SafeDM: Making Digital Communication Safer with AI

Inspiration

Digital communication has become an essential part of our daily lives, but it also exposes users to phishing attacks, online scams, malicious links, and social engineering. Fraudulent messages can appear completely legitimate, making it difficult for users to recognize potential threats before it is too late.

We were inspired to build SafeDM to help people identify suspicious messages before interacting with them. Our goal is to make digital communication safer by providing users with clear warnings, understandable explanations, and practical recommendations.

What It Does

SafeDM is an Android application designed to detect potentially malicious messages from WhatsApp, SMS, and email notifications.

The application uses Gemini 2.5 Flash to analyze message content and identify suspicious patterns, such as urgent requests, phishing attempts, and attempts to obtain sensitive information. When a message contains URLs, SafeDM uses VirusTotal to assess their potential risk.

Instead of simply labeling a message as dangerous, SafeDM aims to explain why it may be suspicious and recommend appropriate actions.

Key features include:

  • Automatic threat detection: Analyze notifications from user-selected applications.
  • AI-powered analysis: Identify suspicious language, phishing attempts, and social engineering tactics.
  • URL security analysis: Check detected links using VirusTotal.
  • Risk assessment: Present a risk score, severity level, explanations, and recommendations.
  • Manual analysis: Allow users to copy and paste suspicious messages for examination.
  • Community reporting: Enable users to report suspicious messages and help build a shared database of known threats.
  • Threat awareness: Allow users to consult previously reported threats and access a guide to safer digital practices.
  • Privacy-focused design: Keep analyzed messages off the server by default, retaining their content for the community database only when users explicitly report them.

SafeDM is designed as a preventive tool. It informs and advises users without blocking their messages or preventing them from making their own decisions.

How We Built It

We designed SafeDM around three main components: an Android application, a backend API, and an administration dashboard.

1. Mobile Application

We chose React Native to build the Android application and create an accessible user interface. Because notification monitoring requires native Android capabilities, we designed a native NotificationListenerService to retrieve the available content of notifications from applications selected by the user.

2. Backend and Database

We selected FastAPI to handle authentication, message analysis, threat reporting, and communication with external services. PostgreSQL serves as the database for user accounts, reported threats, community reports, URL analysis results, and educational content.

3. AI-Powered Threat Detection

We designed an analysis pipeline that combines semantic analysis with URL threat intelligence.

The message content is analyzed using Gemini 2.5 Flash to identify suspicious behavior and generate structured results. URLs found in the message are checked using VirusTotal. The backend then combines the available results to produce a risk assessment and actionable recommendations.

4. Community-Based Threat Intelligence

We incorporated a community reporting mechanism to help SafeDM recognize threats that have already been reported. Reported messages can serve as references for future analyses, while duplicate reports from the same user are controlled to reduce artificial inflation of community reports.

5. Administration Dashboard

We also planned a React-based administration dashboard to monitor platform activity, review reports, track emerging threats, manage educational resources, and supervise the overall system.

What We Learned

Working on SafeDM helped us explore how artificial intelligence can be applied to a practical cybersecurity problem.

We learned the importance of combining different sources of information rather than relying on a single detection mechanism. AI can help interpret the meaning and intent of a message, while URL analysis provides additional information about potentially dangerous links.

We also learned that security is not only about detecting threats; it is about communicating risk clearly. Users need to understand why a message is suspicious and what they should do next.

Another important lesson was the importance of privacy by design. Message analysis can involve sensitive personal information, so data collection and retention must be carefully limited. SafeDM therefore distinguishes between temporary analysis and the explicit reporting of content to the community.

Finally, we gained a better understanding of the challenges of integrating mobile operating system capabilities, backend services, external APIs, and community-driven threat intelligence into a coherent application.

Challenges We Faced

Accurate Threat Detection

Not every message containing a link or urgent language is malicious. One of our main challenges was designing an approach that considers the context of a message and avoids treating every suspicious-looking message as a confirmed threat.

Integrating Multiple Services

Combining Gemini 2.5 Flash, VirusTotal, FastAPI, PostgreSQL, and native Android notification monitoring requires reliable communication between multiple components. The system must also handle network failures, timeouts, unavailable services, and incomplete notification content without incorrectly declaring a message safe.

Protecting User Privacy

Messages can contain personal and confidential information. We therefore designed a data-retention policy in which ordinary analyses are not stored on the server by default, while explicitly reported messages can contribute to the shared threat database.

Building a Useful Community Database

Community reporting can improve threat recognition, but duplicate reports and inaccurate classifications can affect the quality of the results. We designed mechanisms to prevent duplicate reports from the same user from artificially increasing a threat's community score.

Working Within the MVP Scope

We deliberately limited the initial scope to Android, WhatsApp, SMS, and email notifications. This allowed us to focus on the core experience: detecting suspicious messages, analyzing their links, explaining the risk, alerting users, and supporting community reporting.

What's Next?

Our next steps are to implement and validate the complete detection pipeline, improve the reliability of risk assessments, test the application against realistic phishing and scam scenarios, and refine the user experience.

We also aim to strengthen community threat intelligence, improve administration tools, and evaluate the system's accuracy under different conditions.

Our long-term vision is to make SafeDM a practical and accessible tool that helps people recognize digital threats before they become victims of online scams.

Our Vision

SafeDM is built on a simple principle: everyone deserves safer digital communication.

By combining AI-powered message analysis, URL threat intelligence, understandable warnings, and community collaboration, we want to help users make more informed decisions and navigate the digital world with greater confidence.

Built With

Share this project:

Updates

Submission history