Can a simple mask fool facial recognition?

The AI Camouflage mask cut out with its straps, green and brown adversarial pattern.
ARTICLE · AUGUST 18, 2026 · BY YANN CARBONNE

Discover how facial recognition can be disrupted and generate your own experimental pattern on an open-beta app.

Generate and test your own camouflage →

What the machine sees

A facial-recognition system does not see your face the way a human does. It turns the image into a mathematical representation, a digital fingerprint, which it can then compare to those of thousands or millions of other people.

Your test photo. Photo
The same photo, with the face located by a box. Face detection
[ 0.03, -0.51, 0.22, 0.87, -0.14, … ]
Digital fingerprint
Comparison
The reference photo comes out with the highest score: that’s you. Identification the highest score, that’s you

That raises a simple question: if an algorithm recognizes us from this fingerprint, can we change what it sees to make recognition harder?

That is the idea behind AI Camouflage: an adversarial pattern printed on a mask. To a human, your face remains perfectly recognizable. To the machine, the digital fingerprint is scrambled.

The idea of an adversarial pattern already exists digitally in the research world. But a pattern that works on screen does not necessarily keep working in the real world. Ink, fabric folds, lighting and the camera sensor all alter the image: a pattern that is perfect in simulation can collapse once printed. The whole challenge is to craft a pattern robust enough to survive the physical world in specific applications: that is one of the new grounds we are exploring.

Why wearing a mask is not enough

A legitimate first intuition would be “just cover your face”. It does not work: modern facial-recognition systems are increasingly trained to recognize a face despite occlusions, especially since Covid.

Mask, scarf, glasses, a hand in front of the face: during training, they learn to exploit the cues that stay visible (the outline of the eyes, the forehead, proportions, the structure of the face) to keep producing an identification.

An adversarial pattern follows a logic different from occlusion. It does not simply try to hide the face, but to distort the way the algorithm perceives it.

The pattern is designed to disturb the numerical features the model extracts from the face and to push its biometric fingerprint away from the one it would normally produce. The system can still detect a face, analyze it and measure it, but the representation it computes no longer matches the wanted person as closely.

In short: the mask conceals; the adversarial pattern disturbs. One removes information, the other tries to mislead the algorithm.

Yann wears a plain blue surgical mask.
Match: ≈ 98%
Yann wears a mask printed with an adversarial camouflage pattern.
Match: < 1%

And it works: in our tests, against several open-source algorithms, our printed masks currently prevent the system from identifying you.

The detailed results against several well-known open-source facial-recognition algorithms:

The camouflage against five open-source engines
1:1 “Is it really you?”: the resemblance collapses
100% ≈ 0
ArcFace cancelled
100% ≈ 0
ArcFace compact cancelled
100% ≈ 0
AntelopeV2 cancelled
100% 11%
AdaFace −89%
100% 34%
FaceNet −66%
resemblance without a pattern with AI Camouflage
1:N “Who is this?”: your face sinks into the crowd
Without a pattern, every engine identifies you at rank 1 among 2,995 faces. With the camouflage:
ArcFace 1st · without a pattern 2,551st · with pattern →
AntelopeV2 1st 1,839th →
ArcFace compact 1st 1,477th →
AdaFace 1st → 158th
FaceNet 1st → 115th
rank 1 · identifiedrank 2,995 · lost in the crowd

A personal camouflage

The pattern is not universal: two people do not have the same face and do not produce the same digital fingerprint. So we are exploring an approach where each pattern is computed for one given person, from a few photos of their face. Rather than an “anti-AI” fabric identical for everyone, the camouflage is closer to a made-to-measure product: you provide a few photos, a pattern specific to your face is computed, and you can then print it, wear it and measure its effect.

Concretely, a mask computed for you protects only you: worn by someone else, it loses most of its effect. That is not a flaw, it is the very logic of camouflage: the pattern is built against your digital fingerprint, not your neighbor’s.

Yann Sarah
With their own pattern computed for their face
Yann wears the pattern computed for his face: not identified. Not identified
Sarah wears the pattern computed for her face: not identified. Not identified
With the other’s pattern the masks swapped
Yann wears Sarah’s pattern: recognized at rank 1. Recognized · rank 1, same as without a mask
Sarah wears Yann’s pattern: recognized at rank 1. Recognized · rank 1, same as without a mask

A combination rather than a miracle object

One result opens an unexpected path, with the most ordinary of objects: a baseball cap.

Worn alone, a cap leaves a person perfectly recognizable. Paired with a standard surgical mask, it hardly protects any better: algorithms still find the person easily. But in our experiments, adding that same cap to a mask carrying an adversarial pattern produced far more than a small gain: the observed effect was multiplied, as if the occlusion created by the cap and the pattern reinforced each other.

Cap + surgical mask Cap and surgical mask: still recognized.
Recognized
Cap + AI Camouflage Cap and AI Camouflage mask: not identified.
Not identified

Effective anti-AI camouflage probably lies less in a miracle object than in the combination of several complementary signals, designed to work together. The field keeps widening: glasses? headwear? makeup? several adversarial surfaces worn at once?

The goal for what comes next is now clear: AI Camouflage would like to move beyond the mask and become a true system of personal camouflage, one that guides a person to make themselves invisible to AI through several techniques.

And against algorithms we do not know?

Facial-recognition systems are many. Some are open source. Others are entirely proprietary. We know neither their exact architecture, nor their training data, nor the internal parameters that drive their decisions. The real question is transfer: can a pattern built with certain algorithms also defeat a system it has never encountered?

To find out, we pitted our patterns against AWS Rekognition, the facial-recognition service of Amazon’s cloud. We have no access to its inner workings, and our algorithm cannot lean on its model to optimize the camouflage: it is a blind test.

The protocol is simple. We give Rekognition 10 reference photos of a person and a database of 10,000 different people, then ask it to find them in new images. This protocol is deliberately hard: usually you use only a few photos (often a single one) of the reference person rather than 10, and the database holds millions of photos of people, not 10,000.

Without camouflage, it finds them without difficulty. With the mask, the person no longer comes up in the matches returned by the system, repeatedly across our tests.

Test photo without camouflage. Without camouflage 100% similarity with your face Rekognition finds you immediately: 1st match, rank 1 of 10,010.
Test photo, surgical mask and cap. Surgical mask + cap 98.6% similarity with your face Hiding the face is not enough: 1st match is you (99.4%), still rank 1 of 10,010.
Test photo, pattern alone, no cap. Pattern alone 13.4% similarity with your face The 1st match is a stranger (28.1%). You slip to rank 11 of 10,010.
Test photo, pattern and cap. Pattern + cap 0.5% similarity with your face The 1st match is a stranger (56.5%). Your face sinks to rank 1,579 of 10,010.

This result matters: it suggests the pattern does not merely exploit a quirk of one open-source model, but that some of its properties transfer to entirely different proprietary systems. The “recipe” of this transfer is still under research, and we will not detail it here.

A permanent race of adaptation

A pattern that works today will not keep working forever. As in cybersecurity, attacks and defenses evolve constantly: if a family of adversarial patterns becomes widespread, future recognition algorithms will be trained to resist it, and something else will have to be found. New textures, new surfaces, new combinations.

The pattern we are developing today is therefore not meant to be timeless. We are not trying to discover “an anti-facial-recognition pattern” once and for all: that does not seem possible. The goal is to keep a capacity for citizen research, so we can give ourselves the means to protect against facial recognition. So we must continually understand how systems evolve, measure their robustness, uncover new weaknesses and develop the next generations of camouflage.

The stakes will also be economic: protecting facial-recognition algorithms against these masks will cost money and development time. Finding other camouflage techniques will too. How this economic balance evolves between attack and defense will be paramount.

This is a good moment to restate some of AI Camouflage’s values: the point is to give ourselves the power of balance, not to systematically break every facial-recognition system. The use of these algorithms cannot happen without a governed, clear and transparent framework, to ensure sound use. For instance, a legal, regulated identification by the French police or gendarmerie is healthy. Its illegal use, which has been reported by some media outlets, is not.

What now?

We are only at the beginning. Much remains to be understood: how the patterns behave against the diversity of people, other proprietary systems, how they hold up to distance and camera diversity, which physical combinations work best, how future models will adapt.

But one idea is already taking shape: camouflage in the age of artificial intelligence will be personal, computed and evolving. Personal, because it is created for your own face. Computed, because its appearance is not merely aesthetic: it is optimized around the way machines perceive us. Evolving, because it will have to keep changing as recognition algorithms evolve themselves.

This is what we want to explore with AI Camouflage, and you can take part right now: generate your pattern, print it, wear it, and tell us what you observe.

Generate and test your own camouflage →

Take part in the project

Want to take part in our upcoming tests, try AI Camouflage against a recognition system you are faced with, or test how robust your own system is?

Write to us at yann.carbonne@proton.me.