inspiration Most cyber security tools are built for massive enterprises with dedicated IT teams and huge budgets. Local businesses—like neighborhood pharmacies, hardware stores, and clinics—hold highly sensitive customer data but have virtually zero defense against data breaches. They cannot afford complex software, nor do they have the technical knowledge to read raw database logs. The inspiration was to bridge this gap: building an invisible, automated security guard that uses AI to detect threats instantly and explain them in plain English, giving local shop owners enterprise-grade protection with zero friction.
What it does Digital-Tripwire is a Compound AI-powered honeypot and threat detection system. It silently plants highly attractive, fake "bait" data (like a vault_secrets table) inside a business's local database. Because legitimate software never touches this fake data, any interaction with it guarantees a breach is occurring.
The moment the trap is sprung, the system:
Instantly engages an OS-level kill switch to lock down the application.
Uses a fast AI model to classify the attack type in milliseconds.
Uses a heavy-reasoning AI model to generate a plain-English incident report and a technical code patch.
Pushes an instant emergency notification to the business owner's phone via ntfy.sh. It also includes an ML-powered anomaly detector to catch insider threats who abuse legitimate access.
How we built it The core engine was built natively in a pure Linux environment using Python, Flask, and SQLite. We utilized SQLite’s set_trace_callback() to intercept every SQL query in real-time.
For the intelligence layer, we built a two-tier Compound AI System:
Tier 1 (The Watchdog): We integrated the NVIDIA NIM API (Llama 3 8B) for ultra-fast, low-latency threat triage, forcing it to output strict JSON threat profiles.
Tier 2 (The Strategist): We routed the high-level threats to the Google Gemini 2.5 Flash API, utilizing its massive context window to generate human-readable alerts and actionable remediation code. We also utilized the Python watchdog library to interface with Linux's inotify for OS-level file monitoring, preventing attackers from bypassing the web app entirely.
Challenges we ran into Our biggest initial challenge was API Denial of Service (Wallet Draining). We realized an attacker could write a script to hit the honeypot 10,000 times a minute, which would spam our AI APIs and drain our credits. We engineered around this by implementing an in-memory debouncing cache to rate-limit the alerts.
We also faced the risk of Prompt Injection, where a smart attacker could write a SQL query containing natural language instructions to trick the AI. We solved this by strictly sanitizing inputs with code delimiters and hardening our system prompts to force the LLMs to act strictly as parsers.
Accomplishments that we're proud of Successfully orchestrating a Compound AI System. Instead of relying on one massive, expensive model for everything, routing fast/cheap tasks to NVIDIA NIM and complex reasoning tasks to Gemini makes the architecture highly efficient and scalable.
We are also extremely proud of achieving a true Zero-False-Positive architecture through the honeypot method, and moving beyond just application security by implementing the OS-level file monitor to catch direct database theft.
What we learned We learned that in cybersecurity, latency is the enemy. Building this taught us how to optimize data flow so that an attack can be detected, parsed by an AI, and sent as a push notification to a phone in under two seconds. We also learned how to effectively translate raw, messy technical logs (like SQL injection syntax) into actionable, empathetic alerts that a non-technical user can immediately understand and act upon.
What's next for Digital-Tripwire The immediate next step is solving the deployment friction. We plan to package the entire system—Flask app, database, and background monitors—into a single Docker container for a one-click installation process.
Log in or sign up for Devpost to join the conversation.