I’ve tried giving screenshots of phishing emails to a local Qwen instance and so far it always correctly detected it as scam, even points out the exact elements that it based its judgement on. Sending screenshots to it ad-hoc isn’t too scalable for family and friends. I’d like to be able to either forward emails for screening, or perhaps have it screen everything from a mailbox.

Has anyone done anything like this? Is there anything self-hostable that does this?

  • Shadow@lemmy.ca
    link
    fedilink
    English
    arrow-up
    26
    ·
    11 hours ago

    I’d be pretty concerned about prompt injection risks with feeding a LLM unsanitized data. You definitely need a good harness around it…

    • Avid Amoeba@lemmy.caOP
      link
      fedilink
      English
      arrow-up
      11
      arrow-down
      1
      ·
      11 hours ago

      Good point. It’ll have to have no access to the internet or anything local outside of its container. Just text in, text out.

      • Dran@lemmy.world
        link
        fedilink
        English
        arrow-up
        6
        ·
        6 hours ago

        You could (and probably should) use a system-one style inference system for spam classification. Much cheaper and the structured output means it’s impossible to go rogue and curl some malware or whatever. It can absolutely misclassify but its output is programmatically structured and just ranks a pre-selected set of output tokens.

        In your case that’s

        Spam

        Not_spam

      • Zikeji@programming.dev
        link
        fedilink
        English
        arrow-up
        8
        ·
        10 hours ago

        Yeah if it’s just a basic input with a function call for spam or not spam the risk is low. What’s the worst case outcome, it tricks it into saying no it isn’t a scam and you have to delete it manually? Hahaha