field note

Camera tamper detection explained

Camera tamper detection is catching a camera that is still online but no longer seeing its scene: covered, moved, sprayed, or defocused. How a fleet handles it.

2026-08-23

Camera tamper detection is noticing that a camera is still on the network but no longer seeing the scene it was installed to see. The lens is covered, the housing was turned, the glass was sprayed, or the image went so far out of focus that the view is gone. The device can still answer. The recording path can still be up. What you needed from that camera is not there.

An offline camera is a different failure. It is not reachable. The runbook for that is why security cameras go offline. Tamper is the failure a ping-only check will call healthy.

What tamper looks like on a real camera

Physical interference with the view is the event. A person walking through the frame is ordinary activity for the VMS. Motion, line-crossing, and loitering analytics fire on what is in front of a working camera. Tamper is the camera no longer being a working camera in the place you paid to cover.

Covered. A bag, a hand, a sticker, paint, or a hat left on a dome. Construction and painting are the honest version: someone bagged the camera on purpose and never took the bag off. The camera is powered. The stream is alive. The scene is a blur or a block of color.

Moved. The housing was knocked, the mount loosened, or someone pointed the camera at a wall, a ceiling, or a different door. A PTZ that left its home preset looks the same from a thumbnail: a sharp, healthy picture of the wrong place. The stream is fine. The coverage plan is not.

Sprayed or blinded. A substance on the glass, a light shoved into the lens, a laser. Daylight cameras also go dark-looking when IR reflects off a nearby wall or the inside of the bubble at night. That last case is a commissioning problem that presents as tamper, and it will keep presenting until the mount or the illuminator is fixed.

Defocused. The lens was twisted, the varifocal slipped after a bump, or focus was never locked at install. Fine detail is gone. A live-view thumbnail can still look “on,” which is why a person glancing at a grid will not catch it.

Axis, Bosch, and Hanwha cameras can raise a tamper alarm from the device when that function is enabled. That alarm is a useful signal. It is not a fleet program. It fires only if it was turned on, if the threshold matches the scene, and if something is listening when it fires. A camera that is powered down, isolated, or never configured will not send you a tamper event to ignore.

Firmware “tamper” is a different word. Signed-image and secure-boot language is about refusing a corrupted or wrong firmware file. This post is about the view.

Reachable is not healthy

Two checks produce three camera states. On the network: yes, yes, no. Scene matches the install: yes, no, cannot check. Those pairs are healthy, tamper, and offline. A reachability check reads only the first row and treats a tampered camera as up. two checks, three states healthy tamper offline on the network yes yes no scene matches the install yes no cannot check a reachability check treats both as up covered, moved, sprayed, defocused: the device answers, the view does not
A ping-only check reads the first row. Tamper lives on the second row, with the camera still answering.

That split is the same one camera health monitoring software has to pass: does the product tell reachable apart from healthy. A VMS camera-down icon does not. A switch port that still has PoE does not. A recorder that is still wrapping a stream does not, if the stream is a bag over a dome.

A current image is not enough either. The offline post treats a camera that cannot produce a fresh frame as down where it counts. Tamper is the next case: the camera can produce a fresh frame of the wrong scene. Proof that an image arrived is not proof that the coverage plan still holds.

The failure is quiet in the same way firmware drift and shared passwords are quiet. Nobody is staring at that pane. The gap shows up when someone needs the recording from the door that has been looking at a wall since Tuesday.

Why the camera’s own alarm is not enough

Device-side tamper is worth turning on. It is also noisy and incomplete.

Thresholds are scene-specific. A loading dock at dusk, a glass lobby, a camera that pans, a dome under a tree: each one false-alarms differently. Set the sensitivity for the quiet hallway and the dock screams all night. Set it for the dock and a bag over the hallway camera never trips. There is no fleet-wide number that is right.

Night and IR lie. IR bounce off a nearby wall, a spider web, rain on the bubble, a cleaner with a rag, a PTZ that left its preset. All of those can look like a covered or moved camera to a device alarm. All of them are also real reasons to go look, which is why you cannot auto-close them. A night operator who learns to ignore that camera has trained the fleet to miss the next bag.

If nothing is listening, the alarm died in the camera. Integrators find this during a truck roll: tamper was enabled in the web UI in 2019, the recorder was swapped, the event map was never rebuilt, and the camera has been shouting into an empty room. Enabling the detector is a camera setting. Getting the event to a person is a recording-path setting, and those two get separated every time a VMS, a server, or a site is replaced.

A powered-off or isolated camera will not report that it was bagged. Tamper after the device is already down is an offline problem first. You still want the physical check when it comes back, because bagging a camera and pulling power is a common pair. Relying on the camera to confess only works while the camera is up enough to confess.

A fleet program treats the device alarm as one input. It still has to notice a camera that is up, authenticated, and no longer looking at the commissioned view, including when the device alarm never fired.

The reference is the commissioned view

You cannot call a camera moved unless you know where it was supposed to look. The reference is the as-built: the coverage drawing, the home preset, the photograph from the day it was accepted. A sharp picture of a ceiling is tamper against that reference. Against “is there an image,” it is a healthy camera.

That is why a live-view grid is a weak tamper program. The grid proves something is producing pixels. It does not prove those pixels are the door, the dock, or the pharmacy the drawing named. A technician who “checks cameras” by scrolling a wall of thumbnails will catch a black frame and miss a 30-degree yaw.

Privacy masks and scene changes get mixed in here. A mask that was added after commissioning can look like a cover. A renovation that removed the thing the camera was aimed at looks like a move. Both are inventory problems: the installed view no longer matches the plan, and someone has to update one or the other. Until that happens, the camera is failing the job you think it is doing.

What to do with a tamper event

Handle it as a device-health incident with an owner. Video review does not repair a camera that is pointing at a wall.

  1. Confirm it is still reachable. If it is not, you are in the offline runbook, not this one.
  2. Confirm the view against what was commissioned, not against “is there an image.” A sharp picture of a ceiling is a tamper. A black frame can be a cover, a failed illuminator, or night with the IR cut in the wrong state. Those are different tickets.
  3. Keep stills from around the event. MentatNOC takes still snapshots in ordinary operation, and a tamper event retains them. That is evidence of the scene at the time, for the people who have to decide whether to roll a truck. It is not a substitute for the VMS recording.
  4. Do not clear it because the stream came back. A camera that was moved can sit in the new position forever, healthy as far as the recorder is concerned. Reaching “up” again is the failure mode, not the fix.
  5. Write down whether it was interference, weather, cleaning, a preset, or a commissioning miss. If you do not, the next event at that camera looks like the first, and the night operator learns to ignore it.

The same discipline as camera hardening applies: an inventory that matches the floor, a standard you can check, and a re-check that is not optional. A camera whose view no longer matches the coverage plan is a camera that failed the inventory, even if the serial number is still in the spreadsheet.

Doing this across 500 cameras

On one camera you open live view and you know in five seconds. Across a few hundred, nobody is opening live view. The VMS is green. Three cameras have been looking at a wall since the weekend. One was bagged for a renovation and never uncovered. One has a web across the bubble that the device alarm called tamper forty times and the night operator learned to ignore.

MentatNOC watches for a physical tamper event as a health state, next to device-down, and opens the integrator’s PSA ticket from that event, with evidence captured around it. It monitors device health, not video. The Monitor tier is where that alert lives; the rest of the action set is on the platform. The fastest way to see the distinction between down and tampered on a fleet shaped like yours is a live platform demo.