<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Pranto Bala</title>
    <description>The latest articles on DEV Community by Pranto Bala (@pranto_bala_).</description>
    <link>https://dev.to/pranto_bala_</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4066426%2Ffe4b5ef6-5bc6-406f-aa20-5c2508c7b193.jpg</url>
      <title>DEV Community: Pranto Bala</title>
      <link>https://dev.to/pranto_bala_</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/pranto_bala_"/>
    <language>en</language>
    <item>
      <title>FriendShield: I Built a Scam Shield for My Roommate Joy</title>
      <dc:creator>Pranto Bala</dc:creator>
      <pubDate>Sun, 04 Oct 2026 17:48:07 +0000</pubDate>
      <link>https://dev.to/pranto_bala_/friendshield-i-built-a-scam-shield-for-my-roommate-joy-1fml</link>
      <guid>https://dev.to/pranto_bala_/friendshield-i-built-a-scam-shield-for-my-roommate-joy-1fml</guid>
      <description>&lt;p&gt;&lt;em&gt;This is a submission for the &lt;a href="https://dev.to/challenges/hacktoberfest-weekend-2026-10-01"&gt;Hacktoberfest Weekend Challenge: Build for a Friend&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  What I Built
&lt;/h2&gt;

&lt;p&gt;Last week, my roommate &lt;strong&gt;Joy&lt;/strong&gt; handed me his phone and asked one question:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“Bhai, is this real?”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;The message looked urgent:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“Your bKash account will be closed within 24 hours. Verify immediately: bkash-verify.xyz”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;It used a trusted brand name. It was written in Bangla. It created an artificial deadline. And on a small smartphone screen, the link looked believable enough to make someone pause in panic.&lt;/p&gt;

&lt;p&gt;But it was not from bKash.&lt;/p&gt;

&lt;p&gt;It was a phishing message designed to exploit urgency, steal credentials, and drain mobile-wallet funds.&lt;/p&gt;

&lt;p&gt;That moment made me realize the core problem: &lt;strong&gt;people do not need another abstract browser warning. They need a clear, definitive answer before they click.&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Is this message real or fake?&lt;/li&gt;
&lt;li&gt;Why is this specific link suspicious?&lt;/li&gt;
&lt;li&gt;What should I do right now?&lt;/li&gt;
&lt;li&gt;How can I explain the danger to a parent or friend who does not understand cybersecurity jargon?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;So I built &lt;strong&gt;Friend Shield&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Friend Shield is an open-source, multilingual scam and phishing detection assistant for suspicious &lt;strong&gt;messages, URLs, QR codes, and screenshots&lt;/strong&gt;. A user can paste a message, upload a screenshot (&lt;code&gt;Ctrl + V&lt;/code&gt;), or a QR code. Friend Shield extracts links, safely unshortens redirects, analyzes threats through local ONNX machine learning, deterministic security rules, and Google Safe Browsing, then explains the risk in &lt;strong&gt;Bangla, English, or Banglish&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;In Bangladesh, attackers frequently impersonate &lt;strong&gt;mobile financial services (MFS)&lt;/strong&gt; like bKash and Nagad. While these local scams are a primary use case, the underlying issue is global: attackers leverage urgency, trusted brand names, and deceptive domains to exploit everyday people.&lt;/p&gt;

&lt;p&gt;Friend Shield does not simply output a cryptic error code or a generic label. It turns concrete evidence into actionable advice:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“This link is pretending to be Nagad, but it is not the official domain. Do not enter your PIN or OTP.”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;&lt;strong&gt;The language model explains the evidence in human terms, but it does not make the security decision.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Friend Shield is the calm second opinion I wanted Joy to have before urgency or fear makes the decision for him.&lt;/p&gt;

&lt;h3&gt;
  
  
  Friend Shield’s analysis
&lt;/h3&gt;

&lt;p&gt;Friend Shield extracts the suspicious link, evaluates multi-layer evidence, and gives clear safety advice in the user’s preferred language.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0ko7ky87h4a1orzld1sr.gif" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0ko7ky87h4a1orzld1sr.gif" alt="Friend Shield Progressive Triage &amp;amp; Gemma Explanation Demo" width="560" height="847"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Live demonstration of Friend Shield’s deterministic triage providing an immediate risk verdict, SEMI psychological score, and containment advice, followed by an asynchronous upgrade with open-weight Gemma’s empathetic reasoning.&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Demo
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Live Web Application:&lt;/strong&gt; &lt;a href="https://friend-shield.onrender.com/" rel="noopener noreferrer"&gt;Friend Shield on Render&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Source Code Repository:&lt;/strong&gt; &lt;a href="https://github.com/Pranto210102/friend-shield" rel="noopener noreferrer"&gt;Friend Shield on GitHub&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Try this sample scam message in the live app:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;অভিনন্দন! আপনি নগদ ৫,০০০ টাকা জিতেছেন। এখনই ক্লেইম করুন:
http://nagad-cash-bonus.site/claim
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;


&lt;p&gt;Friend Shield flags the fake Nagad domain, identifies the unencrypted HTTP connection, detects financial bait and urgency, and explains the risk in plain Bangla.&lt;/p&gt;
&lt;h2&gt;
  
  
  Code
&lt;/h2&gt;


&lt;div class="ltag-github-readme-tag"&gt;
  &lt;div class="readme-overview"&gt;
    &lt;h2&gt;
      &lt;img src="https://assets.dev.to/assets/github-logo-5a155e1f9a670af7944dd5e12375bc76ed542ea80224905ecaf878b9157cdefc.svg" alt="GitHub logo"&gt;
      &lt;a href="https://github.com/Pranto210102" rel="noopener noreferrer"&gt;
        Pranto210102
      &lt;/a&gt; / &lt;a href="https://github.com/Pranto210102/friend-shield" rel="noopener noreferrer"&gt;
        friend-shield
      &lt;/a&gt;
    &lt;/h2&gt;
    &lt;h3&gt;
      
    &lt;/h3&gt;
  &lt;/div&gt;
  &lt;div class="ltag-github-body"&gt;
    
&lt;div id="readme" class="md"&gt;&lt;div class="markdown-heading"&gt;
&lt;h1 class="heading-element"&gt;🛡️ Friend Shield&lt;/h1&gt;
&lt;/div&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Defense-in-Depth Phishing &amp;amp; Scam Detection Engine with In-Process ONNX ML Inference, Anti-SSRF Redirect Expansion, Google Safe Browsing Reputation Checks, and Open-Weight AI Explanations.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;&lt;a href="https://nodejs.org/" rel="nofollow noopener noreferrer"&gt;&lt;img src="https://camo.githubusercontent.com/cd63694f29006f4ba1c6d8aa5617afd48adec62ec7b33bc1c2a8b1948a77041a/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f4e6f64652e6a732d7632302b2d677265656e2e737667" alt="Node.js"&gt;&lt;/a&gt;
&lt;a href="https://expressjs.com/" rel="nofollow noopener noreferrer"&gt;&lt;img src="https://camo.githubusercontent.com/3ab44afa56ac644249bf9f0335f5a5ca7236881c402c32449b26075dc543efdf/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f457870726573732d76352e322d626c61636b2e737667" alt="Express"&gt;&lt;/a&gt;
&lt;a href="https://onnxruntime.ai/" rel="nofollow noopener noreferrer"&gt;&lt;img src="https://camo.githubusercontent.com/8de11b2a209920ba634ab696e4ff4e26aa7cb618b29e38ec3d0295445ad482e5/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f4f4e4e585f52756e74696d652d76312e33302d626c75652e737667" alt="ONNX Runtime"&gt;&lt;/a&gt;
&lt;a href="https://scikit-learn.org/" rel="nofollow noopener noreferrer"&gt;&lt;img src="https://camo.githubusercontent.com/0303722731342a08efa330650a2772914ab73f1910206bb4cd24c4374d10a0f7/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f5363696b69742d2d4c6561726e2d76312e392d6f72616e67652e737667" alt="Scikit-Learn"&gt;&lt;/a&gt;
&lt;a href="https://developers.google.com/safe-browsing" rel="nofollow noopener noreferrer"&gt;&lt;img src="https://camo.githubusercontent.com/137c71cf62e8e5870956e1ab6369f6d9bfd535be15f94d3f3dde55522c884fe4/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f476f6f676c655f536166655f42726f7773696e672d76342d7265642e737667" alt="Google Safe Browsing"&gt;&lt;/a&gt;
&lt;a href="https://ai.google.dev/gemma" rel="nofollow noopener noreferrer"&gt;&lt;img src="https://camo.githubusercontent.com/8e0cb809d61cc91ea1314b2942b4a4e2af223a94495f27920e4d45476dacb5b1/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f4f70656e2d2d5765696768745f41492d476f6f676c655f47656d6d615f345f28333142292d626c756576696f6c65742e737667" alt="Gemma 4 31B"&gt;&lt;/a&gt;
&lt;a href="https://hacktoberfest.com/" rel="nofollow noopener noreferrer"&gt;&lt;img src="https://camo.githubusercontent.com/97e33bf0284e9704bb44f6a3c5c1f0bca81e06d21ed7c50e660a92f8748f0eac/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f4861636b746f626572666573742d323032362d6666363962342e737667" alt="Hacktoberfest"&gt;&lt;/a&gt;
&lt;a href="https://github.com/Pranto210102/friend-shield/LICENSE" rel="noopener noreferrer"&gt;&lt;img src="https://camo.githubusercontent.com/fdf2982b9f5d7489dcf44570e714e3a15fce6253e0cc6b5aa61a075aac2ff71b/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f4c6963656e73652d4d49542d79656c6c6f772e737667" alt="License: MIT"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;div class="markdown-heading"&gt;
&lt;h2 class="heading-element"&gt;🤝 The Friend Behind the Idea (Hacktoberfest: Build for a Friend)&lt;/h2&gt;
&lt;/div&gt;
&lt;p&gt;Last week, my roommate &lt;strong&gt;Joy&lt;/strong&gt; handed me his phone and asked one question:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;“Bhai, is this real?”&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;The message looked urgent:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;“Your bKash account will be closed within 24 hours. Verify immediately: bkash-verify.xyz”&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;It used a trusted brand name. It was written in Bangla. It created a deadline. And on a small phone screen, the link looked believable enough to make someone pause. But it was not from bKash—it was a phishing message designed to create panic, steal credentials, and compromise his wallet.&lt;/p&gt;
&lt;p&gt;That moment made me realize the real problem: &lt;strong&gt;people do not need another technical warning. They need a clear, empathetic answer before they click.&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;The Target Friend&lt;/strong&gt;: Roommates, family…&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
  &lt;/div&gt;
  &lt;div class="gh-btn-container"&gt;&lt;a class="gh-btn" href="https://github.com/Pranto210102/friend-shield" rel="noopener noreferrer"&gt;View on GitHub&lt;/a&gt;&lt;/div&gt;
&lt;/div&gt;


&lt;p&gt;The complete open-source codebase is hosted on GitHub: &lt;a href="https://github.com/Pranto210102/friend-shield" rel="noopener noreferrer"&gt;Friend Shield on GitHub&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;The system consists of three main components:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Node.js &amp;amp; Express API Backend:&lt;/strong&gt; URL extraction, Anti-SSRF redirect expansion, Safe Browsing lookup, in-process ONNX inference, deterministic brand rules, and Gemma explainer coordination.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Modern Responsive Frontend:&lt;/strong&gt; Lightweight web UI supporting text paste, clipboard screenshot OCR, in-browser QR scanning, and multilingual localization.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Python Training Pipeline:&lt;/strong&gt; 17-point feature extraction, Scikit-Learn Random Forest training on 149,900 balanced URLs, domain-disjoint validation, and ONNX export.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;For the complete API contract, evaluation methodology, and latency benchmarks, check out the &lt;a href="https://github.com/Pranto210102/friend-shield#readme" rel="noopener noreferrer"&gt;project README on GitHub&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  How I Built It
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Why one warning is not enough
&lt;/h3&gt;

&lt;p&gt;A scam link can defeat a single detection layer in several ways:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Attack technique&lt;/th&gt;
&lt;th&gt;Why one layer fails&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Newly registered phishing domain&lt;/td&gt;
&lt;td&gt;It does not yet appear in global reputation blocklists&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;URL shortener&lt;/td&gt;
&lt;td&gt;The destination is masked behind a redirect&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Fake brand domain&lt;/td&gt;
&lt;td&gt;
&lt;code&gt;nagad-cash-bonus.site&lt;/code&gt; contains “Nagad,” but is not official&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Emotional pressure&lt;/td&gt;
&lt;td&gt;“Verify now” pushes users to act before thinking&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Technical browser warnings&lt;/td&gt;
&lt;td&gt;“Punycode spoofing” does not help an anxious user&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Friend Shield uses &lt;strong&gt;defense in depth&lt;/strong&gt;: multiple independent checks produce evidence before the system issues a final verdict.&lt;br&gt;
&lt;/p&gt;

&lt;pre data-lang="mermaid"&gt;&lt;code&gt;flowchart TD
    A["Raw Message / Screenshot / QR"] --&amp;gt; B["Delimiter-Aware Link &amp;amp; OCR Extraction"]
    B --&amp;gt; C["Anti-SSRF Safe Redirect Unshortening"]
    C --&amp;gt; D["Parallel Threat Intelligence"]
    D --&amp;gt; D1["17-Point Feature Extraction + ONNX ML Inference"]
    D --&amp;gt; D2["Deterministic Rules Engine (MFS Brand &amp;amp; Raw IP)"]
    D --&amp;gt; D3["Google Safe Browsing v4 Reputation Lookup"]
    D --&amp;gt; D4["Social Engineering Manipulation Index (SEMI)"]
    D1 --&amp;gt; E["Uncertainty-Aware Decision &amp;amp; Abstention Policy"]
    D2 --&amp;gt; E
    D3 --&amp;gt; E
    D4 --&amp;gt; E
    E --&amp;gt; F["Open-Weight AI Safety Explainer (Google Gemma / Fallback)"]
    F --&amp;gt; G["Actionable Advice (Bangla, English, Banglish)"]&lt;/code&gt;&lt;/pre&gt;



&lt;h3&gt;
  
  
  Local ML inference with ONNX
&lt;/h3&gt;

&lt;p&gt;I trained a Random Forest classifier in Python using a balanced dataset of 149,900 URLs from the Kaggle Malicious URLs dataset. After domain-level deduplication and strict domain-disjoint splitting, the model was evaluated on 29,980 unseen test URLs:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Metric&lt;/th&gt;
&lt;th&gt;Result&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Accuracy&lt;/td&gt;
&lt;td&gt;86.19%&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Malicious Precision&lt;/td&gt;
&lt;td&gt;87.59%&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Malicious Recall&lt;/td&gt;
&lt;td&gt;84.33%&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Malicious F1-Score&lt;/td&gt;
&lt;td&gt;85.93%&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ONNX Model Size&lt;/td&gt;
&lt;td&gt;12 MB&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;The model runs in-process inside Node.js via ONNX Runtime without requiring a secondary Python microservice.&lt;/p&gt;

&lt;p&gt;Because statistical classifiers can be uncertain on novel domains, Friend Shield enforces an explicit abstention policy:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;🔴 &lt;strong&gt;HIGH_RISK:&lt;/strong&gt; Confirmed threat signals or critical structural hazards.&lt;/li&gt;
&lt;li&gt;🟠 &lt;strong&gt;SUSPICIOUS:&lt;/strong&gt; High statistical ML risk ($P \ge 0.85$).&lt;/li&gt;
&lt;li&gt;🟡 &lt;strong&gt;NEEDS_REVIEW:&lt;/strong&gt; Model abstention zone ($0.40 \le P &amp;lt; 0.85$) or cautionary signals.&lt;/li&gt;
&lt;li&gt;🟢 &lt;strong&gt;NO_KNOWN_THREAT:&lt;/strong&gt; No threat indicators detected.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;code&gt;NO_KNOWN_THREAT&lt;/code&gt; is an evidence-grounded assessment, not an absolute guarantee of safety.&lt;/p&gt;

&lt;h3&gt;
  
  
  Protecting users from hidden redirects
&lt;/h3&gt;

&lt;p&gt;Scammers routinely hide destinations behind URL shorteners. Friend Shield expands redirects hop by hop, but with strict &lt;strong&gt;Anti-SSRF protection&lt;/strong&gt;:&lt;/p&gt;

&lt;p&gt;Before following each hop, the engine resolves DNS records and blocks private subnets (&lt;code&gt;10.0.0.0/8&lt;/code&gt;, &lt;code&gt;192.168.0.0/16&lt;/code&gt;), loopback (&lt;code&gt;127.0.0.1&lt;/code&gt;), and cloud-metadata endpoints (&lt;code&gt;169.254.169.254&lt;/code&gt;). It cancels response body streams and limits chains to 5 hops to prevent denial-of-service loops.&lt;/p&gt;

&lt;h3&gt;
  
  
  Detecting scam psychology with SEMI
&lt;/h3&gt;

&lt;p&gt;Scam messages rely on predictable emotional manipulation. Friend Shield computes a &lt;strong&gt;Social Engineering Manipulation Index (SEMI)&lt;/strong&gt; measuring four psychological vectors:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Urgency &amp;amp; Panic&lt;/strong&gt; (e.g., “account will be closed in 24 hours”)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Financial Bait &amp;amp; Greed&lt;/strong&gt; (e.g., “you won 5,000 taka bonus”)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Authority Impersonation&lt;/strong&gt; (e.g., “official verification team”)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Credential Coercion&lt;/strong&gt; (e.g., “enter your PIN/OTP immediately”)&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;SEMI does not replace URL analysis; it helps the user understand &lt;em&gt;why&lt;/em&gt; the message is trying to manipulate them.&lt;/p&gt;

&lt;h3&gt;
  
  
  Gemma: fast, evidence-grounded progressive explanations
&lt;/h3&gt;

&lt;p&gt;This is where &lt;strong&gt;Gemma&lt;/strong&gt;, Google’s open-weight model, becomes central to the user experience.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Friend Shield does not ask Gemma, “Is this link safe?”&lt;/strong&gt; An LLM should never make an ungrounded security decision.&lt;/p&gt;

&lt;p&gt;Instead, Friend Shield implements a &lt;strong&gt;Progressive Safety Architecture&lt;/strong&gt;:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Instant Deterministic Triage (&amp;lt; 500 ms):&lt;/strong&gt; The pipeline first returns an immediate risk verdict, SEMI psychological score, and containment advice using ONNX ML, deterministic rules, and Safe Browsing. The deterministic triage returns in under 500 ms so the user never waits on an AI queue to know whether a link is dangerous.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Asynchronous Gemma Deep Explanation:&lt;/strong&gt; While the user reads the initial triage, Friend Shield requests a detailed Gemma explanation in the background. Gemma receives verified structured evidence (domain mismatch, HTTP protocol, SEMI vectors, ML score) and translates it into calm, empathetic guidance:
&lt;/li&gt;
&lt;/ol&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;এই লিংকে ক্লিক করবেন না। এটি নগদের অফিসিয়াল ডোমেইন নয়।
আপনার PIN, OTP বা পাসওয়ার্ড কাউকে দেবেন না।
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Friend Shield provides three parallel explanation modes:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Bangla&lt;/strong&gt; for native-language clarity&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;English&lt;/strong&gt; for broad accessibility&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Banglish&lt;/strong&gt; (Bengali written in Latin alphabet) for how users naturally type on smartphones&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;All output is validated against a strict JSON schema. If the model is slow or unreachable, the user already has the instant deterministic explanation on screen.&lt;/p&gt;

&lt;h3&gt;
  
  
  Why cloud Gemma for mobile, local Gemma for privacy
&lt;/h3&gt;

&lt;p&gt;Friend Shield supports both deployment modes:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;For the deployed web app&lt;/strong&gt;, Friend Shield connects to Google AI Studio's hosted Gemma endpoint (&lt;code&gt;gemma-4-26b-a4b-it&lt;/code&gt;). A person checking a suspicious SMS on a smartphone should not need to download a multi-gigabyte model or own high-end hardware before receiving help.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;For privacy-sensitive users&lt;/strong&gt;, Friend Shield supports local inference through Ollama (&lt;code&gt;ollama run gemma2:2b&lt;/code&gt;). In that mode, sensitive messages and Gemma explanations remain entirely on the user’s own machine without sending message content to an external service.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;In both modes, Gemma receives only precomputed evidence. It never decides whether a link is safe.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why Open Innovation Matters
&lt;/h2&gt;

&lt;p&gt;Friend Shield is built for users who should not be forced to send private messages to a closed proprietary service. Open innovation matters here for four reasons:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Privacy &amp;amp; Data Sovereignty:&lt;/strong&gt; In local Ollama mode, message analysis and Gemma explanation can run entirely on the user’s own machine without sending message content to an external service.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Auditability &amp;amp; Transparency:&lt;/strong&gt; Verdicts are explainable. Users can inspect the extracted URL, redirect hops, ML score, rule triggers, and Safe Browsing results.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Cultural &amp;amp; Regional Localization:&lt;/strong&gt; Commercial security tools often overlook non-English attacks. Friend Shield natively protects regional MFS brands (bKash, Nagad) and understands Bangla/Banglish scam syntax.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Resilience &amp;amp; No Vendor Lock-in:&lt;/strong&gt; The core pipeline runs on open-weight models (ONNX Runtime and Google Gemma). Deterministic fallbacks keep the core safety workflow usable if a cloud endpoint is unavailable.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  Prize Categories
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Best Use of Render
&lt;/h3&gt;

&lt;p&gt;Friend Shield is deployed in production on Render: &lt;a href="https://friend-shield.onrender.com/" rel="noopener noreferrer"&gt;Friend Shield on Render&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Render provides the live runtime environment for the Node.js/Express API: orchestrating delimiter parsing, executing in-process ONNX inference, validating SSRF-safe redirects, and managing asynchronous Gemma explanation streaming. Render’s Git-backed CI/CD pipeline enabled rapid, automated updates throughout development, while its environment variable manager securely stores API credentials.&lt;/p&gt;

&lt;h3&gt;
  
  
  Best Use of Gemma
&lt;/h3&gt;

&lt;p&gt;Friend Shield showcases &lt;strong&gt;Google Gemma&lt;/strong&gt; as an empathetic, culturally localized security explanation layer:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Evidence-Grounded Explanations:&lt;/strong&gt; Gemma does not decide whether a link is malicious. It receives structured evidence from deterministic rules, local ONNX inference, Safe Browsing, and SEMI, then explains that evidence in user-friendly language. Output is schema-validated, with a deterministic fallback if validation fails.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Progressive Safety UX:&lt;/strong&gt; Solves the latency dilemma of AI in security: deterministic triage delivers immediate protection in under 500 ms, while Gemma upgrades the UI with rich reasoning asynchronously in the background.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Dual Deployment Flexibility:&lt;/strong&gt; Accommodates zero-install mobile web users via cloud Gemma while offering 100% air-gapped local execution via Ollama (&lt;code&gt;AI_PROVIDER=ollama&lt;/code&gt; with &lt;code&gt;gemma2:2b&lt;/code&gt;) for total data privacy.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Culturally Grounded Multilingual Synthesis:&lt;/strong&gt; Generates nuanced, parallel advice across Bangla, English, and Banglish.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  Limitations
&lt;/h2&gt;

&lt;p&gt;Friend Shield is an educational decision-support tool, not an absolute guarantee of safety. A &lt;code&gt;NO_KNOWN_THREAT&lt;/code&gt; verdict means no known threat indicators were found; newly registered phishing domains or phone-based social engineering can still bypass automated checks. That is why Friend Shield always reminds users never to disclose PINs, OTPs, or passwords.&lt;/p&gt;

&lt;h2&gt;
  
  
  How I Used AI
&lt;/h2&gt;

&lt;p&gt;I used AI tools to accelerate development, including code assistance, debugging, documentation drafting, and refining this write-up. The multi-layer security architecture, deterministic evidence rules, abstention policy, ONNX model training and evaluation, Gemma integration, Render deployment, and final testing were designed, implemented, and reviewed by me.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Joy Said
&lt;/h2&gt;

&lt;p&gt;When I showed Joy the working build, he tested the suspicious message he had received.&lt;/p&gt;

&lt;p&gt;Friend Shield immediately flagged the fake domain in red and explained in Banglish that bKash never asks for account verification via third-party &lt;code&gt;.xyz&lt;/code&gt; links.&lt;/p&gt;

&lt;p&gt;He looked up and said:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“Bhai, this would have saved me a lot of tension.”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;That is why Friend Shield exists. It is the calm second opinion we all need before panic, urgency, or deception takes over.&lt;/p&gt;

</description>
      <category>devchallenge</category>
      <category>weekendchallenge</category>
      <category>hf26challenge</category>
    </item>
  </channel>
</rss>
