This Researcher Is Designing Clothes That Break Facial Recognition Software

A security researcher plans to unveil clothing patterns that confuse the AI systems governments use to track people in public, without their knowledge or consent.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 4 min read
Illustration: a boldly patterned geometric hoodie hanging on a plain concrete wall under harsh fluorescent light
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Clearview AI has collected billions of photos from social media without users' permission and sells access to US law enforcement agencies, including ICE.
  • The Department of Homeland Security acknowledged in writing in 2025 that ICE does not give people any chance to consent to or refuse collection of their face data.
  • Security researcher Bill Swearingen will demonstrate anti-surveillance clothing at Black Hat USA 2026 next month.
  • Swearingen tested his designs against 11 real AI models and found that geometric, high-frequency patterns can cause facial recognition software to fail or misidentify a person.
  • Any single clothing pattern works only until the software is updated, after which a new pattern would need to be released.

About ten years ago, a developer named Hoan Ton-That quietly scraped photos from social media and fed them into a database. That database became Clearview AI. Your face is almost certainly in it.

Since then, Clearview has grown to billions of images and signed multimillion-dollar contracts with US law enforcement agencies, ICE among them. The story goes beyond one private company. The Department of Homeland Security (DHS), which oversees border and immigration enforcement, stated plainly that ICE gives people no opportunity to decline having their face collected. We first covered Clearview AI's role in this picture on 3 July 2026.

You were never asked. There is no opt-out.

How can ordinary clothes stop a camera from recognising you?

Facial recognition is a chain of steps. A camera captures your image, software converts it into data points, a matching engine checks those data points against a database. Break any link and the chain fails.

Bill Swearingen, known online as @hevnsnt, spotted that the weakest link is often the second step: converting image to data. This processing frequently runs on the camera itself rather than a powerful remote server, because it needs to work in real time. That means it runs on a stripped-down version of the AI, fast but not particularly sophisticated.

Swearingen's clothing targets exactly that stripped-down software. He extracted 11 AI models from real surveillance hardware, then spent millions of test rounds generating patterns, measuring how much each reduced the software's confidence that it was looking at a human body, and discarding what did not perform. Bold geometric designs won out, the kind you might mistake for a loud streetwear print or psychedelic art.

Precision explains why they work. These AI systems learn to recognise people by stacking thousands of tiny detectors for edges and textures, plus the arrangement of eyes, nose, and mouth. A high-frequency geometric pattern, one with rapid contrasts and repeating shapes, floods those detectors with noise. The system hesitates, loses confidence, sometimes stops seeing a person entirely.

It is the same failure mode that has long haunted computer vision: the gap between how humans read a picture and how a machine parses raw pixel data. Swearingen is using that gap as a door.

Should you worry about the practical limits?

Yes, and Swearingen does not pretend otherwise. A pattern tested against a virtualised camera on a GPU may behave differently on real fabric under real lighting. The designs will not suit everyone's idea of acceptable clothing. And the effectiveness ceiling is built in by design: surveillance companies update their models, and a specific pattern that worked last month may not work next month.

"If I were to sell a thousand t-shirts that are exactly the same, they would work exactly the same for all those people, until the model upgraded," Swearingen told Dark Reading. "And then I could release another pattern that would do the same thing."

He is also looking further ahead. Future versions, he says, could encode a different identity near the face rather than simply making the wearer disappear, causing the system to match the wearer to someone else.

"You never opted into this, and there's no way to opt out," Swearingen says. The clothes are not a permanent fix. What they are is a one-step-ahead counter to surveillance infrastructure that was never designed with your agreement in mind. Watch whether Black Hat 2026 produces working retail designs, and watch whether surveillance vendors respond with model updates inside weeks rather than months. That turnaround time is the real measure of how long any individual pattern stays useful.

© 2026 Threat Vectr