๐ฅ Roast My Pick ยท SIH26151
Dark web threat actor de-anonymization
National Technical Research Organisation (NTRO)
Reasonable choice. The scoreboard liked it. The scoreboard is not the one asking questions on the day.
Worth considering. The entity-graph and stylometry are solid, buildable work, but be honest that you are demonstrating a de-anonymisation method on constructed personas โ you cannot manufacture the real adversary mistakes that genuine unmasking depends on. Roughly 70โ160 teams are expected to go here.
The receipts
Every red flag on this statement, in full. These are the four places it bites.
Exhibit A
Real de-anonymisation depends on adversary operational-security failures you cannot reproduce on demand, so the headline capability is demonstrated on synthetic personas rather than genuine actors
It gets worse
Scraping live dark-web marketplaces is legally and ethically hazardous, so build on archived or synthetic corpora and say so explicitly
Still reading?
Stylometry accuracy collapses when an actor deliberately varies their writing, which sophisticated threat actors do, so your persona linking is weaker against exactly the targets that matter
And the finisher
Attribution is an accusation, so every link must carry confidence and evidence rather than being asserted
The damage report
Every score this statement earned, and what each one actually costs you.
Feasibility
2/5You have picked a fight with physics, procurement, or both. One of them always wins.
The entity-graph and stylometry pieces are buildable on public forum data, but the core capability โ actually de-anonymising live Tor hidden services and linking to real entities โ depends on adversary operational-security failures you cannot reliably reproduce, and scraping live dark-web marketplaces is legally and ethically fraught for a student team, so you will work on archived or synthetic data that cannot demonstrate real de-anonymisation.
Innovation scope
4/5There is something genuinely new here. Do not bury it under another dashboard.
How you fuse misconfiguration signals, cross-marketplace identifiers and stylometric evidence into a single attribution confidence is genuinely open, and combining these three very different signal types is where the real contribution lies.
Clarity
4/5The ask is unambiguous, which quietly removes your favourite excuse.
The description numbers the three core capabilities precisely โ misconfiguration matching, cross-marketplace identity graphing, and stylometric persona linking โ so the target is well defined even though the data is not provided.
Acceptance potential
3/5Middle of the pack. This statement will not win the room for you โ you will have to.
The entity-graph and stylometry are genuinely valuable and the field is thin, but the headline capability of de-anonymising real actors rests on adversary mistakes you cannot manufacture, and NTRO judges who do attribution professionally will distinguish a working method demonstrated on synthetic personas from an actual de-anonymisation.
Effort
MassiveA semester of work wearing a hackathon costume. Something is getting cut; decide what now, not in week five.
A crawling and collection layer, a misconfiguration scanner, an entity-resolution graph and a stylometry model are four substantial subsystems in different disciplines.
Demo-ability
MediumDemoable, if you rehearse it. Nobody rehearses it.
Linking two personas through a shared key and a stylometric match is a compelling story, but real de-anonymisation cannot be shown, so the demo runs on data you constructed and demonstrates the method rather than a genuine unmasking.
Data
None suppliedNo dataset comes with this one, so every accuracy figure you quote is a number about labels you invented.
Nothing is provided with the statement. You are sourcing, cleaning and labelling it yourself, and that work is invisible in the demo but very visible in the questions.
The demo they will have already seen
Somewhere around 70โ160 teams are heading here, and the description is doing the choosing for most of them. They will read the same brief, reach the same architecture, and build a version of the same demo you are planning. Being correct is the floor. If your five minutes could be swapped with the team before you and nobody in the room would notice, you have not picked badly โ you have built predictably, which costs exactly the same and hurts more.
What survives
The ground worth standing on when the questions start.
- Stylometry to link rebranded personas is a real, buildable technique that works on any text corpus you assemble, including public forum archives
- The PGP-key and wallet entity graph is deterministic linkage that does not depend on any model accuracy
- SSL-certificate-to-clearnet leakage is a documented real-world de-anonymisation vector you can demonstrate on a deliberately misconfigured test service
Nothing here is fatal. It is just the list of places this statement pushes back, and you now get to push there first.
The framing is a joke. The findings are not โ they are the same analysis on the statement page, and every line above is attached to a score or a fact in the record. It is one opinion with its reasoning attached, so argue with it before you trust it.