Inspiration
Most privacy tools use a static blocklist: either traffic is blocked or it is not. But the right privacy policy can depend on what the network is actually doing.
I wanted to build a privacy firewall that could observe changes in network behavior, reason about those changes with AI, and adapt its filtering policy without sending raw browsing data to the cloud.
That became PrivacyPi: an AI-powered adaptive privacy firewall with a human in the loop.
What it does
PrivacyPi monitors DNS activity locally and supports three privacy profiles:
- NORMAL — a compatibility-oriented baseline
- STRICT — stronger general tracking and telemetry filtering
- YOUTUBE — a specialized profile for video-heavy workloads that preserves core video delivery while applying video-related privacy rules
Raw domains, URLs, browsing history, and packet contents stay local.
Instead, PrivacyPi converts local activity into privacy-preserving aggregate metrics such as request volume, blocked ratio, tracking categories, and video-related request counts.
Those aggregate measurements are stored in Tiger Data as time-series telemetry. Gemini analyzes the recent history together with benchmark results and returns a structured recommendation for the most appropriate privacy profile.
The AI never changes the firewall automatically. The recommendation is shown to the user, who explicitly approves the policy change.
How I built it
The firewall uses AdGuard Home as the DNS filtering engine. I created layered policy sets for Normal, Strict, and YouTube modes and built Bash tooling to switch profiles dynamically.
For testing, I created an isolated Linux network namespace with a virtual client, DNS routing, and controlled workloads. This makes it possible to replay the exact same traffic under different policies.
A Flask dashboard shows:
- live DNS request and blocking statistics
- locally classified privacy categories
- blocked domains that remain local to the machine
- Gemini's activity classification and policy recommendation
- recommendation confidence and reasoning
- Tiger Data time-series history
- before/after policy measurements
Tiger Data stores only aggregate telemetry. Gemini receives that aggregate history rather than raw browsing information.
For a general tracking workload, the same 20-request test produced:
- NORMAL: 2 / 20 blocked — 10%
- STRICT: 16 / 20 blocked — 80%
PrivacyPi then records both measurements, making the effect of the AI-recommended policy directly measurable.
I also created a video-heavy workload containing 20 requests, 16 of which were classified locally as video-related. In that case, Gemini recommended YOUTUBE instead of STRICT, despite STRICT having the highest overall benchmark score. This demonstrates that the system adapts to workload context rather than always choosing the most aggressive filter.
Challenges
One of the biggest challenges was separating useful AI context from sensitive network data. Sending raw domains to an external model would undermine the privacy goal of the project, so I redesigned the pipeline around aggregate features computed locally.
Another challenge was making the recommendation genuinely adaptive. Initially, the strongest benchmark profile could dominate the decision. I added workload-specific aggregate signals and time-series context so that general tracking traffic can lead to STRICT while video-heavy traffic can lead to YOUTUBE.
I also had to make the demo reproducible. DNS caching, rolling time windows, network namespaces, policy switching, and asynchronous AI requests all introduced edge cases. I built reset and workload scripts so the same controlled traffic can be replayed consistently across profiles.
Accomplishments
I am especially proud that PrivacyPi forms a complete closed loop:
local measurement → privacy-preserving aggregation → Tiger Data time series → Gemini reasoning → human approval → real policy change → measurable result
The system does not just ask an LLM for generic security advice. Gemini reasons over measured network behavior and benchmark evidence, and its recommendation can be applied to the actual firewall.
What I learned
I learned that using AI meaningfully in a systems project requires more than adding a chatbot. The quality of the AI decision depends heavily on how measurements are structured, what context is preserved, and what information is deliberately withheld.
I also learned how useful time-series history is for distinguishing an isolated snapshot from an actual change in behavior.
What's next
I would like to extend PrivacyPi with longer-term adaptive policies, additional workload profiles, latency and compatibility measurements, and deployment on a dedicated edge device.
I would also like to evaluate the recommendation system on real-world household traffic while continuing to keep raw browsing information local.
Built With
- adguard
- bash
- css
- dnsmasq
- flask
- gemini
- html
- javascript
- linux
- nftables
- postgresql
- python
- tigerdata
- timescaledb
- wsl
Log in or sign up for Devpost to join the conversation.