Block chain case research and judgment method and system, program product, equipment and storage medium

By constructing a financial network graph using a large language model, the problem of low efficiency in traditional blockchain case analysis is solved, enabling efficient case assessment and providing comprehensive data support.

CN120912306APending Publication Date: 2025-11-07成都链安科技有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511059852.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-30
Publication Date
2025-11-07

AI Technical Summary

Technical Problem

Traditional blockchain case analysis relies heavily on manual analysis, which is complex and inefficient.

Method used

By using a large language model to perform semantic parsing on the case input information, a fund network graph is constructed for comprehensive analysis in a global and multi-dimensional manner. This integrates on-chain transaction data with off-chain semantic information and uses the fund network graph to make case judgments.

Benefits of technology

It improves the efficiency of case analysis, addresses the problem of low efficiency in manual case analysis, and provides data support that is both machine-readable and human-understandable.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120912306A_ABST
    Figure CN120912306A_ABST
Patent Text Reader

Abstract

The invention provides a block chain case research and judgment method and system, a program product, equipment and a storage medium, and the method comprises the steps: obtaining a case semantic context corresponding to a block chain case based on the case input information of the block chain case through a large language model; the case semantic context is used for capital flow tracking; the case semantic context comprises on-chain traceable information and / or under-chain semantic information; based on the case semantic context, determining a target block chain address associated with the case-involved block chain address, and constructing a fund network graph; and analyzing the fund network atlas to obtain a case research and judgment result. According to the method, a large language model is utilized to perform semantic analysis on case input information, a fund network graph is constructed based on case-related block chain addresses in the case input information, and then global and multi-dimensional comprehensive analysis is performed on the constructed fund network graph, so that the case research and judgment efficiency is improved, and the problem of low manual analysis and judgment efficiency is solved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of blockchains, in particular to a blockchain case research and judgment method, system, program product, device and storage medium. BACKGROUND

[0002] With the rapid development of blockchain technology, cryptocurrencies and decentralized finance (DeFi) are increasingly popular, and related financial crimes such as fraud, money laundering, and dark web transactions are also showing explosive growth. Traditional blockchain case analysis relies on a large amount of manual analysis, with a complex process and low case judgment efficiency. SUMMARY

[0003] The purpose of the embodiments of the present application is a blockchain case research and judgment method, system, program product, device and storage medium, which uses a large language model to perform semantic analysis on case input information, constructs a fund network graph based on the involved blockchain addresses, and then performs global and multi-dimensional comprehensive analysis on the constructed fund network graph, improving the case research and judgment efficiency and improving the problem of low efficiency of manual analysis and judgment.

[0004] In a first aspect, the embodiments of the present application provide a blockchain case research and judgment method, comprising: obtaining a case semantic context corresponding to a blockchain case based on case input information of the blockchain case through a large language model; the case semantic context is used for fund flow tracking; the case semantic context includes on-chain traceable information and / or off-chain semantic information; determining a target blockchain address associated with an involved blockchain address based on the case semantic context, and constructing a fund network graph; wherein the involved blockchain address and the target blockchain address are nodes of the fund network graph, and the relationship between the nodes is an edge of the fund network graph; analyzing the fund network graph to obtain a case research and judgment result.

[0005] In the above implementation process, the large language model is used to perform semantic analysis on the case input information, extract the case semantic context corresponding to the blockchain case, replace the manual data processing process, and improve the research and judgment efficiency. The fund network graph is constructed based on the involved blockchain addresses, and the on-chain transaction data and off-chain semantic information are integrated in the fund network graph, which has machine readability and human understandability, and provides comprehensive data support for subsequent case research and judgment. The constructed fund network graph is globally and multi-dimensionally analyzed, improving the case research and judgment efficiency and improving the problem of low efficiency of manual analysis and judgment.

[0006] Optionally, in the embodiment of the present application, based on the case semantic context, the target blockchain address associated with the case-involved blockchain address is determined, and a fund network map is constructed, including: taking the case-involved blockchain address as a core address, obtaining an opponent address having a transaction behavior with the core address through a large language model; screening the opponent address using a preliminary screening rule, and taking the screened opponent address as a core address, jumping to the step of: taking the case-involved blockchain address as a core address, obtaining an opponent address having a transaction behavior with the core address through a large language model, until a termination condition is reached, obtaining a candidate opponent address; based on the case semantic context, performing case feature screening on the candidate opponent address through a large language model, obtaining a target blockchain address associated with the case-involved blockchain address; and constructing a fund network map based on the target blockchain address.

[0007] In the implementation process described above, low-relevance opponent addresses are pre-filtered through the preliminary screening rule, and case feature screening is performed on the candidate opponent addresses after preliminary screening, so that subsequent large model analysis only needs to process high-potential targets, reducing invalid calculation on irrelevant addresses and improving research and judgment efficiency. A progressive multi-round access strategy is adopted to track and cover multiple levels of fund transfer, making the evidence chain more complete and improving the overall case research and judgment.

[0008] Optionally, in the embodiment of the present application, taking the case-involved blockchain address as a core address, obtaining an opponent address having a transaction behavior with the core address through a large language model, includes: taking the case-involved blockchain address as a core address, calling a chain data access interface through a large language model, based on the case semantic context, obtaining an opponent address having a transaction behavior with the core address; the chain data access interface is constructed by using the collected blockchain data through the MCP protocol, and the chain data access interface is used to provide transaction query services for the large language model.

[0009] In the implementation process described above, the opponent address having a transaction behavior with the core address is obtained by calling the MCP protocol to call the chain data access interface, so that the opponent address can be obtained through a unified calling manner, reducing the multi-chain adaptation cost. The returned opponent address data is standardized through the protocol layer, reducing the address coding difference. The MCP is used to update the base value in real time, so that the latest opponent address can be obtained in time.

[0010] Optionally, in the embodiment of the present application, the opponent address is screened by using a preset rule, and the screened opponent address is taken as a core address, comprising: respectively calculating the multi-dimensional feature similarity between the core address and the opponent address; the multi-dimensional feature similarity comprises at least one of the transfer amount factor, the interaction frequency factor, the amount feature similarity and the activity time similarity; the transfer amount factor represents the proportion of the transfer amount between the opponent address and the core address to the proportion of the core address; the interaction frequency factor represents the proportion of the fund interaction frequency between the opponent address and the core address to the activity frequency of the core address; the amount feature similarity represents the similarity of the income and expenditure amount distribution characteristics between the opponent address and the core address; the activity time similarity represents the activity time feature similarity between the opponent address and the core address; the opponent address is screened based on the multi-dimensional feature similarity between the core address and the opponent address, and the screened opponent address is obtained.

[0011] In the above implementation process, the multi-dimensional feature similarity is quantized to accurately capture the opponent address with higher correlation, and the transfer amount factor in the multi-dimensional feature similarity reflects the fund correlation strength, the interaction frequency factor measures the relationship closeness, the amount feature similarity detects the behavior consistency, and the activity time similarity assists in judging whether it is controlled by the same subject from the time dimension. These preliminary screening rules measure the transaction behavior correlation degree of the opponent address and the core address from multiple aspects, reduce the invalid calculation of irrelevant addresses, and improve the research and judgment efficiency.

[0012] Optionally, in the embodiment of the present application, the case feature screening is performed on the candidate opponent address based on the large language model to obtain the target blockchain address associated with the case blockchain address, comprising: inputting the candidate opponent address into the large language model, calling the knowledge base access interface through the large language model, performing case feature analysis on the candidate opponent address based on the case semantic context, and obtaining the target blockchain address; the knowledge base access interface is constructed based on the MCP protocol and is used to provide case feature query service for the large language model; the case feature includes abnormal interaction data, fund flow data of the candidate opponent address and the case blockchain address, and / or abnormal label of the candidate opponent address.

[0013] In the above implementation process, the "preliminary screened candidate opponent address" is given to the large language model, the knowledge base (on-chain data, off-chain data and on-the-way cases) is called for secondary screening, the case feature screening is performed based on the semantics of the candidate opponent address, the explainability of the finally determined target blockchain address is improved, and the related nodes involved in the case are more accurately queried, thereby effectively balancing the efficiency and accuracy. On the one hand, a large number of low-relevance addresses are avoided from being input into the model, and on the other hand, high-potential-risk opponents are retained, thereby improving the quality of the constructed fund network.

[0014] Optionally, in the embodiments of the present application, the fund network graph is analyzed to obtain a case research result, including: The knowledge base access interface is called by the large language model to obtain semantic information of the target blockchain address in the fund network graph; upstream and downstream structure information of the target blockchain address in the fund network graph is obtained; the upstream and downstream structure information is used to represent the topological position relationship of the target blockchain address in the fund network graph; based on the upstream and downstream structure information, the semantic information of the target blockchain address is aggregated to obtain a case research result; the case research result is used to describe the global information in the fund network graph; the global risk information includes at least one of the fund role of the target blockchain address, the risk fund path in the fund network graph, the risk node list, and the global research report.

[0015] In the above implementation process, the upstream and downstream structure information is used to embed the individual address into the topological context of the fund network, improving the misjudgment of deviating from the transaction path. By aggregating semantic and topological information, a case-level global research result is generated to improve the limitations of single-address analysis. The complete fund network that has been constructed is comprehensively analyzed globally and multidimensionally to realize the macroscopic portrait of the case, the identification of the key path, and the explicit inference of the involved role.

[0016] Optionally, in the embodiments of the present application, the knowledge base access interface includes an off-chain public opinion access interface and / or a historical case access interface; before the knowledge base access interface is called by the large language model, the method further includes: collecting off-chain data to generate an off-chain public opinion knowledge base; the off-chain data includes at least one of address labels, attack event information, and chat records collected on social platforms; based on the off-chain public opinion knowledge base, an off-chain public opinion access interface is generated through the MCP protocol; and / or, a historical case knowledge base is generated according to historical cases, and the historical case knowledge base includes at least one of fund networks of different case types, industrial term explanations, analysis processes based on case types, and address abnormal transaction behaviors; based on the historical case knowledge base, a historical case access interface is generated through the MCP protocol.

[0017] In the above implementation process, the on-chain data, the off-chain data, and the historical cases generate corresponding data interfaces respectively, and cross-chain data is obtained through a single query of the MCP interface, improving the data response speed. The original transaction data is processed by behavior labeling, so that the large language model can be directly used after calling, reducing the data processing burden of the large model. The fragmented data of the social platform is stored in the knowledge base structure, which is converted into machine-readable evidence with confidence, improving the case analysis capability. Multiple retrieval methods are supported to make data calling more flexible.

[0018] Optionally, in the embodiments of the present application, before the case semantic context corresponding to the blockchain case is obtained based on the case input information of the blockchain case by the large language model, the method further comprises: receiving multi-modal data input by a user, the multi-modal data comprising at least two of text data, image data, audio data and video data; performing analysis processing on the multi-modal data to obtain the case input information of the blockchain case; the analysis processing comprises filtering irrelevant information, extracting entity information and / or meaning classification; the entity information comprises at least one of a case-involved blockchain address, a transaction time, a transaction address and a transaction user; the meaning classification comprises at least one of a crime type, a behavior warning, a judicial exposure and an opinion evaluation.

[0019] In the above implementation process, multi-modal data input by a user is supported, more complete case information is captured through multi-modal complementary analysis, and the problem of incomplete information in a single mode is improved. Moreover, multi-modal data such as addresses spoken in audio, transaction hashes in screenshots, and time descriptions in text can be cross-verified during analysis processing, improving the accuracy of case input information, and thus improving the accuracy of case research and judgment and reducing subsequent analysis deviation caused by incorrect single information.

[0020] Optionally, in the embodiments of the present application, after the target data is accessed by the large language model by calling the on-chain data access interface or the knowledge base access interface, if the target data needs to be accessed again, the target data that has been accessed is reused; by configuring different prompt word templates, different analysis targets and / or calling different contexts, the corresponding functions of the large language model in different steps are realized.

[0021] In the above implementation process, by configuring different prompt word templates, different analysis targets and / or calling different contexts, the same large language model agent has different levels of analysis intelligence in different stages, improving the overall research and judgment depth and intelligent level of the system. It also enhances the logical consistency and explainability between each stage in the research and judgment chain. And the target data that has been accessed is reused, reducing repeated calls and reducing resource consumption.

[0022] Optionally, in the embodiments of the present application, the method further comprises: constructing an animation timeline based on the transaction time sequence and / or the logical sequence of the target blockchain address through a graphical user interface; labeling the state information of the nodes according to the transaction time sequence of the target blockchain address in the animation timeline, rendering the nodes corresponding to the target blockchain address, generating an interactive animation, and displaying the corresponding state of the nodes in the fund network graph in the animation timeline in time sequence in the interactive animation.

[0023] In the implementation process described above, the complete logical chain from initial input analysis to data collection, fund network hierarchical expansion, and global analysis is displayed through interactive animation. The input data of each decision node, the calling service (MCP protocol), and the visual evidence of the output conclusion are visualized to show the dynamic process of the fund network graph from single-point growth to complex structure, and to better review and trace the case investigation process.

[0024] Optionally, in the embodiments of the present application, after generating the interactive animation, the method further includes: receiving an operation instruction for the interactive animation; the operation instruction is used to control the playing state of the interactive animation; the playing state includes at least one of pausing playing, continuing playing, ending playing, fast playing, playing back, node selection, and node state display; and the interactive animation is played based on the operation instruction.

[0025] In the implementation process described above, the interactive animation is controlled by implementing the operation instruction, the playing of the interactive animation is controlled, the entire case investigation process is flexibly watched, for example, the derivation process of any conclusion is verified through playback (such as why address E is marked as a transit hub), and the reasoning process is reproduced in an interpretable, traceable, and interactive manner.

[0026] Optionally, in the embodiments of the present application, in the interactive animation, the state information of the nodes changing over time is displayed in different display modes; the state information of the nodes includes node role information and / or transaction information; the display modes include color display, bright-dark display, and / or flashing display; and the node role information is generated by reasoning of the large language model.

[0027] In the implementation process described above, the state information of the nodes changing over time is displayed in different display modes, for example, the role of the transaction entry is changed to the role of the transaction exit, the change of the nodes at different times is displayed from the visual dimension, the change characteristics of the nodes are more obviously and explicitly determined, and the abnormal nodes are quickly locked from the complex network.

[0028] In a second aspect, the embodiments of the present application also provide a blockchain case investigation system, which includes: a case information understanding module, a fund network expansion module, and a fund network analysis module; the case information understanding module is used to obtain the case semantic context corresponding to a blockchain case based on the case input information of the blockchain case through a large language model; the case semantic context is used for fund flow tracking; the case semantic context includes on-chain traceable information and / or off-chain semantic information; the fund network expansion module is used to determine target blockchain addresses associated with the involved blockchain addresses based on the case semantic context, and construct a fund network graph; wherein the involved blockchain addresses and the target blockchain addresses are nodes of the fund network graph, and the relationship between the nodes is an edge of the fund network graph; and the fund network analysis module is used to analyze the fund network graph and obtain a case investigation result.

[0029] Optionally, in the embodiments of the present application, the blockchain case research and judgment system further comprises an MCP protocol module, the MCP protocol module is configured to receive data on the blockchain, off-chain data and / or historical cases in real time; encapsulate the data on the blockchain, off-chain data and / or historical cases to generate a corresponding data access interface, and provide the large language model with the case semantic context by responding to the call of the large language model to the data access interface; the MCP protocol module is further configured to share data between the case information understanding module, the fund network expansion module and the fund network analysis module.

[0030] In a third aspect, the embodiments of the present application further provide a computer program product, comprising computer program instructions, which, when executed by a processor, perform the method provided in the first aspect or any one of the implementation manners of the first aspect.

[0031] In a fourth aspect, the embodiments of the present application further provide an electronic device, comprising a processor and a memory, the memory storing computer program instructions, which, when executed by the processor, perform the method provided in the first aspect or any one of the implementation manners of the first aspect.

[0032] In a fifth aspect, the embodiments of the present application further provide a computer readable storage medium, which stores computer program instructions, which, when executed by a processor, perform the method provided in the first aspect or any one of the implementation manners of the first aspect.

[0033] By using the blockchain case research and judgment method, system, program product, device and storage medium provided in the present application, the large language model is used to perform semantic analysis on the case input information, the case semantic context corresponding to the blockchain case is extracted, the process of manually processing data is replaced, and the research and judgment efficiency is improved. The fund network graph is constructed based on the involved blockchain address in the case, the on-chain transaction data and off-chain semantic information are fused in the fund network graph, and the fund network graph has machine readability and human understandable, thereby providing comprehensive data support for subsequent case research and judgment. The constructed fund network graph is comprehensively analyzed in a global and multi-dimensional manner, the case research and judgment efficiency is improved, and the problem of low efficiency of manual analysis and judgment of cases is improved. BRIEF DESCRIPTION OF DRAWINGS

[0034] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiments of the present application. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as a limitation on the scope. For those skilled in the art, other related drawings can also be obtained without creative labor on the basis of these drawings.

[0035] Figure 1A flowchart of a blockchain case research method provided by an embodiment of the present application is shown. Figure 2 A fund network map provided by an embodiment of the present application is shown. Figure 3 A structure diagram of a blockchain case research system provided by an embodiment of the present application is shown. Figure 4 A structure diagram of an electronic device provided by an embodiment of the present application is shown. DETAILED DESCRIPTION

[0036] The embodiments of the technical solutions of the present application will be described in detail below with reference to the accompanying drawings. The following embodiments are only used to more clearly illustrate the technical solutions of the present application, and therefore only serve as examples, and cannot limit the protection scope of the present application.

[0037] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which the present application belongs; the terms used herein are only for the purpose of describing specific embodiments and are not intended to limit the present application.

[0038] In the description of the embodiments of the present application, the technical terms "first", "second", etc. are only used to distinguish different objects, and cannot be understood as indicating or implying relative importance or implicitly indicating the number, specific order or primary and secondary relationship of the indicated technical features. In the description of the embodiments of the present application, the meaning of "multiple" is two or more, unless otherwise explicitly specified.

[0039] Please refer to Figure 1 A flowchart of a blockchain case research method provided by an embodiment of the present application is shown. The blockchain case research method provided by the present application can be applied to an electronic device, which can include a server, a PC, a tablet computer or a smart phone, etc. physical device, or also can be a virtual machine or a container, etc. virtual device, the electronic device can be a single device, or a combination of multiple devices or a cluster of a large number of devices. The blockchain case research method can include: Step S110: obtaining the case semantic context corresponding to the blockchain case based on the case input information of the blockchain case through a large language model; the case semantic context is used for fund flow tracking; the case semantic context includes on-chain traceable information and / or off-chain semantic information.

[0040] Step S120: determining the target blockchain address associated with the involved blockchain address based on the case semantic context, and constructing a fund network map; wherein the involved blockchain address and the target blockchain address are nodes of the fund network map, and the relationship between the nodes is the edge of the fund network map.

[0041] Step S130: analyzing the fund network graph to obtain a case research result.

[0042] In step S110, the case input information of the blockchain case can be information about the case input by a user, including a text description or an image screenshot (single modal data), or can be multi-modal data; the case input information can also be generated after the user input information is parsed, extracted, and processed.

[0043] The case semantic context can be a machine-readable case summary generated by a large language model, containing on-chain traceable information and off-chain semantic information, as a unified input framework for subsequent analysis. Among them, the on-chain traceable information: such as the involved blockchain address, transaction hash, block name, transaction time data and other structured information. These information are directly used for subsequent fund flow tracking and address behavior analysis. The off-chain semantic information: including case background description (such as the time of the case, the number of victims, etc.), case type (such as fraud, online gambling, money laundering, etc.), clues text provided by law enforcement agencies, involved entities (such as platform name, suspect nickname, etc.) and other unstructured information.

[0044] Example of obtaining on-chain traceable information: the case input information is "address 0xabc transfers funds to multiple accounts in May", and the large language model extracts 0xabc as the involved blockchain address and the time window as "May" as the on-chain traceable information.

[0045] Example of obtaining off-chain semantic information: the large language model identifies case features in unstructured descriptions, for example: the input text mentions "the address was reported in the dark web forum", and the large language model classifies "dark web forum" as an off-chain risk label.

[0046] In step S120, the on-chain traceable information parsed from the case input information includes the involved blockchain address, which can be several or more, and the involved blockchain address can be the fund transfer-in party or the fund transfer-out party or other intermediate nodes in the transaction.

[0047] Taking the involved blockchain address as an extension starting point, a progressive multi-round access strategy is adopted to gradually explore target blockchain addresses associated with the involved blockchain address, which can be fund interaction counterparty addresses, frequent transaction relationship nodes, and potential intermediary stepping stone nodes.

[0048] For example, all direct transaction counterpart addresses (e.g., B, C, and D) of the target blockchain address A are obtained through a large language model. The node relationship is established: A→B, A→C, and A→D, and the edge attribute includes transaction time, amount, and asset type. Then, multi-layer progressive expansion is performed. For the counterpart address (e.g., B), the above process is repeated: the counterpart addresses E and F of B are obtained, and the relationships B→E and B→F are added. For the counterpart addresses C and D, the counterpart addresses can also be obtained. The cycle continues until the termination condition (e.g., 5 layers of expansion or 50 nodes covered) is met. The above counterpart addresses B, C, D, E, F, and other queried addresses can be used as target blockchain addresses associated with the target blockchain address. Of course, in order to reduce the number of irrelevant nodes included in the fund network graph, the fund network graph can be constructed after screening the addresses B, C, D, E, F, and other queried addresses.

[0049] In an optional embodiment, during the determination of the target blockchain address, the expansion range can be dynamically adjusted (e.g., network depth, total number of nodes, number of edges, or number of expansion iterations), and the specified time window, asset type, or chain level can be supported.

[0050] After the target blockchain address is determined, the fund network graph can be structured and encapsulated based on the queried nodes and the relationships between the nodes. For example, the node attributes include transaction addresses, address risk labels, and fund roles. The edge attributes include transaction direction, cumulative transaction amount, and transaction timestamp.

[0051] In step S130, when the fund network expansion process reaches the preset threshold, the expansion operation can be terminated, and the constructed fund network graph can be subjected to global and multi-dimensional comprehensive analysis to obtain a case research result. For example, a large language model is used to identify semantic information of each node in the fund network graph, and the context semantic information of each node is aggregated based on its upstream and downstream structural positions in the network to form a case research result describing the global information in the fund network graph. This solution will be described later.

[0052] The roles of global nodes can also be identified, such as source nodes (e.g., address A) with no incoming transaction and an outgoing transaction amount ratio exceeding 70%, and export nodes (e.g., address F) with funds flowing to exchanges or stable coin issuers. Risk fund paths and risk node lists can also be identified as case research results.

[0053] After obtaining the case research result, a corresponding report template can be selected according to the application scenario to present diversified visual results. This module supports two core output types: natural language type output and structured data type output, which serve the dual needs of artificial decision reference and system integration reuse.

[0054] In the implementation process described above, the semantic analysis of the case input information by the large language model extracts the case semantic context corresponding to the blockchain case, replaces the manual data processing process, and improves the research and judgment efficiency. Based on the involved blockchain address, a fund network map is constructed, and the chain transaction data and off-chain semantic information are integrated in the fund network map, which has machine readability and human understandable, providing comprehensive data support for subsequent case research and judgment. The comprehensive analysis of the constructed fund network map improves the case research and judgment efficiency and solves the problem of low efficiency of manual analysis and judgment.

[0055] Optionally, in the embodiment of the present application, before obtaining the case semantic context corresponding to the blockchain case based on the case input information of the blockchain case by the large language model, the method further comprises: Receiving user input multi-modal data, the multi-modal data including at least two of text data, image data, audio data and video data. For example, text input: support short text (such as a sentence prompt: “help me analyze whether the address is involved in fraud”); support long documents (such as case briefs, electronic records, report excerpts); language support for Chinese and English automatic detection. Image input: support screenshot input (for example, address activity map screenshot in the browser); use visual model for image text recognition and semantic understanding; can be processed jointly with text input to perform cross-modal understanding. The embodiment of the present application supports multiple input modalities to enhance the applicability and human-computer interaction ability of the system.

[0056] Analyzing and processing the multi-modal data to obtain the case input information of the blockchain case; the analysis and processing includes filtering irrelevant information, extracting entity information and / or meaning classification; the entity information includes at least one of the involved blockchain address, transaction time, transaction address and transaction user; the meaning classification includes at least one of the crime type, behavior warning, judicial exposure and opinion evaluation.

[0057] In order to reduce the waste of resources in subsequent analysis, the multi-modal data input by the user can be identified for case relevance, and irrelevant information can be filtered to lay the foundation for subsequent analysis strategy. The relevant information identified includes but is not limited to: event information: time, place, task, etc. Involved type: identify the possible crime types involved in the input, such as theft, fraud, money laundering, etc. Transaction information: whether there is account information such as blockchain address, bank card number, etc. Perform noise removal on other unstructured data: for example, remove advertisements, emoticons in text; crop irrelevant areas in images / videos; filter background noise in audio.

[0058] For the input data confirmed to be related to the case, core entities with judgment value can be extracted. Entity information is an objective fact element extracted from the original data, which can include: blockchain address, transaction hash, transaction information such as amount, time, and other information. As an implementation, text regular matching can be used to identify 0x / bc1 format strings; image OCR recognition can also be used to parse wallet address QR codes from screenshots; and audio speech-to-text + keyword extraction can be used to extract entity information.

[0059] Meaning classification refers to the determination of the nature of the case and the risk attribute. The crime type label in meaning classification can use a large model to analyze the text semantics: for example, classifying “inducing investment and then disappearing” as “fraud”. Image content understanding: identifying gambling APP interface screenshots labeled “online gambling”. Behavior warning, such as detecting high-frequency small-amount transfer patterns, aligning the label “suspected money laundering”. Judicial exposure, such as matching historical case-related address library: if the case-related blockchain address has appeared in a court judgment, it is labeled as “already judicially investigated”. Opinion evaluation can be: the subjective evaluation tendency of the public or victims to the address; or KOL (Key Opinion Leader) evaluation, which refers to the evaluation made by people with professional knowledge in a specific field. Opinion evaluation, for example, extracts emotional tendencies from social text: “This address has very poor credibility (negative review)”, which is classified as a negative evaluation label.

[0060] As an implementation, after analyzing the relevant information, extracting entity information, and / or meaning classification, the analysis results can be integrated to form structured data as case input information.

[0061] In the implementation process of the above embodiments: support user multi-modal data input, capture more complete case information through multi-modal complementary analysis, and improve the problem of incomplete information in a single mode. And the address spoken in the audio, the transaction hash in the screenshot, and the time description in the text, etc. Multi-modal data can be cross-verified during the analysis process, improving the accuracy of case input information, and thus improving the accuracy of case analysis and reducing the deviation caused by a single piece of incorrect information.

[0062] After obtaining the case input information, the fund network graph can be constructed based on the case input information and analyzed, etc. During these steps, the large model needs to call the corresponding data interface to obtain the relevant data, so before that, the generation process of the data interface that needs to be called during the construction of the fund network graph and analysis is introduced.

[0063] First, data collection and knowledge integration are performed. The collected data can include on-chain data, off-chain data, and / or historical cases. Among them, the on-chain data is used to generate an on-chain data access interface through the MCP protocol to provide transaction query services for the large model, such as obtaining address transactions, address counterparts, address labels, etc. The off-chain data is used to build an off-chain public opinion knowledge base, and based on the off-chain public opinion access interface generated through the MCP protocol, the large language model is provided with case feature query services. The historical cases are used to build a historical case knowledge base, and a historical case access interface is generated through the MCP protocol to provide the large language model with knowledge resources such as similar case retrieval, typical path patterns, and suspicious behavior labels.

[0064] The MCP protocol refers to a model context protocol that encapsulates heterogeneous data into a standardized format (including service type, data subject, and attribute field) readable by machines for cross-system calls. Through the standardized data services exposed by the MCP protocol, the large language model can query the knowledge base content according to conditions such as address, event type, and behavior pattern.

[0065] The processes of collecting the above three kinds of data and generating the corresponding interfaces are introduced as follows: (1) On-chain data collection can be multi-chain data collection, such as connecting different blockchain nodes (e.g., using Etherscan API for ETH, connecting TronGrid for TRON, and calling Blockchain.info for BTC) through a multi-chain adapter to listen to new block generation in real time. On-chain data is collected according to conditions such as address dimension, transaction dimension, and block dimension, including but not limited to: historical transactions (including counterpart addresses), contract behavior, etc. Then, the on-chain data is cleaned to reduce invalid transactions and noise data.

[0066] Behavioral features and risk labels can also be extracted from the collected on-chain data. For example, the daily transaction frequency of an address is calculated, the fund aggregation feature is counted, or high-frequency transaction counterparts are identified to generate their behavior features. Then, the rule engine is used to label the behavior features with risk labels, such as money laundering suspicion: consistent with the "diversified transfer-in and centralized transfer-out" pattern.

[0067] Then, through the MCP protocol, the collected on-chain data and corresponding behavior features and risk labels are encapsulated according to the standard data format to generate an on-chain data access interface. The on-chain data access interface can provide address query services: input address 0xabc, return all transactions (counterpart addresses, address historical transactions), and behavior labels; it can also provide behavior retrieval services: input behavior_tags="diversified transfer-in and centralized transfer-out", return matching address list. As an implementation, when a new block contains a target address transaction, the interface data is automatically refreshed.

[0068] (2) Off-chain data can be collected through multiple sources of off-chain data (such as social platforms, public opinion platforms, forums, and blacklisted sites). The scope of collection includes address labels: extracting users' public labels for blockchain addresses from social platforms (e.g., "fraudulent addresses" and "dark web payment accounts"); attack event information: collecting attack reports from hacker organization announcements and vulnerability disclosure platforms (e.g., "a certain exchange was hacked, and the funds were transferred to address 0xabc"); chat records: crawling black market forums and encrypted community conversations (e.g., "receive gambling funds with address 0xdef and settle daily").

[0069] The collected off-chain data can be preprocessed, such as data cleaning. Then, the entities and events are associated, for example, address 0xabc is bound to related events (e.g., "phishing attack event on May 1, 2023 → funds flow into 0xabc"); and confidence can be labeled (e.g., user reporting class label confidence 60%, official announcement class confidence 95%). Then, according to the address structure, store multiple sources of evidence to generate an off-chain public opinion knowledge base. For example, the storage format can be "address 0xabc: label, attack event, chat record".

[0070] Then, through the MCP protocol, the off-chain public opinion knowledge base is packaged according to the standard data format to generate an off-chain public opinion access interface. The off-chain public opinion access interface supports querying by address: input 0xabc, return all labels and associated events; and supports event reverse lookup: input "exchange X stolen", return the list of addresses involved.

[0071] (3) Historical cases can come from real case research and judgment experience, analysis records, fund paths, and blockchain case files accumulated by the company. These can be converted into structured knowledge assets, such as knowledge extraction from different cases, including fund networks, industry terminology explanations, analysis processes based on case types, and address abnormal transaction behaviors. Then, based on the extracted support, a historical case knowledge base can be built. For example, the storage format can be "case type (cryptocurrency fraud): fund network, industry terminology explanation, analysis process, address abnormal transaction behavior".

[0072] Then, through the MCP protocol, the historical case knowledge base is packaged according to the standard data format to generate a historical case access interface. The historical case access interface can return knowledge by case type: input "cryptocurrency fraud", return the fund network characteristics and terminology explanations of this type of case; and support behavior matching: input transaction mode description, return similar historical cases.

[0073] The above data interfaces can be implemented through MCP to achieve high granularity and multi-dimensional context encoding, supporting subsequent research and judgment using "by address", "by transaction", "by contract behavior", "by time window", and other ways to retrieve on-chain evidence.

[0074] In the implementation of the above embodiments: on-chain data, off-chain data, and historical cases generate corresponding data interfaces, respectively, to improve data response speed through single query of MCP interface to obtain cross-chain data. Raw transaction data is processed by behavior labeling, so that it can be directly used after calling a large language model, reducing the data processing burden of the large model. Fragmented data of social platforms is stored in a knowledge base structure, and is converted into machine-readable evidence with confidence, improving case analysis capabilities. Multiple retrieval methods are supported to make data calling more flexible.

[0075] Optionally, in the embodiments of the present application, based on the semantic context of the case, the target blockchain address associated with the case-involved blockchain address is determined, and a fund network map is constructed, including the following steps: The case-involved blockchain address is taken as a core address, and an opponent address having a transaction behavior with the core address is obtained through a large language model. The large language model combines the semantic context of the case (including preset conditions such as case type and time range), can call a chain data access interface, and extract a list of opponent addresses having a direct fund flow with the core address.

[0076] The opponent addresses are screened by using a preliminary screening rule, and the screened opponent addresses are taken as core addresses, and the step of taking the case-involved blockchain address as a core address and obtaining an opponent address having a transaction behavior with the core address through a large language model is jumped to, until a termination condition is reached, to obtain candidate opponent addresses.

[0077] The preliminary screening rule is a mechanism for filtering low-correlation addresses by quantitatively evaluating the fund interaction features (such as amount proportion, frequency, behavior similarity, etc.) of the opponent addresses and the core address. For example, the core address queries three opponent addresses (A, B, and C), and the preliminary screening rule is used to calculate scores of the core address and the three opponent addresses, respectively, to filter out a low-score opponent address (C), and high-score opponent addresses (A and B) are the screened opponent addresses. The opponent addresses (A and B) are taken as core addresses, and corresponding opponent addresses are found through a large language model. This cycle is repeated until a termination condition is reached to obtain candidate opponent addresses. The termination condition is, for example, that the network layer number reaches a preset layer number, the number of candidate addresses reaches a preset number, the minimum score reaches a preset threshold, or the scores of the found opponent addresses are all lower than a preset threshold.

[0078] Through a large language model, the candidate opponent address is screened for case characteristics based on the semantic context of the case, and a target blockchain address associated with the case-involved blockchain address is obtained. The remaining candidate fund opponent addresses after the preliminary screening will be input into the "large model analysis node" for in-depth analysis at the semantic level. The model combines context semantics, historical fund behavior, and expert knowledge to determine whether it has characteristics related to the case (such as abnormal interaction frequency with the case-involved address, synchronized fund flow within the same time window, presence of suspicious labels, etc.), thereby deciding whether to include it in the fund network graph.

[0079] A fund network graph is constructed based on the target blockchain address. The case-involved blockchain address and the target blockchain address are nodes of the fund network graph, and directed edges (such as 0xabc → B1) are added according to the actual transaction flow to establish edge relationships, forming the fund network graph. Semantic information can also be injected into the nodes in the fund network graph, such as the preliminary screening score attached to the node (B1: 0.845) and the case characteristic label (B1: "associated with black production"). The edge can be attached with transaction details (amount 1.2 ETH, time 2023-05-05).

[0080] In the implementation process of the above embodiments: low-relevance opponent addresses are pre-filtered through preliminary screening rules, and case characteristic screening is performed on candidate opponent addresses after preliminary screening, so that subsequent large model analysis only needs to process high-potential targets, reducing invalid calculations on irrelevant addresses and improving research and judgment efficiency. A progressive multi-round access strategy is adopted to track and cover multiple levels of fund transfers, making the evidence chain more complete and improving the overall case research and judgment.

[0081] Optionally, in the embodiments of the present application, the case-involved blockchain address is taken as a core address, and the opponent addresses having transaction behavior with the core address are obtained through a large language model, including: The case-involved blockchain address is taken as a core address, and the opponent addresses having transaction behavior with the core address are obtained through a large language model calling a chain data access interface based on the semantic context of the case. The chain data access interface is constructed by using the collected on-chain data through the MCP protocol, and the chain data access interface is used to provide transaction query services for the large language model.

[0082] The case-involved blockchain address is included in the semantic context of the case, and the case-involved blockchain address is taken as a core address. The large language model converts the semantic context into a chain data access interface query instruction, and the chain data access interface returns a structured result: a list of transaction opponent addresses: B1 (1.2 ETH transferred on May 3), B2 (8.5 ETH transferred on May 10). It can also return behavior labels and associated risks, etc. The construction process of the chain data access interface is described above, and the chain data access interface can support address-based queries and return opponent addresses.

[0083] In the implementation process of the above embodiments: the counterparty address with a transaction behavior with the core address is obtained by calling the data access interface on the MCP protocol call chain, and the counterparty address can be obtained through a unified calling manner, reducing the multi-chain adaptation cost. The returned counterparty address data is standardized through the protocol layer, reducing the address coding difference. The base value is updated in real time through the MCP, and the latest counterparty address can be obtained immediately.

[0084] Optionally, in the embodiments of the present application, the preset rule is used to screen the counterparty address, and the screened counterparty address is taken as the core address, comprising: The multi-dimensional feature similarity between the core address and the counterparty address is calculated respectively; the multi-dimensional feature similarity includes at least one of the transfer amount factor, the interaction frequency factor, the amount feature similarity and the activity time similarity.

[0085] The transfer amount factor represents the transfer amount between the counterparty address and the core address and the proportion of the core address in the flow. For example, the total flow amount of the core address (such as 0xabc) in a specified time window can be obtained, the total amount of two-way transfer between the address and each counterparty address (such as B1) is counted, and the transfer amount factor = the total amount of two-way transfer / total flow amount. The transfer amount factor can identify the counterparty with large amount of fund transfer and exclude occasional transaction objects.

[0086] The interaction frequency factor represents the fund interaction frequency between the counterparty address and the core address and the proportion of the core address activity frequency. For example, the total transaction times of the core address are counted; the interaction times between the core address and the counterparty address are counted; and the interaction frequency factor = interaction times / total transaction times. The interaction frequency factor can capture high-frequency transaction counterparties and filter one-time transfer addresses.

[0087] The amount feature similarity represents the similarity of the income and expense amount distribution characteristics between the counterparty address and the core address. The income and expense distribution of the core address 0xabc (such as 30% of the transactions are 0.1-1 ETH small amount of collection, and 70% are 5-10 ETH large amount of transfer) can be analyzed; the income and expense mode of the counterparty address B1 (such as 45% of the transactions are 0.1-1 ETH collection, and 55% are 4-9 ETH transfer) can be analyzed. The histogram comparison method is used to quantify the difference in amount interval distribution as a similarity score (for example: the difference in 0.1-1 ETH interval between the two addresses |30%-45%|=15%, and the overall similarity =1-cumulative difference→score 0.82). The amount feature similarity can identify behavior pattern cloned counterparties (such as money laundering gang member addresses).

[0088] The active time similarity represents the similarity of the active time characteristics of the adversary address and the core address. For example, the peak transaction period or active period of the core address and the adversary address can be counted, and the overlap rate of the peak transaction period or active time window of the two addresses can be calculated. The active time similarity can locate the addresses controlled by the same operator (such as the puppet accounts with synchronous activities at night).

[0089] Based on the multi-dimensional feature similarity between the core address and the adversary address, the adversary address is screened to obtain a screened adversary address. For example, the multi-dimensional feature similarity can be weighted and summed respectively to obtain a total score of the adversary address, all adversary addresses are sorted in descending order of the total score, and the top N (such as the top 50%) or addresses above a threshold (>0.35) are retained as the screened adversary address. For example, the total score (S) can be calculated using a weighted average method:

[0090] Wherein: S is the total score; is the transfer amount factor; is the interaction frequency factor; is the amount feature similarity; is the active time similarity; is the weight coefficient of the transfer amount factor; is the weight coefficient of the interaction frequency factor; is the weight coefficient of the amount feature similarity; is the weight coefficient of the active time similarity. Wherein, is a dynamically adjustable weight coefficient, for example, the weight coefficients of the multi-dimensional features can be adjusted according to the case type. For example, in a coin theft case, there are more transfer addresses, and the transfer addresses can better highlight their characteristics in time, so the weight related to time will be higher, such as increasing the weight coefficient of the active time similarity .

[0091] In the implementation process of the above embodiment: through the quantitative multi-dimensional feature similarity, the adversary address with higher correlation is accurately captured, and the transfer amount factor in the multi-dimensional feature similarity reflects the fund correlation strength, the interaction frequency factor measures the relationship closeness, the amount feature similarity detects the behavior consistency, and the active time similarity assists in judging whether it is controlled by the same subject from the time dimension. These preliminary screening rules measure the transaction behavior correlation degree of the adversary address and the core address from multiple aspects, reduce the invalid calculation of irrelevant addresses, and improve the research and judgment efficiency.

[0092] Optionally, in the embodiment of the present application, the case feature screening is performed on the candidate adversary address based on the large language model to obtain a target blockchain address associated with the case blockchain address, including: The candidate adversary address is input into the large language model, a knowledge base access interface is called through the large language model, case characteristics of the candidate adversary address are analyzed based on a case semantic context, and a target blockchain address is obtained; the knowledge base access interface is constructed based on an MCP protocol and is used to provide a case characteristic query service for the large language model; the case characteristics include abnormal interaction data, fund flow data of the candidate adversary address and the involved blockchain address, and / or an abnormal label of the candidate adversary address.

[0093] For example, candidate addresses (such as B1 and C1) are screened out, and case characteristic analysis is performed on the candidate addresses (B1 and C1). First, the large language model loads a case semantic context (for example, a case type "fraud", a time window "May 2023", and an involved address 0xabc) of each candidate adversary address; an independent analysis task is generated for each candidate address, for example, "analyze whether address B1 has abnormal interaction with the involved address 0xabc during May 2023 and is associated with a fraud behavior characteristic".

[0094] The MCP protocol is used to call three types of data access interfaces to obtain case characteristics, for example, a chain data access interface is called to return abnormal interaction data and fund flow data; a chain data access interface is called to return abnormal labels and attack events; and a historical case access interface is called to return a historical case matching model.

[0095] The case characteristics obtained by the above query are analyzed, for example, "8.5 ETH single transfer-in" of B1 returned in the abnormal interaction data meets the large-incoming-fund characteristic of a fraud case; the fund flow data shows that B1 receives funds from five small addresses at the same time, and the abnormal label of B1 is "fraud", which meets any characteristic, so it is determined that the candidate adversary node is a target blockchain address associated with the involved blockchain address. The same analysis is performed on other candidate adversary nodes, such as C1, to determine whether they are target blockchain addresses. Only addresses that pass the characteristic verification are retained as target blockchain addresses (for example, B1 meets the conditions, and C1 is excluded without risk evidence).

[0096] In the implementation process of the above embodiment: the "pre-screened candidate adversary address" is input into the large language model, the knowledge base (on-chain data, off-chain data, and on-the-way cases) is called for secondary screening, case characteristics are screened based on the semantics of the candidate adversary address, the explainability of the finally determined target blockchain address is improved, and the related nodes involved in the case are more accurately queried, so that the efficiency and accuracy are effectively balanced. On the one hand, a large number of low-relevance addresses are avoided from being input into the model, and on the other hand, high-potential-risk adversaries are retained, thereby improving the quality of the fund network construction.

[0097] Optionally, in the embodiment of the present application, the fund network graph is analyzed to obtain a case research result, including the following steps: The knowledge base access interface is called through the large language model to obtain semantic information of the target blockchain address in the fund network graph. Referring to the case feature process of determining the candidate adversary address, the on-chain data access interface is called to return abnormal interaction data and fund flow data; the off-chain public opinion access interface is called to return abnormal labels and attack events; the historical case access interface is called to return a historical case matching model, and the data can be used as semantic information of the target blockchain address.

[0098] Subsequently, upstream and downstream structure information of the target blockchain address in the fund network graph is obtained; the upstream and downstream structure information is used to represent a topological position relationship of the target blockchain address in the fund network graph. The upstream and downstream structure information can be determined through upstream tracing and downstream tracing. For example, the upstream tracing locates the address transferred to B1, the calculation dependence depth = 2, the downstream tracing identifies the fund export of B1, and the export quantity is counted: only one direct export. Then the upstream and downstream structure information of the target blockchain address can be B1 connected to 2 input addresses + 1 output address.

[0099] After obtaining the semantic information and the upstream and downstream structure information, the semantic information of the target blockchain address is aggregated based on the upstream and downstream structure information to obtain a case research and judgment result; the case research and judgment result is used to describe global information in the fund network graph; the global risk information includes at least one of a fund role of the target blockchain address, a risk fund path in the fund network graph, a risk node list, and a global research and judgment report. Node role identification: from the global information, the functional roles of the nodes in the network are reasonably divided, including but not limited to: a fund cleaning center node: having the characteristics of fund aggregation and redistribution; a fund stepping stone node: a fund quickly transitions, with extremely short residence time; a gray and black production and withdrawal node: an account directly interacting with a known case address or an off-site service interface; Risk fund path identification: identifying a fund path with highly suspicious characteristics, such as: a closed-loop fund link: a complete ring structure with fund reflux; a fund fast channel: a short link with high transaction frequency and rapid transfer; a cross-chain or cross-platform transfer path: a fund jump logic between different chains or platforms; Key node and path screening: based on structural dependence, risk aggregation, and other indicators, the suspicious nodes and paths are prioritized to form a list to be investigated; Global research and judgment report generation: generating a comprehensive analysis report covering the entire network, including a fund structure graph, a node label distribution, a suspected money laundering path analysis, a risk diffusion trend chart, and the like, to provide intelligent support for subsequent law enforcement investigation and regulatory intervention.

[0100] The following illustrates the process of convergence: convergence refers to the fusion of independent semantic labels of addresses (such as "money laundering node") and upstream and downstream structural information (such as "controls 65% of traffic") to generate more accurate composite conclusions: such as "core cleaning node". The convergence is, for example, according to the path of the target blockchain address: upstream path: D1→C2→B1 (fraud small amount of money collection chain, historical interface matching fraud pattern) downstream path: B1→0xex (money laundering outlet, off-chain interface marked "exchange money laundering channel"). The role of B1's funds is a funds cleaning node, and the role of 0xex's funds is a stolen money outlet. The risk fund path is D1→C2→B1→0xex. The risk node list includes C2, B1, 0xex, etc.

[0101] In the implementation process of the above embodiments: using upstream and downstream structural information, the separate address is embedded in the topological context of the fund network, improving the misjudgment of the transaction path. By converging semantics and topological information, a global case-level research and judgment result is generated, improving the limitations of single-address analysis. The complete fund network is analyzed globally and multidimensionally to realize the macroscopic portrait of the case, the identification of the key path, and the clear inference of the involved role.

[0102] The embodiments of the present application use large language models in the output case semantic context stage, the construction of fund network graph stage, and the graph analysis stage, but by configuring different prompt word templates, different analysis targets, and / or calling different contexts, the analysis direction is switched and the focus of intelligent reasoning is adjusted to realize the corresponding functions of the large language model in different steps.

[0103] a. Prompt word template difference: the prompt word used in the graph analysis stage is more inclined to global situation awareness and risk pattern summary, emphasizing the pattern recognition and role division of the fund flow network as a whole; while the prompt word in the construction of fund network graph stage focuses on local path analysis and single address behavior anomaly detection.

[0104] b. Different analysis targets: the graph analysis stage faces "graph optimization and risk research", emphasizing semantic fusion and structural understanding, while the construction of fund network graph stage focuses on "precise capture of high-relevance opponent nodes".

[0105] c. Different calling contexts: the graph analysis stage has stronger memory integration ability and can combine the semantic trajectories of all expansion processes to form a logically coherent and contextually consistent final judgment.

[0106] Through the differential design of the prompt word system and the distinction of the calling mechanism, the same large language model intelligent agent has different levels of analysis intelligence in different stages, improving the overall research and judgment depth and intelligent level of the system.

[0107] Although the analysis focus is different in different steps, they share a unified context structure. After the large language model accesses the target data through the data access interface or the knowledge base access interface in the calling chain, if the target data needs to be accessed again, the already accessed target data is reused.

[0108] By taking MCP as the standard format of the context, efficient data sharing and state inheritance can be achieved between steps. For example, in the process of constructing the fund network graph, the large language model calls the data interface to obtain the case characteristics of the target blockchain node. In the graph analysis stage, this part of data can be directly reused to generate semantic information of the target blockchain node. For example, if the graph analysis stage has calculated that "address A = money laundering transit address", this result can be used as context information through prompt word engineering, and the prompt word writes in "address A = money laundering transit address" and other information. The large language model can directly reuse this result calculated by the graph analysis. By reducing repeated calls, reducing resource consumption, and enhancing the consistency of analysis logic between models.

[0109] In addition, this mechanism not only improves the system running efficiency, but also enhances the logical consistency and explainability between each stage in the research and judgment chain.

[0110] In the implementation process of the above embodiment: by configuring different prompt word templates, different analysis targets, and / or calling different contexts, the same large language model agent has different levels of analysis intelligence in different stages, which improves the overall research and judgment depth and intelligent level of the system. It also enhances the logical consistency and explainability between each stage in the research and judgment chain. And reuse the target data that has been accessed, reduce repeated calls, and reduce resource consumption.

[0111] As an implementation, the generated analysis context, reasoning path, and case research and judgment result can be formatted and output, and presented as diversified visual results according to different application scenarios. The supported output types include natural language type output and structured data type output, which serve the dual needs of human decision reference and system integration reuse.

[0112] (1) Natural language type output (report suggestion generation): using a large language model combined with a structured prompt word template to generate result text, including but not limited to: case brief, analysis path description, risk point induction, and draft of suggested measures (such as freezing suggestions, further investigation suggestions, etc.) Such output is aimed at business personnel, investigation analysts, and management decision makers, providing highly readable and highly explanatory textual research and judgment results. To enhance accuracy, the system will inject structured intermediate results in the "research and judgment module" into the model prompt to ensure that the report has sufficient factual support and logical chain.

[0113] (2) Structured data type output (graph and data table), which is oriented to the needs of system docking, front-end visualization, and automatic archiving, and outputs standardized structured data results, including: Fund network graph data structure (node-edge model): used to visually display the transaction flow, path structure, and behavior label between addresses; analysis index table: lists the behavior characteristics, risk level, label matching degree, and similarity to historical cases of each key address; path tracking log: records the reason for each step of tracking in the fund flow path, the trigger node, and the data source used, facilitating traceability and auditing; JSON / CSV format export: facilitates the results to be stored in a database, archived, or transmitted to other systems.

[0114] This structured output not only enhances the integration capabilities of the system with external platforms (such as on-chain analysis platforms, law enforcement systems, and visualization dashboards), but also facilitates subsequent statistical analysis and machine learning modeling.

[0115] (3) Display interface and interaction support: the system front-end supports multi-dimensional and multi-view data display, with main functions including: case overview view: displays case summaries, main risk points, and fund flow directions in combination with text; fund network graph visualization: supports dynamic scaling, node click details, path highlighting, and other operations; result playback view: integrates the above animation playback functions to display the entire process of the research and judgment process; one-key export function: supports generating PDF reports, EXCEL tables, and JSON data packages. The front-end interface can adaptively adjust the display content according to user roles, ensuring that analysis personnel, auditors, and decision-makers can all obtain the required information.

[0116] Optionally, in the embodiments of the present application, the method further includes: constructing an animation timeline based on the time sequence and / or logical sequence of transactions in the target blockchain address through a graphical user interface.

[0117] The system automatically records the trigger timestamps of each reasoning node in the research and judgment process, such as address behavior judgment and rule preliminary screening. The timeline generation unit sorts all reasoning nodes according to the actual occurrence timestamps to form a linear sequence: T0 (user submits case analysis request) → T1 (address A analysis) → T2 (address B rule preliminary screening) → T3 (address B case feature screening) →... → T n (Global report generation).

[0118] The causal relationship between nodes can also be analyzed, for example: the case feature screening of address B (T3) must be after the rule preliminary screening of B (T2).

[0119] According to the transaction time sequence in the target blockchain address in the animation timeline, the state information of the node is marked, the node corresponding to the target blockchain address is rendered, and an interactive animation is generated. In the interactive animation, the nodes in the fund network graph are displayed in the animation timeline in time sequence according to the corresponding state.

[0120] The three of the timeline unit, the state visualization unit, and the graph linkage unit are displayed together. Taking address B as an example, the timeline unit marks T2 as an "address B initial screening completion" event; the state visualization unit synchronously displays, and a prompt box can be popped up on the interface: rule initial screening: address B score 0.82 (Top1), and address B is marked as a yellow question mark icon (indicating to be verified by a model); similarly, the graph linkage unit also synchronously displays, and a new node B and an edge A→B (a gray dashed line) are added in the fund graph.

[0121] See Figure 2 An embodiment of the application provides a fund network graph schematic diagram.

[0122] The involved address A can be an involved blockchain address, which is a node of the fund network graph. The node can be marked with attributes in the graph, for example, 115 entries and 96 withdrawals. The specific address or other attributes of the involved address A can also be marked, for example, the involved address D is an underground money shop, and the involved address B is a wallet service. The involved address A transfers 24 to the involved address B, a total of 8665 USDT. Each edge can be marked with transaction attributes (not shown in the figure).

[0123] In the implementation process of the above embodiment: the complete logical chain from initial input analysis to data collection, fund network hierarchical expansion, and global analysis is displayed through the interactive animation. The input data, called services (MCP protocol), and visualized evidence of output conclusions of each decision node are visualized to display the dynamic process of the fund network graph from single-point growth to complex structure, and the case research and judgment process is better reviewed and traced.

[0124] Optionally, in the embodiment of the application, after the interactive animation is generated, the method further includes: receiving an operation instruction for the interactive animation; the operation instruction is used to control a playing state of the interactive animation; the playing state includes at least one of pausing playing, continuing playing, ending playing, playing at a speed, playing back, node selection, and node state display; and the interactive animation is played based on the operation instruction.

[0125] In the implementation process of the above embodiment: the interactive animation is played by implementing the operation instruction on the interactive animation, the whole process of case research and judgment is flexibly watched, for example, the derivation process of any conclusion (for example, why address E is marked as a transfer hub) is verified through playback, and the reasoning process is reproduced in an interpretable, traceable, and interactive manner.

[0126] Optionally, in the embodiments of the present application, in the interactive animation, the state information of the nodes changing over time is displayed through different display modes; the state information of the nodes includes node role information and / or transaction information; the display modes include color display, bright-dark display and / or flicker display; wherein the node role information is generated by inference of a large language model.

[0127] The node rendering follows the time sequence, that is, the rendering of the inference nodes occurring earlier is first: at T1 moment: only render the node A corresponding to the involved blockchain address (light up A in the graphical interface), and display the state information of A at this time; at T2 moment: render the direct opponent addresses B, C and D of A (indicated as "to-be-verified state" by gray dashed lines); at T3 moment: when B is verified by the model, the line of B is changed to a red solid line and the node of B is lighted up; at T4 moment: render the opponents E and F of B taking B as the core (newly added dashed lines).

[0128] In the implementation process of the above embodiments: the state information of the nodes changing over time is displayed through different display modes, for example, the role of the transaction entry is changed to the role of the transaction exit, the changes of the nodes at different times are displayed from the visual dimension, and the change characteristics of the nodes are more obviously and explicitly locked from the complex network.

[0129] Please refer to Figure 3 The structural schematic diagram of the blockchain case research and judgment system provided by the embodiments of the present application is shown; the embodiments of the present application provide a blockchain case research and judgment system 200, which comprises: a case information understanding module 210, a fund network expansion module 220, and a fund network analysis module 230; The case information understanding module 210 is configured to obtain the case semantic context corresponding to the blockchain case based on the case input information of the blockchain case through a large language model; the case semantic context is used for fund flow tracking; the case semantic context includes on-chain traceable information and / or off-chain semantic information; The fund network expansion module 220 is configured to determine the target blockchain address associated with the involved blockchain address based on the case semantic context, and construct a fund network graph; wherein the involved blockchain address and the target blockchain address are nodes of the fund network graph, and the relationship between the nodes is an edge of the fund network graph; The fund network analysis module 230 is configured to analyze the fund network graph to obtain a case research and judgment result.

[0130] Optionally, in the embodiment of the present application, the blockchain case research and judgment system 200 further comprises an MCP protocol module connected with the case information understanding module, the fund network expansion module and the fund network analysis module; the MCP protocol module is configured to receive data on the blockchain, off-chain data and / or historical cases in real time; encapsulate the data on the blockchain, off-chain data and / or historical cases to generate corresponding data access interfaces, and provide the large language model with case semantic context by responding to the call of the large language model to the data access interfaces. The MCP protocol module is further configured to share data between the case information understanding module, the fund network expansion module and the fund network analysis module.

[0131] The processes of generating the on-chain data access interface according to the data on the blockchain, generating the off-chain public opinion access interface according to the off-chain data, and generating the historical case access interface according to the historical cases are described above.

[0132] Optionally, in the embodiment of the present application, the blockchain case research and judgment system 200, the fund network expansion module 220 is specifically configured to take the case-involved blockchain address as a core address, obtain opponent addresses having transaction behaviors with the core address through the large language model; filter the opponent addresses by using the preliminary screening rule, and take the filtered opponent addresses as core addresses, and jump to the step of taking the case-involved blockchain address as a core address, obtaining opponent addresses having transaction behaviors with the core address through the large language model, until a termination condition is reached, to obtain candidate opponent addresses; perform case feature screening on the candidate opponent addresses based on the case semantic context through the large language model, to obtain target blockchain addresses associated with the case-involved blockchain address; and construct a fund network map based on the target blockchain addresses.

[0133] Optionally, in the embodiment of the present application, the blockchain case research and judgment system 200, the fund network expansion module 220 is specifically configured to take the case-involved blockchain address as a core address, call the on-chain data access interface through the large language model, and obtain opponent addresses having transaction behaviors with the core address based on the case semantic context; the on-chain data access interface is constructed by using the collected data on the blockchain through the MCP protocol, and the on-chain data access interface is configured to provide transaction query services for the large language model.

[0134] Optionally, in the embodiment of the present application, the blockchain case research and judgment system 200, the fund network expansion module 220 is specifically used for calculating the multi-dimensional feature similarity between the core address and the opponent address respectively; the multi-dimensional feature similarity includes at least one of the transfer amount factor, the interaction frequency factor, the amount feature similarity and the activity time similarity; the transfer amount factor represents the proportion of the transfer amount between the opponent address and the core address to the proportion of the core address; the interaction frequency factor represents the proportion of the fund interaction frequency between the opponent address and the core address to the proportion of the core address activity frequency; the amount feature similarity represents the similarity of the income and expenditure amount distribution characteristics between the opponent address and the core address; the active time similarity represents the active time feature similarity between the opponent address and the core address; based on the multi-dimensional feature similarity between the core address and the opponent address, the opponent address is screened to obtain the screened opponent address.

[0135] Optionally, in the embodiment of the present application, the blockchain case research and judgment system 200, the fund network expansion module 220 is specifically used for inputting the candidate opponent address into the large language model, calling the knowledge base access interface through the large language model, and based on the case semantic context, the candidate opponent address is analyzed to obtain the target blockchain address; the knowledge base access interface is constructed based on the MCP protocol, and is used to provide case feature query service for the large language model; the case feature includes abnormal interaction data, fund flow data of the candidate opponent address and the involved blockchain address and / or abnormal label of the candidate opponent address.

[0136] Optionally, in the embodiment of the present application, the blockchain case research and judgment system 200, the fund network analysis module 230 is used for calling the knowledge base access interface through the large language model to obtain the semantic information of the target blockchain address in the fund network graph; the upstream and downstream structure information of the target blockchain address in the fund network graph is obtained; the upstream and downstream structure information is used to represent the topological position relationship of the target blockchain address in the fund network graph; based on the upstream and downstream structure information, the semantic information of the target blockchain address is aggregated to obtain the case research and judgment result; the case research and judgment result is used to describe the global information in the fund network graph; the global risk information includes at least one of the fund role of the target blockchain address, the risk fund path in the fund network graph, the risk node list and the global research and judgment report.

[0137] Optionally, in the embodiments of the present application, the blockchain case research and judgment system 200, the knowledge base access interface includes an off-chain public opinion access interface and / or a historical case access interface; the MCP protocol module is further configured to collect off-chain data, and generate an off-chain public opinion knowledge base; the off-chain data includes at least one of address tags, attack event information and chat records collected on a social platform; based on the off-chain public opinion knowledge base, the MCP protocol is used to generate the off-chain public opinion access interface; and / or, a historical case knowledge base is generated according to historical cases, and the historical case knowledge base includes at least one of a fund network of different case types, an industry term explanation, an analysis process based on a case type and address abnormal transaction behavior; based on the historical case knowledge base, the MCP protocol is used to generate the historical case access interface.

[0138] Optionally, in the embodiments of the present application, the blockchain case research and judgment system 200 further includes a multi-modal input module configured to receive multi-modal data input by a user, the multi-modal data including at least two of text data, image data, audio data and video data; the multi-modal data is analyzed and processed to obtain case input information of the blockchain case; the analysis and processing includes filtering irrelevant information, extracting entity information and / or meaning classification; the entity information includes at least one of a case-involved blockchain address, a transaction time, a transaction address and a transaction user; the meaning classification includes at least one of a crime type, a behavior warning, a judicial exposure and an opinion evaluation.

[0139] Optionally, in the embodiments of the present application, the blockchain case research and judgment system 200 is further configured to, after the large language model accesses target data by calling the on-chain data access interface or the knowledge base access interface, if the target data needs to be accessed again, reuse the target data that has been accessed; by configuring different prompt word templates, different analysis targets and / or calling different contexts, the corresponding functions of the large language model in different steps are respectively realized.

[0140] Optionally, in the embodiments of the present application, the blockchain case research and judgment system 200 further includes a dynamic research and judgment playback module configured to construct an animation timeline based on a transaction time sequence and / or a logical sequence in a target blockchain address through a graphical user interface; mark state information of a node according to the transaction time sequence in the target blockchain address in the animation timeline, render the node corresponding to the target blockchain address, generate an interactive animation, and display the corresponding state of the node in the fund network graph in the animation timeline in a time sequence in the interactive animation.

[0141] Optionally, in the embodiment of the present application, the blockchain case research and judgment system 200, the dynamic research and judgment playback module is further used for receiving an operation instruction for the interactive animation; the operation instruction is used for controlling a playing state of the interactive animation; the playing state includes at least one of pausing playing, continuing playing, ending playing, playing at a speed, playing back, node selection and node state display; and the interactive animation is played based on the operation instruction.

[0142] Optionally, in the embodiment of the present application, the blockchain case research and judgment system 200, the dynamic research and judgment playback module is further used for displaying state information of the node changing over time in the interactive animation through different display modes; the state information of the node includes node role information and / or transaction information; the display mode includes color display, bright-dark display and / or flashing display; and the node role information is generated by inference of a large language model.

[0143] It should be understood that the system corresponds to the blockchain case research and judgment method embodiments described above, and can perform each step involved in the above method embodiments. The specific functions of the system can be referred to the description above. To avoid repetition, the detailed description is appropriately omitted here. The system includes at least one software function module that can be stored in the memory in the form of software or firmware or solidified in the operating system (OS).

[0144] Please refer to Figure 4 The electronic device provided by the embodiment of the present application is shown in the structural schematic diagram. The electronic device 300 provided by the embodiment of the present application includes a processor 310 and a memory 320. The memory 320 stores machine readable instructions executable by the processor 310. When the machine readable instructions are executed by the processor 310, the method described above is performed.

[0145] Figure 4 The components shown in the above embodiments can be realized in hardware, software or a combination thereof. The electronic device 300 can be a physical device such as a server, a PC, etc., or a virtual device such as a virtual machine, a virtualization container, etc. Moreover, the electronic device 300 is not limited to a single device, but can also be a combination of multiple devices or a cluster of a large number of devices.

[0146] The embodiment of the present application further provides a storage medium, and the storage medium stores a computer program. When the computer program is run by a processor, the method described above is executed.

[0147] The storage medium can be implemented by any type of volatile or nonvolatile storage devices or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk or optical disk.

[0148] The embodiments of the present application further provide a computer program product comprising computer program instructions, and the computer program instructions are executed by a processor to perform the method described above.

[0149] In several embodiments provided by the embodiments of the present application, it should be understood that the disclosed apparatus and method can also be implemented by other manners. The apparatus embodiments described above are merely illustrative, for example, the flowcharts and block diagrams in the drawings show the possible implementation architecture, function and operation of the apparatus, method and computer program product according to the embodiments of the present application. In this regard, each block in the flowcharts or block diagrams can represent a module, a program segment or a part of code, and the module, program segment or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementation manners, the functions noted in the blocks can also occur in different order from that noted in the drawings. For example, two consecutive blocks can actually be executed substantially in parallel, and sometimes they can be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and the combination of blocks in the block diagrams and / or flowcharts, can be implemented by a special hardware-based system for executing the specified functions or actions, or can be implemented by a combination of special hardware and computer instructions.

[0150] In addition, each functional module in each of the embodiments of the present application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.

[0151] The above description is only optional implementation of the embodiments of the present application, but the protection scope of the embodiments of the present application is not limited thereto, any person skilled in the art can easily think of changes or replacements within the technical range disclosed by the embodiments of the present application, which should be covered in the protection scope of the embodiments of the present application.

Claims

1. A blockchain case analysis method, characterized in that, The method comprises the following steps: obtaining a case semantic context corresponding to a blockchain case based on case input information of the blockchain case through a large language model; the case semantic context is used for fund flow tracking; the case semantic context comprises on-chain traceable information and / or off-chain semantic information; determining a target blockchain address associated with an involved blockchain address based on the case semantic context, and constructing a fund network graph; wherein the involved blockchain address and the target blockchain address are nodes of the fund network graph, and the relationship between the nodes is an edge of the fund network graph; analyzing the fund network graph to obtain a case research result.

2. The method of claim 1, wherein, determining a target blockchain address associated with an involved blockchain address based on the case semantic context, and constructing a fund network graph, comprising: taking the involved blockchain address as a core address, and obtaining a counterpart address having a transaction behavior with the core address through the large language model; screening the counterpart address using a preliminary screening rule, and taking the screened counterpart address as the core address, and jumping to the step of taking the involved blockchain address as the core address, and obtaining a candidate counterpart address through the large language model until a termination condition is reached; screening the candidate counterpart address based on the case semantic context through the large language model to obtain a target blockchain address associated with the involved blockchain address; constructing the fund network graph based on the target blockchain address.

3. The method of claim 2, wherein, taking the involved blockchain address as a core address, and obtaining a counterpart address having a transaction behavior with the core address through the large language model, comprising: taking the involved blockchain address as a core address, and obtaining a counterpart address having a transaction behavior with the core address through the large language model based on the case semantic context; the on-chain data access interface is constructed by using the collected on-chain data through the MCP protocol, and the on-chain data access interface is used to provide transaction query services for the large language model.

4. The method of claim 2, wherein, screening the counterpart address using a preliminary screening rule, and taking the screened counterpart address as the core address, comprising: calculating the multi-dimensional feature similarity between the core address and the counterpart address; the multi-dimensional feature similarity comprises at least one of a transfer amount factor, an interaction frequency factor, an amount feature similarity, and an active time similarity; the transfer amount factor represents the transfer amount between the counterpart address and the core address and the core address flow proportion; the interaction frequency factor represents the fund interaction frequency between the counterpart address and the core address and the core address activity frequency proportion; the amount feature similarity represents the similarity of the income and expenditure amount distribution characteristics between the counterpart address and the core address; and the active time similarity represents the active time feature similarity between the counterpart address and the core address. Filtering the adversary address based on a multi-dimensional feature similarity between the core address and the adversary address, to obtain a filtered adversary address.

5. The method of claim 2, wherein, Through the large language model, the candidate adversary address is subjected to case feature filtering to obtain a target blockchain address associated with the involved blockchain address, including: The candidate adversary address is input into the large language model, and a knowledge base access interface is called through the large language model. Based on the semantic context of the case, the candidate adversary address is subjected to case feature analysis to obtain the target blockchain address. The knowledge base access interface is constructed based on the MCP protocol and is used to provide case feature query services for the large language model. The case features include abnormal interaction data, fund flow data of the candidate adversary address and the involved blockchain address, and / or abnormal labels of the candidate adversary address. The knowledge base access interface includes an off-chain public opinion access interface and / or a historical case access interface. Before the knowledge base access interface is called through the large language model, the method further includes: Collecting off-chain data to generate an off-chain public opinion knowledge base. The off-chain data includes at least one of address labels, attack event information and chat records collected on social platforms. Based on the off-chain public opinion knowledge base, the off-chain public opinion access interface is generated through the MCP protocol. And / or, a historical case knowledge base is generated according to historical cases. The historical case knowledge base includes at least one of fund networks of different case types, industry term explanations, analysis processes based on case types, and address abnormal transaction behaviors. Based on the historical case knowledge base, the historical case access interface is generated through the MCP protocol.

6. The method of claim 1, wherein, The fund network graph is analyzed to obtain a case research result, including: The semantic information of the target blockchain address in the fund network graph is obtained through the knowledge base access interface called by the large language model. The upstream and downstream structure information of the target blockchain address in the fund network graph is obtained. The upstream and downstream structure information is used to represent the topological position relationship of the target blockchain address in the fund network graph. Based on the upstream and downstream structure information, the semantic information of the target blockchain address is aggregated to obtain the case research result. The case research result is used to describe the global information in the fund network graph. The global risk information includes at least one of the fund role of the target blockchain address, the risk fund path in the fund network graph, the risk node list, and the global research report.

7. The method of claim 1, wherein, The method further includes: An animation timeline is constructed based on the transaction time sequence and / or the logical sequence of the target blockchain address through a graphical user interface. The state information of the node is labeled according to the transaction time sequence of the target blockchain address in the animation timeline, and the node corresponding to the target blockchain address is rendered to generate an interactive animation. In the interactive animation, the nodes in the fund network graph are displayed in the animation timeline in the corresponding state in time sequence.

8. The method of claim 7, wherein, After generating the interactive animation, the method further includes: An operation instruction for the interaction animation is received; the operation instruction is used to control a playing state of the interaction animation; the playing state includes at least one of paused playing, continued playing, ended playing, speeded playing, playback, node selection and node state display; The interaction animation is played based on the operation instruction.

9. The method of claim 8, wherein, The method further includes: in the interaction animation, state information of the nodes changing over time is displayed in different display modes; the state information of the nodes includes node role information and / or transaction information; the display modes include color display, bright-dark display and / or flicker display; wherein the node role information is generated by inference of a large language model. 10.A blockchain case analysis system, characterized in that, Comprise: A case information understanding module, a fund network expansion module, and a fund network analysis module; The case information understanding module is configured to obtain a case semantic context corresponding to a blockchain case based on case input information of the blockchain case by using a large language model; the case semantic context is used for fund flow tracking; the case semantic context includes traceable information on a chain and / or semantic information off the chain; The fund network expansion module is configured to determine a target blockchain address associated with a blockchain address involved in a case based on the case semantic context, and construct a fund network graph; wherein the blockchain address involved in the case and the target blockchain address are nodes of the fund network graph, and a relationship between the nodes is an edge of the fund network graph; The fund network analysis module is configured to analyze the fund network graph to obtain a case research and judgment result.