Inspiration

What it does

How I built it

Challenges I ran into

The 2 AM Phone Call

Imagine your father gets a call at 2 AM. A voice says it's the CBI. There's a case filed against him. He needs to stay on the line. He needs to transfer money to a "verification account." He can't tell anyone. He can't hang up.

He doesn't know that this is a "digital arrest" — India's fastest-growing scam. He doesn't know that losses from this one scam grew 21x in two years, from ₹91 crore in 2022 to ₹1,935 crore in 2024. He doesn't know that reported cases nearly tripled to over 1.2 lakh in 2024.

He just knows he's scared. And nobody is there to tell him: "Pause. This is a scam. Here's why."

That's the moment RakshaOS exists for.

The Problem Nobody's Solving

Digital fraud in India isn't a niche risk anymore. It's a daily, national-scale emergency — and it's landing hardest on the people least equipped to spot it.

  • India recorded 12.71 lakh cyber-fraud complaints in just the first six months of 2026. Losses exceeded ₹10,178 crore. Only 29% of that money was ever placed on hold or recovered.
  • The Supreme Court has noted that cumulative digital scam losses for Indians now exceed ₹52,000 crore — larger than the annual budget of several states.
  • Victims are disproportionately elderly citizens, first-time UPI users, and people under sudden psychological pressure — fake police calls, fake courier fees, fake KYC deadlines.

And here's the gap that makes your blood boil:

Truecaller, spam blockers, antivirus apps — they only filter known bad numbers or known bad links.

None of them look at what a message is actually asking you to do.

Nobody helps an ordinary person answer the one question that matters in the moment:

"Is what I'm being asked to do right now actually safe?"

RakshaOS answers that question. In plain language. Before it's too late.

What It Does

Forward RakshaOS anything suspicious — a message, a screenshot, a QR code, a document — and it hands back three things:

  1. A risk verdict — Safe / Warning / High Risk / Emergency
  2. Plain-language reasons — itemised, not black-box
  3. A recommended next step — e.g., "Don't pay. Verify through the official provider's app or helpline."

The reasoning follows a simple chain any human can follow:

  • Who sent it — and can that identity actually be trusted?
  • What is it asking you to do — pay, click, share an OTP, install something?
  • Is there artificial urgency or fear baked into it?
  • Is the sender impersonating authority — police, bank, government, courier?
  • Where does the link or QR actually lead — not where it claims to lead?
  • Is money, an OTP, or login credentials being requested?
  • Does the requested action even make logical sense?
  • How closely does it match known scam patterns?

These signals collapse into one risk score, a short list of reasons, and one clear action.

And for families with elderly relatives: a high-risk flag can be shared with one tap to a trusted contact — so the person facing the scam isn't the only line of defence.

Why This Is Different

Most scam detectors stop at a yes/no label. RakshaOS asks a better question — and answers it with depth.

Typical scam detector RakshaOS
"Is this message a scam?" "What is the user being asked to do, how risky is that action, why, and what's the safest next step?"
Binary scam / not-scam label Every scam is represented as a behavioural signature — urgency, authority impersonation, payment request, external link — so new variants get caught, not just previously-seen ones
Black-box flag Always shows an itemised, plain-language explanation behind the risk score
Stops at detection Covers the full lifecycle — prevent, detect, explain, respond, and recover, including help for users who've already paid
Cybersecurity-only framing Also covers consumer protection (fake discounts, manipulative urgency) and accessibility, with explanations read aloud in the user's own language
Gemini Nano scam-call screening (Nov 2025) — calls-only, English-first, Pixel 9+ only, under 1% of Indian Android base Works across every channel a scam actually arrives through — SMS, WhatsApp, QR, screenshots, documents — on any phone, with multilingual voice output on the roadmap

The one-line version: Everyone else detects known scams. RakshaOS understands what you're being asked to do — and that's what catches the ones nobody's seen yet.

Who It's For

  • Everyday smartphone and UPI users drowning in SMS, WhatsApp, email, and call-based scam attempts.
  • Elderly and less digitally-literate Indians — the group most frequently targeted, and hit hardest.
  • First-time digital-payment users in semi-urban and rural areas.
  • Families who want to protect older relatives without turning them into cybersecurity experts.

The Impact We're Chasing

  • Stop the payment before it happens — not just help after the money's gone.
  • Give people a path forward even after they've paid — directly attacking India's brutal ~29% fund-recovery rate.
  • Build real scam literacy over time — every interaction comes with a reason, not just a warning.
  • Go beyond financial fraud — into consumer protection (fake discounts, manipulative selling) and public-service safety (fake government or scholarship notices).
  • Surface new scams early — as more people use it, fast-spreading patterns can trigger a regional warning before the scam peaks.
  • Track progress concretely — classifier precision/recall, time-to-verdict, and the share of high-risk flags where users report they didn't proceed.

How We Built It

Four layers. Simple enough to demo live. Honest enough to grow later.

1. Perception Layer

  • OCR (Tesseract or similar) turns screenshots and documents into text.
  • QR-decoding libraries extract destination URLs.
  • Basic domain and keyword heuristics.

2. Reasoning Layer

  • A single, carefully-prompted call to Gemma 4 E2B/E4B — Google DeepMind's small, multimodal, open-weight models (April 2026).
  • Returns a structured output: risk score, detected signals, plain-language explanation.
  • Small enough to run on-device — sensitive screenshots and messages stay off a server by default.
  • Grounded with real scam patterns from I4C, the 1930 cyber-fraud helpline, cybercrime.gov.in, and verified news reports.

3. Decision Engine

Maps the verdict to one of four states: Safe → Warning → High Risk → Emergency.

4. Response Layer

Warns the user. Suggests verification steps. Guides them. Drafts a complaint if needed. Saves evidence. Alerts a trusted contact. Reads the explanation aloud in the user's own language.

Tech Stack

Component Technology
Reasoning core Gemma 4 E2B/E4B (on-device)
OCR Tesseract
QR decoding Standard QR libraries + heuristics
Frontend Flutter / Android (Kotlin)
Backend (optional) Python / FastAPI
Voice output TTS in 2–3 languages
Grounding data I4C, 1930 helpline, cybercrime.gov.in advisories

The Hard Parts (And How We Handled Them)

1. False positives can be dangerous. A "high risk" verdict on a genuine urgent action could stop someone from doing something they need to do. So we don't hard-block — we give confidence-scored guidance: "High risk — verify first."

2. Novel scams don't use known keywords. That's why we use behavioural signatures instead of blocklists. Urgency + authority + payment request = suspicious, regardless of the exact words. Grounding gets refreshed from I4C and 1930-helpline advisories as new patterns emerge.

3. LLMs hallucinate explanations. We constrain the model with a structured output schema and cross-check it against deterministic signals — known scam-URL lists, domain age, QR destination. The model's reasoning alone is never trusted.

4. Sensitive data must stay sensitive. On-device inference by default. No permanent storage of screenshots or financial details beyond the session — unless the user opts in to save evidence for a complaint.

5. Family alerts should never be automatic. Trusted-contact sharing is always a one-tap user action. Never silent. Never automatic.

What We Learned

  • Scam detection is a communication problem, not just a classification problem. The explanation matters as much as the verdict.
  • Behavioural signatures beat keyword lists. Every time.
  • On-device AI is finally practical for this — but prompt engineering and structured outputs are non-negotiable.
  • Designing for elderly users forces radical simplicity. One verdict. One reason list. One action.
  • The recovery flow is as important as prevention. With a ~29% fund-recovery rate, "what to do after you've paid" is not an edge case — it's the main event for lakhs of people.

What's In Scope (MVP) vs. What's Roadmap

✅ In scope for the hackathon

  • Text / WhatsApp message input → risk analysis → risk card with reasons + recommended action
  • Screenshot input → OCR → same pipeline
  • QR code input → decoded → heuristics → same pipeline
  • "I already paid" flow → pre-filled complaint draft + evidence checklist
  • One-tap trusted-contact sharing for high-risk results
  • Basic voice output in two or three languages

🔜 Out of scope for now — but very much the plan

  • Live voice-call monitoring (needs telephony-level integration)
  • Real-time bank / telecom / government integration (no public API exists today)
  • Custom-trained NLP or CV models (a single LLM call replaces this for the hackathon timeline)

Where This Goes Next

Beyond the hackathon, the same core engine can sit behind every channel a person actually uses — WhatsApp, SMS, email, browser, payments, QR codes, calls, shopping — all resolving to one verdict: Safe. Warn. Protect.

  • Live call analysis, including detection of AI-generated (deepfake) voices.
  • Bank or telecom-level integration that can place a real-time hold on a high-risk transaction.
  • Family-shield mode that runs by default for elderly users who opt in.
  • Public early-warning feed built from aggregated, anonymised signals — shared with local cyber-cells and consumer-protection bodies.
  • Voice support expanding across more regional languages.
  • Freemium sustainability path — free core detection, paid family-shield tier for multi-relative monitoring, plus an embedded-protection SDK/API for banks, UPI apps, and telecom operators who have a direct financial incentive to cut fraud losses on their own books.

Built With (Detailed)

  • Gemma 4 E2B/E4B — Google DeepMind's small, multimodal, open-weight models (April 2026)
  • Tesseract OCR — screenshot and document extraction
  • QR decoding libraries — destination URL extraction
  • Flutter / Android (Kotlin) — cross-platform mobile frontend
  • Python / FastAPI — optional backend for grounding refresh
  • TTS engine — multilingual voice output
  • I4C, 1930 helpline, cybercrime.gov.in — grounding data
  • On-device inference — privacy-first architecture

RakshaOS isn't another scam detector. It's the answer to the question every Indian asks too late: *"Wait — was that actually safe?"*

Built With

  • accessibility
  • android
  • consumer-protection
  • cybersecurity
  • edge-ai
  • fastapi
  • flutter
  • fraud-prevention
  • gemma
  • gemma-4
  • google-deepmind
  • kotlin
  • llm
  • multilingual
  • multimodal
  • ocr
  • on-device-ai
  • privacy
  • python
  • qr-code
  • scam-detection
  • tesseract
  • text-to-speech
  • upi
Share this project:

Updates

Submission history