Moineau 🐦 — scam screenshot detector

Moineau ("sparrow") is a small CNN that scores screenshots for scams: fake crypto giveaways ("send 0.1 BTC, get 0.2 back"), fake celebrity promotions, fake casino / promo-code pop-ups, fake X (Twitter) support notices, fake Discord Nitro offers, and similar social-engineering images.

It was built to help moderate a Discord server: it runs on a plain CPU, uses ~60 MB of RAM with ONNX Runtime and needs no GPU and no PyTorch.

⚠️ Experimental, assistance-only. It misses many real scams and makes some false positives (see below). Use it to flag images for human moderators, not to punish users automatically.

Quick start

pip install onnxruntime pillow numpy
python predict.py screenshot.png another.jpg --threshold 0.6
SCAM   0.975  scam_mrbeast.png
clean  0.160  official_profile.png

predict.py contains the exact preprocessing. In short:

Step Value
Color RGB, transparent pixels composited on white
Pre-shrink longest side ≤ 384 px (bicubic)
Model input 224 × 224 (bilinear), float32, NCHW, input name image
Normalization (x / 255 - 0.5) / 0.5
Output 2 logits [clean, scam] → softmax, index 1 = scam probability

Model

Architecture small convolutional network trained from scratch (no pretrained backbone)
Parameters ~1.17 M
Compute ~0.5 GFLOP per image
File Moineau.onnx, 4.7 MB, opset 17, dynamic batch
Classes clean, scam
Recommended threshold 0.6 (used in production); the threshold calibrated on validation is 0.77

The ONNX file also carries metadata (threshold, img_size, cache_size, classes, name), readable with onnxruntime.InferenceSession(...).get_modelmeta().custom_metadata_map.

Trained entirely on a laptop CPU 💻

Moineau was trained from scratch on my own laptop CPU: an AMD Ryzen 3 5400U (4 cores), 7.3 GB of RAM, no GPU, no cloud. That was not a given: before optimizing, a single training run took over 3 hours, and the laptop often has only ~1.5 GB of free memory. It took research and careful measuring to make it work:

  • progressive resolution in 4 steps (128 → 160 → 192 → 224 px, the last 30 % at full size): ~2.5× faster (a full 40-epoch training in ~1 h 15 instead of ~3 h 10) — and this exact 4-step schedule is what made Moineau better than a single jump from 160 to 224 px (fewer false positives on dark game scenes);
  • a memory layout faster on CPU (channels-last) and images pre-shrunk once to a JPEG cache, so nothing has to fit in RAM;
  • a small model by design (~1.17 M parameters, ~0.5 GFLOP per image) instead of a ResNet, which was too heavy here;
  • measured dead ends that were dropped (compiling the model, a C++ image pipeline, mixed precision… all slower or unsupported on this CPU).

The result runs the same way: on any CPU, about 10 ms per image, and about 63 MB of RAM with ONNX Runtime in a Discord bot (vs ~290 MB with PyTorch), no GPU needed.

Evaluation (real images, never seen during training)

Test set Content Result at threshold 0.6
Clean images 2,000 everyday images: artworks, web/app UIs, game screenshots, photos 9 false positives (0.45 %) (19 at threshold 0.5)
Real web scams vs. real profiles 36 real scam screenshots, 30 legitimate X profiles AP 0.907; 14 / 36 scams caught (39 %), 0 / 30 false positives
Discord moderation samples 80 clean images, 1 scam 0 / 80 false positives, scam caught

Reading these numbers honestly:

  • It is conservative: when it flags an image, it is usually right, but it lets roughly 60 % of real web scams through at the production threshold.
  • The test sets are small (36 real scams), so differences of 1–2 images are within noise.

Known limitations and failure modes

  • Small text: at 224 px it sees the layout and big text, not fine print. Scams that hide in one sentence of a sober page will be missed.
  • Lookalike legitimate pages can be flagged: donation forms with preset amounts, verified brand profiles on X, colorful mobile-game menus with currency counters, crypto exchange promotions.
  • Dark game scenes sometimes get borderline scores (one dark VR screenshot scores 0.52).
  • New scam styles (it was trained mostly on giveaway / casino / X-impersonation styles) may not be recognized.
  • Not designed for: phishing login pages that look identical to the real site (the scam is only in the URL), text-only messages, videos (for GIFs, score a few key frames and take the maximum).

Training data (summary)

Trained on ~1,000 scam and ~5,800 clean screenshots and images:

  • synthetic scam screenshots rendered from HTML templates, each with a legitimate twin using the same interface (so the model cannot learn "generated = scam");
  • a small number of real scam screenshots;
  • varied clean images collected from public web image search (games, apps, websites, photos, memes);
  • moderation samples from the author's own Discord bot.

The training data and training code are not released.

Intended use

  • ✅ Flagging suspicious images for human review in community moderation (Discord, forums), research on scam detection.
  • ❌ Fully automatic punishment of users; any commercial use (see license); deciding on its own whether a website is safe.

Misuse note: like any public detector, it could be used to test whether an image evades detection. It is released for defensive, non-commercial use.

License

CC BY-NC 4.0 — free for non-commercial use with attribution. Some of the training images come from sources that only allow non-commercial use, hence this license.

Version

October 2026. Model names follow a bird theme: Moineau (sparrow) is the small, reliable production model; Faucon (falcon, preview) is the experimental model that learns where to zoom.

Citation

If you use Moineau in your work, please cite it (attribution is required by the CC BY-NC 4.0 license):

@misc{charlet2026moineau,
  author       = {Charlet, Th{\'e}o},
  title        = {Moineau: a lightweight scam screenshot detector},
  year         = {2026},
  publisher    = {Hugging Face},
  howpublished = {\url{https://huggingface.co/RDTvlokip/Moineau}}
}

Théo CHARLET

TSSR Graduate (IT Systems & Networks Technician) — AI/ML Specialization
Creator of AG-BPE (Attention-Guided Byte-Pair Encoding)

LinkedIn Website Search

🚀 Seeking internship opportunities

Downloads last month
17
Inference Providers NEW
This model isn't deployed by any Inference Provider. 🙋 Ask for provider support