TL;DR
The market for "anti-facial-recognition" accessories splits into four families: passive infrared-blocking eyewear (Reflectacles is the only sustained commercial brand), active infrared LED glasses (a 2013 NII research prototype that never reached retail), "dazzle" makeup and hairstyles (the CV Dazzle project, whose author has advised against his 2010 patterns since 2016), and academic adversarial patches and 3D-printed frames (Sharif 2016, Thys 2019) that exist in papers, not on shelves. Each technique targets a specific generation of detection algorithm, none has been shown to defeat current commercial face-matching systems in published evaluations, and the broader surveillance stack (gait, license plate, phone location) is unaffected by any of them.
What "Anti-Facial-Recognition" Actually Targets
Face-matching works in two stages. A face detector finds faces in the frame; a face recognizer then compares each detected face against a database. The accessories below target one stage or the other. CV Dazzle blocks detection. Adversarial patches can attack either stage. Infrared-blocking eyewear targets cameras that use infrared illumination (some 3D-mapping systems, some iris scanners, some phone face-unlock rigs). Most commercial face-matching today runs on visible-light photos from cameras with infrared-cut filters, and there is no published evidence that any accessory in this guide defeats those systems.[1][2]
Passive Infrared-Blocking Eyewear: Reflectacles
Reflectacles, operating since 2015 out of Michigan, sells "analog" privacy eyewear: glasses and clip-on lenses that combine infrared-blocking lenses with reflective frame materials, designed to defeat "facial recognition systems that use infrared for illumination" and "systems using 3D infrared mapping/scanning."[1] The product line on the company's homepage lists ten items from a $48 universal IR clip to $228 sunglasses like the Ghost and Phantom lines; the Ghost weighs 46 grams and ships with "IRlight" (day/night) or "IRdark" (day/outdoor) lens options.
What the company says it counters, in its own words: "3D infrared facial mapping (e.g., iPhone Face ID) and iris scanning, day and night"; "smart phone images taken with flash in low light"; "eye measurements on infrared security cameras"; and "2D and 3D facial recognition systems (via reflective frame)."
The honest catch: Reflectacles targets cameras that rely on infrared, including "iPhone Face ID" and similar 3D-mapping systems. Standard visible-light CCTV, the most common face-matching camera today, does not use infrared illumination, and Reflectacles' homepage does not publish effectiveness figures against those systems. A reflective frame is also obvious to a human reviewer.
Active Infrared LED Glasses: the Privacy Visor
In 2013, a team at Japan's National Institute of Informatics (NII), led by Akihisa Yamada with R. Ohmura and others, published two papers on what they called the "Privacy Visor": a wearable eyeglass frame fitted with near-infrared LEDs emitting at 850 nm and 940 nm, designed to break the dark-pupil/bright-eye geometry and nose shadows that the Viola-Jones face detector family relied on.[3][4]
Against the detector family tested in 2013, detection accuracy fell from roughly the upper 90s percent without glasses to single-digit percent with glasses, across the angles tested in the paper.[3] That is the strongest result in this category, and the one with the clearest expiration date: the paper's targets are the Viola-Jones / Haar-cascade family, and most modern pipelines now run convolutional neural networks (CNNs) on visible-light frames. The prototype was covered widely in 2013-2014 (Forbes titled its piece "Wearing a Visor Blocks Facial Recognition, Sort Of") but was never retailed at scale.[5]
CV Dazzle Makeup: the Author Has Advised Against Since 2016
CV Dazzle ("Computer Vision Dazzle") is a camouflage technique created by Adam Harvey in 2010 as his NYU ITP master's thesis, advised by Despina Papadopoulos. Inspired by World War I dazzle ship camouflage, it is described on Harvey's project page as "the first documented camouflage technique to successfully attack a computer vision algorithm."[2] The approach alters the dark-and-light regions of a face so a detector cannot locate it: contrasting makeup tones, partial obscuration of the nose bridge and one or both eyes, an obscuring of the elliptical head shape, and asymmetry across the left and right halves of the face.
Critically, the project page states that "the original patterns (designed between 2010 and 2013) are no longer active looks," because "Viola-Jones gradually became deprecated in security around 2013-2016 and is no longer used." Harvey adds: "this site has advised against using looks 1-5 since 2016." A 2010-vintage CV Dazzle pattern sold today is, per the author's own page, a pattern he stopped recommending a decade ago.
Adversarial Patches and 3D-Printed Frames: Research, Not Retail
The academic literature contains two distinct approaches to adversarial wearable countermeasures, and neither is a consumer product.
The first is the adversarial patch, by Simen Thys, Wiebe Van Ranst, and Toon Goedemé in their CVPR 2019 Workshop paper "Fooling Automated Surveillance Cameras: Adversarial Patches to Attack Person Detection," submitted to arXiv in April 2019. Their method generates a printed patch that, when held in front of a person's body, significantly lowers the accuracy of a person detector filmed in real life. Their target was person detection, not face recognition; the patch does not pretend to defeat a face matcher.[6]
The second is adversarial eyewear, by Sharif, Bhagavatula, Bauer, and Reiter in their ACM CCS 2016 paper "Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face Recognition." Their method uses 3D-printed eyeglass frames whose textures are optimized to either evade a target face-recognition classifier entirely or impersonate a chosen other person. The CMU project page describes the demonstration as "overwhelmingly successful" against the targeted classifier.[7]
What both share is the same limit: each attack is optimized for a specific model. A patch or pair of frames tuned against one face-recognition model does not transfer cleanly to another, and the reader never knows which model is in use at the camera they pass. There is no published evidence that either approach generalizes to current commercial systems. Both are research demonstrations of a real vulnerability class, not products.
What the University of Chicago Found When It Tested Anti-FR Tools
A team at the University of Chicago's SAND Lab (Emily Wenger, Shawn Shan, Jiayun Zhang, Huiying Li, Ben Zhao, and Heather Zheng) presented a framework for evaluating anti-facial-recognition tools at the 44th IEEE Symposium on Security and Privacy in May 2023. Their tool Fawkes, an app that corrupts a user's photos so a face matcher cannot enroll them, has reached roughly 840,000 downloads since its 2020 launch.[8]
Wenger summarized the limits bluntly: "I have come to view Fawkes as more of a normative statement about the importance of giving users agency against unwanted facial recognition, rather than a silver bullet solution to this problem." The team also flagged that anti-FR tools may disproportionately misidentify people with darker skin tones and women. The published evaluation does not support a precision ladder of which accessories are "X percent effective."
What This Means in Practice
Four rules of thumb hold across everything above.
The accessory market is mostly passive IR-blocking eyewear. Reflectacles is the only brand in this guide you can actually order; the NII Privacy Visor is a 2013 research prototype, CV Dazzle patterns are explicitly deprecated by their author, and adversarial patches and frames are academic artifacts.[1][2][3]
"Anti-facial-recognition" is a moving target. Each accessory targets a specific generation of detection algorithm. Viola-Jones detectors (the 2001-2013 era) are largely gone from commercial pipelines; CNN-based detectors and recognizers are the default now. Any accessory whose published evidence is from before 2018 needs an honest disclaimer about what it was tested against.
Most face-matching today does not run on infrared. Reflectacles explicitly targets "systems that use infrared for illumination and systems using 3D infrared mapping/scanning."[1] Standard visible-light CCTV, Ring doorbells, Flock plate readers, and Clearview-style search engines all run on visible-light frames. Against those, the published evidence for every accessory above is thin or absent.
The face is only one surveillance vector. A reflective frame that hides your face from a CCTV camera does not hide your gait, your plate from a Flock reader, your phone's IMSI from a cell-site simulator, or your purchases from a credit-card record. Operational privacy requires addressing all of those, not just the cameras.
The Bottom Line
If you can buy it, it is almost certainly Reflectacles. The other three categories (NII's Privacy Visor, CV Dazzle, and adversarial patches and frames) are research outputs whose authors have published mixed messages about their current utility against state-of-the-art systems. None of the published evidence supports a precision ranking. Each technique targets a specific generation of detection algorithm, modern CNN pipelines have moved past most of those targets, and the wider surveillance stack is unaffected by any of them.
Related Coverage
- How to defeat facial recognition: what actually works in 2025
- ICE facial recognition and real-time deportation
- Ring doorbells scanning faces without consent
- Flock Safety's 20 billion monthly scans and ICE access
- A field guide to police surveillance technology
- The full guides hub
Sources
- Reflectacles: privacy eyewear and anti-facial-recognition glasses
- Adam Harvey: CV Dazzle
- Yamada, A., Ohmura, R., Taniguchi, H., Komachi, K., & Sasaki, Y. (2013). Privacy Visor: A Wearable Device to Defeat Face Detection. UbiComp 2013 Adjunct, 1075-1078.
- Yamada, A., Komachi, K., & Sasaki, Y. (2013). Defeating Face Detection with Near-Infrared LED Glasses. ICCV Workshops 2013, 17-24.
- Forbes: Wearing a Visor Blocks Facial Recognition, Sort Of (September 2013)
- Thys, S., Van Ranst, W., & Goedemé, T. (2019). Fooling automated surveillance cameras: adversarial patches to attack person detection. arXiv:1904.08653 (CVPR 2019 Workshop).
- Sharif, M., Bhagavatula, S., Bauer, L., & Reiter, M. K. (2016). Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face Recognition. ACM CCS 2016.
- University of Chicago Physical Sciences: Evaluating Anti-Facial Recognition Tools (May 2023)