Art initiatives (3)
CV Dazzle
Adam Harvey’s foundational computer-vision camouflage project, created in 2010, using makeup, hairstyling, and asymmetry to disrupt face detection while remaining visible to humans.
- Demonstrated
- CV Dazzle demonstrated that hair and makeup alone could lower detection probability below threshold for several OpenCV Haarcascade face-detection profiles in the original proof-of-concept setting.
- Why it matters for Ghostmaxxing
- It is the central historical anchor for Ghostati: a technique-first, system-specific approach to anti-biometric appearance design.
- Ghostmaxxing testability
- Ghostati can retest the general strategy of visible face-region interventions against its own browser detection and matching pipeline, while clearly separating old Haarcascade claims from modern models.
- Limits
- The original looks were designed for Viola-Jones/OpenCV Haarcascade detectors and should not be treated as active protection against modern CNN-based detection or recognition systems. Lighting, pose, algorithm, and wearer-specific design all matter.
Adam Harvey, CV Dazzle, 2010 · documented project Canonical
HyperFace
Adam Harvey’s false-face textile camouflage, developed with Hyphen-Labs, that attempts to redirect face-detection confidence toward surrounding decoy faces rather than the wearer’s real face.
- Demonstrated
- HyperFace demonstrates a ground-based camouflage strategy: instead of hiding the face directly, it supplies machine-readable false faces around it to distract specific detectors.
- Why it matters for Ghostmaxxing
- It expands Ghostati’s design vocabulary from face overlays to surrounding false-face patterns and attention redirection.
- Ghostmaxxing testability
- Ghostati can test surrounding decoy-face graphics against browser detection in a limited way, but the original HyperFace patterns targeted specific Haarcascade detectors and textile contexts.
- Limits
- The documented prototype targeted OpenCV Haarcascade-style detectors and is not designed or tested against modern deep CNN-based face detection systems. Its value as camouflage is explicitly temporary and system-specific.
Adam Harvey, HyperFace, 2016/2017 · documented project Canonical
The Camera-Shy Hoodie
A DIY wearable that uses high-power infrared LEDs to degrade or overexpose night-vision security camera footage around the wearer’s head and upper body.
- Demonstrated
- The project demonstrates a buildable garment that interferes with IR-sensitive security cameras by using the same infrared wavelength commonly used for night-vision illumination.
- Why it matters for Ghostmaxxing
- It is a useful boundary reference: not face makeup and not face recognition in the strict sense, but a clear example of physical sensor disturbance as anti-surveillance design.
- Ghostmaxxing testability
- Ghostati cannot test IR LED glare, camera auto-exposure interference, or night-vision capture in a standard browser AR pipeline.
- Limits
- Its effect depends on camera sensitivity, exposure behavior, LED placement, distance, and lighting. It does not directly test face-recognition matching or browser-based face analysis.
Mac Pierce, The Camera-Shy Hoodie, 2023 · build files available Canonical
Advocacy efforts (2)
DAZZLE
A collaborative art-and-technology experiment by Michelle Tylicki and Lauri Love that turns anti-surveillance makeup into an interactive teaching and testing experience.
- Demonstrated
- The project demonstrates a salon-like interface for teaching Computer Vision Dazzle and testing camouflage against multiple facial recognition systems in an activist and public-learning context.
- Why it matters for Ghostmaxxing
- DAZZLE is one of Ghostati’s closest contemporary relatives: it combines makeup, interface design, quantitative feedback, and anti-surveillance pedagogy.
- Ghostmaxxing testability
- Ghostati can directly retest the browser-lab logic of applying face-region visual interventions and comparing detection or matching behavior before and after the intervention.
- Limits
- Public documentation describes the project and its testing ambition, but does not provide a full reproducible benchmark, exact model list, or protocol. Claims should be read as project documentation unless the implementation and results are independently released.
Tylicki and Love, DAZZLE, 2023 · documented project Canonical
The Dazzle Club
A London-based collective practice using CV Dazzle walks, workshops, films, and public-space research to draw attention to facial recognition and surveillance infrastructure.
- Demonstrated
- The Dazzle Club demonstrates how face paint and CV Dazzle can operate as embodied public research, collective performance, and public education rather than only as a technical evasion method.
- Why it matters for Ghostmaxxing
- It helps Ghostati understand camouflage as a social and workshop practice: a way to make public surveillance visible, discussable, and collectively testable.
- Ghostmaxxing testability
- Ghostati can support similar workshops and local tests, but it cannot reproduce the public-space performance, legal context, or collective embodied research of the project.
- Limits
- The project is primarily an artistic and activist practice, not a controlled technical benchmark. Its value is public research and awareness rather than a reproducible recognition-evasion result.
The Dazzle Club, 2019–2021 · artwork documentation Canonical
Peer-reviewed papers (15)
Adv-Makeup: A New Imperceptible and Transferable Attack on Face Recognition
A key adversarial-makeup paper that synthesizes transferable, imperceptible eye-shadow perturbations over the orbital region to attack face recognition.
- Demonstrated
- The paper demonstrates a task-driven makeup generation method and fine-grained meta-learning strategy intended to improve black-box transferability, including digital and physical scenarios.
- Why it matters for Ghostmaxxing
- This is one of the closest research references for Ghostati because it treats makeup as an adversarial surface on the machine-readable face.
- Ghostmaxxing testability
- Ghostati can approximate orbital-region overlays and compare local recognition behavior, but it does not implement the paper’s adversarial optimization, meta-learning, or commercial-system evaluation protocol.
- Limits
- The reported performance depends on the models, datasets, optimization method, physical-printing or application process, and commercial APIs tested in the paper. A manually designed Ghostyle is not equivalent to Adv-Makeup optimization.
Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face Recognition
A landmark physical attack on face recognition using printed eyeglass frames to support evasion or impersonation attacks in a comparatively inconspicuous form.
- Demonstrated
- The paper defines physically realizable and inconspicuous attacks on facial biometric systems and realizes them by printing adversarial eyeglass frames.
- Why it matters for Ghostmaxxing
- It is one of the strongest technical ancestors for Ghostati’s appearance-based tests: the face is not hidden, but visually modified to change machine matching.
- Ghostmaxxing testability
- Ghostati can approximate glasses-like overlays and compare local matching behavior, but cannot reproduce printed-material effects, physical-camera capture, or the exact optimization pipeline.
- Limits
- The results are tied to the target systems, printed patterns, imaging conditions, and experimental subjects. Newer recognition models or production systems require fresh testing.
Sharif et al., ACM CCS 2016 · code available Canonical · Paper · Project · Code
A General Framework for Adversarial Examples with Objectives
The later framework paper behind adversarial generative nets, including physical eyeglass frames designed to fool face recognition with better robustness, inconspicuousness, and scalability than earlier approaches.
- Demonstrated
- The paper demonstrates adversarial generative nets that can satisfy application-specific objectives, including physical eyeglass-frame examples for face recognition.
- Why it matters for Ghostmaxxing
- It is highly relevant because it treats facial accessories as optimized physical adversarial media, adjacent to Ghostati’s Ghostyle concept even though Ghostati uses browser-rendered visual styles rather than generated eyeglass frames.
- Ghostmaxxing testability
- Ghostati can retest the broad idea of face-region or accessory-like overlays, but not the generator training, eyeglass printing pipeline, or exact attack objective.
- Limits
- The result depends on generated eyeglass-frame patterns, model assumptions, and physical realization. Browser overlays can approximate placement but not validate the original optimization or robustness claims.
Sharif et al., arXiv 2017 / ACM TOPS 2019 · paper available Canonical · DOI
Adversarial Attacks against Face Recognition: A Comprehensive Study
A broad survey of adversarial attacks and defenses against face recognition systems, useful for situating Ghostati within a larger technical taxonomy.
- Demonstrated
- The article surveys attack and defense methods, proposes taxonomies, compares criteria, and identifies challenges and future research directions for adversarial face recognition.
- Why it matters for Ghostmaxxing
- It gives Ghostati a technical map for classifying references by threat model, physical/digital domain, target stage, and defense assumptions.
- Ghostmaxxing testability
- Ghostati can use the survey to classify experiments and limitations, but a survey is not itself a system or attack to retest.
- Limits
- As a survey, it summarizes prior work rather than providing one reproducible experimental setup. Some included systems and defenses may have changed since publication.
Vakhshiteh, Nickabadi, and Ramachandra, 2020/2021 · survey Canonical · DOI
VLA: A Practical Visible Light-based Attack on Face Recognition Systems in Physical World
A visible-light physical attack that projects adversarial perturbations onto a face to conduct targeted or untargeted attacks against black-box face recognition systems.
- Demonstrated
- The paper proposes VLA, a visible-light projection method for crafting physical adversarial perturbations on the face against black-box face recognition systems.
- Why it matters for Ghostmaxxing
- It connects Ghostati’s visual overlay approach to optical projection attacks: both change the appearance captured by the camera, but VLA is optimized and physically projected rather than drawn as a browser layer.
- Ghostmaxxing testability
- Ghostati can simulate a visible overlay on the face and measure local matching changes, but it cannot validate projector optics, camera-image formation, or the paper’s black-box attack setup.
- Limits
- The result depends on projector/camera geometry, brightness, environmental lighting, attack optimization, and the target recognition systems. Browser AR overlays are not equivalent to physically projected light.
Shen et al., UbiComp/IMWUT 2019 · paper available Canonical · Paper
Adversarial Robustness Toolbox v1.0.0
A general-purpose Python library for testing machine-learning models with adversarial attacks and defenses, useful as technical infrastructure rather than as a face-camouflage reference.
- Demonstrated
- ART provides implementations, examples, and documentation for attacks and defenses across many model families and machine-learning frameworks.
- Why it matters for Ghostmaxxing
- It helps situate Ghostati inside adversarial ML practice, but it is not a visual face-camouflage project by itself.
- Ghostmaxxing testability
- Ghostati could conceptually integrate adversarial-evaluation workflows, but ART does not directly map to the current browser-only Ghostyle test loop.
- Limits
- ART is broad infrastructure, not a face-specific or physical-world camouflage result. Applying it to Ghostati would require additional model wrappers and experiment design.
Nicolae et al., 2018/2019 · code available Canonical · Code · DOI
Adversarial Patch
A seminal paper on universal, robust, targeted adversarial image patches that can be printed, added to scenes, photographed, and presented to classifiers.
- Demonstrated
- The work demonstrates printable universal patches that can cause classifiers to ignore other scene content and output a chosen target class across transformations.
- Why it matters for Ghostmaxxing
- It provides the core technical idea behind many visible adversarial surfaces: a localized graphic object can dominate a model’s interpretation of an image.
- Ghostmaxxing testability
- Ghostati can draw patch-like overlays, but the original paper targets image classifiers and requires optimization not present in Ghostati.
- Limits
- The paper is not face-specific. Its relevance to Ghostati is methodological unless a face-recognition-specific patch is optimized and tested.
Brown et al., 2017/2018 · code available Canonical · Code · DOI
Adversarial Manipulation of Deep Representations
A theoretical reference showing that an image’s internal deep-network representation can be manipulated to resemble another image while remaining visually similar to the original.
- Demonstrated
- The paper demonstrates feature adversaries: small perturbations that make internal DNN representations mimic different natural images, raising questions about what representations encode.
- Why it matters for Ghostmaxxing
- It gives Ghostati a conceptual basis for thinking beyond labels: recognition systems operate through internal representations, not human-readable identity alone.
- Ghostmaxxing testability
- Ghostati can discuss representation shifts, but it does not expose or optimize internal DNN layers in the current browser pipeline.
- Limits
- This is not a physical-world or face-specific intervention. Its connection to Ghostati is conceptual unless the project adds model-internal representation testing.
DPatch: An Adversarial Patch Attack on Object Detectors
A black-box adversarial patch attack against object detectors such as Faster R-CNN and YOLO, relevant to the broader genealogy of physical adversarial patches.
- Demonstrated
- DPatch demonstrates that a small, location-independent adversarial patch can attack both bounding-box regression and object classification in object detectors, with transferability across detectors.
- Why it matters for Ghostmaxxing
- It is not face-specific, but it explains why localized graphic surfaces can disrupt detection pipelines, a core idea behind many physical-world adversarial designs.
- Ghostmaxxing testability
- Ghostati can draw face-localized patches, but DPatch targets object detectors and requires detector-specific optimization that Ghostati does not implement.
- Limits
- The attack target is object detection, not face recognition. Transfer to face analysis is conceptual unless a new face-specific optimization and evaluation are performed.
Liu et al., SafeAI 2019 / arXiv 2018 · paper available Canonical · DOI
ShapeShifter: Robust Physical Adversarial Attack on Faster R-CNN Object Detector
A physical adversarial attack on Faster R-CNN object detection that adapts robust transformation methods to real-world detector attacks.
- Demonstrated
- ShapeShifter shows that physical perturbations can be optimized to survive real-world transformations such as distance, angle, lighting, and camera limitations in an object-detection setting.
- Why it matters for Ghostmaxxing
- It is a foundational physical-world adversarial reference: not face-centered, but important for understanding robustness under real-world transformations.
- Ghostmaxxing testability
- Ghostati can borrow its concern with transformations, but cannot directly retest Faster R-CNN stop-sign attacks or autonomous-driving scenarios.
- Limits
- The target domain is object detection, not biometric recognition. Its lessons transfer as methodology, not as a direct Ghostati result.
Chen et al., ECML PKDD 2018 · paper available Canonical · DOI
Shadows can be Dangerous: Stealthy and Effective Physical-world Adversarial Attack by Natural Phenomenon
A physical-world adversarial attack that uses natural-looking shadows rather than stickers or conspicuous projected patterns, tested on traffic-sign recognition rather than face recognition.
- Demonstrated
- The paper demonstrates that optimized shadows can create stealthy black-box physical adversarial examples, with strong simulated and real-world attack results on traffic-sign datasets.
- Why it matters for Ghostmaxxing
- It is useful to Ghostati as a design reference for natural phenomena, lighting, and environmental perturbations, but it is not face-specific.
- Ghostmaxxing testability
- Ghostati can use this as a conceptual reference for light and shadow as adversarial surfaces, but cannot validate the traffic-sign attack or transfer it to face recognition without a new experiment.
- Limits
- The demonstrated target is traffic-sign recognition, not face detection or recognition. Any relevance to Ghostati requires cautious analogy, not direct transfer of the result.
Zhong et al., CVPR 2022 · code available Canonical · Code · DOI
Breaking certified defenses: Semantic adversarial examples with spoofed robustness certificates
A semantic adversarial-example paper that uses large but perceptually plausible perturbations to attack robust classifiers and spoof robustness certificates.
- Demonstrated
- The paper demonstrates a Shadow Attack that can cause certified classifiers to mislabel images while still producing a spoofed robustness certificate.
- Why it matters for Ghostmaxxing
- It is conceptually relevant because it frames adversarial design as a semantic, human-plausible transformation rather than only pixel noise, but it is not face- or makeup-specific.
- Ghostmaxxing testability
- Ghostati can borrow the idea of perceptually plausible visual transformations, but cannot retest certified robustness or the paper’s classifier/certificate setting.
- Limits
- The work is not face-specific and addresses certified image classifiers rather than browser face matching. Relevance to Ghostati is conceptual and should not be presented as evidence for face-camouflage effectiveness.
Ghiasi, Shafahi, and Goldstein, 2020 · paper available Canonical · DOI
Physical-World Optical Adversarial Attacks on 3D Face Recognition
A CVPR 2023 paper on structured-light optical attacks against 3D face recognition systems, moving anti-recognition intervention from visible surface patterns to depth reconstruction and projected perturbations.
- Demonstrated
- The paper demonstrates a structured-light attack that can affect point-cloud-based and depth-image-based 3D face recognition with fewer perturbations and resilience to random head movements.
- Why it matters for Ghostmaxxing
- It helps Ghostati explain that face recognition is not only 2D RGB matching: depth, structured light, and skin reflectance introduce a different attack surface.
- Ghostmaxxing testability
- Ghostati’s browser pipeline can discuss optical perturbations conceptually, but cannot reproduce structured-light 3D scanning, depth-image recognition, or point-cloud attacks.
- Limits
- The setup requires structured-light 3D recognition assumptions and specialized acquisition. It is not evidence that ordinary visible AR makeup affects 3D systems in the same way.
Li et al., CVPR 2023 · paper available Canonical · Paper · Code · arXiv
Human-Imperceptible Physical Adversarial Attack for NIR Face Recognition Models
A 2025 physical attack on near-infrared face recognition using infrared-absorbing ink and optimized patches. It is peripheral to Ghostati’s visible-makeup workflow, but important for understanding how anti-biometric interventions move toward sensors and spectra that humans cannot see.
- Demonstrated
- The paper demonstrates a black-box physical adversarial patch for NIR face recognition, using infrared-absorbing ink, skin-reflection modeling, and optimized patch placement to improve attack success in digital and physical domains.
- Why it matters for Ghostmaxxing
- It extends the anti-recognition design space beyond visible cosmetics into NIR-specific materials. Ghostati can use it as a conceptual reference for sensor-aware camouflage, but cannot directly reproduce NIR behavior with a normal browser webcam pipeline.
- Ghostmaxxing testability
- Ghostati can document the concept of localized face-region perturbations, but it cannot verify NIR absorption, NIR imaging, or infrared-specific recognition models without dedicated hardware and models.
- Limits
- The reported results are tied to NIR cameras, tested models, patch materials, subject set, and controlled acquisition conditions. Effectiveness against visible-light systems, production deployments, or newer NIR pipelines is not established by this reference.
Accessorize in the Dark: A Security Analysis of Near-Infrared Face Recognition
A security analysis of near-infrared face recognition that adapts adversarial accessories to NIR-based systems used in access-control and high-stakes settings.
- Demonstrated
- The work tests NIR-based face recognition against physically realizable adversarial accessories, reporting high physical attack success across defended and undefended models.
- Why it matters for Ghostmaxxing
- It is relevant because it shows that face-recognition fragility is not limited to visible-light cameras or RGB makeup. It helps Ghostati explain why different sensors require different camouflage strategies.
- Ghostmaxxing testability
- Ghostati can approximate the visible placement of a wearable accessory around the face, but cannot test NIR capture, NIR-specific perturbations, or defended NIR models in the browser.
- Limits
- The result depends on NIR capture assumptions, model set, accessory realization, and experimental protocol. A standard RGB webcam test in Ghostati would not confirm the NIR-specific claim.
Cohen and Sharif, ESORICS 2023 / LNCS 2024 · code available Canonical · Paper · Code
How to suggest a new entry.
Every possible reference should be read and transformed into the format of REFERENCES.json,
check out on github
(https://github.com/vecna/ghostati/blob/rebranding/ghostmaxxing/references/REFERENCES.json) how detailed
is.
Once you're sure it might suit us, and potentially we can even program a Ghostyle to retest it, please
open an issue or submit a pull request.