Inspiration
Scams, phishing, impersonation, and fraudulent messages are becoming increasingly convincing, especially as AI makes it easier to create realistic communication. Many people know they should be careful, but they often cannot identify why a message is suspicious.
We were inspired to build ScamLens to give people a simple way to pause and verify before they click, pay, or share sensitive information.
Our goal is to turn a complex cybersecurity assessment into something understandable:
$$ \text{Message} \rightarrow \text{Risk Signals} \rightarrow \text{Explanation} \rightarrow \text{Action} $$
Instead of simply labeling a message as a scam, ScamLens explains the warning signs in a way that anyone can understand.
What it does
ScamLens is an AI-powered scam and impersonation risk assessment tool.
Users can paste a suspicious message or upload a screenshot. ScamLens extracts the text when necessary and analyzes it for indicators such as:
- Impersonation
- Urgency and pressure
- Requests for money or sensitive information
- OTP and credential requests
- Suspicious links
- Fake job offers
- Investment and giveaway scams
- Social-engineering patterns
The system provides an AI Risk Confidence score, risk level, scam category, detected red flags, explanations, and recommended actions.
Instead of simply saying "Scam", ScamLens answers:
What is suspicious? Why does it matter? What should I do next?
We designed the assessment around multiple signals rather than relying on a single keyword. Conceptually, the risk assessment can be represented as:
$$ R = f(S_1,S_2,S_3,\ldots,S_n) $$
where (R) represents the overall risk assessment and (S_i) represents an individual suspicious signal.
How we built it
We built ScamLens as a modular AI application using Python, FastAPI, Streamlit, OCR, and SQLite.
The architecture follows:
User Input
↓
Text / Screenshot
↓
OCR (if required)
↓
Text Analysis
↓
AI Scam Analysis
↓
Risk Assessment
↓
Explainable Results
↓
Recommended Actions
The FastAPI backend handles the analysis pipeline and API requests, while Streamlit provides the user interface.
SQLite stores analysis history and enables users to review previous assessments and view basic statistics.
The AI produces structured information containing the risk level, confidence, scam category, evidence, explanations, and recommended actions.
We deliberately separate the AI assessment from the final user-facing explanation:
$$ \text{AI Analysis} \rightarrow \text{Structured Result} \rightarrow \text{Human-readable Explanation} $$
This makes the output easier to validate, display, and understand.
Challenges we ran into
One of our biggest challenges was balancing usefulness with accuracy.
A legitimate message can sometimes contain urgency, payment instructions, or security warnings, so detecting a single suspicious phrase is not enough. We had to design the analysis around multiple signals and avoid automatically labeling every unusual message as fraudulent.
Another challenge was screenshot analysis. OCR can struggle with poor-quality images, unusual fonts, overlapping elements, or incomplete screenshots.
We therefore included an extracted-text review step so users can correct OCR mistakes before analysis.
We also had to think carefully about AI confidence. A confidence score should not be presented as a guaranteed probability that something is fraudulent.
Therefore, ScamLens uses AI Risk Confidence as an indication of how strongly the system supports its assessment rather than claiming:
$$ P(\text{Scam}) = \text{True Probability} $$
This distinction helps us communicate the limitations of AI-based risk assessment more responsibly.
Accomplishments that we're proud of
We are proud that ScamLens goes beyond a basic "Scam / Not Scam" classifier.
The system provides an explainable assessment that connects:
$$ \boxed{\text{Risk} \rightarrow \text{Evidence} \rightarrow \text{Explanation} \rightarrow \text{Action}} $$
We built a screenshot analysis workflow, OCR extraction, risk categorization, analysis history, and dashboard around the core AI functionality.
Most importantly, we created a practical cybersecurity tool focused on helping everyday users make safer decisions rather than requiring them to understand cybersecurity terminology.
What we learned
We learned that building an AI application is not only about getting a model to produce an answer. The surrounding system matters just as much.
We learned the importance of:
- Structured AI outputs
- Input validation
- OCR reliability
- Explainable AI
- Handling uncertainty
- False-positive considerations
- Secure handling of untrusted user input
- Designing AI results for non-technical users
We also learned that a good cybersecurity product should help users make better decisions, rather than simply giving them a classification.
A useful AI security system should therefore optimize for more than classification accuracy:
$$ \text{Useful AI} = \text{Detection} + \text{Explanation} + \text{Actionability} $$
What's next for ScamLens
We want to expand ScamLens into a broader personal cybersecurity assistant.
Future improvements include:
- Browser extension for suspicious webpages and messages
- Email analysis
- Multilingual scam detection
- Voice scam detection
- Stronger URL and domain verification
- Organization identity verification
- Real-time scam intelligence
- Mobile applications
- On-device analysis for improved privacy
Our long-term goal is to make ScamLens a simple first line of defense that helps people recognize, verify, and respond to suspicious communication before it becomes a loss.
Ultimately, we want to move from:
$$ \text{“Is this a scam?”} $$
to:
$$ \text{“What should I verify before I act?”} $$
Log in or sign up for Devpost to join the conversation.