Status
Open source · prototype
Period
May – June 2026
Stack
FastAPI · scikit-learn · NetworkX · React
Source
Missing a fraud is worse than showing an analyst a borderline post.
Four independent signals, one weighted score. The threshold is set low on purpose: the system surfaces, a person decides.
1Problem
Fraud aimed at bank customers spreads through the same channels as the news about it. The messages repeat a handful of scripts: a card or account “blocked” until you pay, a prize that needs a fee, a call from a fake bank security service asking for an SMS code, fake state payouts, delivery and customs fees, investment and crypto schemes, loans with an upfront fee, fake tech support, and remote jobs that are recruitment scams.
2Task
Build the implementation part of a thesis in information security (10.03.01): a working system that monitors messages and flags likely fraud, with targets of F1 at least 0.68 and precision at least 0.70. Later the priority changed to recall — a missed fraud costs more than an analyst’s click.
3Method
Collect
Messages come in over a REST endpoint and CSV upload, from RSS feeds of finance press and the central bank, and from public Telegram channels through their web preview.
Clean
Text is lowercased; links, phone numbers and emails are masked; author ids are stored only as hashes.
Rules
A list of Russian keyword stems for the scripts above; each hit adds to a rule score.
Classifier
TF-IDF over character n-grams of 2–4 letters with logistic regression. Character n-grams survive Russian word endings and the Latin-for-Cyrillic letter swaps spammers use.
Training data
21,853 messages: a public dataset of real Russian Telegram spam, plus about 400 phishing messages generated from templates and 30 hand-written legitimate ads and news items — there is no open Russian phishing dataset.
Author graph
Authors are linked when their messages trigger the same flags. An author’s score mixes their own worst message, their neighbours’ average and how often they repeat themselves.
Decide
The four signals combine into one risk score. Anything at 0.2 or above becomes an incident that an analyst confirms or rejects in the web interface.
4Results
char_wb n-grams: robust to Russian morphology AND the latin/cyrillic letter-swapping obfuscation that spammers use.app/ml/model.py
5Limitations
- No real social-network APIs: collection is RSS, public Telegram previews and uploads, chosen for reproducibility.
- The graph is simple and lives in memory — no centrality or community detection — and only messages sent through the API get a graph score.
- Fixed weights; no retraining from the analyst’s decisions; no explanation of individual scores.
- The broad keyword list knowingly flags some legitimate ads and news.
- The evaluation numbers come from development runs, not a separate, fixed test set.