Comment by CircuitSeuss
There is at least one attempt [0] of input manipulation I am aware of, but it was several years ago, unproven, and I have to assume that input data manipulation vulnerabilities are unlikely to be present. If a new destructive attack could be found by visual data input, mass simultaneous deployment would be the most effective use of it, the logistical issues of which are a substantial barrier to efficacy.Changing stickers or vehicle color would have little effect since they would all be read normally: you change your clothes daily but that does not have any impact on the database itself or the cameras. Swapping or covering plates is illegal, and even things like ghost plates [1] are just misdirection and would do nothing to combat the surveillance system itself.
Wrapping tour vehicle in a custom tailored adversarial pattern [2] may work, but this is mostly unproven technology in the field, and it would only work until the failures it caused became part of the training set, at which point you would need to re-wrap tour vehicle. It would also be a lot of effort and expense to do something that wouldn't make any impact on the surveillance systems themselves (by definition the best case scenario here is that object detection does not work on the wrapped vehicle, but it could still be recorded and you would not be doing anything to combat the surveillance itself).
Ultimately, our best bet is to start with the end goal: stop the data from being collected in the first place, don’t just try to hide from it. Social and political campaigning is probably the most effective path currently. Map your neighborhood on deflock.me, put flyers on your local streets, talk to your neighbors, attend city council meetings, and call your reps incessantly. Change the incentives… If you are independently wealthy, offer your county or PD a donation (via their PAC or a grant) in exchange for signing an agreement for X years to not use these technologies. If you work in governance, tie funding to privacy agreements. Make individual donations to groups like the Ludlow Institute or EFF, or ask them about grant funding for your projects. If we are able to pass better privacy laws, it’s possible that a private right of action would make it prohibitively costly for private companies to create programs like this which mass infringe on personal rights.
Some individuals have taken to the more expedient solution of direct action, physically disabling cameras with spray foam, tin snips, etc for a more expedient solution (vandalism is obviously illegal, don’t do crimes, that would be bad and naughty).
[0] https://www.ioactive.com/sql-injection-in-the-wild/ [1] https://www.bbc.com/news/articles/cq9860162dj2o [2] https://sandbox.norecognition.org/