Part of BPUT Hackathon 2026
Odisha Knowledge Corporation Limited
Open
CYBERGUARD: Trust Nothing, Explain Everything
The attacker now has AI too. Yours had better be able to explain itself.
Evaluation only · Open
Design and develop an AI-powered Cyber Threat, Phishing and Digital Impersonation Detection & Response System capable of identifying, analysing, explaining and responding to emerging cyber threats in near real time — protecting both the technology layer and the human layer of cybersecurity.
Overview
Outcomes - Detection that covers technical threats and human-targeted attacks in one platform - Every alert carrying a risk score, an explanation and the evidence behind it - Recommended response actions, not just red text on a screen - A cybersecurity command dashboard giving a single operational view of what is happening - A prototype with a credible path to becoming a deployable AI cyber defence and digital trust platform for academic, government and enterprise bodies Overview The rapid adoption of digital platforms, online communication, cloud services, social media, digital payments and e-governance has sharply increased exposure to sophisticated cyber threats. Attackers now use AI and generative AI to produce convincing phishing emails, fake websites, malicious links, cloned voices, deepfake videos, fraudulent identities and personalised social engineering. Organisations simultaneously face abnormal login attempts, credential theft, account takeover, malware, suspicious network behaviour, API abuse and data exfiltration. Traditional rule-based security is often inadequate against threats that evolve and are themselves AI-generated. The Story The email is perfect. Correct logo, correct signature block, correct tone, correct name of the correct manager, and a domain that differs from the real one by a single character nobody has ever noticed. Twenty minutes later a voice note arrives from the same manager, sounding exactly like him, saying it is urgent. Nothing in this attack was written by a human. Your defence needs to be at least as clever, and considerably better at showing its work.
The brief
- The system should use AI, machine learning, NLP, computer vision, behavioural analytics, anomaly detection or generative AI to analyse multiple sources of digital activity — emails, SMS and messages, URLs, images, audio, video, authentication logs, system logs, network traffic and API logs
- It should not merely generate alerts. Every detection must carry a threat classification, a risk or severity score, an explanation of the detected threat, the evidence or indicators contributing to the decision, and recommended preventive or response actions
- Threat scenarios teams may address: AI-powered phishing detection across emails, SMS, social media messages, QR-code phishing, fraudulent websites and deceptive URLs, identifying indicators such as urgency, impersonation, suspicious domains, credential requests and unusual communication patterns
- Deepfake detection across images, video, voice clips, video calls and AI-generated media, with an authenticity or confidence score and manipulation indicators
- Digital impersonation detection targeting government officials, senior management, university authorities, financial institutions, brands and known contacts, analysing identity, communication style, metadata and behavioural patterns
- Credential theft and account takeover detection through failed login patterns, password spraying, unusual locations, unknown devices and sudden behavioural change
- Malicious URL and website detection covering domain spoofing, look-alike domains, URL manipulation, malicious redirects, suspicious SSL characteristics and fake login pages
- Broader threat detection covering malware indicators, suspicious network traffic, API abuse, data exfiltration, insider threats and abnormal system logs
- Risk scoring and explainability: assign every suspicious event a level such as Safe → Low → Medium → High → Critical, and explain the major factors behind it. Instead of "Phishing Detected", the system should say something like: high risk, because the sender domain closely resembles an authorised organisation, the message demands urgent credential verification, and the embedded URL redirects to an unrelated domain. Deepfake detections should similarly explain the indicators driving the confidence score
- Response recommendations may include: blocking a suspicious URL, quarantining an email, warning the user, requiring additional authentication, revoking an active session, blocking an IP or device, flagging multimedia for manual verification, reporting impersonation, notifying the administrator or SOC, and escalating the incident
- Innovation opportunities: generative-AI-assisted cyber defence, AI-generated phishing detection, multimodal deepfake and voice-cloning detection, email sender authenticity analysis, digital identity verification, behaviour-based fraud detection, explainable AI, graph-based attack analysis, real-time threat intelligence, MITRE ATT&CK mapping, zero-day anomaly detection, privacy-preserving AI, federated learning, autonomous defence agents and automated incident-response playbooks
- Minimum expected prototype: demonstrate at least three different cybersecurity scenarios — preferably one phishing or social engineering case, one digital impersonation, deepfake or identity fraud case, and one technical threat or abnormal behaviour case — running the full chain of detection, classification, risk assessment, explanation, alert and recommended response
Deliverables
- A working prototype demonstrating the threat-detection mechanism across at least three cybersecurity scenarios spanning the required categories
- A risk-scoring mechanism with explainable threat assessment — evidence and contributing indicators shown for every decision
- A cybersecurity command dashboard covering events analysed, threats detected, categories, risk levels, attack timeline, frequently targeted users or services, recommended actions and incident status
- An intelligent response recommendation and mitigation layer tied to the detected threat type
- Technical documentation: system architecture, models and algorithms used, accuracy and performance evaluation on simulated, authorised or publicly available datasets, and the scalability and deployment approach
Evaluation criteria
- Detection accuracy and breadth across the three required scenario types — 30%
- Quality of risk scoring and explainability of every decision — 25%
- Usefulness of response recommendations and mitigation logic — 20%
- Command dashboard, architecture and scalability of the approach — 15%
- Performance evaluation rigour and demo quality — 10%
More challenges to enter
- Open
Data Genesis 2026
Programs
- Open
Real-Time Factory Safety Vision
Software Technology Parks of India
- Open
3D Autonomous Path Planning
Software Technology Parks of India
- Open
NASA Space Apps Challenge '26
Programs
- Open
HustleHub '26
Wooble
- Open
MethaneGuard AI '26
Wooble
- Open
Blue Workforce Connect '26
Wooble
- Open
CipherMind AI '26
Wooble
Prizes are offered and awarded by Odisha Knowledge Corporation Limited, not by Wooble. Amounts shown are as stated by the host and may include the host’s own valuation of non-cash items. Who places, how and when a prize is paid, and any tax or deduction, are between the winner and the host. A challenge may close, change or be withdrawn before results are declared.