<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Shruti Chaudhary</title>
    <description>The latest articles on DEV Community by Shruti Chaudhary (@shruti_ch19).</description>
    <link>https://dev.to/shruti_ch19</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4149682%2Fa8f988c2-10e3-4cb4-84f4-36d5707073f7.png</url>
      <title>DEV Community: Shruti Chaudhary</title>
      <link>https://dev.to/shruti_ch19</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/shruti_ch19"/>
    <language>en</language>
    <item>
      <title>Scam or Genuine? An Offline Message Checker for a Friend (Gemma 3)</title>
      <dc:creator>Shruti Chaudhary</dc:creator>
      <pubDate>Mon, 05 Oct 2026 03:03:18 +0000</pubDate>
      <link>https://dev.to/shruti_ch19/scam-or-genuine-an-offline-message-checker-for-a-friend-gemma-3-1pff</link>
      <guid>https://dev.to/shruti_ch19/scam-or-genuine-an-offline-message-checker-for-a-friend-gemma-3-1pff</guid>
      <description>&lt;p&gt;&lt;em&gt;This is a submission for the &lt;a href="https://dev.to/challenges/hacktoberfest-weekend-2026-10-01"&gt;Hacktoberfest Weekend Challenge: Build for a Friend&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  What I Built
&lt;/h2&gt;

&lt;p&gt;A friend of mine wanted a way for his father and himself to check whether the messages they get from banks and other senders are scams or genuine. So I built a first version of one.&lt;/p&gt;

&lt;p&gt;You paste an SMS or WhatsApp message. The tool answers &lt;strong&gt;SCAM&lt;/strong&gt;, &lt;strong&gt;SUSPICIOUS&lt;/strong&gt; or &lt;strong&gt;SAFE&lt;/strong&gt;, gives a short reason in simple Hinglish, and says what to do next. It runs entirely on my laptop with Google's Gemma 3 through Ollama, so messages that can contain account and transaction details never leave the machine.&lt;/p&gt;

&lt;p&gt;It is a second opinion, not a safeguard. In my testing it missed some scams and wrongly flagged some genuine messages, and I show those failures below.&lt;/p&gt;

&lt;h2&gt;
  
  
  Demo
&lt;/h2&gt;

&lt;p&gt;  &lt;iframe src="https://www.youtube.com/embed/i65XilR74FU" width="710" height="399"&gt;
  &lt;/iframe&gt;
&lt;/p&gt;

&lt;h2&gt;
  
  
  Code
&lt;/h2&gt;


&lt;div class="ltag-github-readme-tag"&gt;
  &lt;div class="readme-overview"&gt;
    &lt;h2&gt;
      &lt;img src="https://assets.dev.to/assets/github-logo-5a155e1f9a670af7944dd5e12375bc76ed542ea80224905ecaf878b9157cdefc.svg" alt="GitHub logo"&gt;
      &lt;a href="https://github.com/ShrutiChaudhary08" rel="noopener noreferrer"&gt;
        ShrutiChaudhary08
      &lt;/a&gt; / &lt;a href="https://github.com/ShrutiChaudhary08/Scam-Checker" rel="noopener noreferrer"&gt;
        Scam-Checker
      &lt;/a&gt;
    &lt;/h2&gt;
    &lt;h3&gt;
      
    &lt;/h3&gt;
  &lt;/div&gt;
  &lt;div class="ltag-github-body"&gt;
    
&lt;div id="readme" class="md"&gt;&lt;div class="markdown-heading"&gt;
&lt;h1 class="heading-element"&gt;Scam Checker: works offline, built for a friend&lt;/h1&gt;
&lt;/div&gt;
&lt;p&gt;Submission for the &lt;strong&gt;Hacktoberfest Weekend Challenge: Build for a Friend&lt;/strong&gt; (DEV, 2 to 5 October 2026).&lt;/p&gt;
&lt;p&gt;A friend wanted a way for his father and himself to check whether the messages they get from banks and other senders are scams or genuine, so I built this for them.&lt;/p&gt;
&lt;p&gt;You paste an SMS or WhatsApp message. The checker answers &lt;strong&gt;SCAM&lt;/strong&gt;, &lt;strong&gt;SUSPICIOUS&lt;/strong&gt; or &lt;strong&gt;SAFE&lt;/strong&gt;, gives a short reason in simple Hinglish, and says what to do next. It runs on an ordinary laptop with &lt;strong&gt;Gemma 3 through Ollama&lt;/strong&gt;. No message leaves the machine and it needs no internet after the model is downloaded.&lt;/p&gt;
&lt;div class="markdown-heading"&gt;
&lt;h2 class="heading-element"&gt;How it works&lt;/h2&gt;
&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;code&gt;checker.py&lt;/code&gt; sends the message to a local Gemma model through the Ollama Python library, asks for JSON, uses temperature 0, and includes two worked Hinglish examples in the prompt. Replies that are not valid JSON…&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
  &lt;/div&gt;
  &lt;div class="gh-btn-container"&gt;&lt;a class="gh-btn" href="https://github.com/ShrutiChaudhary08/Scam-Checker" rel="noopener noreferrer"&gt;View on GitHub&lt;/a&gt;&lt;/div&gt;
&lt;/div&gt;


&lt;h2&gt;
  
  
  How I Built It
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Model:&lt;/strong&gt; Gemma 3 through Ollama, called from Python with the &lt;code&gt;ollama&lt;/code&gt; library. I ran the 4B model (the default) and the 1B model so I could compare them.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Prompt:&lt;/strong&gt; it asks for a JSON answer at temperature 0 and lists the usual warning signs. At first Gemma answered in English even though I asked for Hinglish. Adding two worked Hinglish examples fixed that.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Fallback:&lt;/strong&gt; if the model's reply is not valid JSON, the result is "UNKNOWN", which is treated as a warning.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Page:&lt;/strong&gt; a small Streamlit app. When the verdict is SAFE it adds a reminder to confirm with the bank before clicking a link, sharing an OTP or sending money.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Checks:&lt;/strong&gt; 14 unit tests and an evaluation script that scores the tool on labelled messages.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;AI help:&lt;/strong&gt; I used an AI assistant (Claude) for planning and code, and ran and tested everything myself on a Windows laptop with 16 GB RAM.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Results, Including the Failures
&lt;/h2&gt;

&lt;p&gt;I tested on three small sets and kept them separate because they come from different sources. The results are indicative, not proof of real-world accuracy.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Set&lt;/th&gt;
&lt;th&gt;gemma3 (4B)&lt;/th&gt;
&lt;th&gt;gemma3:1b&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;24 hand-written messages (12 scam, 12 genuine)&lt;/td&gt;
&lt;td&gt;23/24 right, 1 false alarm, 0 scams missed&lt;/td&gt;
&lt;td&gt;20/24 right, 4 false alarms, 0 scams missed&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;7 public scam examples&lt;/td&gt;
&lt;td&gt;6/7 caught&lt;/td&gt;
&lt;td&gt;7/7 caught&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;3 genuine messages from my own inbox&lt;/td&gt;
&lt;td&gt;1/3 right&lt;/td&gt;
&lt;td&gt;0/3 right&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Average time per message&lt;/td&gt;
&lt;td&gt;about 18 to 21 s&lt;/td&gt;
&lt;td&gt;about 8 to 9 s&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;What I learned:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;In my test sets the 1B model never missed a scam, but it flagged nearly half of the genuine messages. A tool that keeps warning about real bank alerts will stop being trusted, so I made the 4B model the default.&lt;/li&gt;
&lt;li&gt;Both models flagged a genuine one-time-password message and a genuine SBI debit alert as scams.&lt;/li&gt;
&lt;li&gt;The 4B model marked a fake "Did you initiate this? YES or NO" bank text as SAFE. It reads almost exactly like real bank fraud alerts, and the tool only sees the text, not who sent it.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;How the test messages were made: the 24 were written by me with AI assistance, using made-up numbers and links. The 7 scam examples were transcribed from publicly shown examples (Berkeley Lab IT, Aura, Net Protector Antivirus, BankFive and Doing More Today), with links and numbers replaced. The 3 genuine messages are from my own inbox, anonymised. I did not tune the prompt on any of these sets.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why Does Open Innovation Matter?
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;It runs offline. I tested it with Wi-Fi off and it still answered.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Bank messages are sensitive.&lt;/strong&gt; With a local model, they stay on the laptop instead of going to someone else's server.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;I could swap models and measure the difference.&lt;/strong&gt; The 4B against the 1B showed a real trade-off between speed and false alarms, which I could see and choose between.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;I could change its behaviour myself.&lt;/strong&gt; Two examples in the prompt were enough to change its language.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;It costs nothing to run&lt;/strong&gt; after the model download.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The trade-off: it is slow, about 20 seconds per message on my laptop. I did not compare it with a closed model, so I can't say whether a closed model would be more accurate.&lt;/p&gt;

&lt;h2&gt;
  
  
  Limitations
&lt;/h2&gt;

&lt;p&gt;My small test sets made the tool look more reliable than it is, and it will miss scams. It cannot verify who sent a message, so for anything involving money, call the bank on the number printed on your card.&lt;/p&gt;

&lt;h2&gt;
  
  
  What My Friend Said
&lt;/h2&gt;

&lt;p&gt;I handed it to my friend and his father. Here is what they said, shared with their permission:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;This will help us in getting rough idea of the messages we receive before we proceed with our next set of actions. Thank You.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Prize Categories
&lt;/h2&gt;

&lt;p&gt;Best Use of Gemma: I ran Gemma 3 locally through Ollama.&lt;/p&gt;

</description>
      <category>devchallenge</category>
      <category>weekendchallenge</category>
      <category>hf26challenge</category>
    </item>
  </channel>
</rss>
