Can a simple mask fool facial recognition?
Discover how facial recognition can be disrupted, generate your own experimental pattern, and help us test how well it works in real conditions.
What the machine sees
A facial-recognition system does not see your face the way a human does. It turns the image into a mathematical representation, a digital fingerprint, which it can then compare to those of thousands or millions of other people.
Photo
Face detection
9 %
14 %
6 %
12 %
97 %
21 %
8 %
17 %
11 %
Identification
the highest score, that’s you
That raises a simple question: if an algorithm recognizes us from this fingerprint, can we change what it sees to make recognition harder?
That is the idea behind AI Camouflage: an adversarial pattern printed on a mask. To a human, your face remains perfectly recognizable. To the machine, the digital fingerprint is scrambled.
But a pattern that works on screen does not necessarily keep working in the real world. Ink, fabric folds, lighting and the camera sensor all alter the image: a pattern that is perfect in simulation can collapse once printed. The whole challenge is to craft a signal robust enough to survive the physical world.
Simulation helps us explore ideas quickly, but only real-world tests can tell whether a pattern actually works. So we test our patterns once printed, with real cameras and several open-source recognition algorithms.
Modern facial-recognition systems are increasingly trained to recognize a face despite occlusions. Mask, scarf, glasses, a hand in front of the face: during training, they learn to exploit the cues that stay visible (the outline of the eyes, the forehead, proportions, the structure of the face) to keep producing an identification.
An adversarial pattern follows a different logic. It does not simply try to hide the face, but to distort the way the algorithm perceives it.
The pattern is designed to disturb the numerical features the model extracts from the face and to push its biometric fingerprint away from the one it would normally produce. The system can still detect a face, analyze it and measure it, but the representation it computes no longer matches the wanted person as closely.
It is a bit like a deliberately distorted signature: it still reads as a signature, but it no longer matches the one on file.
In short: the mask conceals; the adversarial pattern disturbs. One removes information, the other tries to mislead the algorithm.
And it works: in our tests, against several open-source algorithms, our printed masks currently prevent the system from identifying you.
The goal now is to make this research accessible as a simple product: provide a few photos, generate your own pattern, print it, wear it and test your camouflage.
You can access the open beta here.
A personal camouflage
The pattern is not universal: two people do not have the same face and do not produce the same digital fingerprint. So we are exploring an approach where each pattern is computed for one given person, from a few photos of their face. Rather than an “anti-AI” fabric identical for everyone, the camouflage is closer to a made-to-measure product: you provide a few photos, a pattern specific to your face is computed, and you can then print it, wear it and measure its effect.
Concretely, a mask computed for you protects only you: worn by someone else, it loses most of its effect. That is not a flaw, it is the very logic of camouflage: the pattern is built against your digital fingerprint, not your neighbor’s.
Not identified
Not identified
Recognized · rank 1, same as without a mask
Recognized · rank 1, same as without a mask
A combination rather than a miracle object
One result opens an unexpected path, with the most ordinary of objects: a baseball cap.
Worn alone, a cap leaves a person perfectly recognizable. Paired with a standard surgical mask, it hardly protects any better: algorithms still find the person easily. But in our experiments, adding that same cap to a mask carrying an adversarial pattern produced far more than a small gain: the observed effect was much larger, as if the occlusion created by the cap and the pattern reinforced each other.
The future of camouflage probably lies less in a miracle object than in the combination of several complementary signals, designed to work together. The field keeps widening: glasses? headwear? makeup? several adversarial surfaces worn at once? In time, AI Camouflage would like to move beyond the mask and become a true system of personal camouflage.
And against algorithms we do not know?
Facial-recognition systems are many. Some are open source. Others are entirely proprietary. We know neither their exact architecture, nor their training data, nor the internal parameters that drive their decisions. The real question is transfer: can a pattern built with certain algorithms also defeat a system it has never encountered?
To find out, we pitted our patterns against AWS Rekognition, the facial-recognition service of Amazon’s cloud. We have no access to its inner workings, and our algorithm cannot lean on its model to optimize the camouflage: it is a blind test.
The protocol is simple. We give Rekognition reference photos of a person, then ask it to find them in new images. Without camouflage, it finds them without difficulty. With the mask, the person no longer comes up in the matches returned by the system, repeatedly across our tests.
Without camouflage
100%
similarity with your face
Rekognition finds you immediately: 1st match, rank 1 of 10,010.
Surgical mask + cap
98.6%
similarity with your face
Hiding the face is not enough: 1st match is you (99.4%), still rank 1 of 10,010.
Pattern alone
13.4%
similarity with your face
The 1st match is a stranger (28.1%). You slip to rank 11 of 10,010.
Pattern + cap
0.5%
similarity with your face
The 1st match is a stranger (56.5%). Your face sinks to rank 1,579 of 10,010.
This result matters: it suggests the pattern does not merely exploit a quirk of one open-source model, but that some of its properties transfer to entirely different proprietary systems. The “recipe” of this transfer is still under research, and we will not detail it here.
A permanent race of adaptation
A pattern that works today will not keep working forever. As in cybersecurity, attacks and defenses evolve constantly: if a family of adversarial patterns becomes widespread, future recognition algorithms will be trained to resist it, and something else will have to be found. New textures, new surfaces, new combinations.
The pattern we are developing today is therefore not meant to be timeless. We are not trying to discover “the anti-facial-recognition pattern” once and for all. We are trying to build a capability to keep moving the target.
That is also where the project’s value lies. Not in the pattern that works today, but in a continuous research capability: understanding how systems evolve, measuring their robustness, discovering new weaknesses and developing the next generations of camouflage.
What now?
We are only at the beginning. Much remains to be understood: how the patterns behave against the diversity of people, other proprietary systems, how they hold up to distance and camera diversity, which physical combinations work best, how future models will adapt.
But one idea is already taking shape: camouflage in the age of artificial intelligence will be personal, computed and evolving. Personal, because it is created for your own face. Computed, because its appearance is not merely aesthetic: it is optimized around the way machines perceive us. Evolving, because it will have to keep changing as recognition algorithms evolve themselves.
This is what we want to explore with AI Camouflage, and you can take part right now: generate your pattern, print it, wear it, and tell us what you observe.
Take part in the project
Want to take part in our upcoming tests, try AI Camouflage against a recognition system you are faced with, or test how robust your own system is?
Write to us at yann.carbonne@proton.me.