These Fake License Plate Clothes Were Designed To Confuse Surveillance Cameras


At DEF CON 27 in August 2019, one table stood out for a reason that had nothing to do with hacking laptops or cracking passwords. It was covered in cotton clothing printed with dozens of tiny license plates, each one designed to fool the same automated cameras that quietly track millions of vehicles every day.

The shirts, crop tops and pencil skirts looked like unusual fashion pieces. Point the right surveillance system at them, however, and the camera could start logging the wearer as a stream of vehicles that never existed. The project was called Adversarial Fashion, and its creator had built it around one simple weakness: surveillance technology is often willing to collect far more data than it can reliably understand.

Dozens Of Fake Plates On Every Garment

Kate Bertash, who originally published the work under the name Kate Rose, designed the collection as an experiment in what happens when surveillance technology encounters carefully engineered visual noise. By day, she directs the Digital Defense Fund, a nonprofit focused on digital security for abortion access and other movement groups. Her work frequently sits where technology, organizing and art collide, and Adversarial Fashion brought all three together in a particularly strange way.

The garments were printed with rows of small framed license plates, tiled across the fabric like wallpaper. Each design was built to look ordinary enough to wear while presenting automated license plate readers with dozens of potential targets. Bertash tested the patterns against commercial reader software, including OpenALPR and EasyALPR, adjusting the designs until the systems consistently recognized the printed rectangles as genuine plates.

The numbers themselves were selected from public data sets and decorative sources so the experiment would not accidentally attach false sightings to real drivers. That detail mattered because the project was never presented as a way to impersonate someone or hide a person’s identity. The goal was to exploit how broadly the cameras search for possible license plates in the first place.

As Bertash explained, an automated license plate reader searches for something in the camera’s view that appears likely to be a rectangle containing letters and numbers associated with a plate. Once the system finds one, it can crop the image, run the characters through optical recognition, attach a time and location, and add the result to a searchable database. A piece of fabric covered in carefully designed rectangles could therefore become a surprisingly effective source of false data.

  • T-shirts: Covered with repeated plate-like graphics.
  • Pencil skirts: Designed to place multiple potential targets in view.
  • Crop tops: Printed with the same adversarial plate patterns.
  • Free design resources: Released so other makers could experiment with the concept.

The Fourth Amendment Became Part Of The Pattern

One of the most striking designs turned the license plate frame itself into a political message. Instead of displaying the name of a dealership, the frames carried words from the Fourth Amendment, the constitutional protection against unreasonable searches and seizures. The result created an unusual collision between the technology and the message printed directly in front of it. A surveillance system designed to record vehicle movement could scan the clothing and potentially capture text invoking constitutional protections against government searches.

That was part of what made the project more than a novelty. Adversarial Fashion exposed the strange mechanics of automated surveillance by making them visible in public. Most people never think about the software watching roads, parking lots and intersections until a camera becomes part of a criminal investigation. The technology usually operates quietly in the background, collecting images at enormous scale.

A shirt that causes the system to mistake fabric for a vehicle turns that invisible process into something people can actually see and question. The joke works because the software is doing exactly what it was designed to do. It is simply doing it too generously.

Cameras Can Collect More Than They Understand

Automated license plate readers are built to capture possible plates quickly. That broad approach helps the technology avoid missing legitimate vehicles, but it also creates room for mistakes. Bertash later explained that these systems can be willing to ingest images of objects that were never intended to be tracked, including picket fences and billboards. Clothing became another unexpected target because the software was looking for visual patterns rather than understanding the full context of what the camera was seeing.

Adversarial Fashion did not need to break into a surveillance network or disable a camera. It took advantage of a weakness created by the system’s own appetite for data. Every false plate that enters a database can create additional work for the technology processing it. The image may need to be stored, indexed and searched alongside legitimate records. Bertash described the strategy as economic as much as technical. If surveillance systems are forced to collect more useless information, the data can become more expensive to manage and potentially less useful at scale. One shirt was never going to overwhelm a nationwide network, but the project raised a more uncomfortable question about surveillance technology: what happens when systems designed to collect everything start collecting too much?

Why Junk Data Was The Point

The project was built around the idea of introducing noise rather than disappearing from view. That distinction matters because the wearer was still visible. The clothing did not function as invisibility gear, and Bertash never claimed it could defeat surveillance on its own. Instead, the garments encouraged the cameras to produce questionable records. The theory was straightforward: a system flooded with enough irrelevant information becomes harder and more expensive to operate efficiently.

That approach also turned the clothes into a public demonstration of how automated surveillance works. People could see the fake plates with their own eyes, then understand that software might see something entirely different. The technology was no longer an abstract concern buried inside a data center. It was reacting to a pencil skirt.

The Surveillance Network Has Only Grown

Seven years after the original DEF CON demonstration, the scale of automated vehicle surveillance has become far larger. Flock Safety operates more than 120,000 automatic license plate readers across at least 6,000 cities, according to figures cited by the ACLU. The cameras capture vehicle information that can be stored in searchable cloud databases, allowing investigators to search records after a vehicle has passed through a particular location.

Supporters argue that the technology helps law enforcement investigate a substantial number of crimes every year. Critics have raised concerns about how widely the systems can track movement, who can access the information and how clearly companies describe their capabilities to local governments. The technology is also moving beyond traditional plate searches. Flock has tested artificial intelligence tools designed to identify vehicles through patterns of movement, potentially allowing searches based on where and how a vehicle traveled rather than relying entirely on a license plate number.

Questions About How The Data Is Used

The ACLU has documented disputes involving statements made to officials considering surveillance contracts. In one case involving Oshkosh, Wisconsin, questions emerged over whether the system could generate maps showing patterns in a vehicle’s movements. The company later acknowledged capabilities that differed from earlier assurances given to local officials. Separate concerns also emerged around access to plate data by federal agencies, adding another layer to the debate over how widely the information can travel once it has been collected.

One local official summarized the frustration bluntly after the conflicting claims. The Oshkosh council cancelled its contract shortly afterward. Cases like that show why a fashion experiment from 2019 still feels relevant. The original clothes were built around a simple observation: surveillance systems can collect information at a scale that most people never directly see. The debate over what happens to that information has only become more intense.

The Clothes Stopped Selling Around 2023

Adversarial Fashion is not currently operating as an active clothing line. The collection stopped being sold around 2023, and the former store now directs visitors to Bertash’s website with a message suggesting that a future re-release could happen. The project remains visible online, but the garments themselves have become harder to find.

Bertash has also been clear about the limits of the idea. A single shirt cannot bring down a surveillance network, and the project was never a magic solution for privacy concerns. Its value came from exposing a weakness in a system that often operates without attracting attention. The designs also outlived the original store because Bertash released resources that allowed other people to study and experiment with the approach. That decision helped transform Adversarial Fashion from a short-lived product into a continuing conversation about surveillance and adversarial technology.

A New DEF CON Experiment Took It Further

The concept returned to DEF CON in a different form in August 2026. Kansas City security researcher Bill Swearingen demonstrated adversarial patterns developed through reinforcement learning after roughly 31 million tests. His approach aimed for a different result from Bertash’s original clothing designs. Instead of feeding surveillance cameras false information, the patterns were designed to interfere with object detection itself.

Swearingen said the patterns defeated all 11 open-source detection algorithms he tested, including software associated with systems used for license plate readers, body cameras and facial recognition technology. Real-world testing also revealed a major complication: vehicles have moving parts, and the wheels proved particularly difficult to account for. He has kept some of his strongest patterns off the internet, arguing that public release could give surveillance companies an opportunity to train their systems against them.

The difference between the two projects shows how quickly the field has developed. Bertash’s clothing encouraged cameras to see things that were not there. Swearingen’s work attempted to make cameras miss things that were. Both experiments were built around the same uncomfortable reality: artificial intelligence and surveillance systems can be manipulated because they do not see the world in the same way humans do.

The Fabric Still Carries The Same Challenge

The fake license plate clothes never brought automated surveillance to its knees. Their creator never pretended they would. What they did accomplish was far more interesting than a simple fashion stunt: they made a hidden technological weakness visible in a form anyone could understand.

A camera can mistake a shirt for a collection of cars. A surveillance system can record fences, billboards and fabric because its definition of a useful target is sometimes far broader than a human observer would expect. Seven years later, researchers are still experimenting with ways to exploit those gaps. The clothes may no longer be on sale, but the question printed into their design has become even harder to ignore: how much data should a surveillance system be allowed to collect when it cannot always tell what it is looking at?

Loading…

, ,

Leave a Reply

Your email address will not be published. Required fields are marked *