对抗性时尚:对人工智能全景监狱的宣言
Adversarial Fashion Makes a Statement on AI Panopticon

原始链接: https://spectrum.ieee.org/adversarial-fashion

针对无处不在的人工智能监控,公众的抵制正推动“对抗性时尚”运动的兴起。Cap_able、Urban Privacy 等品牌以及近期在 DEF CON 大会上展示的创新成果,纷纷推出了印有几何图案的服装,旨在干扰、误导计算机视觉系统。这些活动人士通过诱导算法将穿戴者识别为动物或无生命物体,以抗议数字追踪中缺乏知情同意的问题。 然而,专家警告称,这些工具并非“隐身斗篷”。其有效性受限于拍摄角度、光照条件以及监控模型的可适应性,后者最终可能通过训练学会识别并忽略这些图案。此外,隐私倡导者指出,现代监控依赖于数据聚合——即结合步态分析、位置记录和社交媒体活动——仅靠改变服装很难做到完全匿名。 归根结底,支持者并不将这些服装视为万无一失的盾牌,而是将其看作个人表达和积极抵抗的有形工具。它们代表了隐私话语的转变,即从被动的期望转向主动的防御,主张个人在日益受到监控的数字世界中,必须采取主动权来保护自己的身份。

这篇 Hacker News 帖子讨论了“对抗性时尚”(Adversarial Fashion)的有效性,即旨在干扰人工智能目标检测和面部识别的服装图案。 关于这些设计的实用性,观点各不相同。一些用户认为这只是一种有趣的审美“噱头”,并指出通过简单的图像裁剪或重新训练人工智能模型来识别这些图案,即可轻松破解。另一些人则认为,对抗性设计是对抗无处不在的监控的一种必要反抗手段;有人甚至建议采取更激进的方法——比如在衣服上印上成千上万个人工智能生成的面孔——以压垮检测系统。 这段对话凸显了隐私倡导者与监控技术之间更广泛的“猫鼠游戏”动态。尽管一些评论者渴望穿上这些设计来增加数据采集的难度,但怀疑论者指出,人工智能终将适应。最终,许多参与者得出结论:技术上的变通方案只是暂时的;他们认为,持久的隐私保护只能通过立法手段来实现,而不是靠时尚选择或行为调整(如改变步态)。
相关文章

原文

AI-powered cameras dot streets across the world, equipped with the power to identify faces or vehicle license plates. But a public backlash is gaining momentum.

Privacy concerns abound, encompassing the lack of consent for capturing data, how that data is stored and used, and the risk of misuse. Those concerns are motivating people to fight back. The DeFlock project, for instance, maps automated license plate readers (ALPRs) to raise awareness. Some people resort to extreme measures, such as vandalizing or damaging ALPRs. Others are stitching together more creative responses, crafting “adversarial fashion” to evade surveillance cameras, like a Kickstarter project called noRecognition, presented at last month’s DEF CON hacker convention.

Scrambling surveillance

In 2025, cybersecurity expert Bill Swearingen began experimenting with a simple Python-based fuzzer, a tool that provides invalid inputs to reveal software bugs, security vulnerabilities, or unexpected behavior. The fuzzer targeted one of the most popular object detection frameworks, called YOLO. He then developed what he’d learned into a reinforcement learning algorithm that generates various adversarial patterns, which he presented at DEF CON.

Each pattern is a colorful geometric abstraction he has tested against 11 object detection models—four that search faces, two that recognize faces, and five that detect people—most of which are publicly available. Successful patterns thwart the object-detection systems, lowering their confidence scores, sometimes even to the point of no detection.

“Privacy is a human right, and the popularity of this just goes to show that people are interested in preserving their privacy,” Swearingen says.

Cap_able and Urban Privacy are already selling physical garments. Cap_able’s patented manufacturing method weaves its bright and bold motifs into jacquard knitted fabrics. The ethically produced and sustainably made dresses, pants, and tops interfere with certain computer vision systems, particularly those backed by fast convolutional neural networks, which may lead them to classify wearers as animals or objects.

“If we’re able to camouflage a person as something else, then we’re obtaining our goal,” says Cap_able founder Rachele Didero, who’s also an assistant professor at the Free University of Bozen-Bolzano in Italy. “We use this very visible and tangible item to talk about something that most of the time is intangible.”

Meanwhile, Urban Privacy aims to baffle some facial recognition systems based on OpenCV algorithms with its latest Faception Reloaded collection. Black-and-white prints abstracted from a human face show up as additional faces on detectors, slowing them down. Asymmetrical cuts and wide silhouettes intend to conceal, making it harder to discern your body’s shape and gait. “The idea is to create false data,” says cofounder Daniel Preuß.

Three individuals modeling a neck gaiter, t-shirt and hoodie with abstract vibrant patterns. Simulated patterns of the kind intended to disrupt machine vision person detectors.noRecognition

“Not an invisibility cloak”

Anti-surveillance fashion can trace its roots to the art pieces, DIY projects, and thought experiments that emerged in response to the onset of AI surveillance systems more than a decade ago. For instance, technologist Adam Harvey developed multiple designs in the 2010s—from hairstyles and makeup that foil face detectors to heat-reflecting attire that avert drone-enabled thermal surveillance. In 2019, artist and activist Kate Bertash created her aptly named Adversarial Fashion clothing line decked with fake license plate numbers to inject junk data into ALPR databases.

The trend is now growing into a more solidified small industry. “Clothing is something you can actually buy and put on, unlike policy,” says Niloofar Mireshghallah, incoming professor of engineering and public policy at Carnegie Mellon University. “It’s a way of saying, ‘I didn’t consent to this.’”

But real-world conditions might reduce the effectiveness of countersurveillance clothing, such as camera angles, lighting, and how fabric folds as you move. “One good frame is all a system needs,” Mireshghallah says.

Motion and gait recognition are also influential factors. “Even if the camera thinks you’re a bear for a few frames, there’s a bear walking like you,” Mireshghallah says.

The adversarial patterns must also be tuned to specific object recognition models, so they cannot resist a different model. And once surveillance system operators train a future generation of models on a given adversarial pattern and the person wearing it, which they could do manually, clothing will no longer be a sufficient defense.

“It remains a fragile shield against a threat that is constantly improving from multiple angles,” says Dippu Kumar Singh, senior director of emerging data and analytics at Fujitsu North America who specializes in vision AI and AI ethics.

Makers are aware of their creations’ limitations. “It’s not an invisibility cloak,” Preuß says. “Surveillance aims to capture your identity, and fashion is about expressing your identity. We’re making clothing that people can wear to make a statement about the importance of privacy in a digital world.”

Active defense

Even with these hurdles, Cap_able’s Didero is determined to keep innovating. Urban Privacy will continue to release other parts of its collection, including a “shadow cap” that has an acrylic face shield layered with cutouts to blur facial contours. Swearingen plans to explore a few anomalies he has encountered, such as a pattern that shifted the bounding box and another pattern that changed a camera setting.

Adversarial fashion holds promise despite its pitfalls. “At its core, this fashion is about taking back control of your face and body,” Singh says. “People are starting to realize that privacy isn’t just a right they can passively expect to be handed to them—it is something they have to actively defend.”

Mireshghallah offers a more cautious approach, viewing countersurveillance fashion as a speed bump rather than an ultimate solution. The real risk, she notes, is aggregation: Models take a group of weak signals, such as a partial face, a building in the background, a time stamp, a social media post someone tagged you in, and stitch them together to make a confident guess about who you are and where you were.

“None of those pieces give you away on their own, but together they do,” Mireshgallah says. “My advice is don’t just think about hiding your face from a lens. Think about what else you’re leaking that can be combined with it. That side information is often what actually identifies you— and no pattern on a shirt fixes that.”

From Your Site Articles

Related Articles Around the Web

联系我们 contact @ memedata.com