
Model called Smish-Checker analyzes content, domains and connections in real time to combat text message fraud.
Unicamp researchers developed Smish-Checker, an artificial intelligence model created to identify and block SMS smishing scams in real time, analyzing suspicious texts, domains and connections.
AI-generated summary
Research developed at Unicamp's Computing Institute created an AI model to combat SMS fraud.
Receiving a text message with a link apparently sent by a bank, store or other well-known company is already part of the routine of anyone who uses a cell phone. The problem is that, in some cases, the address can lead to a fake page created to steal data.
Research developed at the Computing Institute (IC) of the State University of Campinas (Unicamp) created an artificial intelligence model capable of analyzing different characteristics of these messages and helping to identify possible fraud.
📩 Understand: this type of scam is known as smishing, a combination of the words SMS and phishing. Fraud occurs when criminals use text messages to try to get the victim to reveal information or access malicious pages.
Smish-Checker was created by computer scientist Stephane Schwarz, during her doctorate, at the Recod.ai laboratory, coordinated by professor Anderson Rocha. The research arose from a need presented by a cloud communication company.
According to the researcher, the idea was to find a way to filter fraudulent messages in real time without blocking legitimate communications. The system is being applied and helps to stop suspicious SMS before they reach users.
"The tool not only seeks to block fraudulent content, but it also needs to maintain a very high assertiveness rate. Because blocking legitimate content is very bad in a real business context", explains Stephane.
How does AI try to identify a scam?
The solution combines different pieces of evidence. Instead of relying solely on the appearance or writing of a message, the system can observe everything from small changes in characters to information about a website's domain and connection-related characteristics.
💡 Stephane says that the development began with an attempt to understand how fraudsters themselves seek to circumvent security systems.
One of the strategies identified is to make very small changes to messages or email addresses. The change may be practically imperceptible to a person, but it changes the way the computer interprets that character.
Imagine a message that tries to impersonate a well-known company. To do this, the fraudster can:
replace a letter with another visually similar character;
insert spaces or characters in the middle of words;
subtly change the way a brand is written;
hiding a real address inside a URL shortener;
create a fake page visually similar to the original.
"What we noticed is that what he often did was change subtle characters in a message so that the message could pass through the model, but in the end the user would not notice this change."
An example cited by Stephane involves the letters capital I, lowercase i and lowercase L, which can have a similar appearance depending on the combination used. For the computer, however, they are different characters because they have different codes.
Camouflaged links are also included in the analysis
Another strategy used by criminals involves URL shorteners. A long email address can reveal, for example, that the website to which the person will be directed does not belong to the company mentioned in the message. With shortening, the original link is hidden.
According to Stephane, fraudsters can use these general purpose services to make it difficult to identify the malicious URL. The tool developed in the research can analyze these characteristics related to the domain. Among the data considered are:
domain age;
who registered the page;
when the domain was created;
when there were changes;
TLD, which corresponds to the final part of the electronic address, such as ".com".
This information is public and can be used in conjunction with analysis of the message content. The analysis therefore does not depend on a single signal.
"We don't stick to just one vantage point. We look at multiple layers and multiple information so that we have a more accurate and precise response", explains Stephane.
What if the fake page is practically identical to the real one?
A scam may also use a fake page that copies the look of a legitimate website, as a clone. The person enters, sees an apparently real screen and starts filling in their data.
In some cases, the criminal manages to make the fake website connect to the real one. The strategy is known as man in the middle. In practice:
the victim accesses the fake page, thinks it is real and enters his data;
the scammer monitors the information that the victim places on the fake page;
it passes this information and data to the legitimate website through this connection;
the victim may not realize that their data is passing through the criminal's system;
the criminal can access the person's data on the real website.
To try to identify this type of behavior, the tool created by Stephane also analyzes how long it takes for a connection to be established. This occurs because when someone clicks on a link, the cell phone needs to communicate with the server where the page is hosted.
This process involves a series of procedures that take place behind the scenes and are not noticed by the user. Smish-Checker analyzes characteristics of this process, such as the time it takes for the website to respond and load.
💻 In short: in addition to analyzing the content of the message and the link address, the technology also looks for suspicious signs in the website's own behavior.
Is the technology already being used?
Part of the research is already used by an international communications company, according to the researcher. The company works as an intermediary between other brands and their customers and, among other services, works with sending SMS.
In a simplified way, the message path is as follows:
a brand hires a communications company to send SMS to customers;
the communications company acts as an intermediary between this brand and the customers’ operator;
the operator receives the messages and forwards them to customers;
customers receive the message on their cell phone.
It is precisely in this intermediation stage, before the message reaches the operator, that artificial intelligence is used. If it finds suspicious behavior in the message, it stops it from being sent and prevents it from reaching customers.
Why is artificial intelligence necessary?
The researcher points out that fraudulent messages no longer necessarily need to present gross errors in Portuguese or an obviously suspicious appearance. With generative artificial intelligence tools, criminals can produce more natural and convincing texts. This makes it more difficult to rely on superficial characteristics of the message.
Additionally, there is the challenge of volume. A person would not be able to read, compare and identify patterns in millions of individual messages. Artificial intelligence makes it possible to do this work on a large scale, bringing together similar messages and identifying patterns between them.
In one of the experiments, the Smish-Checker system grouped 12 million messages into 17 thousand groups. Thus, instead of analyzing each message separately, the tool can first work with groups of similar content and, based on examples, identify which of them may be fraudulent.
Therefore, the project proposal is to combine different types of evidence:
what is written;
where the link leads;
domain information;
and technical characteristics of the connection.
It's a race between whoever creates the blow and whoever tries to block it
Technology, however, does not represent a definitive solution. The researcher compares the fight against scams to a constant dispute between criminals and security systems.
"It's always a fight between a cat and a mouse. While one develops a way to block, the other is already thinking of a way to circumvent that system you just developed."
This means that a pattern identified today may no longer be useful tomorrow if fraudsters change their strategy. Therefore, according to Stephane, there is still room for new research and continuous improvement of detection tools.
Furthermore, she remembers that the user's attention and distrust continue to be fundamental. For her, education and awareness are important for people to recognize signs of scams and protect themselves.
"The first thing we have to think about improving is education. It's how to get this message across, how we can train people to distrust messages that are often too good to be true."

OpenAI reports that user-submitted images were published on hosting sites and that research agents improperly transmitted data to third parties.

Five IFPA students in Marabá (PA) won the national stage of the Sustainable Schools Award with the EcoLuz Trap, a R$20 trap for Aedes and Culex mosquitoes. The group will represent Brazil in the international final.

Research indicates that users turn to AI chatbots to make personal decisions and everyday dilemmas. Experts warn of the risk of technological dependence and deviations in consumption recommendations.

TikTok and ByteDance agreed with the state of Alabama to pay at least US$100 million, potentially reaching US$300 million, in an agreement that establishes a limit of two hours of daily use, breaks after 15 minutes and stricter age verification mechanisms, days before a trial that accused the platform of addicting teenagers and contributing to mental health crises.

The U.S. Court of Appeals for the Columbia Circuit upheld Anthropic's designation as a risk to the U.S. national security supply chain, a decision the company says cost it billions in lost business and damaged its reputation ahead of a long-awaited IPO. Anthropic respectfully disagreed with the decision and is evaluating legal options, including judicial review.

PG Tech 2026 takes place at the Municipal Kartódromo in Santos, with more than 250 lectures on ten stages, attractions such as Startup Vila, Hands-On Arena and 360º planetarium, as well as competitions with prizes of up to R$10,000. The event takes place from Thursday to Sunday, with varying times, and accreditation is available via the official website.