Flock cameras have earned their moment in the crosshairs, and it isn't hard to see why. License plate-reading cameras were sold on the premise of sharper law enforcement, but the rollout has produced misuse, false flags, and a public that increasingly wants nothing to do with the surveillance apparatus quietly spreading across the country.

fooling flock the car wrap that blinds plate cameras
fooling flock the car wrap that blinds plate cameras

The horror stories are piling up. Officers have been caught using the technology to stalk their wives. Automotive journalist Joel Feder was detained after a camera falsely flagged the press car he was driving as stolen. That kind of error isn't a fluke, either. An LAPD audit found that 32% of the stolen cars Flock cameras flagged were false positives, according to Jalopnik. And the town of Roseville, California, reported its Flock cameras only read plates correctly 29% of the time.

Into that mess walks Bill Swearingen, a lifelong cybersecurity professional who has spent the past year building a countermeasure.

Swearingen's project, called noRecognition, is built around adversarial patterns - computer-generated visuals designed to scramble the detection software that powers plate cameras. The Kickstarter for the project shows a T-shirt printed with the Flock-fooling patterns, but the headline demo was more ambitious: a Toyota Yaris wrapped head to toe in the stuff.

fooling flock the car wrap that blinds plate cameras
fooling flock the car wrap that blinds plate cameras

He brought that Yaris to Def Con in Las Vegas, where it passed a demo at fooling surveillance cameras. The wrap was applied "with help from" Donut Media, the automotive YouTube channel that happens to share a parent company with The Drive, Feder's publication. Small world.

TechCrunch summed up the pitch this way: the project "allows people to escape the automatic detection and algorithmic surveillance used across the U.S. and beyond."

Details on the actual science are thin, and Swearingen isn't especially forthcoming. Which is fair enough - nobody expects the first person to pick a lock to publish a how-to. He did say the patterns were developed through a trial-and-error, self-training learning model, essentially machine learning turned against machine learning.

The rough analogy is a CAPTCHA in reverse. Where a CAPTCHA asks a human to decode a warped, fuzzy image that a bot can't parse, these adversarial patterns cloak real humans and vehicles in warped, fuzzy visuals the cameras can't interpret. That comparison is offered as an educated guess rather than a confirmed mechanism, so take it as such.

fooling flock the car wrap that blinds plate cameras
fooling flock the car wrap that blinds plate cameras

However it works, the reach is the interesting part. Swearingen says his patterns defeated 11 open-source surveillance algorithms, which puts more than Flock in the blast radius. The same patterns reportedly fool Axon body cams and devices running Clearview AI. The model is described as generating new patterns every minute, with measurable improvements per group - a moving target designed to stay ahead of whatever the cameras learn next.

Strip away the Def Con showmanship and the wrapped Yaris, and what's left is a fairly pointed statement about where things stand. When a private surveillance network posts a 71% error rate in one California town and a one-in-three false-positive rate on stolen-car flags in Los Angeles, the appetite for a workaround more or less builds itself.

Whether a car wrap holds up against the next software update is another question entirely. For now, noRecognition is less a permanent solution than proof that the cameras watching everyone can, in fact, be made to blink.

Become a TTAC insider. Get the latest news, features, TTAC takes, and everything else that gets to the truth about cars first by  subscribing to our newsletter.