WhatsApp introduces On-Device Machine Learning to Detect Scams

WhatsApp is preparing to strengthen its security features by introducing a new scam-alert system powered by machine learning that runs directly on users’ devices. The technology is designed to identify potentially fraudulent messages and calls, particularly those coming from people who are not saved in the user’s contacts. By analyzing conversational structures and linguistic patterns, the system can assess whether an interaction resembles known scam behavior.

The machine-learning tool is designed to examine a set of predetermined parameters associated with suspicious communication. Instead of relying entirely on cloud-based analysis, the proposed system processes the relevant information locally on the user’s smartphone. This approach is intended to provide an additional layer of protection while maintaining WhatsApp’s strong focus on privacy.

Users would need to download and enable the machine-learning-based Scam Alert tool before it can analyze suspicious communications. Once activated, the feature can classify interactions as potentially fraudulent or legitimate based on the characteristics of the conversation. Importantly, WhatsApp says that information required for the analysis is processed on the device rather than being routinely transmitted to remote servers for examination.

The on-device approach is particularly significant from a privacy perspective. WhatsApp has emphasized that its Scam Alert system is designed around three key principles: processing information locally, avoiding the unnecessary transmission of data to remote servers, and giving users control over how the security feature operates. By keeping the analysis on the device, the company aims to reduce concerns about sensitive conversational information being shared externally.

The feature also leaves the final decision with the user. If a message or call is flagged as potentially suspicious, users can choose to block or report the sender. Alternatively, they can continue the conversation if they believe the communication is legitimate or that the system has incorrectly identified it as suspicious. This gives users an opportunity to make their own judgment rather than automatically restricting communications.

On-device spam and scam detection is not an entirely new concept. Similar technologies have already been used in parts of the Android ecosystem, particularly through network operators and smartphone security services, to identify and filter unwanted calls and messages. WhatsApp’s approach, however, seeks to integrate machine-learning-based scam detection directly into its messaging environment.

The company is also involving security researchers through its Bug Bounty Program, encouraging external experts to examine the technology and identify potential weaknesses. The beta version of the feature has reportedly been made available to a limited group of users in selected Western markets.

With scams becoming increasingly sophisticated, WhatsApp’s move toward on-device machine learning could provide users with an additional layer of protection without compromising its broader privacy objectives. The combination of automated detection and user control could make it easier for people to recognize potentially harmful communications before they become victims of fraud.

Join our LinkedIn group Information Security Community!

Naveen Goud
Naveen Goud is a writer at Cybersecurity Insiders covering topics such as Mergers & Acquisitions, Startups, Cyber Attacks, Cloud Security and Mobile Security

No posts to display