Adversarial Fashion Makes a Statement on AI Panopticon

(spectrum.ieee.org)

53 points | by rbanffy 4 hours ago

10 comments

  • bsenftner 1 hour ago
    There is a weak component to facial recognition systems that can be exploited to make one invisible to facial recognition, but you stick out like a sore thumb to people. The exploit is to not have a human face, meaning the regular pattern of two eyes centered above a nose and mouth. The exploit is as simple as placing a sticker of a 3rd eye, a 2nd nose, or any other facial feature that is "not human" and you will be invisible to facial recognition. The reason this works is because the initial test for finding faces in images is a weak test, it has to be fast because it has to evaluate every possible rectangle in a video frame. That test is looking for the regular human pattern of a human face, and it that test passes that rectangle get more investigation. Failing that initial test, that rectangle is invisible...
  • yndoendo 1 hour ago
    Anyone else think of "A Scanner Darkly" movie with the interpolate mask that transitions between different faces as the means for better Adversarial Fashion?

    Wouldn't one be able to use a hyper real mask to create false evident to frame someone? People are so blind in trusting AI that innocent people are being left in jail were primitive detective work would prove they were not he culprit. [0]

    [0] https://www.forbes.com/sites/larsdaniel/2026/04/01/innocent-...

  • krunck 13 minutes ago
    These garments need to function in both visible and infrared environments as cameras use both. Otherwise these are not serious.
  • arjie 2 hours ago
    Face detection on the example images immediately focused on the right part and after that recognition becomes much easier when you crop out the rest. Not convinced. It’s a cool gimmick though. I like the MARPATish look of the black and white one.

    The most effective socially acceptable mechanism is a burqa or COVID mask or motorcycle helmet sock.

    • rusk 1 hour ago
      As Phil Zimmerman might opine, it’s not so much about defying every attack, it’s moreso about making it more difficult en masse by increasing the unit cost. Though perhaps in the 90s surveillance tech wasn’t quite scaling as quickly as it is now.
  • focusedone 2 hours ago
    I hope designs like this become easier to purchase soon. It'd be fun to experiment with cameras I've got access to and I'd totally wear it out places on the weekend.

    Totally get that it's a cat-and-mouse thing, but I don't mind making more work for the people trying to force this on us all.

    • layer8 1 hour ago
      At some point there might be a DMCA-like law that makes such adversarial clothing illegal.
      • pluc 26 minutes ago
        They've made covering your face illegal in lots of places before the pandemic made it obligatory. We had protests here where people wore masks and masks were swiftly banned. It's ok for police though.
      • idle_zealot 1 hour ago
        I would expect it to be covered under any existing laws about circumventing security systems or impeding law enforcement. A mire specific law would probably pass in this environment though.
  • stronglikedan 1 hour ago
  • Xmd5a 2 hours ago
    > statement logged. standing by.
  • measurablefunc 2 hours ago
    There is a lot irony in using AI to generate adversarial examples for AI object segmentation.
    • pixl97 43 minutes ago
      Why? If you complete the loop it's just a GAN.
  • andai 2 hours ago
    Excellent, this will allow me to disappear completely!
  • threethirtytwo 2 hours ago
    Nah these designs can never proliferate very far because you can EASILY train AI to recognize the difference between these patterns and an actual face.

    You need to make a hoodie covered with actual size faces. That will fool the AI and will be harder to account for. Use AI itself to generate these faces so every hoodie has unique faces. Then imagine everyone in a crowd wearing this.

    Boom. THAT will fool AI for long time. But let's not fool ourselves... AI can eventually even be trained to recognize this. But it buys us a bit more time before the end.

    • prophesi 55 minutes ago
      It will always be a cat-and-mouse game. I don't think it's possible to have any sort of visual that an algorithm can't be trained to recognize.

      sidenote: did Adversarial Fashion stop selling the ALPR shirts/hoodies? That was my favorite thing to wear years back. And they're probably still effective at inserting noise.

    • thenthenthen 1 hour ago
      Projects like this pop up multiple times per year. Mostly one off student project, sometimes famous designers. Its such low hanging fruit that wont change anything. Better start teaching politics in art school?
    • drcongo 2 hours ago
    • exo762 2 hours ago
      Gait analysis - good luck faking your gait.

      What we need is a legislative solution to street surveillance proliferation. Germans figured that one out, rest of the world is capable of doing it too.

      • fhdkweig 2 hours ago
        A pebble in one shoe will change your gait.
        • pixl97 41 minutes ago
          "Oh look, its that asshole that puts rocks in his shoes again"
      • nickthegreek 2 hours ago
        Nothing a dress that touches that ground cant help obscure.
      • villish 1 hour ago
        We all get Segways, problem solved.
      • rusk 1 hour ago
        You need a system that does gait analysis, which requires upgrades across the board. All those sunk costs on pervasive facial recon systems. Sucks teeth.