This is a submission for the Hacktoberfest Weekend Challenge: Build for a Friend
What I Built
I built W-SENTRY, an autonomous, privacy-first wireless security sentinel for my college project partner and friend, Vikas.
Vikas lives in a college hostel where the network environment is far from ideal: budget Wi-Fi, cheap smart plugs, IoT devices, and frequent connection drops.
Whenever his Wi-Fi suddenly disconnected during a call or gaming session, he was left wondering:
Did the router crash? Is someone spoofing the network? Did one of the IoT devices get compromised?
The problem was not just that something could be wrong with the network. The bigger problem was that there was no simple way for him to understand what was actually happening.
Existing network security tools are generally designed either for security professionals or enterprise environments. They can expose huge amounts of low-level packet information without giving a normal user a clear answer.
I wanted to build something different for Vikas.
W-SENTRY runs locally on his own laptop and combines neural network-based intrusion detection with a local AI security copilot.
The system has two main components.
First, a custom PyTorch Hybrid CNN-BiLSTM with Self-Attention analyzes 12 behavioral network features in real time. It is designed to detect anomalous wireless behavior including deauthentication activity, RF jamming patterns, TCP SYN floods, and stealth port probes.
Second, when suspicious activity is detected, Google Gemma 3 (4B) runs locally through Ollama and acts as an incident copilot.
Instead of showing Vikas something like:
CLASS: DEAUTH
CONFIDENCE: 98.4%
Gemma can explain the event in normal language:
Someone appears to be sending repeated disconnect signals
to your device.
W-SENTRY classified the behavior as a likely
deauthentication attack and applied the configured
local containment rule.
The system will continue monitoring the network.
The important part is that the AI runs locally.
Network telemetry, device information, and incident conversations do not need to be sent to a cloud AI service.
The project is built around the idea that security software should not require sacrificing privacy in order to be understandable.
Demo
The W-SENTRY dashboard acts as a real-time mission-control interface for the wireless environment.
It provides:
Neural Threat Radar
Displays the current network state, detected threat class, confidence score, and probability distribution.
Behavioral Telemetry
Tracks metrics including packet rate, byte throughput, TCP SYN ratios, packet statistics, and destination port entropy.
Scenario Simulator
Allows users to reproduce controlled security scenarios such as:
RF Jamming
Deauthentication
TCP SYN Flood
Stealth Port Probe
This makes it possible to demonstrate the complete detection and response pipeline without requiring a real attack.
Automated Containment Feed
Displays the local response taken by the system, including configured firewall and network mitigation actions.
Gemma 3 AI Incident Copilot
Provides a conversational interface where Vikas can ask questions about detected incidents.
For example:
Why did you block this device?
What caused my Wi-Fi to disconnect?
Is this attack still happening?
What does a SYN flood mean?
What did W-SENTRY do when it detected this?
The complete pipeline looks like:
Wireless Traffic
│
▼
Behavioral Features
│
▼
Normalization
│
▼
Sliding Window
│
▼
CNN + BiLSTM + Self-Attention
│
▼
Threat Classification
│
├───────────────┐
▼ ▼
Containment Gemma 3 4B
│ │
└───────┬───────┘
▼
Mission Control
Dashboard
The moment that mattered
When I handed the finished dashboard over to Vikas and triggered a simulated deauthentication burst, his reaction was immediate:
"Every time my Wi-Fi used to drop, I genuinely wondered if someone was snooping on our network or if my laptop was dying. Seeing Gemma explain in plain English that someone was spamming deauth packets, while W-Sentry quietly blocked the MAC and kept everything on my own machine—that is peace of mind I couldn't buy from any store."
That was the point of building W-SENTRY.
Not just detecting an attack.
Making the result understandable to the person who is actually experiencing it.
Code
The complete project is open source on GitHub:
Riteesh-Thiruveedhula/W-Sentry
The repository contains the:
FastAPI backend
PyTorch model architecture
Pretrained model weights
Feature preprocessing pipeline
Gemma 3 + Ollama integration
Frontend dashboard
Threat simulation components
Local mitigation logic
How I Built It
W-SENTRY is built around an entirely open-source AI pipeline.
PyTorch Threat Detection
The detection engine uses a custom:
HybridCNNLSTMAttention
architecture.
The model combines three components.
1. 1D CNN
The convolutional layers extract local relationships between the 12 behavioral traffic features.
These include characteristics such as:
Packet rate
Packet sizes
Inter-arrival behavior
Payload entropy
TCP flag ratios
SYN behavior
Destination port behavior
Flow statistics
2. Bidirectional LSTM
The CNN representation is passed through a two-layer BiLSTM.
The system processes network behavior using a five-step sliding window:
t1 → t2 → t3 → t4 → t5
This allows the model to learn temporal patterns rather than treating every network observation as an isolated event.
3. Self-Attention
A scaled dot-product attention layer identifies the most important timesteps within the window.
The resulting representation is passed to the threat classifier.
The model was trained/evaluated using cybersecurity datasets including:
WSN-DS
CIC-IoT-2023
Edge-IIoTset
The reported evaluation results include:
WSN-DS → 98.1% accuracy
CIC-IoT-2023 → 97.8% accuracy
Local Gemma 3
The second AI component is Google Gemma 3 (4B) running through Ollama.
The backend communicates with the local Ollama instance:
http://127.0.0.1:11434
When the detection model identifies an incident, FastAPI passes structured information to Gemma:
Threat Class
Confidence
Packet Rate
SYN Ratio
Flow Metrics
Mitigation Action
Mitigation Details
Gemma then converts that technical information into a short incident briefing.
The basic integration looks like this:
def generate_incident_briefing(detection, mitigation_action):
prompt = f"""
Anomalous wireless traffic detected on Vikas's home network:
- Detected Threat:
{detection['class_name']} ({detection['confidence']}%)
- Telemetry:
Packet Rate: {detection['features']['packet_rate']} pps
SYN Ratio: {detection['features']['syn_flag_ratio']}
- Mitigation Action:
{mitigation_action['action']}
{mitigation_action['details']}
Give Vikas a friendly 3-sentence incident briefing
explaining what this means, why he does not need to panic,
and what was just protected.
"""
payload = {
"model": "gemma3:4b",
"prompt": prompt,
"system": VIKAS_SYSTEM_PROMPT,
"stream": False
}
return query_ollama(payload)
The model runs locally, so the architecture is:
W-SENTRY
│
▼
FastAPI
│
│ localhost
▼
Ollama
│
▼
Gemma 3 4B
│
▼
Incident Explanation
There is no cloud LLM API in this core inference path.
Why I used an LLM at all
The neural network is good at answering:
"What does this traffic pattern look like?"
But a normal user does not necessarily want a classification label.
They want to know:
"What happened to my Wi-Fi?"
"Did the system do anything about it?"
"Should I be worried?"
That is where Gemma fits.
The LLM is not the security-critical classifier.
It is the human interface to the security system.
The underlying detection and configured mitigation remain deterministic parts of the pipeline.
Why Does Open Innovation Matter?
Open innovation was essential to building W-SENTRY.
The biggest advantage was not simply that the models were free to use.
It was that I could compose different open technologies into a system designed around a specific person's problem.
PyTorch gave me the flexibility to build and train a custom neural architecture instead of adapting my problem to a closed API.
Open benchmark datasets gave me access to realistic cybersecurity traffic for experimentation.
And Gemma 3 gave me a local, open-weight conversational model that could run on the same machine as the rest of the security pipeline.
That combination would be much harder to achieve with a closed AI API.
A closed API could give me a powerful conversational model, but it would fundamentally change the architecture:
Network
│
▼
Telemetry
│
▼
Remote API
│
▼
Cloud LLM
│
▼
Response
For a security application, that creates a privacy problem.
With local inference, the architecture becomes:
Network
│
▼
Feature Extraction
│
▼
PyTorch
│
├──────────────┐
▼ ▼
Containment Gemma 3
│
▼
Explanation
Everything can stay on the user's machine.
That is what open innovation made possible for this project: I could choose the model, runtime, architecture, datasets, and deployment strategy independently and combine them into one privacy-first system.
It also made experimentation possible.
I could modify the detection architecture, change the preprocessing pipeline, replace the conversational model, inspect the model behavior, and integrate everything into a custom workflow without depending on a single vendor's platform.
For me, that is the most interesting part of open innovation.
It allows developers to take powerful building blocks and turn them into highly specific tools for real people.
My Agent Session
The core W-SENTRY implementation was developed through an iterative coding and debugging workflow involving the detection pipeline, FastAPI backend, local Gemma integration, dashboard, and simulation environment.
Agent session: Add your DevRelay session link here if you are submitting one.
Prize Categories
I am entering W-SENTRY in the partner categories that align with the technologies used in the project:
Google / Gemma
W-SENTRY uses Google Gemma 3 (4B) as its local AI incident copilot.
Open Source / Open Innovation
The project combines open-source ML frameworks, datasets, local inference, and an open-source repository into an end-to-end privacy-first security application.
AI / Machine Learning
The core detection system uses a custom PyTorch CNN + BiLSTM + Self-Attention architecture for behavioral network intrusion detection.
Built for a Friend
At the end of the day, W-SENTRY started with a very simple problem:
My friend kept asking:
"Why does my Wi-Fi keep doing this?"
Instead of giving him another troubleshooting checklist, I wanted to build something that could actually watch the network, recognize suspicious behavior, take configured local action, and explain what happened.
That became W-SENTRY.
A wireless security sentinel that watches quietly, responds locally, and explains what it sees.
Top comments (0)