Skip to content

Repository files navigation

CyberShield — Adaptive Multi-Modal Cyber Deception Detection System

An end-to-end threat-intelligence platform that detects phishing URLs, fraudulent job postings, and manipulated images by combining four machine learning models through a weighted risk-fusion engine.

Built solo as my MCA major project at RV College of Engineering. Graded A+.

Screenshots


Dashboard

URL scan — phishing detector

Text scan — job scam detector

Image scan — manipulation detector

Multi-modal scanner

Batch scanner

Performance — model metrics

Scan history

What it does

  • URL Scanner — detects phishing URLs using an XGBoost + Random Forest voting classifier
  • Text Scanner — detects fraudulent job postings using TF-IDF + XGBoost
  • Image Scanner — detects manipulated images using Error Level Analysis, DCT/FFT frequency analysis, and Grad-CAM visual explanations
  • Multi-Modal view — combines all signals through a weighted Risk Fusion Engine into a single unified threat score
  • Batch Scanner — scan multiple items at once
  • Performance dashboard — real-time model accuracy, AUC-ROC, and evaluation metrics
  • History — past scan results and trends
  • Explainability — LIME/SHAP-based explanations for why something was flagged

Results

Computed via scikit-learn cross-validation (not hardcoded):

  • 96.4% accuracy, 0.993 AUC-ROC — phishing URL detection
  • 94.2% accuracy — job-fraud text detection
  • 91.7% accuracy — image-forgery detection
  • Sub-2.1s end-to-end inference

Tech stack

Backend: FastAPI, scikit-learn, XGBoost, SQLite, Pillow (image processing), NumPy/SciPy Frontend: React (Vite), Tailwind CSS, React Router Deployment: Dockerized (frontend + backend)

Project structure

majorproject/
├── backend/
│   ├── main.py              # FastAPI app + routes
│   ├── fusion.py            # Risk fusion logic
│   ├── models/
│   │   ├── url_detector.py       # XGBoost + Random Forest
│   │   ├── text_detector.py      # TF-IDF + XGBoost
│   │   ├── image_detector.py     # ELA/DCT/FFT + Grad-CAM
│   │   └── anomaly_detector.py   # Isolation Forest
│   ├── train_phishing_model.py
│   └── requirements.txt
└── frontend/
    ├── src/pages/           # Dashboard, URLScanner, TextScanner, ImageScanner,
    │                        # MultiModal, BatchScanner, Performance, History
    ├── src/components/      # Navbar, RiskBadge, ScoreBar, ThreatGauge,
    │                        # AnomalyPanel, ExplainabilityPanel
    └── src/hooks/           # useApi, usePdfExport

Running it locally

Two parts — backend and frontend — run both, in separate terminals.

Backend:

cd backend
python -m venv venv
source venv/bin/activate  # Windows: venv\Scripts\activate
pip install -r requirements.txt
python main.py

Runs at http://localhost:8000 (check .env.example if you've changed the port).

Frontend:

cd frontend
npm install
npm run dev

Runs at http://localhost:5173. This project uses Vite, so it's npm run dev, not npm start — that'll fail with "Missing script: start".

Docker

Both backend/ and frontend/ include Dockerfiles if you'd rather run it containerized:

docker-compose up

About me

Mohit Raj, MCA graduate from RV College of Engineering (CGPA 7.90, First Class with Distinction). GitHub · LinkedIn · LeetCode

About

CyberShield — multi-modal cyber deception detector: phishing URLs, fraudulent job posts & manipulated images, fused into one risk score. FastAPI/XGBoost backend, React frontend.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages