Academics from a Belgian university have devised a method that uses a simple 2D image that can be printed on shirts or bags to make wearers invisible to camera surveillance systems that rely on machine learning to recognize humans in live video feeds.

The 2D image (called a "patch" in the research paper) must be placed around the middle of a person's "detection box" and must face the surveillance camera at all times.

This does not hide a person's real face from the video feed (unless the person also wears a mask), but it prevents any human detection algorithm from spotting a human body when entering the frame and triggering a subsequent facial recognition check.

Looking for your next t-shirt?

Nowadays, the need to come up with a video-detection-dodging method has arisen after machine-learning-powered surveillance systems are now being widely deployed in some areas of the globe, mainly by law enforcement, oppressive regimes, or large retailers.

For the past few months, academics from the Catholic University in Leuven (KU Leuven) have experimented with the idea of overlaying a malformed image (called a "patch") on top of a person's detection box in order to trick machine learning systems into misclassifying a human as a nondescript object.

The research team experimented with various types of patches, such as randomly-generated image noise or blurred out images, but found out that photos of random objects that go through multiple image processing operations fair better than others.

For example, the image patch they came up with (Fig4, c) was created by taking a random image, which they rotated 20 degrees each way, scaled up and down randomly, added random noise, and modified rightness and contrast at random.

KU Leuven bypass surveillance camera patches
Image: Thys et al.
[2]

Read more from our friends at ZDNet