seems pretty doable in the age of printed t-shirt websites etc.
Or just, you know, more diversity in clothing. I bet surveillance ml gets a massive advantage from people’s tendencies to stick to some sort of norm - aka fashion.
In any case none of this actively opposes the huge datacenters sucking up land, water and electricity first in the US, soon all over the planet … and that’s what saddens me. I don’t know what to do about it either though.
Thing is, I feel like having bright dazzling lights on your hoodie just fingerprints you even more, no?
Maybe if you use it strategically it could help, but I wouldn’t be sold on that feature
I don’t think that’s a problem, but I suppose it depends on your goals. Facial recognition in low-light conditions is already hard enough of a problem that they, presumably, are not building IR-light-clothing detection into their algorithms. And if IR-blasting clothing becomes commonplace enough that they start working on it, then it’s also no longer distinctive. So, if the goal is to defeat passive surveillance of your movements, this should be highly effective.
If a human reviews the footage, then none of this likely matters anyway, since they’ll be able to identify other identifying features about you—but that’s a scalability problem. You’d need to have done something very “interesting” to be worth investing the time into tracking across hundreds of video feeds through a surveillance network.
If your goal is to get away with a crime or actively resist detection while protesting, then this is (obviously) a bad idea to wear this. You should instead choose something as non-descript as possible, like all black, long sleeves, gloves, face mask, and tinted goggles. But you can’t just walk around in public like that, in general.
Translation is they don’t work.
They don’t have a lot of technical details but essentially what these do is try to look maximally like ‘eyes’ or whatever other targets are used by facial recognition to some AI model.
They have to choose which model(s) to train against and there is no guarantee that the same output would fool a differently trained model.
The IR LED dazzlers should work against anything that is using IR as they work by overloading the sensor. The issue is that most cameras are not using IR in most conditions and will switch to visible wavelengths with enough light.
You could technically do the same thing with visible lights, but you’re going to annoy people if you’re walking around in a hoodie ringed with 1,000 lumen LEDs.
Because finding the weirdo wearing $500 the eyeball pants will be hard.
Won’t work. Try something like https://www.amazon.com/Custom-Printed-Face-Mask-Personalized/dp/B0FW42TZ6H rather. Won’t obscure your gait biometrics.
Fremen ramblings about walking the dunes, here. On gait hiding
Throw a pebble in your shoe to change your walk. Wear a smaller or bigger shoe on one foot. Wear knee and ankle braces on one leg…
There are easy ways to change your gait for an outing.
Fortunately gait biometrics are junk science anyway lol
As if that stops police from using it to target randos or prosecutors from using it in court. The executive branch REALLY loves its junk science.
If anything, that re-enforces quick_snail’s point that all these individualistic anti-surveillance tips and tricks are pointless.
Even if you did succesfully change your gait and wear black and use a special phone and didn’t attend the action they’re accusing you of attending, they’ll jiggle the random number generator until it says you’re guilty (p<0.05).
There is a point in a surveillance state where it makes more sense to [REDACTED] fascists in plain view rather than waste energy trying to do anything subversively. Either follow the CIA manual on malicious compliance or blow up a pipeline, no real middle ground.
Machine learning is getting quite good at it https://www.sciencedirect.com/org/science/article/pii/S1546221824001802
Doesn’t sound that good that changing clothes is one of the problems they are facing. What about different camera angles and heights in imaging that is an issue also.
Fuck. All us autistic people with the 14 pairs of the same items of clothes are gonna get screwed :(
Get someone to kick you in the leg hard every few days to change your limp.
wear a politician styled mask, commit a crime, system flags politician as criminal, repeat.
that’s just being a politician with extra steps
Did you just figure out an infinite money glitch?
Sunglasses, hat, and facemask.
Those glasses with an attached nose and moustache work also well
Fursuit.
This only works if everyone wears the same fursuit
Otherwise, insert that xkcd with the guy who has ambiguous 1s and Ls in this license plate
Does it come with air-conditioning?
Some of the fancier ones do.
Yes, but they won’t work
That says a lot about the times we live in…
Everyone should just agree to wear the same clothing all the time. Maybe black pants and shirt. Remove it as a differentiator.
Not a new idea: https://en.wikipedia.org/wiki/Black_bloc
I could easily do this with one of those custom mall tshirts circa the 1990s that you could get printed to commemorate a graduation or remember a dead baby or w/e
Oh, what about the ones with gangsta Bugs Bunny / SpongeBob / Tweety Bird. Memba?
Me n Taz all foolin AI spy cams with our gold chains and backwards ball caps
this is the most recent arxiv paper on adversarial clothing (since a lot of people are speculating about if it’s possible): [2511.16020] Physically Realistic Sequence-Level Adversarial Clothing for Robust Human-Detection Evasion https://share.google/VMhtGB8P2kTMorGx6
they boast an 80%+ success rate at evading the instance level (each time you walk past an ai enabled camera) detection with sequential models (more difficult to fool as they see more of your sillouette).
not saying they are fashionable and obviously aren’t commercially available yet, but it definitely seems possible.
my main complaint is i wish these companies could make a good baseline so we could compare their efficacy. evaluating the trade off with the level of drip.













