A video filmed at Berlin’s Kottbusser Tor shows pedestrians passing through the frame, each marked with a “PERSON” bounding box. Then a man wearing a Hawaiian shirt covered in fluorescent greens, pinks, and tangled shapes walks by—and the box disappears. The person has not vanished. The camera has simply stopped reading him as a person.

© Simon Weckert – “Digital Camouflage”
Photo: Simon Weckert; https://youtu.be/A5QTnUlgcJQ

This is not footage from Berlin police surveillance. It is a demonstration created by Berlin-based artist and technologist Simon Weckert to present his project, Digital Camouflage. Weckert tested the shirt against the open-source object-detection model YOLO, and under certain conditions, the model failed to detect the wearer as a person. He describes the work as an artistic response to public spaces increasingly being “read” by machines.

Why Does It Look Like This?

There is a reason the shirt looks so visually aggressive. Its pattern was shaped less by human taste than by machine judgment.

Object-detection models analyze visual features such as changes in color, edges, shapes, and textures across multiple stages, then combine those signals to decide that “there is a person here.” When features associated with the head, torso, arms, and legs are arranged in relationships the model recognizes as human, its detection confidence rises accordingly.

Digital Camouflage is designed to disrupt that process. Strong color contrasts and densely overlapping shapes interfere with the visual cues that would normally be grouped into a coherent human figure, while drawing the detector’s attention toward other signals. To a person, the result may simply look like a loud and unusual pattern. To the machine, however, the combination of features it normally relies on to identify a person becomes less stable.

The production process also differs from conventional fashion design. Weckert drew on previous research into adversarial patterns and public systems, generated patterns, fed them into YOLO, and measured how far the model’s confidence in detecting a person dropped. He then adjusted the colors, shapes, and placement before repeating the process. In other words, the design was not completed first and tested afterward. The pattern itself kept changing in response to how the detector’s confidence score moved.

© Simon Weckert – “Digital Camouflage”
Photo: Simon Weckert; https://www.simonweckert.com/digitalcamouflage.html

Distance, camera angle, lighting, and the model being used can all change the result. Even so, what makes the shirt distinctive is clear. The key design question was not, “How good does this look to a person?” but “How much less certain can we make the AI that this is a person?” To us, it may look like a brightly colored Hawaiian shirt, but its individual shapes and colors were chosen to interfere with the calculations an algorithm uses to locate a human figure.

These Clothes Have an Expiration Date

Fashion designed to fool machines is not a new idea.

In 2010, Adam Harvey used bold hairstyles and makeup in his NYU ITP master’s project, CV Dazzle, to disrupt the facial features and symmetry that computer-vision systems relied on.

Adam Harvey’s “CV Dazzle.” Hairstyles and makeup disrupt facial features and symmetry in order to interfere with the judgments made by face-detection algorithms.; https://adam.harvey.studio/cvdazzle/

The Viola-Jones face-detection algorithm widely used at the time relied on relatively stable visual features, including the eyes, nose, and patterns of light and shadow across the face, to decide whether a face was present. CV Dazzle deliberately disturbed those rules using asymmetrical hair, strong contrasts, and blocks of color crossing the face. Harvey describes the project as the first documented camouflage technique to successfully attack a computer-vision algorithm.

But the story did not end there. Face-detection technology evolved rapidly, and Viola-Jones eventually lost its place as a dominant approach in security applications as convolutional neural network, or CNN, systems became widespread. As the underlying technology changed, the early CV Dazzle patterns created in the 2010s no longer produced the same results.

Research then expanded from the face to the entire body. In 2019, researchers at KU Leuven experimented with printable adversarial patches that could be attached to clothing or other objects to make person detectors fail to recognize the wearer correctly. The significance was that the attack moved beyond changing a few pixels in a digital image and into a physical pattern that could be printed, carried, and used in the real world. The researchers also tested whether the effect could persist as the distance and position between the camera and the person changed.

In 2020, researchers from Northeastern University and the MIT-IBM Watson AI Lab went a step further with the Adversarial T-shirt. Clothing folds, stretches, and continuously changes shape as a person moves, making it a much more difficult target than a flat patch. The researchers incorporated those deformations into the pattern design and reported an attack success rate of 74% against YOLOv2 in digital settings and 57% in physical-world tests. The research question had shifted from simply asking, “Can a particular image fool the model?” to “Can detection still be disrupted when a person is actually wearing the pattern and moving around?”

Digital Camouflage brings this line of experimentation back into the street as both wearable fashion and an art project. Instead of obscuring the face, it covers the body with an adversarial pattern and shows how an object detector reacts as a person physically walks through public space. Like the projects before it, however, the shirt is not a universal camouflage capable of fooling every AI system. Because it was developed against particular detection models and conditions, its effectiveness can change when the model or camera environment changes.

Over the past decade, what has changed is not so much the idea of “clothing that fools machines” as the kind of machine being targeted. As face detectors changed, the makeup changed with them; as full-body person detectors emerged, adversarial patches expanded into T-shirts and body-covering patterns. Digital Camouflage was also developed with contemporary object-detection systems in mind, but it has a clear limitation. What Weckert actually tested was the publicly available YOLO object detector, not the behavioral-analysis system used by Berlin police at Kottbusser Tor. A YOLO model failing to detect the wearer therefore should not be interpreted as evidence that the shirt can evade Berlin’s real surveillance system.

Invisible to Machines, More Visible to People

The more interesting problem comes next. A Hawaiian shirt covered in fluorescent colors, strong contrasts, and complex patterns does not easily disappear into the background of a city street. An object detector may occasionally fail to recognize the wearer, but to the people nearby, the shirt may make that person even easier to notice. The clothing becomes less visible to a machine while becoming more visible to humans.

© Simon Weckert – “Digital Camouflage”
Photo: Simon Weckert; https://www.simonweckert.com/digitalcamouflage.html

The difference becomes easier to understand once we consider what digital camouflage is actually trying to accomplish. Traditional camouflage uses colors and shapes that resemble the surrounding environment in order to hide a person from human sight. Digital Camouflage, by contrast, is designed to interfere with an object-detection algorithm. Whether the shirt looks natural on the street matters less than which colors and shapes the machine interprets as evidence of a human figure. The strong contrasts and complex forms that disrupt the algorithm can therefore appear unusually distinctive to the human eye.

That leads the shirt to a question beyond simply, “Can someone become invisible to AI?” It also asks, invisible to whose eyes? Even if one object detector can be fooled, a street contains other cameras, other systems, and, above all, people looking directly at the scene. Weckert himself does not present the shirt as equipment for evading police or as a product that guarantees anonymity.

The significance of Digital Camouflage lies instead in making this difference visible. To a person, there is clearly an ordinary pedestrian standing in the frame. An object detector, however, breaks the image down into colors, edges, shapes, and other visual features before assigning a probability and confidence score to the category “person.” When the shirt disrupts that judgment and the “PERSON” label disappears, the normally hidden logic of machine perception becomes visible as well.

Ultimately, this is less a garment for hiding people than a garment that shows us how machines see people—and where that vision can go wrong.