Transaction graph time sequence information and attention embedding fused Ethereum phishing node detection method
By constructing first-order and second-order transaction graphs and combining attention mechanisms, GAT and GRU are used to detect phishing nodes in the Ethereum network, the problems of low detection accuracy and limited processing capabilities for complex transaction graph structures and timing information in the existing technology are solved, and efficient and intelligent phishing node detection is achieved.
Patent Information
- Application Number
- CN202510056365.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-14
- Publication Date
- 2025-05-16
AI Technical Summary
When dealing with complex transaction behaviors and dynamic changes in attack strategies, the existing Ethereum phishing node detection methods have low detection accuracy, insufficient real-time performance, and limited ability to process complex transaction graph structure and timing information.
By constructing first-order and second-order transaction graphs centered on the target node, combining the attention mechanism of transaction amount, the multi-order transaction graph is embedded and analyzed using graph attention network (GAT) and gated loop unit (GRU) to achieve accurate detection and identification of potential phishing nodes in the Ethereum network.
It significantly improves the accuracy and real-timeness of phishing node detection, can fully tap the structural characteristics in the transaction graph and capture the timing dynamic information of the transaction, and enhances the security and credibility of the Ethereum network.
Smart Images

Figure CN120017323A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of blockchain technology, and in particular to a method for detecting phishing nodes in an Ethereum network. The method constructs the first-order and second-order transaction graphs of the target node as the center, and combines the transaction amount as an attention mechanism to merge multiple transaction edges. The second-order transaction graph is embedded using a graph attention network (Graph Attention Network, GAT), and the transaction timing information of the first-order transaction graph is analyzed by a gated recurrent unit (GRU). By comprehensively analyzing the structural characteristics and timing dynamic characteristics of multi-order transaction graphs, accurate detection and identification of potential phishing nodes in the Ethereum network are achieved. The present invention provides an efficient and intelligent blockchain security solution, which enhances the security and credibility of the Ethereum network. Technical Background
[0002] As a distributed ledger technology, blockchain technology has developed rapidly and been widely used in finance, Internet of Things, supply chain management and other fields since the advent of Bitcoin. Among them, Ethereum, as a second-generation blockchain platform, further expands the application scenarios of blockchain technology by supporting smart contracts and decentralized applications (DApp), and becomes an important part of the blockchain ecosystem.
[0003] However, with the rapid development of the Ethereum network, its security issues have become increasingly prominent. Phishing attacks, as a common and highly concealed attack method in blockchain networks, seriously threaten the asset security of users and the trust mechanism of the entire network. Phishing nodes disguise themselves as legitimate nodes and induce users to conduct false transactions, thereby stealing users' digital assets. Such attacks not only cause direct economic losses, but also weaken users' trust in blockchain networks, hindering their further popularization and application.
[0004] Currently, the detection methods for phishing nodes in the Ethereum network mainly include rule-based detection, machine learning-based detection, and graph analysis-based detection. Among them:
[0005] Rule-based detection method: This method uses predefined rules and patterns to identify abnormal transaction behaviors, such as abnormal transaction frequency, unreasonable transaction amount, etc. Although simple to implement, its detection capability depends on the comprehensiveness and accuracy of the rules, and it is difficult to cope with complex and changeable attack methods, and there is a high false positive rate and false negative rate.
[0006] Machine learning-based detection methods: This type of method extracts the features of transaction data and uses supervised learning or unsupervised learning algorithms to build detection models. For example, algorithms such as support vector machines (SVM), decision trees, and random forests are widely used to identify phishing nodes. However, these methods usually rely on manual feature engineering, which makes it difficult to fully capture the complex structure and timing information in the transaction graph, and have the problem of low computational efficiency when processing large-scale transaction data.
[0007] Detection methods based on graph analysis: Considering that blockchain transactions have natural graph structural characteristics, graph analysis-based methods construct transaction graphs and use graph mining technology to identify abnormal nodes and abnormal transaction patterns. For example, deep learning models such as graph convolutional networks (GCNs) and graph attention networks (GATs) are applied to embedding and node classification of transaction graphs. This type of method can better capture the structural features in the transaction network, but it still has shortcomings in combining the temporal dynamic information of transactions.
[0008] In summary, the existing Ethereum phishing node detection methods often have problems such as low detection accuracy, insufficient real-time performance, and limited ability to process complex transaction graph structures and timing information when dealing with complex transaction behaviors and dynamically changing attack strategies. Therefore, there is an urgent need for an efficient detection method that can comprehensively utilize multi-order transaction graph structure characteristics and timing dynamic information to improve the detection accuracy and real-time performance of phishing nodes in the Ethereum network and enhance the security and credibility of the entire blockchain system.
[0009] The present invention is proposed in the above context, aiming to accurately detect and identify potential phishing nodes in the Ethereum network by constructing first-order and second-order transaction graphs centered on the target node, combining the attention mechanism of the transaction amount, and using the graph attention network (GAT) and gated recurrent unit (GRU) to embed and analyze multi-order transaction graphs. This method can not only fully mine the structural features in the transaction graph, but also effectively capture the temporal dynamic information of the transaction, significantly improving the detection effect and the overall performance of the system. Summary of the invention
[0010] The present invention aims to provide an Ethereum phishing node detection method based on multi-order transaction graph structural features and time series dynamic information, to solve the problems of low detection accuracy, insufficient real-time performance, and limited processing capabilities for complex transaction graph structures and time series information in the prior art. By constructing first-order and second-order transaction graphs centered on the target node, combined with the attention mechanism of the transaction amount, the multi-order transaction graph is embedded and analyzed using the Graph Attention Network (GAT) and the Gated Recurrent Unit (GRU), thereby achieving accurate detection and identification of potential phishing nodes in the Ethereum network.
[0011] The present invention provides an Ethereum phishing node detection technology that integrates transaction graph timing information and attention embedding, such as Figure 1 As shown, the following steps are included:
[0012] Step 1: Construct the first-order transaction graph G with the target node v as the center (1) =(V (1) ,E (1) ). Among them, the node set V (1) Contains the target node v and its first-order neighbor nodes (nodes that have direct transactions with the target node) {v 1 ,v 2 ,…,v n}. Edge set E (1) Contains all transactions between the target node and each direct transaction node. Each edge Represents the target node and node v i A transaction between and trading hours As an attribute.
[0013] Step 2: Based on the first-order transaction graph, further construct the second-order transaction graph G (2) =(V (1) ∪{V i,j},E (2) ), where V i,j Represents the first-order neighbor node v i The node set of the transaction. (2) Contains node v and its first-order neighbor node v i and the second-order neighbor node v j Through this extension, the second-order transaction graph is able to capture the indirect transaction behavior of the target node.
[0014] Step 3: In the process of processing the second-order transaction graph, in order to simplify the structure of the second-order transaction graph and facilitate subsequent embedding processing, multiple transaction edges {e} between the same node pair are merged into one transaction edge and their transaction amounts are Directly add them together to get the combined transaction amount As attributes of the merged edges.
[0015] Step 4: For the first-order transaction graph G (1) , the gated recurrent unit (GRU) is used to perform time-series embedding analysis on the transaction time sequence information. i Transactions between Sort and get the time series Take each transaction as the input sequence of GRU to form the input sequence X = [x (1) ,x(2) ,…,x (m) ]. Process the input sequence through GRU to generate the state sequence h (k) :
[0016]
[0017] Among them, Aggregate adopts average pooling.
[0018] Step 5: For the second-order transaction graph G (2) , using the graph attention network (GAT) for embedding. GAT can effectively capture the weight relationship between nodes in the transaction graph by introducing the transaction amount as the attention weight. i Allocate initialization vector For each layer l of GAT, calculate the attention coefficient between node i and its neighbor node j
[0019]
[0020] Among them, W (l) is the weight matrix of the lth layer, a is the attention weight vector, || represents the vector concatenation operation, and the transaction amount A ij Fusion as part of the attention weights:
[0021]
[0022] Among them, Ν(i) represents the set of neighbor nodes of node i.
[0023] Step 6: Fuse the embedding vectors of the first-order transaction graph and the second-order transaction graph to form a node representation H that comprehensively reflects the transaction structure and time series dynamic characteristics:
[0024] H=H (1) ||H (2)
[0025] Among them, H (1) is the first-order transaction embedding vector, H (2) is the embedding vector of the second-order transaction graph, and || represents the vector concatenation operation.
[0026] Step 7: Based on the fused node representation H, a single-layer perceptron is used to identify fishing nodes. The fused node representation H is used as the input vector and a set of learnable parameters W is used to identify fishing nodes. c (weight) and b c (Bias) Linearly map H:
[0027] z=W c H+b c
[0028] Use the Sigmoid function to perform nonlinear mapping on z to obtain the predicted probability
[0029]
[0030] Indicates the probability that a node is a fishing node. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] Figure 1 This is an overall flow chart of an Ethereum phishing node detection method that integrates transaction graph timing information and attention embedding in the present invention;
[0032] Figure 2 It is a schematic diagram of the first-order transaction graph temporal embedding (GRU) in the present invention;
[0033] Figure 3 It is a schematic diagram of embedding the second-order transaction graph in the present invention;
[0034] Figure 4 This is a framework diagram of an Ethereum phishing node detection method that integrates transaction graph timing information and attention embedding in the present invention; DETAILED DESCRIPTION
[0035] 1. Data acquisition and preprocessing
[0036] Obtain block and transaction-related data through the Ethereum official API, blockchain browser, or locally deployed Ethereum full node. The data includes the transaction initiation address, receiving address, transaction amount, and transaction timestamp. Clean the obtained raw data, including removing null value records, abnormal transactions, invalid addresses, etc. Convert the amount to the standard unit wei and the timestamp to the universal time format to provide input data for subsequent graph construction and analysis. Store the processed data in an efficient database NoSQL, and establish a mapping and index between the addresses of both parties to the transaction, so as to quickly build the transaction graph of the target node.
[0037] 2. Transaction graph construction
[0038] The present invention takes the target node v to be detected as the center, constructs the first-order and second-order transaction graphs, and thus describes the direct and indirect association relationships of the node in the transaction network.
[0039] First-order transaction graph G (1) : Retrieve from the database all the nodes that have direct transactions with node v (1) (v) and the transaction parties in the node set N (1) All transactions in (v) are recorded as transaction set E (1)(v) Obtain the first-order transaction graph, sort it by transaction time, and obtain the transaction time sequence of the first-order transaction graph Used for subsequent timing embedding.
[0040] Second-order transaction graph G (2) :Based on the first-order transaction graph, further retrieve each N (1) (V) Middle node V i Direct neighbor node N (1) (V i )(i.e. V gets the second-order neighbor node N (2) (V)) and the transactions between them constitute a second-order transaction graph. If there are multiple transactions between two identical nodes, multiple transactions are merged into one transaction edge, and the cumulative sum of their amounts is used as the weight of the new edge, that is:
[0041]
[0042] The edge weight Representing the total amount of transactions with the neighboring node, a second-order transaction graph is obtained, which can reflect the indirect connection of the target node in a wider relationship network, thereby more comprehensively reflecting the possible abnormal behavior characteristics of the node.
[0043] 3. Temporal Embedding of First-Order Transaction Graph (GRU)
[0044] For the first-order transaction graph G (1) , focusing on capturing the temporal dynamic characteristics of transactions. i All transactions by time The transaction amount of the target node as the recipient is positive, and the transaction amount of the target node as the initiator is negative, which reflects the flow of transactions and forms a transaction sequence. The sequence is used as the input of GRU. The state update formula of GRU is:
[0045] z (k) =σ(W z x (k) +U z h (k-1) ),r (k) =σ(W r x (k) +U r h (k-1) ),
[0046]
[0047] where x (k) is the input (transaction amount) of the kth transaction, z (k) With r (k)are the update gate and reset gate respectively, σ is the sigmoid function, and tanh is the hyperbolic tangent activation function.
[0048] Through GRU's time series modeling capability, we can get the feature representation of each transaction. Aggregate the GRU representations of all first-order adjacent nodes to obtain the temporal embedding representation H of the target node in the first-order transaction graph (l) .
[0049] 4. Embedding of the second-order transaction graph (GAT introduces the attention mechanism of transaction amount)
[0050] For the second-order transaction graph G (2) , the graph attention network (GAT) is used to embed the nodes. For each node v in the second-order transaction graph i Assign initial eigenvectors This feature can be obtained based on the basic information of the node or through training. The attention mechanism of GAT is improved. In the lth layer of GAT, for the neighbor node j of node i, the unweighted attention score is first calculated:
[0051]
[0052] Where W (l) is the weight matrix of the first layer, a is the attention weight vector, and || is the vector concatenation operation. Then the transaction amount A ij Integrate into attention weight calculation:
[0053]
[0054] By introducing the amount feature, high-amount transaction edges have a higher weight in the attention calculation, which helps to highlight the transaction relationship. Then, the feature is updated and the node features are weighted and aggregated using the attention coefficient:
[0055]
[0056] After multiple layers of iteration, the final embedding vector of each node is obtained, and then average pooling is performed to obtain the embedding representation H of the target node in the second-order transaction graph. (2) .
[0057] 5. Feature fusion and classification decision
[0058] Embed the time series from the first-order transaction graph into the result H (1) The structure and amount weighted attention embedding results of the second-order transaction graph H (2) To perform the fusion:
[0059] H=H (1) ||H (2)
[0060] The comprehensive node representation H is obtained, which contains both temporal dynamics and structural relationships and transaction amount characteristics. Then, H is input into the single-layer perceptron module for binary classification:
[0061]
[0062] when When , the target node is judged as a fishing node, otherwise it is judged as a normal node. The classifier can be trained on a labeled dataset to minimize the binary cross entropy loss. The generalization performance and robustness of the classifier can be improved through appropriate regularization, early stopping strategy, and hyperparameter tuning.
Claims
1. An Ethereum phishing node detection method integrating transaction graph temporal information and attention embedding, characterized in that: The following steps are involved: (1) Data acquisition and preprocessing step: obtaining raw data including the target node and its related transaction data from the Ethereum network, and cleaning and standardizing the raw data; (2) Steps for constructing first-order and second-order transaction graphs: 1) With the target node as the center, a first-order transaction graph between the target node and its direct transaction nodes is constructed. The repeated transaction edges in the first-order transaction graph are not merged, and the original transaction structure and time series information are retained, finally forming a first-order weighted directed multigraph; 2) Based on the first-order transaction graph, the second-order transaction graph is further constructed using its first-order neighbor nodes, and only multiple transaction edges that appear at the same node in the second-order transaction graph are merged, and the amounts of repeated transaction edges are accumulated as the amount of the merged edge, the direction and transaction time attributes are eliminated, and the amount weight is retained, and finally a second-order weighted undirected graph is obtained; (3) First-order transaction graph time series embedding steps: 1) Arrange the transactions in the first-order transaction graph in order of transaction time to form a time series; 2) Using a gated recurrent unit (GRU) to extract temporal dynamic features of the transaction time series, and obtaining a temporal embedding representation of the first-order transaction graph; (4) Second-order transaction graph embedding steps: 1) Perform initial feature representation on each node in the second-order transaction graph; 2) Using the Graph Attention Network (GAT) to embed the second-order transaction graph, the transaction amount on the edge is used as the weighting factor in the attention calculation, and the node features are weighted and aggregated to obtain an embedding representation that contains the second-order structural features and amount weight information; (5) Feature fusion and classification steps: 1) Fusing the first-order transaction graph temporal embedding representation with the second-order transaction graph structural embedding representation to obtain a target node feature representation; 2) Use the classification model to perform binary classification prediction on the fused target node feature representation. When the prediction result is greater than or equal to the preset threshold, the target node is judged to be a fishing node, otherwise it is judged to be a normal node.
2. The method according to claim 1, characterized in that: In step (2), when there are multiple transactions for the same node pair, the combined amount is obtained by adding up the amounts of each transaction, thereby reducing duplicate edges in the transaction graph and simplifying the graph structure.
3. The method according to any one of claims 1 or 2, characterized in that: When using GRU for time series embedding in step (3), the transaction amount sequence between the target node and the first-order opponent node is used as the GRU input. GRU captures long-term dependencies and time dynamic characteristics through the update gate and reset gate mechanism.
4. The method according to claims 1 to 3, characterized in that: In step (4), the calculation formula of the attention coefficient in the graph attention network (GAT) is: e ij =LeakReLU(a T [Wh i ||Wh j ]) Among them, h i and h j is the node feature, W is the mapping parameter, a is the attention weight vector, A ij is the sum of the transaction amounts, and Ν(i) is the neighbor set of node i.
5. The method according to any one of claims 1 to 4, characterized in that: When fusing the second-order transaction graph embedding with the first-order transaction graph temporal features, the feature concatenation method is used to concatenate the corresponding feature vectors of the two to obtain the target node representation.
6. The method according to any one of claims 1 to 5, characterized in that: A single-layer perceptron is used as the classifier, and the classifier parameters are trained through the binary cross entropy loss function. When the output probability value is greater than or equal to 0.5, it is determined to be a fishing node.
Citation Information
Cited By
Ethereum phishing account detection method, device and equipment
CN120415897A
High-precision Ethereum phishing account detection method based on high-order topology
CN122179130A