Skip to content
A wrapped Toyota Yaris with a Flock camera in the background.

A Hacker Wrapped A Toyota And Flock’s Cameras Couldn’t Tell It Was A Car

Stephen M 10 min read

A patterned Toyota Yaris reportedly confused a Flock camera at DEF CON 34. Here's how adversarial computer vision works and what the test actually proves.

Key Takeaways

  • A patterned wrap applied to a Toyota Yaris was demonstrated against a Flock Safety camera at DEF CON 34 in Las Vegas.
  • The demonstration involved the noRecognition project, which researches adversarial patterns designed to interfere with computer-vision detection.
  • The test targeted vehicle detection rather than simply attempting to hide a license plate.
  • Flock cameras are designed to identify vehicles using characteristics such as make, model, color, body type and other visible features in addition to license plates.
  • The demonstration is an interesting proof of concept, but one successful test does not establish that the technique will consistently defeat Flock cameras in real-world conditions.
  • Adversarial patterns are an established area of computer-vision research, although their effectiveness can vary depending on the camera, software, viewing angle, distance and environmental conditions.

What Happened to the Toyota Yaris?

A Toyota Yaris became the centerpiece of a computer-vision experiment at DEF CON 34 after researcher Bill Swearingen demonstrated a vehicle wrap designed to interfere with automated detection systems.

The project, known as noRecognition, uses specially generated visual patterns intended to confuse machine-learning systems. During the public demonstration, the wrapped Yaris was driven past a Flock Safety camera and reportedly was not classified by the system in the expected way.

The significance of the demonstration is that it went beyond simply trying to interfere with a license plate reader. The research targeted the computer-vision detection process that identifies an object as a vehicle in the first place.

The noRecognition project is publicly documented by its creators at noRecognition, where the research focuses on adversarial patterns and their interaction with surveillance and detection systems.

How Does Flock’s Vehicle Detection Work?

Flock Safety’s cameras are designed to capture more than license plate numbers. The company’s Vehicle Fingerprint technology analyzes visible characteristics of vehicles, including make, model, color, body type and distinguishing features.

Flock says its systems can identify details such as roof racks, bumper stickers and other visible characteristics. That broader approach allows a vehicle to potentially be searched for based on its appearance even when a license plate is unavailable or difficult to read.

Flock describes this capability as vehicle intelligence rather than facial recognition. According to the company’s current documentation, its ALPR systems focus on vehicle information and do not use facial recognition.

More information about how Flock describes its vehicle-recognition technology is available on the company’s official Vehicle Fingerprint technology page.

What Are Adversarial Patterns?

Adversarial patterns are visual inputs deliberately created to cause a machine-learning model to make an incorrect detection or classification.

To a person, an adversarial pattern can simply look like an unusual collection of shapes, colors or visual noise. A computer-vision model, however, processes an image mathematically and can respond differently to patterns that would not necessarily appear meaningful to a human observer.

This is not a new concept. Researchers have demonstrated for years that carefully designed physical patterns can interfere with computer-vision systems under certain conditions.

What makes the noRecognition demonstration notable is the attempt to apply that concept to a real vehicle and a commercially deployed surveillance camera rather than limiting the experiment to a computer-generated image.

Did the Flock Camera Stop Seeing the Car?

The demonstration should not be interpreted as proving that Flock cameras are universally unable to detect the wrapped vehicle.

According to the project demonstration, the particular test resulted in the Flock system failing to classify the Yaris as expected. That is different from proving that every Flock camera, software version or configuration would produce the same result.

Computer-vision performance can change depending on distance, viewing angle, lighting, camera hardware, software updates and the visual characteristics of the object being analyzed.

Flock itself publishes testing showing that its cameras use computer vision to classify vehicles and reports high accuracy under tested conditions. That makes independent testing particularly relevant because adversarial research can reveal edge cases that may not appear during ordinary performance testing.

Why Is Vehicle Classification Important?

Vehicle classification is an important part of modern automated license plate reader systems because the vehicle’s appearance can provide additional information when a plate cannot be read or when investigators are searching for a vehicle based on its characteristics.

Flock says its technology can identify vehicles using attributes such as make, model, color, body type and visible distinguishing characteristics.

A system that relies on multiple layers of computer vision therefore has more than one potential point at which an unusual visual input could affect the final result.

The noRecognition project is specifically interested in that broader detection layer rather than treating license plate recognition as the only component that matters.

How Is This Different From Blocking a License Plate?

Traditional attempts to interfere with automated plate recognition generally focus on the license plate itself. The noRecognition research takes a fundamentally different approach by attempting to interfere with the computer-vision system’s ability to recognize the vehicle as an object.

That distinction is important because Flock’s systems are designed to capture vehicle characteristics in addition to plate information.

If a detection system never correctly identifies the vehicle in the first place, subsequent classification and identification processes may be affected as well. However, the DEF CON demonstration does not establish that this effect is permanent or universal.

What Happened at DEF CON?

The demonstration took place during DEF CON 34, which was held in Las Vegas from August 6 through August 9, 2026.

The research was presented as part of a broader investigation into adversarial patterns and computer-vision detection. The project documentation describes testing against multiple detection systems and emphasizes the difference between digital experiments and testing physical patterns against real cameras.

That distinction matters because a pattern that works perfectly in a computer simulation can behave differently when printed or applied to a physical object. Changes in lighting, perspective, resolution and distance can all affect the result.

Does One Successful Test Prove the System Can Defeat Flock?

No.

A successful public demonstration is evidence that a particular pattern can interfere with a particular detection setup under particular conditions. It does not establish a universal method for defeating Flock’s technology.

Computer-vision systems are regularly updated, and different camera models or software versions may respond differently to the same visual input.

The most useful takeaway from the demonstration is therefore not that Flock cameras have been permanently defeated, but that physical adversarial examples can represent a genuine research challenge for machine-learning-based surveillance systems.

Why Does the Research Matter?

The research raises questions about the reliability and limitations of automated vehicle detection.

Flock cameras are increasingly used to collect vehicle information for investigations, and the company markets its technology as a way to help identify vehicles using both license plates and visual characteristics.

If adversarial patterns can cause a system to miss or misclassify a vehicle under certain circumstances, that could be relevant to researchers, law-enforcement agencies and communities evaluating the limitations of automated surveillance technology.

It does not necessarily mean that the technology is unreliable. Instead, it demonstrates why performance claims should be evaluated across a wide range of real-world conditions rather than relying exclusively on controlled benchmarks.

Could Flock Update Its Technology?

Yes. Computer-vision systems are software-driven, meaning detection models can be retrained or updated when researchers identify new failure modes.

This creates a continuing cycle between adversarial research and defensive improvements. A pattern optimized against one model may become less effective after the underlying detection system changes.

The same principle applies in reverse: researchers can continue testing new models and new physical conditions to determine whether previously effective patterns still work.

That makes adversarial machine learning an ongoing research area rather than a one-time technological breakthrough.

What Does Flock Say Its Cameras Detect?

Flock says its cameras capture vehicle information rather than identifying people through facial recognition. Its published information says the technology can identify characteristics including license plates, make, model, color, body type and other visible vehicle details.

The company’s current privacy documentation states that its ALPR system collects license plate images, vehicle characteristics, dates and times, and camera locations, while facial recognition data and biometric data are listed as information the ALPR system does not collect.

Flock’s official data privacy documentation provides additional information about what the company says its ALPR systems collect and do not collect.

Frequently Asked Questions

What is the noRecognition project?

noRecognition is a research project focused on adversarial patterns designed to interfere with computer-vision detection systems. Its work includes testing physical patterns against real-world surveillance and detection technology.

Did a Toyota Yaris really fool a Flock camera?

A public demonstration at DEF CON 34 reportedly showed a patterned Toyota Yaris interfering with the expected detection or classification behavior of a Flock camera. The result was a specific demonstration rather than proof that all Flock cameras can be defeated in the same way.

What are adversarial patterns?

Adversarial patterns are specially generated visual inputs designed to cause machine-learning systems to make incorrect detections or classifications. They can appear unusual or chaotic to humans while producing a different response from computer-vision software.

Does Flock only read license plates?

No. Flock says its vehicle intelligence technology also identifies characteristics such as make, model, color, body type and other visible vehicle features.

Does Flock use facial recognition?

Flock says its ALPR technology does not use facial recognition and is designed to focus on vehicles rather than people.

Does the demonstration mean Flock cameras are permanently defeated?

No. The demonstration involved a particular camera and test condition. Camera hardware, software, lighting, distance, viewing angle and future model updates can all affect whether an adversarial pattern works.

Why is the noRecognition demonstration significant?

It demonstrates that physical adversarial patterns can potentially interfere with a real-world vehicle detection system, providing an example of a limitation that can be studied by computer-vision researchers and surveillance technology developers.

Pros and Cons of the Demonstration

Potential Significance

  • Demonstrates adversarial computer vision against a real-world system
  • Targets vehicle detection rather than only license plate recognition
  • Provides a physical-world test rather than a purely digital simulation
  • Highlights potential limitations of automated vehicle classification
  • Creates an opportunity for further research into detection reliability

Limitations

  • The public demonstration represents a limited test
  • Results can vary between camera models and software versions
  • Lighting, distance and viewing angle can affect performance
  • A successful test does not establish universal effectiveness
  • Surveillance systems can be updated to address newly discovered weaknesses

Bottom Line

The noRecognition demonstration at DEF CON 34 provides an intriguing example of how adversarial patterns can challenge computer-vision systems used in the real world.

A patterned Toyota Yaris reportedly interfered with the expected behavior of a Flock Safety camera during the demonstration. The important part is that the research went beyond simply attempting to obscure a license plate and instead examined whether a visual pattern could interfere with the vehicle-detection layer itself.

Flock’s technology is designed to identify vehicles using characteristics including make, model, color, body type and other visible details, making vehicle detection an important part of its system.

However, the demonstration should be viewed as research rather than proof that Flock cameras can universally be defeated. One test under particular conditions cannot establish how the technique would perform across different cameras, environments or future software versions.

The larger significance is that automated surveillance systems, like other machine-learning technologies, have measurable limitations. Public demonstrations such as this one can help researchers identify those limitations and encourage manufacturers to test their systems against increasingly sophisticated real-world adversarial conditions.

Specifications

SpecificationDetails
ProjectnoRecognition
Demonstration vehicleToyota Yaris
Technology testedFlock Safety computer-vision vehicle detection
Research methodPhysical adversarial visual pattern
EventDEF CON 34
LocationLas Vegas, Nevada
Event datesAugust 6-9, 2026
Flock vehicle attributesMake, model, color, body type and other visible characteristics
Facial recognitionFlock says its ALPR system does not use facial recognition
Demonstration statusSingle public test; further testing is required

Official sources: noRecognition Project | Flock Safety: What Do Flock Cameras Actually Capture?

Related Articles