AI Anti-Spam Shield
Machine-learning defense against AI-generated phishing across SMS, voice and chat.
- Engagement
- Cambotix product
- Industry
- Security & AI
- Year
- 2026
The challenge
Generative models made convincing scams cheap. A phishing message that once read as obviously fake now arrives in fluent Khmer, and voice cloning turned the 'I recognized their voice' defense into a liability. Consumer devices ship with no meaningful protection against any of it.
Our approach
We split the system where the skills differ: a Python service handles inference, while a Node backend handles the product. The ML side can improve models without touching authentication, accounts or alerts. Detection combines a fine-tuned transformer for semantics with cheaper URL and brand-impersonation rules. The transformer catches persuasion; the rules catch the payload.
What it had to achieve
- Classify a suspicious message in under a second on a mid-range phone
- Cover three attack surfaces: text, voice and links, not only email spam
- Explain why something was flagged, so users learn instead of blindly trusting
- Keep model serving isolated from the product backend
Architecture
The decisions that made the rest possible.
Inference isolated behind FastAPI
Models run in their own Python service with a separate scaling profile. Swapping or rolling back a model requires deploying only that service. The product backend does not change.
Layered detection instead of one model
A BERT-family classifier scores the message text, while separate passes handle URL reputation and brand-impersonation patterns. Each layer is independently tunable, so a false-positive spike can be traced to one component.
Speech-to-text as a front door, not a special case
Voice messages are transcribed and then run through the same text pipeline. One detection path to maintain and improve, three input types supported.
Explanations shipped with every verdict
The API returns the contributing signals alongside the score, so the app can tell a user which part of a message looked wrong rather than just showing a red badge.
What we delivered
- Flutter app with message scanning, voice-note analysis and alert history
- Text spam and phishing classifier with confidence scoring
- Speech-to-text pipeline feeding the shared text classifier
- URL and brand-impersonation detection for embedded links
- Node.js backend for accounts, scan history and real-time alerts
- FastAPI ML service with versioned model endpoints
Security & reliability
- Message content processed for classification and not retained beyond the scan record
- Model versions pinned per request so a rollback restores prior behavior exactly
- Server-side confidence thresholds that can be tuned without an app release
Outcomes
What changed once it was live.
- Three attack surfaces covered by one detection pipeline
- Model improvements ship without a mobile release
- Flagged messages come with a reason, making the tool teach rather than dictate
What we would do differently
Every project teaches something. Publishing it is how you tell whether a team is reflecting or just selling.
- Routing transcribed voice into the text classifier was the highest-leverage decision in the project. It turned a second product into a second input.
- Explainability was treated as a UI nicety at first. It turned out to be the difference between users trusting a flag and disabling the feature.
Let's find out if this is worth building.
A 45-minute discovery call, free. You describe the problem, we tell you honestly what it takes, what it costs, and whether you should build it at all.