WhatsApp confirms on-device AI scam alert feature.SOPA Images/LightRocket via Getty ImagesHot on the heels of a confirmed WhatsApp scam attack campaign that doesn’t require your password to access your account, Meta has announced it is starting to roll out new protections for WhatsApp users by way of an optional Scam Alert feature powered by an on-device machine learning model.“The feature complements end-to-end encryption while enabling a user-controlled, optional scam alert when the model believes there’s a likely scam,” Meta said in an August 12 engineering team announcement. Scam Alert is currently being rolled out in a limited Beta, and Meta has confirmed it is working with the WhatsApp bug bounty community to stress-test the feature. There is no word yet on when the feature might become available to a wider audience, or on how users can sign up for the limited Beta test program. Here’s what we do know.ForbesWhatsApp Scam Bypasses Passwords Using 6 Digit Code To Access AccountsBy Davey WinderHow The New WhatsApp Scam Attack Feature WorksScam protections are something that most communications platforms are working hard to implement in the face of continuing threats. Google recently announced “fake call detection” that verifies the legitimacy of the call as long as both parties are using Phone by Google, and already has an AI-powered scam detection feature for Android users. This employs AI to provide real-time warnings and analyze calls and messages, but the conversations themselves remain private, as the AI processing is all done right there on the device itself. Now Meta is taking a similar route with its Scam Alert functionality for WhatsApp users.“No message content leaves the device for classification or is auto-reported to WhatsApp, Meta, or anyone else,” the engineering team stated. This is thanks to it being relatively simple in terms of such models, small enough to run on any device without any server-side components being required. The Scam Alert is entirely optional, but once enabled, it downloads the machine learning model to the device. From there, it “runs inferences to classify whether incoming messages from non-contacts match known scam patterns.” These patterns are those the AI has trained on using scams that users have reported to WhatsApp. Meta said that the probabilistic classification is based on conversational structure and linguistic signals, and that no content needs to be automatically reported to anyone for the feature to be effective.MORE FOR YOUIf triggered, Scam Alert issues, erm, an alert. This warning is not visible to the sender, and the user can opt to block, report or continue. “If they decide that a warning is incorrectly flagged,” Meta said, “the user can mark the chat as trusted, in which case the warning is removed, and Scam Alert will not flag that chat again.”Scam Alert is another slice in what is known as the Swiss Cheese security model. This defense-in-depth approach works by layering slices of Swiss cheese on top of each other. The holes are random in position and size, so the more layers there are, the harder it becomes for a threat to find its way through the stack. Other layers already in place for WhatsApp users include a recent security tools update that can alert users to potential device linking code attacks, as well as the optional Strict Account Settings configuration that automatically silences unknown calls, blocks attachments from unknown users and prevents link previews.