Walk past a security camera wearing an ordinary shirt and the camera records you as it would record anything else in the scene. But some specially designed clothes are made to interfere with what happens after that image is captured.

They're called adversarial clothing, and the idea sounds stranger than it really is.

The camera itself isn't necessarily fooled. It can still take a perfectly good picture of the person wearing the shirt. The unusual part happens inside the computer system analyzing that picture.

A human might see a colorful pattern, a strange arrangement of shapes or an ordinary-looking design. A computer-vision model sees a large collection of numbers representing pixels, edges, textures, colors and other visual features. An adversarial pattern is designed to disturb those features in a way that can make the model less confident about what it is looking at.

Researchers have demonstrated versions of this idea in the physical world, including clothing designed to interfere with person detectors and infrared systems. (Open Access CVF)

That doesn't mean the wearer becomes invisible.

It means something more specific, and more interesting: the machine can be looking directly at a person and still have trouble deciding that a person is there.

What is adversarial clothing?

Adversarial clothing is clothing designed with patterns, textures or materials intended to interfere with a machine-learning vision system.

The word adversarial comes from a broader area of AI research involving adversarial examples. Researchers discovered that carefully altered images can cause machine-learning models to make mistakes even when the changes look minor or meaningless to a person. (DOI)

That idea eventually moved from computer screens into the physical world.

Researchers developed adversarial patches that could be printed and placed into real scenes. Google's 2017 research showed that specially designed patches could be photographed and still interfere with image classifiers under different conditions. (Google Research)

Clothing is a natural extension of the idea.

Instead of putting a small patch onto an object, the pattern can be printed or woven across a garment. The garment then becomes part of the image that the computer is trying to interpret.

Several research groups have demonstrated physical adversarial clothing against different types of computer-vision systems. (Open Access CVF)

Why can a pattern confuse a computer when it doesn't confuse you?

The difference starts with how humans and computer-vision systems process an image.

When you look at a person wearing a patterned shirt, you don't normally analyze every individual pixel. You recognize the overall shape of the person, the head, arms, legs, clothing and surroundings, then use those pieces of information to understand the scene.

A computer-vision model works differently.

The image is represented as numerical data. The model processes patterns within that data through many layers, gradually extracting features that help it decide what objects are present.

Those features might relate to edges, shapes, textures, colors and combinations of visual patterns.

The model doesn't have a human's common-sense understanding of what a shirt is supposed to look like.

That's part of the weakness adversarial examples exploit.

A pattern can be designed to change the information reaching the model in a way that matters to its calculations, even when the overall image still looks perfectly ordinary to a person.

The result can be something like this:

Human: "That's a person wearing a colorful shirt."

Computer vision system: "I'm not sufficiently confident that this image contains a person."

The important part is that the shirt isn't magically blocking the camera. It's interfering with the interpretation of the image.

What does an AI camera actually see?

The phrase "AI camera" can make the whole process sound mysterious.

There usually isn't a little digital brain inside the camera staring at you and deciding who you are. A camera captures light and turns it into an image. Software can then analyze that image.

Depending on the system, that software might be trying to answer very different questions:

  • Is there a person in this image?
  • Where is the person?
  • Is there a face?
  • Whose face is it?
  • Is there a vehicle?
  • What type of object is that?
  • Where are several objects located?
  • Is the scene showing something the system has been trained to detect?

These aren't the same task.

That's why saying that a shirt "fools facial recognition" can be misleading. Some adversarial clothing research targets person detection, where the goal is to interfere with the system recognizing a human figure.

Other research targets infrared or thermal detection. Facial recognition is another step, involving the identification or comparison of faces.

A garment that interferes with one of these systems isn't automatically effective against all of them.

The difference between person detection and facial recognition

Imagine a security camera pointed at a sidewalk.

The first system might draw a box around a person and say:

Person: 96%

That's person detection.

A separate system might then locate the person's face and compare its features against a database. That's a different problem.

Three-zone diagram of an AI camera pipeline: the camera records light and pixels without judging anything, a detector answers one narrow question such as person, object, face or heat, and a recognizer works out whose face it is — with legend chips for person detector, object detector, face detector, facial recognition and thermal or infrared detector
Three different jobs, three different weaknesses. The camera only records light. A detector answers one narrow question about the image. Only a recognizer tries to work out whose face it is — and a pattern that disrupts one of them says nothing about the others.

A shirt designed to make the first system less confident about detecting the person's body isn't necessarily going to stop the second system from recognizing the face.

This distinction matters because much of the popular discussion around adversarial clothing lumps several different technologies together. The research is more specific.

For example, the 2022 CVPR research on infrared adversarial clothing targeted pedestrian detectors operating on infrared imagery. The researchers reported physical experiments in which their clothing reduced the performance of the tested YOLOv3 detector. (Open Access CVF)

That's evidence that adversarial clothing can interfere with a particular computer-vision task. It isn't evidence that any shirt can defeat every surveillance camera.

How do researchers make clothing adversarial?

At a high level, the process involves repeatedly showing a machine-learning model candidate visual patterns and measuring how its predictions change.

The basic idea is similar to giving the model a visual problem and then adjusting the image until the model starts making the desired mistake.

Researchers also have to account for the fact that a shirt isn't a flat computer screen. Fabric folds. People move. The shirt can rotate relative to the camera. Parts of the design can be hidden by arms. Lighting changes. The distance from the camera changes. The pattern may look different from different angles.

This is one reason physical adversarial clothing is much harder than simply generating a strange-looking image on a computer.

Research on dynamic adversarial patches has specifically looked at clothing deformation and movement because patterns that work on a perfectly flat digital image can behave differently when they're printed on fabric and worn by a moving person. (Open Access CVF)

More recent research has pushed this further by testing clothing against visible and thermal detection systems and by designing garments that can change their appearance under particular conditions. (Open Access CVF)

Why wrinkles, distance and lighting matter

A computer doesn't receive the same image every time it sees a shirt.

Move the person closer and the pattern occupies more pixels. Move them farther away and it occupies fewer. Turn sideways and parts of the pattern disappear. A fold can stretch one section of the design while compressing another. A shadow can change the apparent color and brightness. The camera itself can introduce changes through focus, exposure, compression and other processing.

This creates a problem for anyone trying to make a physical adversarial pattern reliable. A pattern that performs well under one set of conditions may perform less well under another.

Research into physical adversarial patches has found that real-world factors such as position, rotation, brightness and hue can substantially affect performance. One 2024 study found notable discrepancies between simulated and physical-world results under some testing conditions. (arXiv)

So the hardest part isn't necessarily making a pattern that fools a model once. It's making one that continues to do so when the real world starts getting messy.

Can adversarial clothing fool infrared cameras too?

Sometimes, yes, and this is a separate part of the technology. Visible-light cameras record the wavelengths humans normally see. Thermal infrared systems work with infrared radiation and can use differences in heat to detect people and objects.

Researchers have created clothing specifically intended to interfere with infrared pedestrian detection. A 2022 CVPR study used an adversarial pattern on clothing and tested it against an infrared detector. The researchers reported reduced detection performance in both digital and physical experiments. (Open Access CVF)

More recent research has gone beyond visible-light patterns and investigated clothing designed to affect both visible and thermal detection. A CVPR 2026 study, for example, described clothing using thermochromic materials and a heating system to activate a different visual pattern while altering the garment's thermal characteristics. (Open Access CVF)

That shows how broad the field has become. "Adversarial clothing" isn't one single trick. It's a family of techniques aimed at different kinds of machine perception.

Does adversarial clothing make you invisible?

No. That's probably the biggest misconception surrounding the subject.

The word "invisible" makes for a good headline because the effect can look strange in a demonstration. But the technology isn't making a person physically disappear from the camera's image.

The camera can still capture the person. A human looking at the footage can still see the person. The problem is that the machine-learning system interpreting that footage may make a different decision. And even that result depends on the system being attacked.

A garment developed against one detector isn't automatically effective against another. A change in the model, camera, viewing angle, lighting or detection task can change the result.

Researchers working on physical adversarial systems are well aware of this problem. Robustness across different conditions and unseen models remains an active research area. (Open Access CVF)

Can the same shirt fool every AI camera?

There is no good reason to assume that it can.

Computer-vision systems differ in their architecture, training data, detection targets and operating conditions. A pattern optimized against one model can lose its effect when the model changes.

That's one reason adversarial machine learning is treated as an ongoing security problem rather than a one-time trick.

There is also a difference between a research demonstration and a consumer product. A paper may show that a carefully developed garment affected a particular model under a defined experimental setup. That is valuable evidence, but it doesn't automatically tell us how a commercially sold shirt will behave against an unknown camera in a shopping center, airport or street.

Hands-on testing of antisurveillance products has highlighted this gap between the idea and real-world performance. Mozilla's 2025 review tested several products in this category using an Imou security camera rather than simply accepting manufacturers' claims. (Mozilla Foundation)

That's the sort of distinction worth keeping in mind when looking at dramatic demonstrations online.

Why would anyone want clothing like this?

The reasons vary.

Some designers treat adversarial clothing as privacy technology. Others treat it as experimental fashion or a way of commenting on surveillance. There is also an obvious cultural appeal. Surveillance cameras have become ordinary parts of public spaces, while people often have little idea what software is analyzing the footage.

Adversarial clothing turns that invisible technical problem into something you can actually see. A shirt becomes a statement about the fact that the camera isn't simply recording an image. Increasingly, software is interpreting that image too.

Commercial designers have already started experimenting with this idea. MIT's profile of Cap_able, for example, describes garments intended to interfere with people detectors and protect biometric privacy. (MIT Orbit)

Recent fashion coverage has also treated adversarial clothing as an emerging category rather than a purely academic curiosity. (The Guardian)

So what is actually happening when the shirt "fools" the AI?

The simplest way to think about it is this:

The camera takes a picture. The computer receives the pixels. The vision model looks for patterns that help it identify objects. The adversarial design changes those patterns. The model's calculations shift. Its confidence in the expected object can fall, or it can produce an incorrect classification.

Nothing supernatural happened. The machine didn't suddenly become blind. It was given visual information that its learned system wasn't robust enough to interpret correctly.

That's the strange part of adversarial clothing. The same image can be completely ordinary to a human while being a surprisingly difficult input for a machine-learning system. And that's why a shirt can matter to an AI camera without doing anything particularly impressive to the human eye.

The bigger problem with adversarial clothing

The technology demonstrates something more general about machine learning.

AI systems can be remarkably good at recognizing patterns without necessarily understanding those patterns in the human sense. That distinction is easy to miss because modern computer vision often works extremely well.

A phone can recognize faces. A security system can detect people. A car can identify objects on the road. But high performance doesn't mean the system understands an image in exactly the same way a person does.

Adversarial examples exploit those differences. The clothing is simply a physical way of putting the problem into the real world.

Research is already moving toward more complicated versions that account for movement, fabric deformation, multiple camera modalities and changing environments. (Open Access CVF)

At the same time, researchers are developing ways to detect and defend against adversarial patches. The technology is therefore becoming a moving target: attacks improve, detection improves, models change, and new attacks are developed against the newer defenses. (USENIX)

So the most accurate description isn't "a shirt that makes you invisible." It's a garment designed to exploit weaknesses in the way a particular computer-vision system interprets visual information.

That sounds less like science fiction. It is also considerably more interesting.