Every city block in America is quietly collecting a database on your car. License plate reader cameras, the kind mounted on street poles and traffic signals, log where you drive, when you drive there, and what your car looks like, all without you ever knowing it happened. So a team from Donut decided to test a simple question in one of the most heavily monitored cities in the country: could you build a car these cameras genuinely couldn’t see?
The target was a Flock Falcon, the most widely deployed automated license plate reader on the market. These cameras don’t just photograph a plate. They generate an AI confidence score for everything they see, and once that score crosses 75 percent certainty that it’s looking at a vehicle, the system logs the car, its color, its dents, even its bumper stickers, into a searchable database. Drop that confidence score below the threshold, and in theory, the car simply doesn’t register at all. That was the entire experiment: take an ordinary white Toyota Yaris and find a way to make an AI system decide it wasn’t looking at a car.
Getting access to one of these cameras wasn’t something you could just order online, which is where cybersecurity expert Bill came in. He arrived with an actual Flock Falcon unit, a laptop, and a custom interface built to display exactly what the camera’s AI was seeing in real time, live confidence scores included.
Why this actually matters to anyone
Before touching a single tool, the team brought in Ben Jordan, a security researcher who has spent considerable time investigating Flock’s spread across the country, to explain why any of this should matter to someone with nothing to hide. His answer cut straight past the usual privacy platitudes. Anyone who says they have nothing to hide, he argued, has simply never been stalked, never been wrongly accused of a crime, never had their identity or credit card stolen. Mass license plate tracking doesn’t just watch criminals. It hands enormous surveillance power to anyone with database access, including, as Jordan pointed out, police officers who have used the system to track ex-partners.
That risk isn’t hypothetical. Jordan cited a recent case involving a journalist at The Drive, whose review car was mistakenly flagged as stolen by a Flock camera, leading to him being tracked for days and eventually detained in a parking lot over an error the system itself had made. Beyond the privacy concerns, there’s also a financial one: the cameras are typically funded by local tax dollars, meaning residents are often paying for the exact surveillance infrastructure they might not want in their own neighborhoods.
The easy fixes don’t work
Before building anything custom, the team tested the products the internet insists actually work: a clear anti-photo license plate cover and a spray marketed as a photo blocker. Neither survived contact with an infrared-modified camera. If anything, the spray made the plate more visible, since the reflective background blew out under IR light while the plate’s lettering stayed sharp and legible, the opposite of the intended effect. Even setting aside that these products are illegal to use on a plate in the first place, they simply don’t do what they claim.
They also addressed the laser pointer theory that circulates regularly on social media, the idea that shining a high-powered laser into a Flock sensor can permanently destroy it. According to Jordan, any laser a consumer can legally buy isn’t remotely powerful enough to do meaningful damage. And even if it worked, destroying a camera only costs a city more tax money to replace it, which ultimately benefits the company selling the cameras rather than the person trying to avoid being tracked.
Building a car the AI couldn’t parse
The real experiment centered on adversarial noise, a technique built around exploiting how differently AI actually “sees” compared to a person. A human recognizes a face by its eyes, hair, and general shape. A vision model is instead hunting for specific mathematical patterns, measurements and relationships a person could never consciously describe. Feed the model enough visual noise shaped to disrupt those calculations, and it can lose confidence entirely, discarding the object instead of flagging it.
Bill had already applied similar logic to human detection systems using printed patterns on clothing, and the team wanted to know whether the same principle could work on an entire vehicle. Ahead of the shoot, Bill spent roughly 48 hours of dual-GPU compute time generating a custom, repeating noise pattern specifically fitted to the shape of their Toyota Yaris.
Wrapping the car in that pattern turned into an overnight job, with crew member Max finishing the install solo around 11 p.m. The first passes past the camera were only a partial success. The Yaris’s confidence score dropped noticeably compared to an unwrapped control car, but it still read above the 75 percent threshold, mostly because the exposed glass windows and wheels gave the AI enough recognizable shape to still flag it as a vehicle.
The fix turned out to be more wrap, not a better pattern. Once the team extended the vinyl over the side and rear windows, eliminating the reflective glass the AI had been keying on, the results flipped completely. The Yaris passed the camera reading no vehicle detected at all, and repeat runs in different lighting confirmed it wasn’t a fluke. Even a slow victory lap directly under the sensor kept the car essentially invisible to the system, right up until it passed almost directly beneath the lens.
A win most people can’t replicate
The obvious catch is that not everyone has access to a custom adversarial pattern, 48 hours of GPU rendering time, and a professional hacker to design it. For anyone without those resources, Jordan’s advice was considerably less exotic than a Yaris covered in mathematically engineered noise: show up to city council meetings, talk to neighbors, and push back through the same local political channels that approved these camera networks in the first place. It’s a far less flashy solution than a car that vanishes from AI detection, but according to Jordan, it’s also the one actually available to most people who’d rather not be logged every time they drive to the grocery store.
More from Fast Lane Only
- Unboxing the WWII Jeep in a Crate
- 15 rare Chevys collectors are quietly buying
- 10 underrated V8s still worth hunting down
- Police notice this before you even roll window down
*Research for this article included AI assistance, with all final content reviewed by human editors.





