What I Built
Iām building **
PhishGuard AI
** a phishing-awareness application inspired by a problem faced by a friend who occasionally receives suspicious emails, messages, and job or internship offers.
Phishing messages are becoming increasingly convincing. A fake internship opportunity, an urgent account verification request, or a message asking for an advance payment can easily deceive someone who isn't familiar with common cybersecurity warning signs.
I wanted to build something practical that could help my friend pause and evaluate suspicious messages before taking action.
With PhishGuard AI, users can paste an email, SMS, WhatsApp message, or job offer and receive a screening report highlighting potential phishing indicators, supporting evidence, and recommended next steps.
Some key features include:
- Message Analysis: Screen suspicious emails, texts, chat messages, and offers.
- Rule-Based Detection: Identify urgency, suspicious URLs, account threats, credential requests, and payment-related indicators.
- Evidence-Based Results: Show the parts of a message that triggered warnings.
- Privacy-Conscious Design: Message history is disabled by default, with optional browser-local history.
- Rules-Only Fallback: Basic detection is designed to remain available when the AI service is unavailable.
The project is being developed with the goal of making phishing awareness more accessible and understandable for everyday users.
Demo
The application includes a dashboard for submitting messages, viewing screening results, understanding suspicious indicators, and reviewing safety recommendations.
Live Demo: https://phish-guard-ai--ahmedwasi4407.replit.app/
Code
GitHub Repository: https://github.com/ahmedwasi946/PhishGuard-AI
The project is being developed as an open-source application.
How I Built It
Iām developing PhishGuard AI using Java and Spring Boot for the backend, alongside a lightweight frontend built with HTML, CSS, and JavaScript.
Technology stack:
- Java 21 ā Backend development
- Spring Boot ā REST API and application logic
- HTML, CSS, JavaScript ā Frontend
- Docker Compose ā Service orchestration
The intended architecture combines deterministic Java-based detection with contextual analysis from an open-weight language model.
One important design decision is to keep rule-based detection independent of AI availability. AI is intended to enhance the analysis rather than become a single point of failure.
I also designed URL inspection to be passive: submitted links are not automatically opened.
Why Does Open Innovation Matter?
Open innovation is particularly important for a cybersecurity application because messages submitted for analysis can contain sensitive personal information.
1. Greater control over data processing
Self-hosted inference can provide greater control over where submitted messages are processed, depending on the deployment environment.
2. Freedom to experiment
Open-weight models allow developers to experiment with prompts, compare models, and explore fine-tuning for specific cybersecurity use cases.
3. Flexibility and independence
A modular architecture makes it possible to experiment with different models while retaining deterministic detection capabilities as an independent fallback.
For me, open innovation is about understanding the technology, having the freedom to modify it, and exploring how it can solve real-world problems.
This project is being built for a friend, with the goal of making everyday digital communication a little safer. š







Top comments (0)