What the Study Found
- Detectors barely beat bare eyes: testers missed 58.8% of hidden devices with a gadget, against 66.7% by sight alone.
- Bluetooth-tracker finder apps missed just 21.6% of devices and flagged zero innocent objects as spies.
- Five signal-strength detectors performed statistically indistinguishably from each other, whatever their price.
- Freemium apps averaged 1.38 false alarms per search versus 0.47 for plainer detectors, leaving users second-guessing themselves.
It took a fake living room to prove something uncomfortable about a real safety product. Sofas, bookshelves, houseplants, a notice board, the ordinary clutter of somebody’s front room, built inside a UCL building. Hidden inside a clock, a USB charger, a picture frame, a plush toy and a plant pot: nine surveillance devices, six cameras and three Bluetooth trackers, streaming continuously to nowhere. Thirty-four people were handed one of nineteen commercial spy detectors and told to find them. A new study finds that what mattered was not whether the gadget could sense a hidden device, but whether it could tell a frightened, untrained person what to do next.
The devices at stake are not exotic. Cameras built into USB chargers, smoke alarms and teddy bears are sold openly on major marketplaces, marketed as home security or child-monitoring products. The people they end up watching are often intimate partners, tracked by an abuser exploiting exactly the everyday trust those objects are designed to inherit, against a backdrop of rising recorded stalking offences in England and Wales.
Spy-Camera Detectors often fail to meet user expectations
Against that market has grown a parallel one: handheld detectors and phone apps promising to sweep a room and flag anything transmitting. They read out signal strength, frequency bands, RF interference, the vocabulary of an engineer rather than someone checking their own home. A separate study of the same detector market, published in 2023, had already found most of these products all but useless in lab tests. The UCL-led team, publishing at the USENIX Symposium on Usable Privacy and Security, wanted to know whether that vocabulary actually helped anyone.
It mostly did not. Across 136 search rounds, one unaided and three tool-assisted per participant, testers missed 66.7% of devices searching by eye alone. Handed a detector, they still missed 58.8%. That is a real improvement, the kind that survives statistical correction, but not a large one: about one extra device found, out of nine, with a gadget in hand.
One category broke the pattern entirely. Smartphone apps built to hunt Bluetooth trackers such as Apple’s AirTag, the ones popularised by stalking scandals rather than spy-shop marketing, missed only 21.6% of devices and threw up no false alarms. Every other detector group, five different handheld units among them, performed statistically indistinguishably from each other regardless of price or build quality. Cheap and expensive alike missed roughly two-thirds of what was hidden. The researchers add a caveat of their own: those apps were also used more often in the final search round, once participants had grown more practiced, so some of the gap may be timing as well as design.
The gap was not about sensing. In a radio-frequency-shielded (RF-shielded) chamber, several of the losing detectors picked up a tracker’s Bluetooth signal from 100 centimetres away, proof the hardware worked under ideal conditions. Lead author Akhil Polamarasetty, a doctoral researcher at UCL’s Centre for Doctoral Training in Cybersecurity, put the distinction plainly: “If products are intended to improve people’s safety, they need to be designed around what a typical user actually needs.”
What the successful apps did differently was translate a signal into a named, findable object. Instead of a rising beep, they showed a list: this device, that device, tap to play a sound and follow it to the drawer it is hiding in. Participants who understood exactly what they were chasing verified it in seconds. Participants staring at a flickering LED, with no reference point for whether a change in reading meant they were closer or further away, gave up or guessed. Verification failed 70.2% of the time on those signal-strength units, against 3.8% on the tracker-finding apps, the sharpest split in the entire dataset.
When the Gadget Cries Wolf
False alarms turned out to carry their own cost, separate from missed devices entirely. The freemium phone apps in the study, cluttered with ads and noisy sensor readings, threw an average of 1.38 false positives per search, against 0.47 for the plainer handheld units. Participants described repeatedly rechecking a bookshelf that a detector had flagged, unable to rule the spot out, some later saying the inconsistency made them feel like the fault was their own rather than the device’s; that pattern of self-blame surfaced more often among women in the study than men, though the researchers are careful to note their sample cannot confirm that split statistically. A missed device did the opposite kind of damage: when nothing beeped, participants moved on, satisfied. The paper’s authors argue that the exact wording of a null result matters more than it sounds: a screen stating plainly that nothing was detected preserves caution, while one implying the room itself is safe does not, since a detector’s silence read as an all-clear does nothing to remove a camera and everything to make its owner feel like they already checked.
A Layer, Not a Solution
Senior author Leonie Tanczer, also at UCL Computer Science, located the responsibility upstream, in the products themselves: “Most technology is dual-use, and companies have a responsibility to think about how their products can be misused at the design stage rather than after the harms emerge.” Her broader point extends past detectors and toward the surveillance devices they are built to find, arguing that concealment is the entire feature being sold.
Even the best-performing tool in the study has a narrow ceiling. The tracker-finding apps only cover Bluetooth-broadcasting devices, three of the nine hidden in the trial; a Wi-Fi camera streaming footage never shows up on that scan at all, and a tracker with its speaker disabled by a perpetrator loses the exact feature that made it findable here. None of the nineteen tools tested offered a route to the two camera types that never announce themselves. The researchers frame their design fixes, list-based feedback, sound-triggered verification, softer language around uncertainty, as improvements to one layer of protection rather than a fix for the underlying market, sitting alongside rather than replacing the kind of dedicated tech-abuse support that UK domestic-abuse charities already provide. Full regulation of what is allowed to ship pre-disguised as an ordinary object sits outside what any app interface can solve.
What the study leaves open is what happens for the survivors it deliberately did not recruit. Its 34 testers, drawn from police officers, domestic-abuse advocates and members of the public rather than people currently living with surveillance, searched a mock room with time to spare and nothing genuinely at stake. Whether the same list-and-locate interface still helps under real fear, in a real home, with a real abuser controlling the router, is the next question the researchers have not yet been able to ask.
Reference
Polamarasetty, A., Tanczer, L., Costanza, E., & Chetty, K. (2026). Usability Determines Safety for At-Risk Users: Evaluating Hidden Device Detectors for Intimate Partner Surveillance. University College London. https://doi.org/10.5522/04/32660724
- Study type: Peer-reviewed conference paper, presented at the 22nd USENIX Symposium on Usable Privacy and Security (SOUPS 2026). Mixed-methods: within-subjects in-room search trials plus semi-structured interviews.
- Sample size: 34 participants; 19 detection tools across 8 interface groups; 9 hidden surveillance devices (6 cameras, 3 Bluetooth trackers); 136 total search observations.
- Population: UK-based proxy populations, including general public, domestic-abuse and tech-abuse advocates, technology-facilitated-abuse researchers, police officers and network-security experts. Current or former surveillance survivors were deliberately excluded to avoid retraumatisation.
- Duration: Fieldwork conducted April to May 2024; each participant completed four search rounds, roughly ten minutes each, followed by a 30 to 45 minute interview.
- Funding / conflicts of interest: UK EPSRC grant EP/S022503/1 (UCL Centre for Doctoral Training in Cybersecurity); devices and detectors funded by the UCL Faculty of Engineering Sciences and a UKRI Future Leaders Fellowship (MR/W009692/1). Authors state the views expressed are their own.
- Data availability: Not reported in the published paper or press materials.
- Preregistration: Not reported.
- Main limitation: The sample of 34 participants limited statistical power to detect smaller effects, and none were current or former surveillance survivors, limiting how far the results generalise to a real survivor’s lived experience.
FAQ
Is it true that a phone can find hidden spy cameras?
Only partly. A phone app built to hunt Bluetooth trackers can spot devices like Apple AirTags that broadcast a Bluetooth signal, and in this study those apps missed only 21.6% of hidden devices. Cameras that stream over Wi-Fi rather than Bluetooth never triggered that kind of app at all, so a clean scan is not proof a room is camera-free.
Why did the pricier detectors do no better than the cheap ones?
Because price bought build quality and extra lights, not a different way of telling a user what to do with the reading. All five signal-strength detectors in the study, expensive and basic alike, left people staring at a beep or a flashing light with no way to translate it into a location, so none of them helped more than the others.
Could a false alarm from a detector actually be harmful?
Yes, in a way that goes beyond wasted time. Participants who got repeated false alarms described anxiety spirals, rechecking the same spot without resolution, and some blamed their own competence rather than the device. For someone already living with the vigilance that surveillance can produce, that kind of ambiguous, unresolved alert compounds the strain rather than relieving it.
What is stopping detector makers from just fixing this?
Nothing technical, according to the researchers: the fix they describe is mostly about interface design, showing a named, locatable device rather than a raw signal reading, not a new sensor. What is harder to fix by design alone is the underlying market, since some devices, like Wi-Fi cameras and trackers with disabled speakers, resist this kind of interface improvement entirely and the researchers argue that curbing the sale of concealment-first products is the more durable answer.
Does this study reflect what survivors of surveillance actually experience?
Not directly. The researchers deliberately excluded people currently or formerly experiencing intimate partner surveillance, recruiting police officers, advocates and members of the public instead to avoid retraumatising anyone. That protects participants, but it also means the study cannot say how a real survivor, searching under genuine fear in their own home, would fare with the same tools.
Cite This Page

