AI-Powered Local Anomaly Detection & Privacy Monitoring System
Privacy Sentinel is a real-time host-based anomaly detection system that monitors system behavior to detect suspicious or privacy-invasive activities.
It combines:
- 🔍 System monitoring (process, network, devices, screen)
- 🧠 Rule-based behavioral intelligence
- 🤖 Machine learning (Isolation Forest)
- 💡 (Planned) LLM + RAG for explainable AI
Modern systems run multiple background processes with no visibility into:
- Microphone / camera usage
- Screen recording / sharing
- Hidden data transmission
- Fake or spoofed applications
Traditional antivirus:
- ❌ relies on signatures
- ❌ fails on unknown threats
👉 Privacy Sentinel solves this using behavior + anomaly detection
System (OS Events)
↓
Monitoring Layer (Sensors)
↓
Context Builder
↓
Identity Verification
↓
Behavior Analysis
↓
Brain Engine (Rule-based)
↓
SQLite Database
↓
Feature Engine
↓
ML Model (Isolation Forest)
↓
LLM (RAG - planned)
- Process creation & termination
- CPU usage tracking
- Network connections (IP + port mapping)
- Microphone & camera access detection
- Screen recording / sharing detection
-
Identity verification (path + signature)
-
Behavior correlation (mic + network, screen + network, etc.)
-
Risk classification:
- 🟢 LOW
- 🟡 MEDIUM
- 🟠 HIGH
- 🔴 CRITICAL
- Uses Isolation Forest
- Learns normal system behavior
- Detects anomalies without labeled data
-
Stores structured logs in SQLite
-
Enables:
- training ML model
- historical analysis
- debugging
-
Explain detected anomalies
-
Answer:
- “Is this dangerous?”
- “Why is this flagged?”
-
Local lightweight models (Mistral / Phi)
privacy_sentinel/
│
├── core/
│ ├── process_monitor.py
│ ├── network_monitor.py
│ ├── device_monitor.py
│ ├── screen_monitor.py
│ ├── context_builder.py
│ ├── identity.py
│ ├── behavior.py
│ ├── brain.py
│ ├── feature_engine.py
│ ├── train_model.py
│ └── predict.py
│
├── database/
│ └── db.py
│
├── model.pkl
├── main.py
└── README.md
git clone https://github.com/your-username/privacy-sentinel.git
cd privacy-sentinelpython -m venv venv
venv\Scripts\activate # Windowspip install -r requirements.txtRequired libraries:
psutil
pandas
scikit-learn
joblib
python main.pyThis will:
- start all monitors (process, network, device, screen)
- log events into SQLite DB
- evaluate risk using brain engine
👉 Let it run for 10–20 minutes
Stop monitoring (Ctrl + C), then run:
python core/train_model.pyOutput:
Training on X samples
Model trained and saved!
After training, the system can:
- classify risk (rule-based)
- detect anomaly (ML)
Example output:
[START] STREAMING detected
Process: chrome.exe
[RISK] LOW
[AI] NORMAL
To simulate anomalies:
- Run apps from
DownloadsorTemp - Use microphone + network (Meet/Discord)
- Screen share (Zoom/Meet)
- Run high CPU scripts
- Rename executables (e.g., fake
chrome.exe)
- Unsupervised learning
- Detects deviations from normal behavior
- CPU usage
- Time (hour of execution)
- Path risk
The system uses correlation-based reasoning:
Example:
mic + network + suspicious path → CRITICAL
screen + network → HIGH
mic only → MEDIUM
- 🔥 LLM + RAG integration
- 📊 Dashboard UI
- 🚨 Real-time alerts
- 🛑 Process blocking
- 🌐 Cross-platform support
- Behavior-based detection (not signature-based)
- Identity + behavior correlation
- Works with no labeled data
- Fully local (privacy-friendly)
Built an AI-powered host-based anomaly detection system that monitors system behavior and detects suspicious activities using rule-based intelligence and unsupervised machine learning.
This project is for educational and research purposes only. It does not replace professional security tools.
Vedant Patil Computer Engineering | AI & Systems Enthusiast
Give it a star ⭐ on GitHub!