TinyRod
Matthew Bream, William Hayden · Team Logiq
Submitted to Defensive Acceleration Hackathon. Sprint projects are early-stage work by participants, not Apart Research publications.
Phishing is still the easiest way into most organisations, despite years of machine-learning filters boasting 95%+ accuracy on benchmark datasets. Those models usually live in centralised paid services that demand full access to email content, create single points of failure, and still struggle with fast-moving, AI-generated content and landing pages.
TinyRod is a proof-of-concept email security tool that asks a simple question: how far can we push phishing detection if everything runs locally in the user’s browser? The project couples a Chrome extension with small open-source language models running via WebLLM, so email content never leaves the browser. When a user clicks “scan”, TinyRod pulls structured metadata from the page, feeds it to an SLM, and returns a 0–100 risk score plus a small, fixed list of “red flag” reasons. That keeps the experience close to how people already use email.
The result is a hackathon-built but realistic architecture that shows SLMs in the ~1.7B–8B range can meaningfully support phishing defence at the edge, with clear privacy trade-offs, a documented threat model, and an obvious path for hardening and future work.

Reviews
No public critique yet.
Cite this project
@misc{bream2025tinyrod,
title = {{TinyRod}},
author = {Matthew Bream and William Hayden},
year = {2025},
month = nov,
note = {Submitted to Defensive Acceleration Hackathon, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/tinyrod-gk5k}},
url = {https://apartresearch.com/sprints/projects/tinyrod-gk5k}
}More from Defensive Acceleration Hackathon
- View project: Neops - DevSecOps for the AI era
Neops - DevSecOps for the AI era
Broad Bros
NEOps is a CLI-based tool that embeds AI safety into your product lifecycle from day one. While development teams routinely build cybersecurity checks, AI-safety often comes later—or not at all. NEOps fills that gap by …
- View project: Assisted Audit of Solana Programs
Assisted Audit of Solana Programs
GLAM
Multi-agent solution that assists in auditing Solana programs, allows to consolidate audit findings into a knowledge base, and can integrate into CI/CD pipelines to prevent security regressions.
- View project: Mechanistic Watchdog
Mechanistic Watchdog
SL5
Mechanistic Watchdog is a mechanistic-interpretability-based “cognitive kill switch” for language models. Instead of only filtering final text, we monitor a model’s internal activations in real time and learn linear …