Can Someone Hide From Your CCTV? The AI Blind Spot Risk

Can Someone Hide From Your CCTV? The AI Blind Spot Risk — featured image

by

Can Someone Hide From Your CCTV? The AI Blind Spot Risk

You installed cameras to protect your business. Maybe a few indoor units, one outside the loading bay, another at the front counter. You check the feeds on your phone, and you assume — reasonably — that if someone does something wrong, the system will catch it.

But here’s the uncomfortable question: what if your camera records everything perfectly, and still misses the one thing that matters?

That’s exactly what cybersecurity researcher Bill Swearingen has spent the past year working on. He’s built an “adversarial” pattern — a computer-generated design you can print on clothing or vehicles — that makes AI-powered surveillance cameras unable to detect whatever is underneath it. According to TechCrunch, after 31 million tests, his patterns defeated all 11 open-source detection algorithms he tested — including the software that powers Flock license plate readers, Axon body-worn cameras, and Clearview AI.

TL;DR: A researcher created printed patterns that blind AI camera detection. Not the footage — just the algorithm’s ability to spot people, faces, or vehicle plates. For Malaysian SMEs, this means the “smart” CCTV you rely on may be far easier to fool than you think, and “we have cameras” is no longer a complete security answer.

What This Means in Plain Language

Your CCTV system actually does two jobs. First, it records video. Second — if it’s a modern system — it uses AI to sift through that footage and flag something worth your attention: a person walks in, a vehicle stops, a face appears at the door.

Street cameras and business surveillance have been “supercharged” with this detection ability, from tracking license plates to running facial recognition. But detection is a separate layer on top of recording. Swearingen’s patterns don’t block cameras from filming. They scramble the AI’s object recognition, so the camera captures everything — but the algorithm never triggers an alert. As the article describes it, the person becomes “a needle in a haystack again.”

This isn’t a sci-fi invisibility cloak. It’s a printed pattern, refined using a reinforcement learning model that essentially taught itself “how to paint.” Each time a design failed against one of the 11 algorithms, the model tried again. Over a year of iteration, it found recipes that fooled multiple systems at once — and confirmed the approach works in the real world. At the Def Con cybersecurity conference, a 2009 Toyota Yaris covered in one of the patterns successfully evaded a Flock detection camera.

“Privacy is a fundamental right,” Swearingen told TechCrunch, describing his patterns as a way to allow people to “opt-out of being tracked.”

How This Applies to Malaysian SMEs

You might be thinking: this is America, street cameras, Def Con. I run a hardware shop in Puchong or a café in Johor Bahru. Why does this matter to me?

Because of the exact reason you bought your camera system in the first place: you want to know what’s happening at your business when you’re not there. If your system has any “smart” features — and most systems sold in Malaysia today claim AI person detection or motion alerting — then your security rests on the same kind of pattern-matching algorithms Swearingen just demonstrated defeating. A person or vehicle wearing or carrying the right pattern could walk straight through your camera’s field of view, and your system would simply never register it. The tools that fool a Flock license plate reader on an American street are not fundamentally different from what could be used to fool a smart camera guarding a Malaysian warehouse.

Think about where detection algorithms show up in Malaysia beyond shops: parking enforcement, toll collection, gated community entry systems, and increasingly sophisticated “AI security” suites sold to SMEs. These systems run on the same principles — and share the same fragility. As the TechCrunch article notes, AI surveillance has already produced “mixed success and sometimes terrifying results” in real deployments. If the detection layer can be scrambled by a printed pattern, the entire value proposition of “AI-powered security” deserves a closer look.

There’s also a business opportunity here. If you provide security systems, retail management, property services, or facility maintenance, your clients are asking the same questions you’re asking now. Do you know how your cameras’ detection actually works? Can your vendor explain what happens when the system faces an unusual visual input — a highly patterned backdrop, a printed poster, an oddly decorated vehicle? Most can’t, because the market is focused on adding features, not testing how fragile those features are. If you start asking these questions about your own operations and the systems you recommend, you become a vendor clients actually trust. That’s an edge that has nothing to do with company size.

And there’s a responsibility angle too. Malaysian businesses are becoming savvier about data protection under the Personal Data Protection Act (PDPA). If your camera system relies on automated detection, false positives are a real and present risk. An employee, a delivery rider, a customer’s child moving through the wrong zone at the wrong time — your AI system could flag them as a threat, and that can create a situation you’d rather avoid. Understanding the limits of this technology isn’t just technical diligence; it’s part of running a responsible operation.

What Your Camera Actually Does vs. What You Assume It Does

What you assume What AI actually does
The camera records everything Yes — but detection is a separate, fragile layer
“Person detected” alerts are reliable They’re pattern-matching, and patterns can be fooled
More cameras = more security More cameras = more data, but also more blind spots
Footage will be there as evidence Footage is only useful if someone knows what to look for

Practical Takeaways for Your Business

  • Don’t trust a single layer. Cameras are one input among many. Physical locks, access control, and alert staff are not optional extras — they’re your real first line of defense.
  • Ask your security vendor about detection limits. Ask what algorithms your camera uses and whether it has been tested against unusual or deliberately confusing visual inputs. A vendor who can’t answer is a warning sign.
  • Test your own system. Place a high-contrast patterned poster or an item of patterned clothing in your camera’s view. See if your “person detection” still triggers. You’ll learn a lot in five minutes.
  • Treat your footage as raw data, not a verdict. If everything is recorded but nothing is flagged, your night staff or your own review process is what catches incidents. Make sure someone is actually reviewing.
  • Handle client footage responsibly. You hold more data than you used to. Understanding both the power and the limits of your surveillance systems keeps you — and your customers — safer.

The Bigger Picture

Swearingen’s noRecognition project is running a crowdsourcing campaign to bring the patterns to the public — on T-shirts and hoodies first, with vehicle skins possible later. Whether or not they become a practical everyday tool, the message is clear: algorithmic surveillance is a technology, and all technology has a counter-technology.

For your business, the long-term shift is this: camera detection is an ongoing arms race, not a fixed capability. The companies selling you “AI-powered security” are selling you algorithms that can be studied, tested, and defeated. That’s not a reason to scrap your cameras. It’s a reason to treat them as one tool among many, and to build security habits that don’t depend on a single alert pinging your phone at 2 a.m.

There’s a deeper point too. The same detection technology that watches your shop floor is being used in public streets, toll plazas, and checkpoints. Understanding how it works — including its blind spots — is fast becoming part of operating responsibly as a business. The SME owner who understands this won’t be caught off guard when customers, employees, or regulators start asking harder questions about surveillance.

Your camera records everything. But “everything” isn’t the same as “everything that matters.” You’re the one who has to know the difference.

Ready to Streamline Your Operations?

Your business should run itself. AutoRunBiz deploys AI agents to automate your daily operations — WhatsApp orders, invoicing, customer follow-ups, and accounting. Book a free 15-min ops audit to see where automation fits your business →