TL;DR: Masks work. Sunglasses help. The fancy CV dazzle makeup from 2010? Mostly obsolete against modern systems. New research shows subtle makeup on key facial points (nose bridge, brow lines, jaw) can disrupt algorithms. Anti-surveillance clothing exists but makes you more visible to human eyes. Your best options: physical coverage, avoiding deployment zones, and fighting for bans. No perfect solution exists.
The Honest Truth First
Let's be clear: there's no magic trick to defeat all facial recognition. Modern systems are sophisticated. They're designed to work despite partial obstruction. Some can identify you by gait, voice, or body shape even if your face is covered.
But "hard to defeat completely" isn't the same as "impossible to reduce your exposure." Every technique here makes tracking harder. Some make it much harder. Stack them together and you become significantly more difficult to identify.
The question isn't "can I become invisible?" It's "can I make mass surveillance less effective against me?" Yes. You can.
What Actually Works
1. Physical Coverage (Most Effective)
The ACLU recommends face coverings for protesters specifically because they work. Masks, bandanas, sunglasses: basic physical obstruction remains the most reliable countermeasure.
Why it works: Facial recognition needs to see your face. Cover the key identification points (nose, eyes, mouth, jawline) and the algorithm can't build a template.
What to use:
- N95/KN95 masks (normalized since COVID, covers nose and mouth)
- Sunglasses (disrupts eye region detection)
- Hats with brims (shadows face from elevated cameras)
- Scarves/balaclavas (full coverage when legal)
- Combination of mask + sunglasses + hat (most effective)
Limitations: Some UK police have reportedly asked people to remove face coverings near LFR deployments. You're not legally required to comply unless arrested, but it creates confrontation. Also doesn't help against gait recognition.
2. Subtle Makeup Techniques (2025 Research)
Researchers at PeopleTec published findings in January 2025 showing you don't need dramatic face paint. Subtle darkening of specific facial regions can disrupt recognition without making you look like a punk rock album cover.
Key areas to target:
- Nose bridge (critical for facial geometry mapping)
- Brow lines (above eyebrows)
- Jaw contours (along jawline)
The technique: Subtle darkening of these "high-density key-point regions" disrupts the facial landmarks algorithms use. Think contouring makeup, not warpaint.
Activist Michelle Tylicki adds: "Apply shapes, colours or lines in unusual directions. Algorithms love symmetry, so break it."
Limitations: Requires practice. Results vary by system. Won't stop human identification. Research was conducted on specific algorithms. Real-world systems vary.
3. Anti-Surveillance Clothing
Italian startup Cap_able sells knitted garments with "adversarial patches": patterns designed by AI to confuse facial recognition. The camera sees the pattern as an animal or object, not a person.
Other options:
- Cap_able: Adversarial pattern clothing
- Urban Privacy: FACEPTION and URBANGHOST lines
- AntiAi Clothing: Anti-detection apparel
Limitations: Expensive. Makes you extremely visible to human observers. The loud patterns that confuse cameras make you stand out in crowds. Also, the patterns were designed against specific systems, and newer algorithms may adapt.
What Doesn't Work Anymore
Classic CV Dazzle (Mostly Obsolete)
Artist Adam Harvey coined "CV dazzle" in 2010: dramatic face paint with geometric shapes designed to break up facial features. It made cool photos. It worked against 2010 algorithms.
Modern systems? Not so much.
The original designs were tested on facial recognition software that's now "heavily dated." Current surveillance technology handles partial obstruction better. It can identify you through multiple data points. And frankly, walking around with geometric face paint makes you extremely memorable to every human who sees you.
The newer subtle techniques work better precisely because they're less noticeable.
IR LEDs in Glasses
Some vendors sell glasses with infrared LEDs that "blind" cameras. The theory: IR light saturates the image sensor, obscuring your face.
Problems:
- Only works on cameras without IR filters (most modern cameras have them)
- Creates obvious bright spots that flag you for attention
- Battery-dependent: fails when power dies
- Doesn't work in daylight
Save your money.
The Gait Recognition Problem
Here's what keeps privacy researchers up at night: gait recognition is coming.
Gait recognition identifies you by how you walk. Stride length, arm swing, posture, pace. You can't easily change it. Masks don't help. Makeup doesn't help. You'd have to change your fundamental movement patterns.
One expert quoted: "Gait recognition is becoming quite powerful. It is harder to imagine practical and effective evasion strategies against this technology."
The Home Office consultation mentions gait recognition as a potential future technology. The UK isn't deploying it widely yet, but it's coming. China already uses it.
Possible countermeasures (limited effectiveness):
- Pebble in shoe (changes gait temporarily)
- Different footwear (heels vs flats changes stride)
- Loose/restrictive clothing (affects movement)
- Walking with a limp (obvious, attracts attention)
None of these are reliable long-term solutions. The real answer to gait recognition is political, not technical.
Practical Advice by Situation
Walking Through a Known LFR Zone
• Mask + sunglasses + hat with brim
• Walk with a group (harder to isolate)
• If stopped, you're not required to identify yourself unless arrested
• Document the deployment (note location, time)
Attending a Protest
• Full face coverage (mask, sunglasses)
• Avoid distinctive clothing or tattoos
• Don't bring your phone (or use a burner)
• Travel to/from in plain clothes, change nearby
• Be aware police may photograph crowds
Daily Life in a Surveilled City
• Check Big Brother Watch for deployment alerts
• Alter routes to avoid known camera locations
• Masks remain normalized, so use them
• Sunglasses are always appropriate
In Retail (Asda, etc.)
• Stores with facial recognition: mask up or shop elsewhere
• Check for Facewatch cameras (usually signed)
• File ICO complaints if you're misidentified
• Support Big Brother Watch's legal challenges
The Real Solution Isn't Technical
Every countermeasure here is a bandaid. The real solution is banning the technology.
The EU did it. The AI Act prohibits real-time facial recognition in public spaces. Violators face €35 million fines. Texas won a $1.4 billion settlement against Meta over biometric misuse, and Illinois's landmark BIPA settlement with Meta reached $650 million. Portland banned private facial recognition entirely.
Britain could do the same. The Home Office consultation is open until February 2026. Parliament will eventually vote. The trajectory isn't fixed.
Technical countermeasures buy time. Political action creates permanent change.
What to do:
- Respond to the Home Office consultation
- Contact your MP
- Support Big Brother Watch and Liberty
- Share information: most people don't know they're being scanned
Summary: What Works, Ranked
| Method | Effectiveness | Practicality | Notes |
|---|---|---|---|
| Mask + sunglasses + hat | High | High | Best everyday option |
| Full face coverage | Very High | Medium | May attract attention |
| Subtle makeup (2025 technique) | Medium | Medium | Requires practice |
| Anti-surveillance clothing | Medium | Low | Expensive, visible to humans |
| Classic CV dazzle | Low | Low | Mostly obsolete |
| IR LED glasses | Low | Low | Don't waste money |
| Avoiding deployment zones | Very High | Varies | Check BBW for locations |
| Political action | Potentially Total | High | Only permanent solution |
The Bottom Line
You can make mass facial recognition harder to use against you. Physical coverage works best. Subtle makeup techniques show promise. Avoiding deployment zones is obvious but effective.
But every individual countermeasure is a defensive action in a losing war. The cameras multiply faster than you can avoid them. The algorithms improve faster than countermeasures adapt.
Fight for bans. Support legal challenges. Respond to consultations. That's how you actually win.
In the meantime, wear a mask. It's still legal, it's still effective, and it's still your face.
References
- The Register - Subtle makeup tweaks can outsmart facial recognition (January 2025)
- Dazed - How effective is anti-face make-up to evade AI surveillance?
- Cap_able - Adversarial Fashion
- Wikipedia - Computer vision dazzle
- L.A. Taco - Can Anti-Surveillance Makeup Protect Protesters?
- Big Brother Watch - Stop Facial Recognition Campaign
- Home Office - Facial Recognition Consultation