Sponsored
General News

A Shirt Was Designed to “Confuse” AI Cameras

Digital Camouflage uses an adversarial pattern against generic YOLO, but its creator explicitly says it does not promise anonymity.

Το πουκάμισο Digital Camouflage του Simon Weckert
Simon Weckert’s Digital Camouflage shirt uses an adversarial pattern intended to challenge person detection. Image: Simon Weckert.

Summary

  • Simon Weckert created a shirt with an adversarial pattern for object detection
  • In the official demo, a generic open-source YOLO fails in some frames
  • The project does not claim to defeat a specific state system or guarantee anonymity
  • Its goal is debate about transparency, reliability and accountability in surveillance
Contents
  1. How an adversarial pattern works
  2. The official Digital Camouflage demonstration
  3. Why the project connects to Kottbusser Tor
  4. From screen to fabric
  5. What it proves and what it does not
  6. The shirt as a political object
  7. Who is Simon Weckert
  8. What we think
  9. Frequently asked questions

Berlin-based artist Simon Weckert has created a shirt with an adversarial pattern designed to make a computer-vision system fail to classify its wearer correctly as a person.

The project is called “Digital Camouflage” and is presented as an ongoing wearable installation begun in 2025. In the official demonstration, a generic open-source YOLO object detector labels passers-by as “person” but intermittently fails to recognise the wearer of the colourful shirt.

The artist places clear limits on the claim: he does not say the garment defeats a specific government or police system, does not promise anonymity and does not present it as a tool for evading police. The work is a comment on opaque public surveillance and the ease with which systems can be trusted without public testing.

How an adversarial pattern works

Object detectors do not “see” a person as a human does. They search for learned combinations of edges, textures, shapes and relationships. An adversarial pattern is designed to create features that push the model toward a wrong prediction or lower confidence below its detection threshold.

To a person, the shirt remains an obvious garment on a human body. To the model, the repeated colourful forms may compete with patterns used to locate a torso, limbs and overall human shape. The attack does not block light or make the person invisible to the camera; it attempts to change the mathematical classification.

The official Digital Camouflage demonstration

In the project video, passers-by receive detection boxes while the shirt wearer appears without a stable label during part of the walk. The demo uses a generic open-source YOLO model, as the official page explicitly states. It is not a test on a Berlin surveillance camera and does not prove that the pattern works against every YOLO version.

That distinction is essential. A model trained on different data or using another resolution, temporal tracking, multiple cameras or adversarial defences may behave differently. Even on the same model, angle, distance, lighting, motion, video compression and fabric folds affect results.

Why the project connects to Kottbusser Tor

Weckert places the work within Berlin’s debate over public surveillance, particularly around Kottbusser Tor. The area has been central to discussions about cameras, automated analysis and systems intended to identify behaviour or incidents.

The question is not simply whether a shirt can fool a detector. It is who evaluates an opaque system’s accuracy, who decides what error rate is acceptable and what happens when a false decision affects a real person.

A security camera can continue recording a clear image even if one model does not draw a “person” box. The footage can later be analysed by another system or a human. Digital Camouflage should therefore not be confused with facial anonymisation, encryption or physical concealment.

From screen to fabric

Adversarial attacks are easier in digital files where every pixel is controlled exactly. Printed fabric introduces colour variation, folds, stretching, shadows and motion. To work physically, a pattern must survive many transformations rather than one ideal frame.

The official page cites recent research on adversarial clothing and physically realistic attacks on person detectors. That does not mean the commercial pattern has received independent academic testing under the same protocols. Weckert presents an art project informed by this research direction, not a certified protection device.

What it proves and what it does not

The demo proves that under specific conditions a visual pattern can change the output of a known detector. It does not prove universal effectiveness or that AI cameras are generally useless. It shows that performance depends on environment, data and operational limits.

It also does not prove protection from facial recognition, clothing or gait re-identification, thermal cameras, depth sensors or multi-camera correlation. A surveillance system can use several signals rather than relying only on one “person” label.

The shirt as a political object

Digital Camouflage is sold as a real shirt, but Weckert describes it primarily as a visible signal of disagreement with non-consensual machine reading of bodies. According to the project, part of the proceeds goes to digital civil-rights organisations opposing expanded surveillance.

A wearable object makes the debate visible. Questions about datasets, thresholds and false negatives move from technical reports onto the body being classified. That is the project’s strongest achievement regardless of the percentage of frames in which YOLO fails.

Who is Simon Weckert

Simon Weckert is a Berlin-based artist examining the effect of digital infrastructure on public space. He became widely known for “Google Maps Hacks,” in which a handcart carrying dozens of smartphones created the appearance of a traffic jam on the map. In both works, a simple physical intervention exposes how a digital system turns signals into “reality.”

What we think

Digital Camouflage is more convincing as a critique of automated surveillance than as a security product. The demonstration is striking, but responsible interpretation lies in the artist’s stated limits: generic YOLO, specific conditions and no promise of anonymity. The central question is not whether everyone needs adversarial clothing, but whether systems governing public space can be transparently tested before they gain power over people.

Frequently asked questions

Does the shirt make its wearer invisible to cameras?

No. The camera continues recording. The pattern tries to influence one object detector’s classification.

Does it work against police or government systems?

The artist makes no such claim. The demo uses generic open-source YOLO, not a specific state system.

Why might it fail?

Angle, distance, lighting, fabric folds, compression, the model version and additional defences can all change the result.

What is the project’s purpose?

To open public debate about the opacity, reliability and democratic accountability of automated surveillance.

Comments

Leave a comment