<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Samarth Mukhija</title>
    <description>The latest articles on DEV Community by Samarth Mukhija (@samearth17).</description>
    <link>https://dev.to/samearth17</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fthepracticaldev.s3.amazonaws.com%2Fi%2F99mvlsfu5tfj9m7ku25d.png</url>
      <title>DEV Community: Samarth Mukhija</title>
      <link>https://dev.to/samearth17</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/samearth17"/>
    <language>en</language>
    <item>
      <title>I Built a Private AI Scam Detector for a Friend with Local Open-Source AI</title>
      <dc:creator>Samarth Mukhija</dc:creator>
      <pubDate>Sun, 04 Oct 2026 10:44:50 +0000</pubDate>
      <link>https://dev.to/samearth17/i-built-a-private-ai-scam-detector-for-a-friend-with-local-open-source-ai-48de</link>
      <guid>https://dev.to/samearth17/i-built-a-private-ai-scam-detector-for-a-friend-with-local-open-source-ai-48de</guid>
      <description>&lt;p&gt;&lt;em&gt;This is a submission for the Hacktoberfest Weekend Challenge: Build for a Friend.&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  What I Built
&lt;/h2&gt;

&lt;p&gt;Have you ever received a message that made you stop and think:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;"Is this actually legitimate, or is this a scam?"&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;That was the problem I wanted to solve for a friend.&lt;/p&gt;

&lt;p&gt;Instead of building another generic AI chatbot, I built &lt;strong&gt;ScamShield Local&lt;/strong&gt; a small, privacy focused AI tool that gives you a second opinion when a message looks suspicious.&lt;/p&gt;

&lt;p&gt;You paste a suspicious SMS, WhatsApp message, email, job offer, payment request, or investment message into the application, and it analyzes the text and gives you:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;a risk level&lt;/li&gt;
&lt;li&gt;a risk score&lt;/li&gt;
&lt;li&gt;the warning signs it detected&lt;/li&gt;
&lt;li&gt;recommended actions&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The idea is simple:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Pause before you trust.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Why I Built It
&lt;/h2&gt;

&lt;p&gt;I wanted to build something that could actually be useful to someone I know.&lt;/p&gt;

&lt;p&gt;Scam messages are becoming increasingly convincing. They often create urgency, impersonate companies or people, promise unrealistic rewards, or ask for sensitive information.&lt;/p&gt;

&lt;p&gt;The problem is not always knowing that something &lt;em&gt;feels&lt;/em&gt; suspicious.&lt;/p&gt;

&lt;p&gt;The problem is understanding &lt;strong&gt;why&lt;/strong&gt; it is suspicious.&lt;/p&gt;

&lt;p&gt;That's what ScamShield tries to help with.&lt;/p&gt;

&lt;p&gt;Instead of just saying:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"This is a scam."&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;it explains the signals that made the message risky and gives the user safer next steps.&lt;/p&gt;

&lt;h2&gt;
  
  
  Demo
&lt;/h2&gt;

&lt;p&gt;Here is a short demonstration of ScamShield Local:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://youtu.be/zkFD0ySIWoI" rel="noopener noreferrer"&gt;https://youtu.be/zkFD0ySIWoI&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;In the demo, I paste a suspicious message into the application and let the local AI analyse it.&lt;/p&gt;

&lt;p&gt;The application identifies the warning signs, produces a risk score, and recommends what the user should do next.&lt;/p&gt;

&lt;h2&gt;
  
  
  Code
&lt;/h2&gt;

&lt;p&gt;The complete project is available here:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/Samearth17/scamshield-local" rel="noopener noreferrer"&gt;https://github.com/Samearth17/scamshield-local&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  How I Built It
&lt;/h2&gt;

&lt;p&gt;I wanted the application to be small, fast, and easy to run locally.&lt;/p&gt;

&lt;p&gt;The stack is:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;FastAPI&lt;/strong&gt; for the backend&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;HTML, CSS, and JavaScript&lt;/strong&gt; for the frontend&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Ollama&lt;/strong&gt; for local AI inference&lt;/li&gt;
&lt;li&gt;an &lt;strong&gt;open-weight model&lt;/strong&gt; running locally&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Pydantic&lt;/strong&gt; for structured response validation&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;pytest&lt;/strong&gt; for automated testing&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The architecture looks like this:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Browser
   |
   | POST /analyze
   v
FastAPI
   |
   | Local request
   v
Ollama + Open-Weight Model
   |
   v
Structured JSON
   |
   v
Risk Analysis
   |
   +-- Risk Level
   +-- Risk Score
   +-- Red Flags
   +-- Recommended Actions
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The application doesn't require a hosted AI API or a database.&lt;/p&gt;

&lt;p&gt;The message is sent to the local FastAPI application, which communicates with Ollama running on the same machine.&lt;/p&gt;

&lt;p&gt;I also added validation and safeguards around the model response so that malformed output does not directly reach the user.&lt;/p&gt;

&lt;p&gt;The risk score is normalized so that the displayed score always agrees with the risk level. For example, a HIGH-risk result cannot end up displaying something contradictory like &lt;code&gt;10/100&lt;/code&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why Local Open-Source AI?
&lt;/h2&gt;

&lt;p&gt;This is probably my favorite part of the project.&lt;/p&gt;

&lt;p&gt;A person might paste a very personal message into a scam detector. It could contain a phone number, someone's name, payment information, or part of a private conversation.&lt;/p&gt;

&lt;p&gt;I did not want the basic workflow to require sending that information to a third party AI API.&lt;/p&gt;

&lt;p&gt;With local inference, the model can run directly on the user's machine.&lt;/p&gt;

&lt;p&gt;That means:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;the message doesn't need to be sent to a third-party AI provider&lt;/li&gt;
&lt;li&gt;the user has more control over their data&lt;/li&gt;
&lt;li&gt;there is no requirement for a hosted AI API key&lt;/li&gt;
&lt;li&gt;the underlying model can be changed for another compatible open-weight model&lt;/li&gt;
&lt;li&gt;the application can continue to work independently of a hosted AI service&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;For this particular problem, &lt;strong&gt;open and local AI isn't just a technical choice it is part of the product's privacy story.&lt;/strong&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Building It With AI
&lt;/h2&gt;

&lt;p&gt;I also used AI coding tools during development to accelerate implementation, debugging, testing, and iteration.&lt;/p&gt;

&lt;p&gt;But the goal wasn't to simply generate a chatbot and call it a project.&lt;/p&gt;

&lt;p&gt;The interesting work was deciding:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;what information the user actually needs&lt;/li&gt;
&lt;li&gt;how the model should structure its response&lt;/li&gt;
&lt;li&gt;how to handle malformed model output&lt;/li&gt;
&lt;li&gt;how to keep the risk score consistent&lt;/li&gt;
&lt;li&gt;what safety guidance should appear for high-risk messages&lt;/li&gt;
&lt;li&gt;what the application should explicitly &lt;em&gt;not&lt;/em&gt; claim&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;That distinction became especially important while building a tool that deals with potentially sensitive messages.&lt;/p&gt;

&lt;h2&gt;
  
  
  What I Learned
&lt;/h2&gt;

&lt;p&gt;One thing I learned from this project is that getting an LLM to produce an answer is relatively easy.&lt;/p&gt;

&lt;p&gt;Getting that answer to be &lt;strong&gt;useful, predictable, and responsible&lt;/strong&gt; is much harder.&lt;/p&gt;

&lt;p&gt;I ended up spending significant effort on things that aren't immediately visible in the UI:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;structured output validation&lt;/li&gt;
&lt;li&gt;malformed-response handling&lt;/li&gt;
&lt;li&gt;input validation&lt;/li&gt;
&lt;li&gt;risk-score normalization&lt;/li&gt;
&lt;li&gt;safety guidance&lt;/li&gt;
&lt;li&gt;automated tests&lt;/li&gt;
&lt;li&gt;clear limitations&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;I also learned that a small project can sometimes make a stronger demo than an overly ambitious one.&lt;/p&gt;

&lt;p&gt;Instead of building a huge platform, I focused on solving one problem well.&lt;/p&gt;

&lt;h2&gt;
  
  
  Limitations
&lt;/h2&gt;

&lt;p&gt;ScamShield is not a guarantee that a message is fraudulent or safe.&lt;/p&gt;

&lt;p&gt;It only analyzes the text provided to it. It does not independently verify:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;sender identity&lt;/li&gt;
&lt;li&gt;URLs or their destinations&lt;/li&gt;
&lt;li&gt;attachments&lt;/li&gt;
&lt;li&gt;account activity&lt;/li&gt;
&lt;li&gt;transaction history&lt;/li&gt;
&lt;li&gt;the wider conversation context&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;A LOW risk result does &lt;strong&gt;not&lt;/strong&gt; mean that a message is safe.&lt;/p&gt;

&lt;p&gt;The application is intended to provide an additional perspective and encourage users to verify important requests independently.&lt;/p&gt;

&lt;h2&gt;
  
  
  Built for a Friend
&lt;/h2&gt;

&lt;p&gt;The whole reason this project exists is that I wanted to build something practical for someone I know.&lt;/p&gt;

&lt;p&gt;The workflow is intentionally simple:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Paste → Analyze → Understand → Make a safer decision&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;No complicated setup in the interface.&lt;/p&gt;

&lt;p&gt;No account.&lt;/p&gt;

&lt;p&gt;No database.&lt;/p&gt;

&lt;p&gt;No need to send the message to a hosted AI API.&lt;/p&gt;

&lt;p&gt;Just a small local AI tool that can help someone stop for a moment before clicking, paying, or sharing sensitive information.&lt;/p&gt;

&lt;h2&gt;
  
  
  Final Thoughts
&lt;/h2&gt;

&lt;p&gt;This started as a weekend challenge, but I liked the idea behind it: &lt;strong&gt;build technology for a person, not just for a portfolio.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;ScamShield Local is small, but it gave me a chance to explore local AI, structured LLM outputs, safety-focused UX, and privacy-aware application design in one project.&lt;/p&gt;

&lt;p&gt;If you try it out, I would genuinely love to hear:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What would you want an AI scam detector to explain before you decide whether to trust a message?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;GitHub: &lt;a href="https://github.com/Samearth17/scamshield-local" rel="noopener noreferrer"&gt;https://github.com/Samearth17/scamshield-local&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Demo: &lt;a href="https://youtu.be/zkFD0ySIWoI" rel="noopener noreferrer"&gt;https://youtu.be/zkFD0ySIWoI&lt;/a&gt;&lt;/p&gt;

</description>
      <category>hf26challenge</category>
    </item>
  </channel>
</rss>
