<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Riteesh Thiruveedhula</title>
    <description>The latest articles on DEV Community by Riteesh Thiruveedhula (@riteesh_vnsp).</description>
    <link>https://dev.to/riteesh_vnsp</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3012805%2F2736a531-cccc-4a62-8689-b02596f25cca.png</url>
      <title>DEV Community: Riteesh Thiruveedhula</title>
      <link>https://dev.to/riteesh_vnsp</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/riteesh_vnsp"/>
    <language>en</language>
    <item>
      <title>W-SENTRY: A Local-First AI Wi-Fi Sentinel I Built for My Roommate</title>
      <dc:creator>Riteesh Thiruveedhula</dc:creator>
      <pubDate>Mon, 05 Oct 2026 06:53:08 +0000</pubDate>
      <link>https://dev.to/riteesh_vnsp/w-sentry-a-local-first-ai-wi-fi-sentinel-i-built-for-my-roommate-30g3</link>
      <guid>https://dev.to/riteesh_vnsp/w-sentry-a-local-first-ai-wi-fi-sentinel-i-built-for-my-roommate-30g3</guid>
      <description>&lt;p&gt;&lt;em&gt;This is a submission for the &lt;a href="https://dev.to/challenges/hacktoberfest-weekend-2026-10-01"&gt;Hacktoberfest Weekend Challenge: Build for a Friend&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  What I Built
&lt;/h2&gt;

&lt;p&gt;I built &lt;strong&gt;W-SENTRY&lt;/strong&gt;, an autonomous, privacy-first wireless security sentinel for my college project partner and friend, &lt;strong&gt;Vikas&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Vikas lives in a college hostel where the network environment is far from ideal: budget Wi-Fi, cheap smart plugs, IoT devices, and frequent connection drops.&lt;/p&gt;

&lt;p&gt;Whenever his Wi-Fi suddenly disconnected during a call or gaming session, he was left wondering:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Did the router crash? Is someone spoofing the network? Did one of the IoT devices get compromised?&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;The problem was not just that something could be wrong with the network. The bigger problem was that there was no simple way for him to understand &lt;strong&gt;what was actually happening&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Existing network security tools are generally designed either for security professionals or enterprise environments. They can expose huge amounts of low-level packet information without giving a normal user a clear answer.&lt;/p&gt;

&lt;p&gt;I wanted to build something different for Vikas.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;W-SENTRY runs locally on his own laptop and combines neural network-based intrusion detection with a local AI security copilot.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The system has two main components.&lt;/p&gt;

&lt;p&gt;First, a custom &lt;strong&gt;PyTorch Hybrid CNN-BiLSTM with Self-Attention&lt;/strong&gt; analyzes 12 behavioral network features in real time. It is designed to detect anomalous wireless behavior including deauthentication activity, RF jamming patterns, TCP SYN floods, and stealth port probes.&lt;/p&gt;

&lt;p&gt;Second, when suspicious activity is detected, &lt;strong&gt;Google Gemma 3 (4B)&lt;/strong&gt; runs locally through Ollama and acts as an incident copilot.&lt;/p&gt;

&lt;p&gt;Instead of showing Vikas something like:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;CLASS: DEAUTH
CONFIDENCE: 98.4%
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Gemma can explain the event in normal language:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Someone appears to be sending repeated disconnect signals
to your device.

W-SENTRY classified the behavior as a likely
deauthentication attack and applied the configured
local containment rule.

The system will continue monitoring the network.
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The important part is that the AI runs locally.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Network telemetry, device information, and incident conversations do not need to be sent to a cloud AI service.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The project is built around the idea that security software should not require sacrificing privacy in order to be understandable.&lt;/p&gt;




&lt;h2&gt;
  
  
  Demo
&lt;/h2&gt;

&lt;p&gt;The W-SENTRY dashboard acts as a real-time mission-control interface for the wireless environment.&lt;/p&gt;

&lt;p&gt;It provides:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Neural Threat Radar&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Displays the current network state, detected threat class, confidence score, and probability distribution.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Behavioral Telemetry&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Tracks metrics including packet rate, byte throughput, TCP SYN ratios, packet statistics, and destination port entropy.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Scenario Simulator&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Allows users to reproduce controlled security scenarios such as:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;RF Jamming
Deauthentication
TCP SYN Flood
Stealth Port Probe
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This makes it possible to demonstrate the complete detection and response pipeline without requiring a real attack.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Automated Containment Feed&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Displays the local response taken by the system, including configured firewall and network mitigation actions.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Gemma 3 AI Incident Copilot&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Provides a conversational interface where Vikas can ask questions about detected incidents.&lt;/p&gt;

&lt;p&gt;For example:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Why did you block this device?

What caused my Wi-Fi to disconnect?

Is this attack still happening?

What does a SYN flood mean?

What did W-SENTRY do when it detected this?
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The complete pipeline looks like:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Wireless Traffic
       │
       ▼
Behavioral Features
       │
       ▼
Normalization
       │
       ▼
Sliding Window
       │
       ▼
CNN + BiLSTM + Self-Attention
       │
       ▼
Threat Classification
       │
       ├───────────────┐
       ▼               ▼
Containment        Gemma 3 4B
       │               │
       └───────┬───────┘
               ▼
        Mission Control
           Dashboard
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  The moment that mattered
&lt;/h3&gt;

&lt;p&gt;When I handed the finished dashboard over to Vikas and triggered a simulated deauthentication burst, his reaction was immediate:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"Every time my Wi-Fi used to drop, I genuinely wondered if someone was snooping on our network or if my laptop was dying. Seeing Gemma explain in plain English that someone was spamming deauth packets, while W-Sentry quietly blocked the MAC and kept everything on my own machine—that is peace of mind I couldn't buy from any store."&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;That was the point of building W-SENTRY.&lt;/p&gt;

&lt;p&gt;Not just detecting an attack.&lt;/p&gt;

&lt;p&gt;Making the result understandable to the person who is actually experiencing it.&lt;/p&gt;




&lt;h2&gt;
  
  
  Code
&lt;/h2&gt;

&lt;p&gt;The complete project is open source on GitHub:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href="https://github.com/Riteesh-Thiruveedhula/W-Sentry" rel="noopener noreferrer"&gt;Riteesh-Thiruveedhula/W-Sentry&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The repository contains the:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;FastAPI backend
PyTorch model architecture
Pretrained model weights
Feature preprocessing pipeline
Gemma 3 + Ollama integration
Frontend dashboard
Threat simulation components
Local mitigation logic
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  How I Built It
&lt;/h2&gt;

&lt;p&gt;W-SENTRY is built around an entirely open-source AI pipeline.&lt;/p&gt;

&lt;h3&gt;
  
  
  PyTorch Threat Detection
&lt;/h3&gt;

&lt;p&gt;The detection engine uses a custom:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;HybridCNNLSTMAttention
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;architecture.&lt;/p&gt;

&lt;p&gt;The model combines three components.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;1. 1D CNN&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The convolutional layers extract local relationships between the 12 behavioral traffic features.&lt;/p&gt;

&lt;p&gt;These include characteristics such as:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Packet rate
Packet sizes
Inter-arrival behavior
Payload entropy
TCP flag ratios
SYN behavior
Destination port behavior
Flow statistics
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;2. Bidirectional LSTM&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The CNN representation is passed through a two-layer BiLSTM.&lt;/p&gt;

&lt;p&gt;The system processes network behavior using a five-step sliding window:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;t1 → t2 → t3 → t4 → t5
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This allows the model to learn temporal patterns rather than treating every network observation as an isolated event.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;3. Self-Attention&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;A scaled dot-product attention layer identifies the most important timesteps within the window.&lt;/p&gt;

&lt;p&gt;The resulting representation is passed to the threat classifier.&lt;/p&gt;

&lt;p&gt;The model was trained/evaluated using cybersecurity datasets including:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;WSN-DS
CIC-IoT-2023
Edge-IIoTset
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The reported evaluation results include:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;WSN-DS       → 98.1% accuracy
CIC-IoT-2023 → 97.8% accuracy
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  Local Gemma 3
&lt;/h3&gt;

&lt;p&gt;The second AI component is &lt;strong&gt;Google Gemma 3 (4B)&lt;/strong&gt; running through Ollama.&lt;/p&gt;

&lt;p&gt;The backend communicates with the local Ollama instance:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;http://127.0.0.1:11434
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;When the detection model identifies an incident, FastAPI passes structured information to Gemma:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Threat Class
Confidence
Packet Rate
SYN Ratio
Flow Metrics
Mitigation Action
Mitigation Details
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Gemma then converts that technical information into a short incident briefing.&lt;/p&gt;

&lt;p&gt;The basic integration looks like this:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight python"&gt;&lt;code&gt;&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;generate_incident_briefing&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;detection&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;mitigation_action&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;

    &lt;span class="n"&gt;prompt&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="sa"&gt;f&lt;/span&gt;&lt;span class="sh"&gt;"""&lt;/span&gt;&lt;span class="s"&gt;
Anomalous wireless traffic detected on Vikas&lt;/span&gt;&lt;span class="sh"&gt;'&lt;/span&gt;&lt;span class="s"&gt;s home network:

- Detected Threat:
  &lt;/span&gt;&lt;span class="si"&gt;{&lt;/span&gt;&lt;span class="n"&gt;detection&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="sh"&gt;'&lt;/span&gt;&lt;span class="s"&gt;class_name&lt;/span&gt;&lt;span class="sh"&gt;'&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="si"&gt;}&lt;/span&gt;&lt;span class="s"&gt; (&lt;/span&gt;&lt;span class="si"&gt;{&lt;/span&gt;&lt;span class="n"&gt;detection&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="sh"&gt;'&lt;/span&gt;&lt;span class="s"&gt;confidence&lt;/span&gt;&lt;span class="sh"&gt;'&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="si"&gt;}&lt;/span&gt;&lt;span class="s"&gt;%)

- Telemetry:
  Packet Rate: &lt;/span&gt;&lt;span class="si"&gt;{&lt;/span&gt;&lt;span class="n"&gt;detection&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="sh"&gt;'&lt;/span&gt;&lt;span class="s"&gt;features&lt;/span&gt;&lt;span class="sh"&gt;'&lt;/span&gt;&lt;span class="p"&gt;][&lt;/span&gt;&lt;span class="sh"&gt;'&lt;/span&gt;&lt;span class="s"&gt;packet_rate&lt;/span&gt;&lt;span class="sh"&gt;'&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="si"&gt;}&lt;/span&gt;&lt;span class="s"&gt; pps
  SYN Ratio: &lt;/span&gt;&lt;span class="si"&gt;{&lt;/span&gt;&lt;span class="n"&gt;detection&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="sh"&gt;'&lt;/span&gt;&lt;span class="s"&gt;features&lt;/span&gt;&lt;span class="sh"&gt;'&lt;/span&gt;&lt;span class="p"&gt;][&lt;/span&gt;&lt;span class="sh"&gt;'&lt;/span&gt;&lt;span class="s"&gt;syn_flag_ratio&lt;/span&gt;&lt;span class="sh"&gt;'&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="si"&gt;}&lt;/span&gt;&lt;span class="s"&gt;

- Mitigation Action:
  &lt;/span&gt;&lt;span class="si"&gt;{&lt;/span&gt;&lt;span class="n"&gt;mitigation_action&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="sh"&gt;'&lt;/span&gt;&lt;span class="s"&gt;action&lt;/span&gt;&lt;span class="sh"&gt;'&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="si"&gt;}&lt;/span&gt;&lt;span class="s"&gt;
  &lt;/span&gt;&lt;span class="si"&gt;{&lt;/span&gt;&lt;span class="n"&gt;mitigation_action&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="sh"&gt;'&lt;/span&gt;&lt;span class="s"&gt;details&lt;/span&gt;&lt;span class="sh"&gt;'&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="si"&gt;}&lt;/span&gt;&lt;span class="s"&gt;

Give Vikas a friendly 3-sentence incident briefing
explaining what this means, why he does not need to panic,
and what was just protected.
&lt;/span&gt;&lt;span class="sh"&gt;"""&lt;/span&gt;

    &lt;span class="n"&gt;payload&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;model&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;gemma3:4b&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
        &lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;prompt&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="n"&gt;prompt&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
        &lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;system&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="n"&gt;VIKAS_SYSTEM_PROMPT&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
        &lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;stream&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="bp"&gt;False&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;

    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="nf"&gt;query_ollama&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;payload&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The model runs locally, so the architecture is:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;W-SENTRY
    │
    ▼
FastAPI
    │
    │ localhost
    ▼
Ollama
    │
    ▼
Gemma 3 4B
    │
    ▼
Incident Explanation
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;There is no cloud LLM API in this core inference path.&lt;/p&gt;

&lt;h3&gt;
  
  
  Why I used an LLM at all
&lt;/h3&gt;

&lt;p&gt;The neural network is good at answering:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;"What does this traffic pattern look like?"&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;But a normal user does not necessarily want a classification label.&lt;/p&gt;

&lt;p&gt;They want to know:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;"What happened to my Wi-Fi?"&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;"Did the system do anything about it?"&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;"Should I be worried?"&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;That is where Gemma fits.&lt;/p&gt;

&lt;p&gt;The LLM is not the security-critical classifier.&lt;/p&gt;

&lt;p&gt;It is the &lt;strong&gt;human interface to the security system&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;The underlying detection and configured mitigation remain deterministic parts of the pipeline.&lt;/p&gt;




&lt;h2&gt;
  
  
  Why Does Open Innovation Matter?
&lt;/h2&gt;

&lt;p&gt;Open innovation was essential to building W-SENTRY.&lt;/p&gt;

&lt;p&gt;The biggest advantage was not simply that the models were free to use.&lt;/p&gt;

&lt;p&gt;It was that I could &lt;strong&gt;compose different open technologies into a system designed around a specific person's problem&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;PyTorch gave me the flexibility to build and train a custom neural architecture instead of adapting my problem to a closed API.&lt;/p&gt;

&lt;p&gt;Open benchmark datasets gave me access to realistic cybersecurity traffic for experimentation.&lt;/p&gt;

&lt;p&gt;And Gemma 3 gave me a local, open-weight conversational model that could run on the same machine as the rest of the security pipeline.&lt;/p&gt;

&lt;p&gt;That combination would be much harder to achieve with a closed AI API.&lt;/p&gt;

&lt;p&gt;A closed API could give me a powerful conversational model, but it would fundamentally change the architecture:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Network
   │
   ▼
Telemetry
   │
   ▼
Remote API
   │
   ▼
Cloud LLM
   │
   ▼
Response
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;For a security application, that creates a privacy problem.&lt;/p&gt;

&lt;p&gt;With local inference, the architecture becomes:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Network
   │
   ▼
Feature Extraction
   │
   ▼
PyTorch
   │
   ├──────────────┐
   ▼              ▼
Containment    Gemma 3
                  │
                  ▼
             Explanation
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Everything can stay on the user's machine.&lt;/p&gt;

&lt;p&gt;That is what open innovation made possible for this project: &lt;strong&gt;I could choose the model, runtime, architecture, datasets, and deployment strategy independently and combine them into one privacy-first system.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;It also made experimentation possible.&lt;/p&gt;

&lt;p&gt;I could modify the detection architecture, change the preprocessing pipeline, replace the conversational model, inspect the model behavior, and integrate everything into a custom workflow without depending on a single vendor's platform.&lt;/p&gt;

&lt;p&gt;For me, that is the most interesting part of open innovation.&lt;/p&gt;

&lt;p&gt;It allows developers to take powerful building blocks and turn them into highly specific tools for real people.&lt;/p&gt;




&lt;h2&gt;
  
  
  My Agent Session
&lt;/h2&gt;

&lt;p&gt;The core W-SENTRY implementation was developed through an iterative coding and debugging workflow involving the detection pipeline, FastAPI backend, local Gemma integration, dashboard, and simulation environment.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Agent session:&lt;/strong&gt; Add your DevRelay session link here if you are submitting one.&lt;/p&gt;




&lt;h2&gt;
  
  
  Prize Categories
&lt;/h2&gt;

&lt;p&gt;I am entering W-SENTRY in the partner categories that align with the technologies used in the project:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Google / Gemma&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;W-SENTRY uses &lt;strong&gt;Google Gemma 3 (4B)&lt;/strong&gt; as its local AI incident copilot.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Open Source / Open Innovation&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The project combines open-source ML frameworks, datasets, local inference, and an open-source repository into an end-to-end privacy-first security application.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;AI / Machine Learning&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The core detection system uses a custom PyTorch &lt;strong&gt;CNN + BiLSTM + Self-Attention&lt;/strong&gt; architecture for behavioral network intrusion detection.&lt;/p&gt;




&lt;h2&gt;
  
  
  Built for a Friend
&lt;/h2&gt;

&lt;p&gt;At the end of the day, W-SENTRY started with a very simple problem:&lt;/p&gt;

&lt;p&gt;My friend kept asking:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;"Why does my Wi-Fi keep doing this?"&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Instead of giving him another troubleshooting checklist, I wanted to build something that could actually watch the network, recognize suspicious behavior, take configured local action, and explain what happened.&lt;/p&gt;

&lt;p&gt;That became W-SENTRY.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;A wireless security sentinel that watches quietly, responds locally, and explains what it sees.&lt;/strong&gt;&lt;/p&gt;

</description>
      <category>devchallenge</category>
      <category>weekendchallenge</category>
      <category>hf26challenge</category>
    </item>
  </channel>
</rss>
