✦ AI for Cybersecurity

Catch the scam before
it catches you

ScamShield reads any SMS in English, Hindi or Hinglish, then returns a verdict, the exact signals behind it, and word-level attribution β€” so you know why it flagged a message, not just that it did.

Open full demo β†—
97.5%Test accuracy
0.46%False positives
100Languages (XLM-R)
30k+Training messages
🧠

Reads the message

XLM-RoBERTa encodes the text in 100 languages, so Hindi and Hinglish scams are caught in their own language β€” not just English.

πŸ”—

Checks every link

Nine URL signals β€” suspicious TLDs, shorteners, raw IP hosts, plain HTTP β€” backed by a whitelist of 100+ legitimate domains.

πŸ“Š

Explains itself

SHAP attribution shows which words pushed the score toward scam and which pushed it toward legitimate. No black box.

The problem it solves

Why SMS phishing is hard to catch

  • Messages are tiny β€” often under 160 characters of context.
  • Attackers rewrite wording constantly to slip past filters.
  • Legitimate bank OTPs and recharge alerts look like spam.
  • Hundreds of millions of users still get fooled in multiple languages.

How ScamShield handles it

  • Multilingual encoder trained on 100 languages, fine-tuned on 30k+ messages.
  • Decision threshold raised to 0.55 to stop flagging Indian bank SMS.
  • Synthetic legitimate transactional SMS added to correct class imbalance.
  • Every prediction is attributable β€” word-level, not a bare score.

Scanner

Runs the real model. First scan can take a few seconds while the model wakes up.

Paste a message
πŸ›‘

Scan a message to see the verdict, the signals behind it, and word-level attribution.

Mobile app

The same pipeline the Android build runs β€” here against a seeded inbox, since browsers can't read your messages.

πŸ›‘ ScamShield
InboxScan
β€”Scanned
β€”Flagged
β€”Safe
What the Android app adds
  • Real inbox monitoring β€” polls the Android SMS store every 15s and scans new messages automatically.
  • Background scanning β€” keeps checking when the app is closed and raises a local notification on a threat.
  • Encrypted channel β€” every message is encrypted with AES-256-CBC before it leaves the device.
  • Risk inbox β€” colour-coded badges across the whole conversation list.
Get the build

The Android APK talks to the same API this page uses. Install it on a device, then set the API URL in Settings to https://existedyear-scamshield.hf.space β€” no rebuild needed.

Download APK (74 MB)

Android 7+ Β· requires SMS permission Β· enable β€œinstall unknown apps” to sideload

How it works

XLM-RoBERTa with hand-crafted URL features, late-fused into one classifier.

Pipeline
SMSEnglish Β· Hindi Β· Hinglish
β†’
XLM-RoBERTa768-d CLS embedding
β†’
17 signals9 URL + 8 text
β†’
Fuse β†’ 832-dconcat, project to 64
β†’
Sigmoidthreshold 0.55
URL signals (9)
has_urlnum_urls has_httphas_https suspicious_tldmax_url_len has_ip_urlhas_shortened_url has_legit_domain
Text signals (8)
num_charsnum_words pct_upperpct_digits num_specialurgency_count has_phonehas_currency
Measured on the held-out test split
Accuracy97.54%
Spam F10.94
False positive rate0.46%
Hindi F10.9845
ROC-AUC0.9999
Adversarial F1 drop≀ 0.01
Stack
XLM-RoBERTa-base270M multilingual encoder
PyTorchtraining + inference
SHAPword-level attribution
Gradio + FlaskAPI and demo surface
React NativeAndroid client, AES-256-CBC
tldextractdomain and TLD parsing
Built for

ScamShield is for

  • Anyone receiving bank OTPs, prize notices or "verify your account" texts.
  • Caregivers helping less technical family members stay safe.
  • Researchers studying multilingual social-engineering patterns.

Not a replacement for

  • Judging intent β€” it scores patterns, it does not read intent.
  • Verified sender identity β€” check the number, not just the text.
  • Reporting β€” forward suspicious messages to your bank and the authorities.