Coat makes wearers invisible to AI security cameras
petapixel.com
petapixel.com
It's a similar reason we humans tend to get scared of rustling in the night, when the majority of the time there's nothing dangerous out there. Because predators are evolved for stealth and camouflage, our brains overcorrect pattern matching to try to detect them, but most of our "detections" are false positives.
"Perhaps" is a doing a lot of heavy lifting in your comment, and I find the possible outcome you describe to be very unlikely after looking at the pictures in the article.
Personally, I'm confident that these anti-AI patterns don't work consistently across different person detection models, even though the article doesn't even ask the question, let alone dig into the answer.
The article doesn't present independent evidence that these work at all, let alone against more than just a single toy model built for PoC purposes.
It's an idea that gets clicks, and the oddly-specific "$71" (just an unnecessarily specific conversion from 500 yuan) also helps with attracting clicks. This article is basically just clickbait, in my opinion, not anything substantial.
The original Dazzle camouflage was effective against human eyes too, so there's a pretty high bar for making an algorithm dazzle-proof.
Additionally, most "cvdazzle" results on Google images are trying to obscure the face, not the existence of a person. This research is apparently focused on preventing a person from being detected, not obscuring their face with weird patterns. Even then, the "cvdazzle" stuff that I'm seeing does not make it harder for me to tell there's a person there. It has the same effect of obscuring identity as a ski mask.
> I'm referring more to the jackets with the dark IR spots.
Can your cite your source? Googling for "cvdazzle jacket" turns up nothing. "Dazzle jacket" just turns up a bunch of fashion stuff.
Plus, nothing I've seen from the article -- including the dark IR spots jacket -- is that difficult to identify as a human, so the bar doesn't seem that high.
A choice quote from your cvdazzle link:
> This face is unrecognizable to the Viola-Jones Haar Cascade face detection algorithm. (It does not apply to DCNN face detectors)
So... modern face detectors don't even have trouble with cvdazzle. All four of the detectors in this sample correctly identify the cvdazzled subject from the cvdazzle link: https://huggingface.co/spaces/celebrate-ai/face-detection-cn...
I'll also add a few choice quotes from Wikipedia:
> Unlike other forms of camouflage, the intention of dazzle is not to conceal but to make it difficult to estimate a target's range, speed, and heading.
> The result was that a profusion of dazzle schemes was tried, and the evidence for their success was, at best, mixed.
So, no, dazzle camo does not seem to have a record of being effective against either humans or cameras, so the bar is low to start with, not "pretty high" at all. But, the goal here is also concealment, not obscuring range, speed, or heading, which dazzle camo only had "mixed success" for, and dazzle camo was never designed for concealment at all.
In either case, I'm not talking about hiding a ship on the horizon. I'm talking about the effectiveness of this for hiding a human walking in front of a camera.
What was the goal here? Dazzle camo seems like it was never proven to be that useful, according to wikipedia, and cvdazzle is obsolete according to its own website and a quick test that anyone can perform. As I said from the beginning, the article OP linked appears to be nothing more than clickbait. That $71 coat is not a general solution to AI surveillance, and training a machine learning model to detect it would not make that model suddenly overwhelmed with false positives.
1. They are mutually exclusive 2. They can't be run in close succession 3. They are disclosed and known to the person that tries to avoid them
The surprising truth is that these camouflage anti-patterns often work across many AI models. It's been a fairly baffling result in many research papers that the same trick-images work regardless of the model, but with an important catch...
The models need to have been trained on the same dataset. If the model was trained on COCO (super common for finding objects in an image), then you can fool it. Since there are a handful of academic datasets that underlie a ton of CV models, these tricks will often work.
But if the AI company used their own dataset to train the model, you can't fool it like this. (Unless you have an insider steal the dataset for you.) So if a company is good enough to come up with their own data, this doesn't work.
Not really. For object detection, there are really only two kinds of architecture in common use - the multi-stage RCNN-style and the single-pass YOLO style. YOLO's are much faster, and not as accurate. But within each of these architectures, there's a big knob you can turn to trade-off speed vs accuracy.
But the incredible truth is that those speed/accuracy trade-offs don't matter at all when facing an adversarial attack like this. The attacks will work reliably very well, as long as there are enough pixels and the t-shirt or whatever is facing the right direction, regardless of how the model is tuned for speed vs accuracy. That is, if you know the dataset it was trained on.
Or worse, shell such coat wearers with automatic gunfire: https://www.telegraph.co.uk/world-news/2022/09/26/israel-pil...
They sell mugs that show up as dogs/birds/toasters/nothing ... shirts that are stop signs, stickers that are toasters, etc.
Great secret santa gifts or stocking stuffers for ML nerds.
No affiliation, I just think it's cool :)
If you get hit yourself, though, don't expect sympathy from the courts or your insurance company.
I guess that is an opportunity for subscription "camouflage as a service".
The model would not be trained against "just shirt" == "human". It would just be more samples from the surveillance cameras of actual humans walking around being labeled properly. (The huge assumption here is that the shirt actually worked in the first place, which would only happen against a specific model, and the article doesn't provide any useful insights into anything.)
The model has to keep more of the context or else the bounding rectangles would be all over the place.
If you want to link to some useful examples of dimensionally reduced person detection models that exhibit this behavior, then by all means, but none of this is how any current models I've seen work. It also wouldn't make sense to deploy such a model if it were so easily confused by shirts lying around. That model would be pretty terrible by any standard. If they're using terrible technology, you probably don't need a special shirt anyways.
Teaching a model to notice people walking through the frame regardless of what shirt they're wearing is simply not "a cat and mouse game", assuming they're not intentionally using a terrible model or a terrible dataset.
Nevermind the fact that authorities do not disclose what AI implementations they use to detect people in footage.
A digitized pendant or pin seems to accomplish the same idea and easy to take with you.
They don't even resolve at the distances the camera detect people, what effect could they possibly have?
Citation needed, for each neural network.
In many cases there is simply not enough pixels on target for these patterns to render in a way that makes them at all distinguishable. You also have to account for the fact that you may wind up viewing a person from any range of a 360 arc/angle, so the pattern would need to be around the entire jacket.
Most algorithms are looking for more of an overall target size and proportions, plus things like target location relative to an artificial horizon or ground plane.
In some cases, this might work to reduce the overall classification confidence, but is unlikely to truly make the person "invisible".
Also, thermal cameras are hardly used anymore. They have been stuck at relatively low resolutions (D1 / 640x480), and modern sensors have really good low-light imaging. Because thermal cameras are still very costly, and because they never produce a "good" image with any identifiable detail, they have become really really rarely used overall. Even so, a few patches on a jacket that show small regions of high thermal contrast are unlikely to fool any systems.
I doubt that these researchers had access to current state of the art perimeter protection analytics products. The most likely tested on lower end easily available consumer based products.
It is hard to say what would be effective overall that is practical. Many systems ultimately fail on people crawling, some will detect this, but often at the trade off of many false alarms, so it is usually not enabled. However, crawling around is not really that practical.
Large groups of people moving very closely together are harder to detect, particularly if they are all dressed very similarly. But, I wouldn't call this a reliable evasion technique.
So no, $71 is not that expensive for a coat.
Only if they are really stupid. Adversarial attacks are easily beatable and if anything this only improves the AI. These attacks exploit the specific structure and training of a neural network, they do not make you "invisible to AI".
A device that looks like forehead flashlight, but actually has a camera and some computer vision AI (or some other way of detecting security cameras), and a laser beam that it can use to blind those cameras.
Or you need something like this: https://futurism.com/the-byte/watch-invisibility-cloak-milit...
Anyone who believes this $71 coat will make them "invisible to AI" doesn't know how machine learning works.
All efforts I can find seem rather amateurish. Very little light diffusion on the IR LEDs, or even entire LED strips wrapped around oneself as a way to get a bigger spread.
Or just not leave home.
I've always thought that surveillance footage gathered using our tax money should be available to everybody. I thought if everybody can access them, they would understand how we exposed we all are as soon as you leave the house.
Somebody has this data, but far as I know its not public.
The AI is evolving faster everyday. I work on some ai adjacent work, and we have translation and drawing ai internal service that are basically multiple AI's working together seamlessly. Ideally to automate the localization of one our products across 150 countries, even it boosts our productivity 20% it's going to be a huge win.
Note:
Got my answer: https://www.wikihow.com/Blind-a-Surveillance-Camera
It's no very practical.
Also, it might be able to, for example, hide your face or mask your car's license plate... but it doesn't make you invisible. In fact, just the opposite... using this technique makes you acutely visible, but just (if all goes well) unrecognizable. Or if you masked the entire field of vision, you might be effectively "invisible" but it would be obvious to anyone watching the camera output that something weird is happening. So you'd be making yourself conspicuous if there's a live operator watching.
So yeah... it does kinda work, but definitely of questionable (but probably non-zero) practicality.
Better surveillance cameras will have a "movable cut filter", meaning a mechanism to remove the IR filter from the light path to the sensor to allow for better low-light images. In this mode, the camera reverts to black and white images so you don't get the color shift from the ambient IR light.
Using some average 5mm IR LEDs in a flashlight setup during daylight hours would do nothing most of the time. At night you might be able to cause problems with some cheaper cameras, better units with good Wide Dynamic Range specifications would be able to handle most of these kinds of disruptor devices. You'd need some really powerful IR LEDs, like an array of OSRAM IR LEDs (https://ams-osram.com/products/leds/ir-leds) to create a strong IR floodlight that would cause the camera to be blown out. Also it is common these days for cameras to send alerts on problems with massive image disruption, so you'd have to hope you're trying to disrupt a very cheap system with nobody receiving event notifications (which is admittedly still very common).
Get in on it early. Everyone will be wearing one of these.
You run a competition and test your tech against the entries.
When your tech fails, know what you need to fix.
In a typical capitalistic, privately owned and run company, yes.