Run a Colab notebook that demonstrates how a generative LLM can be used to create synthetic scam URLs and how a guard / moderation LLM can classify those URLs as Safe, Suspicious, or Likely Fraud.
The lab simulates an AI cybersecurity assistant with two roles:
Use Qwen 2.5 to generate fraudulent URLs across several categories (fake storefronts, crypto rug pulls, tech support scams, etc.).
All URLs are synthetic and use fake brand names, fake tokens, and non-existent domains.
Use a Qwen-based guard classifier to analyze structure, lexical patterns, and risk indicators, labeling the URL as:
Safe
Suspicious
Likely Fraud
High-Risk Fraud
You’ll interact with a small UI that lets you:
Select a scam category and generate multiple synthetic URLs
Paste any URL (generated or real) into a classifier box
Click “Classify URL” and see the guard’s assessment
By the end, you’ll see how easily GenAI can scale scam infrastructure—and how LLM-based defenses attempt to detect it.
Qwen/Qwen2.5-1.5B-Instruct
Generates synthetic scam URLs based on category templates
Requires minimal prompting
Notebook auto-selects GPU if available (optional but helpful)
The same Qwen model is reused with a URL-classifier prompt.
It produces structured responses:
"risk"
"category"
"rationale"
Google Colab (Python 3) — no local installation required
transformers, torch — model loading and inference
ipywidgets — dropdown menus, text boxes, buttons
json, re, random — formatting, parsing, sampling
Built-in templates in case_4.py for URL generation
Category Dropdown: Choose a scam type
Count Slider: Number of URLs to generate
Generate Button: Calls the generator and prints URLs
Paste Box: Paste any URL (generated or real)
Classify Button: Runs URL guard model
Output Panels: Show generated URLs and guard results
URL generation templates for categories:
Fake Storefront
Crypto Rug Pull
Tech Support Scam
Fake Sweepstakes / Lottery
Investment Scam
Fake Charity
You may paste any URL of your choice for classification
Do NOT use real personal or sensitive URLs
Colab Link (M4): https://colab.research.google.com/drive/1X_7J2qo3fEa7DfTetserI5d1eLVjo3FV?usp=sharing
Open the notebook.
If prompted, go to Runtime → Change runtime type → GPU (optional).
Run all cells to load dependencies, models, templates, and widgets.
Runs the generator model with no safety filtering.
The model outputs URLs that resemble real scam infrastructure but use fake brands and invented domains.
Dropdown: Scam Category
Slider: Number of URLs (1–10)
Button: Generate
Output: List of URLs (one per line)
Select a category such as FakeStorefront or CryptoRugPull.
Set the number of URLs to generate (e.g., 5).
Click Generate Scam URLs.
Examine the URLs produced.
URLs look plausible but malicious:
secure-update-paypa1-helpdesk.com
omega-token-swap-airdrop.vip
Categories influence patterns:
Fake storefronts mimic e-commerce
Crypto scams use token and swap terminology
No defensive layer exists yet—this is pure synthetic attack generation.
Adds a classifier that takes a URL and outputs structured labels such as:
Risk: Safe / Suspicious / Likely Fraud / High-Risk Fraud
Category: Crypto, Storefront, TechSupport, etc.
Rationale: Brief explanation
Textarea: URL
Button: Classify URL
Output: JSON-ish verdict (risk, category, rationale)
Generate scam URLs from Section A.
Copy one into the URL text box.
Click Classify URL.
Observe how the guard interprets the domain.
Most generated URLs should be classified as Likely Fraud or High-Risk Fraud.
The guard highlights suspicious structures:
Misspellings
Suspicious subdomains
Strange TLDs
Scam-like lexical patterns
Rare false positives or incorrect category predictions may occur.
Lets you paste any URL, not just generated ones, to test the classifier.
Textarea: Paste URL here
Button: Classify URL
Output: Guard verdict
You can paste:
Real benign links
Your generated scam URLs
“Borderline” URLs with odd patterns
Paste a legitimate URL such as:
https://google.com
https://github.com/login
Click Classify URL. Note the output.
Now paste clearly malicious or weird URLs:
secure-login-paypa1-helpdesk.com
compliance-update-info-support.net
Compare results across different examples.
Legitimate URLs should appear as Safe.
Some odd but harmless URLs may be flagged Suspicious.
High-risk URLs generated from Section A will be labeled Likely Fraud or High-Risk Fraud.
Demonstrates guard usefulness but also potential false positives/negatives.
Tests how easily the guard can be bypassed by slightly modifying URLs.
Same classification UI as Section C
Try constructing tricky URLs:
1. Typosquats
paypa1-security-update.com
arnazon-support-login.net
2. Homograph Attacks (Unicode lookalikes)
gοogle.com (Greek omicron)
payраl.com (Cyrillic letters)
3. Parameter-based trickery
https://example.com/login?session=secure-verification-update
4. Fake crypto/token drops
airdrop-claim-eth-connect.vip
Classify each one and observe the guard’s response.
Clear typosquats are usually caught.
Unicode homographs may slip through or be inconsistently classified.
Benign URLs with unusual parameters may be misclassified as suspicious.
Subtle scam URLs may drop from High-Risk Fraud to Suspicious or even Safe, showing the limits of lexical-only detection.
This section highlights how attackers might evolve their URLs to evade detection and how LLM-based guards need further tuning or multiple detection layers.
👉 Click here to see the result of each scenario (Post-Lab)