An anomaly detection method for blockchain transaction behavior

By constructing a transaction network graph and using a time-weighted multi-channel walk model and CNN classifier, the problem of low accuracy in blockchain transaction anomaly detection in existing technologies is solved, and efficient anomaly detection of blockchain transaction behaviors is achieved.

CN114862588BActive Publication Date: 2025-10-03NORTH CHINA ELECTRIC POWER UNIV
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210661014.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-06-13
Publication Date
2025-10-03
Estimated Expiration
2042-06-13

AI Technical Summary

Technical Problem

Existing blockchain transaction anomaly detection methods have shortcomings in detection accuracy, especially in detecting phishing attacks, and cannot be effectively applied to blockchain networks.

Method used

By establishing a transaction network graph, using a transaction network embedding model based on time-weighted multi-channel walk to extract feature sequence vectors, and using a CNN classifier to train a detection model, anomaly detection of blockchain transaction behavior is achieved.

Benefits of technology

Effectively extracting network topology and attribute features improves the accuracy of blockchain transaction anomaly detection and can identify abnormal addresses and transactions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114862588B_ABST
    Figure CN114862588B_ABST
Patent Text Reader

Abstract

The present invention proposes a method for detecting anomalies in blockchain transaction behaviors. The method obtains Ethereum transaction record data in the blockchain, including the addresses of both parties to the transaction, the transaction amount, and the transaction time, distinguishes the transaction addresses between normal addresses and abnormal addresses, and divides the obtained data into a training set and a test set. The obtained transaction records are constructed into a transaction network graph, and the transaction network graph is converted into an adjacency matrix. A transaction network embedding model based on time-weighted multi-channel walk is used, and the adjacency matrix is ​​used as input to extract a feature sequence vector from it. The obtained feature sequence vector is used as input and the corresponding distinction result of the transaction address is used as output, and a CNN classifier is trained to obtain a detection model. The obtained detection model is used to detect abnormal transactions in blockchain transactions.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of network security technology, and in particular relates to an anomaly detection method for blockchain transaction behavior. Background Art

[0002] Network embedding is a learning paradigm that embeds nodes, links, or entire (sub)graphs into low-dimensional networks. Compared to traditional feature engineering methods, network embedding is a more efficient and automated approach to extracting features from large-scale network data. The performance of machine learning methods depends heavily on the choice of data representation (or features). Currently, blockchain technology, due to its decentralization, openness, independence, security, and anonymity, is widely used in finance, the Internet of Things, public services, digital copyright, and other fields. Transactions based on blockchain technology have become a hot topic of research. In particular, detecting abnormal behavior in transactions is crucial, ensuring the security of transactions.

[0003] Currently, most detection methods focus on a specific type of attack, such as double-spending attacks or phishing scams. Existing technologies for general online transaction detection, such as lightweight URL phishing detection systems based on support vector machines (SVMs) and similarity indices, can only detect website-based phishing, resulting in low accuracy and inability to directly address blockchain phishing detection. Summary of the Invention

[0004] To address the above issues, the present invention proposes a method for detecting anomalies in blockchain transaction behaviors, comprising:

[0005] Step 1: Establish an overall transaction network: Obtain Ethereum transaction record data from the blockchain. Transaction records include the addresses of both parties to the transaction, the transaction amount, and the transaction time. Distinguish between normal and abnormal transaction addresses, and divide the acquired data into training and test sets. Construct the acquired transaction records into a transaction network graph, and convert the transaction network graph into an adjacency matrix.

[0006] Step 2: Feature extraction: Using a transaction network embedding model based on time-weighted multi-channel walks, we take the adjacency matrix as input and extract the feature sequence vector from it;

[0007] Step 3: Detection model training: Take the feature sequence vector obtained in step 2 as input and the corresponding transaction address identification result in step 1 as output, and train the CNN classifier to obtain the detection model;

[0008] Step 4: Abnormal transaction detection: Use the detection model obtained in step 3 to detect abnormal transactions in blockchain transactions. The input of the detection model is the feature sequence vector obtained in step 2, and the output is abnormal transactions.

[0009] Furthermore, the transaction network graph in step 1 is denoted as G = (V, E, A, T), where V represents the addresses of the two transaction parties, E represents the directed edge formed by the two transaction parties, A represents the transaction amount of the two parties, and T represents the transaction time; multiple transactions between two nodes of the transaction network graph will not be merged into one transaction, and the sequence number of the directed edge is determined according to the transaction time T, and the earlier the time, the higher the sequence.

[0010] Furthermore, the adjacency matrix includes a transaction adjacency matrix representing whether there is a transaction between the transaction addresses, a transaction amount adjacency matrix of the transaction parties if there is a transaction, and a time adjacency matrix of the transaction parties if there is a transaction. If there is a transaction between the transaction addresses, the transaction adjacency matrix is ​​represented as 1, and if there is no transaction, it is represented as 0. If there is a transaction between the transaction parties, the value of the transaction amount adjacency matrix is ​​the corresponding transaction amount, and the value of the time adjacency matrix corresponds to the value of the transaction timestamp.

[0011] Furthermore, the trading network embedding model based on time-weighted multi-channel walks includes a random walk generator and a feature learning process for network embedding; the random walk generator converts a large-scale network into a set of node sequences sampled from it by performing truncated random walks to capture the structural relationships between nodes; in the feature learning process, the Skip-gram algorithm is used to embed the node sequence into a vector representation.

[0012] Furthermore, we use a time-weighted multi-channel walk-based transaction network embedding model to estimate the number of nodes v that have been observed given all the nodes visited in a random walk so far. i The possibilities are:

[0013] Pr(v i |(v1,v2,...,v i-1 ))

[0014] Define f: is the mapping function from a node to the feature representation learned for the downstream classification task, is a vertex v generated by a neighbor node sampling strategy S i ∈V network neighborhood where d is a parameter representing the dimensionality of feature representation and f is a matrix of size |V|×d;

[0015] Seek to optimize the following objective function, which makes the node v i ∈V observes the network neighborhood under the condition of its feature representation Maximize the log probability of :

[0016]

[0017] Furthermore, the neighborhood sampling strategy of the Ethereum transaction address node is that the random walk generator randomly selects a random walk path for the transaction network graph G. The vertex v i ∈V is uniformly sampled until the maximum length or maximum number of layers l is reached; a biased random walk strategy is adopted for transaction amount and timestamp. In the biased sampling based on transaction amount, the larger the transaction value, the stronger or closer the relationship between the two related nodes; in the biased sampling based on time, the later the transaction time, the greater the impact on the node relationship.

[0018] Furthermore, in the sampling strategy, a time-weighted random walk algorithm based on breadth-first traversal and depth-first traversal is used to search the neighboring nodes of the current node to extract the local and global features of the node; in the depth walk path generator, the idea of ​​depth-first traversal graph is used to obtain n random depth walks with the transition probability of each edge with v i ∈V is a random depth walk path with a fixed length of l at the vertex In the breadth walk path generator, the idea of ​​breadth-first traversal of the graph is used to obtain the vertex v by randomly walking the transition probability of each edge. i The fixed length and fixed level of ∈V are both random breadth walk paths of l

[0019] Furthermore, in the feature learning process of network embedding, the node embedding mapping function f is optimized by stochastic gradient descent for the two walk paths respectively, and the depth-first walk embedding vector E1 and the breadth-first walk embedding vector E2 are obtained, and the two walk paths are merged to obtain the embedding vector

[0020] Furthermore, CNN contains two convolutional blocks, each of which consists of a convolutional layer, a maximum pooling layer, and a fully connected layer.

[0021] Furthermore, the convolutional layers in the two convolutional blocks are set to 3*3*32 and 3*3*64 respectively, the maximum pooling layer is set to 2*2 with a stride of 2, and the output size of the fully connected layer is 64*1.

[0022] The beneficial effects of the present invention are as follows: the network embedding method can effectively extract the structural features and attribute features in the network topology diagram, effectively detect abnormal addresses in the blockchain, and further judge abnormal transactions in the blockchain. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] Figure 1 It is a flow chart of the method of the present invention. DETAILED DESCRIPTION

[0024] The embodiments are described in detail below with reference to the accompanying drawings.

[0025] Figure 1 The flowchart of the present invention shows a method for detecting anomalies in blockchain transaction behavior, which mainly includes:

[0026] Step 1: Establish the overall transaction network: Obtain Ethereum transaction data in the blockchain, including several transaction records and abnormal addresses of transaction addresses in the transaction records, construct the obtained transaction records into a transaction network graph, and convert the transaction network graph into an adjacency matrix.

[0027] Step 1.1: Data Acquisition. Transaction records obtained from official blockchain transaction websites typically contain multiple columns of attribute values. This method only extracts the four required columns: the addresses of both parties to the transaction (including the initiator and recipient), the transaction amount, and the transaction time. The acquired transaction addresses are distinguished between normal and abnormal addresses to facilitate subsequent model training and to determine whether normal or abnormal transactions occur. The principle of judgment is that abnormal addresses and their associated transactions are considered abnormal transactions, and ultimately, transactions conducted by abnormal addresses are considered abnormal transactions. The acquired data is divided into training and test sets.

[0028] Step 1.2: Construct a transaction network graph. Use the acquired transaction record dataset to construct a transaction network graph. The constructed transaction network graph is denoted as G = (V, E, A, T), where V represents the addresses of the two transacting parties, E represents the directed edge formed by the two transacting parties, A represents the transaction amount between the two parties, and T represents the transaction time.

[0029] The transaction network graph constructed in this invention has two prominent features: preserving transaction multiplicity and sorting by time. Preserving transaction multiplicity means that multiple transactions between two nodes are not merged into a single transaction, which is also reflected in the constructed transaction network graph. Sorting by time means that the sequence number of the directed edges in the transaction network graph is determined according to the transaction time T, with earlier times being ranked higher.

[0030] Step 1.3: Generate an adjacency matrix. The transaction network graph is an intermediate product of data processing. The ultimate goal is to generate an adjacency matrix as input for the subsequent step 2. Three adjacency matrices are generated: a transaction adjacency matrix representing whether a transaction exists between transaction addresses, a transaction amount adjacency matrix for both parties if a transaction exists, and a time adjacency matrix for both parties if a transaction exists.

[0031] If a transaction exists between transaction addresses, the transaction adjacency matrix is ​​represented as 1; if not, it is 0. Since a directed transaction graph is constructed, the resulting matrix is ​​an asymmetric adjacency matrix. If a transaction exists between two parties, the value of the amount adjacency matrix is ​​the corresponding transaction amount. The value of the time adjacency matrix between the two parties corresponds to the transaction timestamp.

[0032] Step 2: Feature Extraction. This invention uses a transaction network embedding model based on time-weighted multi-channel walks. It takes the adjacency matrix generated by the transaction network graph G = (V, E, A, T) as input and extracts feature sequence vectors from it. This model primarily consists of two parts: a random walk generator and a feature learning process for network embedding. The core of this model is to repurpose techniques used to simulate natural language to model network topology.

[0033] In this model, a random walk generator performs truncated random walks to convert a large-scale network into a set of node sequences sampled from it, capturing the structural relationships between nodes. During feature learning, the node sequences are embedded into vector representations using the Skip-gram algorithm.

[0034] In this model, a generalization of language modeling is exploited to explore the graph through a series of short random walks. These walks can be thought of as short sentences and phrases in a particular language; a direct analogy is estimating the probability of observing a vertex v given all the vertices visited so far in a given random walk. i Possibilities:

[0035] Pr(v i |(v1,v2,...,v i-1 ))

[0036] The goal is to learn latent representations, not just the probability distribution of node co-occurrences. Therefore, in this paper, feature learning in networks is formulated as a maximum likelihood optimization problem.

[0037] Define f: It is a mapping function from the node to the feature representation learned by the downstream classification task, where d is a parameter representing the dimension of the feature representation. So f is a matrix of size |V|×d. Definition is a vertex v generated by a neighbor node sampling strategy S i ∈V’s network neighborhood.

[0038] Seek to optimize the following objective function, which makes the node v i ∈V observes the network neighborhood under the condition of its feature representation The logarithmic probability of maximizing is expressed as:

[0039]

[0040] Due to the linear nature of text, the concept of neighborhood can be naturally defined by using a sliding window on consecutive words. However, the network topology is not linear, so a richer concept of neighborhood is needed. To solve this problem, this paper proposes a random process to i ∈V is sampled from multiple different neighborhoods. It is not limited to the direct neighborhood, but different structural characteristics of nodes can be obtained according to different sampling strategies S. Specifically, the isomorphism characteristics of nodes can be obtained through the breadth-first walking strategy, and the homology characteristics of nodes can be obtained through the depth-first walking strategy.

[0041] Neighborhood sampling strategy for Ethereum transaction address nodes.

[0042] First, define the vertex v i The random walk path of ∈V is It is a randomly selected vertex from the vertex’s neighborhood. Therefore, It is a random process.

[0043] The random walk generator takes a transaction network graph G and randomly generates a random walk path The source vertex v i ∈V is uniformly sampled until the maximum length or the maximum number of layers l is reached. The value of l is set as needed.

[0044] Given a source vertex v i ∈V, execute a random walk path with a fixed length of l Specifically: If from v i = c0 (node) starts, c j express The jth node in the, then node c j Generated by the following formula:

[0045]

[0046] For financial transaction networks like Ethereum, each edge has a unique transaction amount and timestamp. This is crucial, but cannot be captured by general network embedding methods based on random walks. To more comprehensively understand the characteristics of transaction networks, this paper designs a biased random walk strategy based on transaction amounts and timestamps.

[0047] First, define the time-continuous edge set L t (v i )={e|src(e)=v i ,T(e)≥t}.

[0048] In biased sampling based on transaction amount, generally speaking, the larger the transaction value, the stronger or closer the relationship between the two related nodes. j-1 ,c j ) represents node c j-1 and node c j The sum of transactions in the same direction between nodes c is used to combine the transaction amount information into the sampling probability using a linear function. j-1 To adjacent node c j The transfer probability based on transaction amount is expressed as:

[0049]

[0050] In time-based biased sampling, it is assumed that the later the transaction time is, the greater the impact on the node relationship. First, the real timestamp of the edge is mapped to a discrete time step. Define T(c j-1 ,c j ) represents node c j-1 and node c j The average of the timestamps of the same-direction transactions between nodes c j-1 To adjacent node c j The transition probability based on transaction time is expressed as:

[0051]

[0052] In order to consider both time and amount, the present invention uses parameter α∈[0,1] to balance their influence. j-1 To adjacent node c j The transition probability can be expressed as:

[0053]

[0054] Furthermore, in the sampling strategy, a time-weighted random walk algorithm based on breadth-first traversal and depth-first traversal is used to search the neighborhood nodes of the current node respectively to extract the local features and global features of the node, and finally obtain two walk sequences, namely: depth walk path and breadth walk path.

[0055] In the depth walk path generator, the idea of ​​depth-first traversal of the graph is used to randomly walk the transition probabilities of each edge calculated above to obtain n paths with v as the starting point. i ∈V is a random depth walk path with a fixed length of l at the vertex In the breadth walk path generator, the idea of ​​breadth-first traversal of the graph is used to randomly walk the vertex v through the transition probability of each edge calculated above. i Random breadth walk paths with fixed length and fixed level l ∈V

[0056] In the feature learning process of network embedding, the node embedding mapping function f is optimized by stochastic gradient descent for the walk paths obtained from the two walk sequences, and the depth-first walk embedding vector E1 and the breadth-first walk embedding vector E2 are obtained. Finally, the embedding vectors obtained from the two walk paths are merged.

[0057] Step 3: Detection model training: Take the feature sequence vector obtained in step 2 as input and the corresponding transaction address identification result in step 1 as output, and train the CNN classifier to obtain the detection model;

[0058] In the present invention, the CNN includes two convolutional blocks, each of which consists of a convolutional layer, a maximum pooling layer, and a fully connected layer. Preferably, the convolutional layers in the two convolutional blocks are set to 3*3*32 and 3*3*64 respectively, the maximum pooling layer is set to 2*2 with a stride of 2, and the output size of the fully connected layer is 64*1.

[0059] The output of the convolutional layer is:

[0060]

[0061]

[0062] Where i is the index sequence of the feature, j represents the index sequence of the feature map, Relu is the activation function, W is the weight, B is the bias size, x is the input vector, and 3 represents the size of the convolution kernel.

[0063] The output of the pooling layer is:

[0064]

[0065]

[0066] Where 1 is the stride size and 2 is the pooling size.

[0067] After model training is completed, in order to verify the results predicted by the model of the present invention, the model is tested and the difference between the predicted value and the actual value is compared. The present invention uses the loss function "classification cross entropy" to evaluate the deviation between the current model test probability distribution and the actual distribution. In the model test, 1 is used to represent abnormality and 0 is used to represent normality. The closer the two probabilities are, the smaller the loss value is. The classification cross entropy formula is as follows:

[0068]

[0069] Where n represents the number to be detected, y is the expected output value, and a is the actual output value.

[0070] Step 4: Abnormal transaction detection: Use the detection model obtained in step 3 to detect abnormal transactions in blockchain transactions. The input of the detection model is the feature sequence vector obtained in step 2, and the output is abnormal transactions.

[0071] This embodiment is merely a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present invention should be included in the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be based on the scope of protection of the claims.

Claims

1. A method for detecting anomalies in blockchain transaction behavior, comprising: Step 1: Establish an overall transaction network: Obtain Ethereum transaction record data from the blockchain. Transaction records include the addresses of both parties to the transaction, the transaction amount, and the transaction time. Distinguish between normal and abnormal transaction addresses, and divide the acquired data into training and test sets. Construct the acquired transaction records into a transaction network graph, and convert the transaction network graph into an adjacency matrix. Step 2: Feature extraction: Using a transaction network embedding model based on time-weighted multi-channel walks, the adjacency matrix is ​​used as input to extract a feature sequence vector from it; the transaction network embedding model based on time-weighted multi-channel walks includes a random walk generator and a network embedding feature learning process; The random walk generator converts a large-scale network into a set of node sequences sampled from it by performing truncated random walks to capture the structural relationships between nodes; During the feature learning process, the Skip-gram algorithm is used to embed the node sequence into a vector representation; in the transaction network embedding model based on time-weighted multi-channel walks, it is estimated that given all the vertices visited in a given random walk so far, the observed vertex v i The possibilities are: Pr(v i |(v1,v2,...,v i-1 , definition is the mapping function from a node to the feature representation learned for the downstream classification task, is a vertex v generated by a neighbor node sampling strategy S i ∈V network neighborhood where d is a parameter representing the dimensionality of feature representation and f is a matrix of size |V|×d; Seek to optimize the following objective function, which makes the node v i ∈V observes the network neighborhood under the condition of its feature representation Maximize the log probability of : The neighborhood sampling strategy of the Ethereum transaction address node is that the random walk generator randomly selects a random walk path for the transaction network graph G. The vertex v i ∈V is uniformly sampled until the maximum length or maximum number of layers l is reached; a biased random walk strategy is adopted for transaction amount and timestamp. In the biased sampling based on transaction amount, the larger the transaction value, the stronger or closer the relationship between the two related nodes; in the biased sampling based on time, the later the transaction time, the greater the impact on the node relationship; in the sampling strategy, a time-weighted random walk algorithm based on breadth-first traversal and depth-first traversal is used to search the neighborhood nodes of the current node to extract the local features and global features of the node respectively; In the depth walk path generator, the idea of ​​depth-first traversal of the graph is used to obtain n random depth walks with v as the transition probability of each edge. i ∈V is a random depth walk path with a fixed length of l at the vertex In the breadth walk path generator, the idea of ​​breadth-first traversal of the graph is used to obtain the vertex v by randomly walking the transition probability of each edge. i The fixed length and fixed level of ∈V are both random breadth walk paths of l Step 3: Detection model training: Take the feature sequence vector obtained in step 2 as input and the corresponding transaction address identification result in step 1 as output, and train the CNN classifier to obtain the detection model; Step 4: Abnormal transaction detection: Use the detection model obtained in step 3 to detect abnormal transactions in blockchain transactions. The input of the detection model is the feature sequence vector obtained in step 2, and the output is abnormal transactions.

2. The method for detecting anomalies in blockchain transaction behavior according to claim 1, characterized in that: The transaction network graph in step 1 is denoted as G = (V, E, A, T), where V represents the addresses of the two parties to the transaction, E represents the directed edge formed by the two parties to the transaction, A represents the transaction amount of both parties, and T represents the transaction time; Multiple transactions between two nodes in the transaction network graph will not be merged into one transaction. The sequence number of the directed edge is determined according to the transaction time T. The earlier the time, the higher the sequence.

3. The method for detecting anomalies in blockchain transaction behavior according to claim 1, characterized in that: The adjacency matrix includes a transaction adjacency matrix representing whether there is a transaction between the transaction addresses, a transaction amount adjacency matrix of the two transaction parties if there is a transaction, and a time adjacency matrix of the two transaction parties if there is a transaction; if there is a transaction between the transaction addresses, the transaction adjacency matrix is ​​represented as 1, and if there is no transaction, it is represented as 0; if there is a transaction between the two transaction parties, the value of the transaction amount adjacency matrix is ​​the corresponding transaction amount, and the value of the time adjacency matrix corresponds to the value of the timestamp of the transaction.

4. The method for detecting anomalies in blockchain transaction behavior according to claim 1, characterized in that: In the feature learning process of network embedding, the node embedding mapping function f is optimized by random gradient descent for the two walk paths respectively, and the depth-first walk embedding vector E1 and the breadth-first walk embedding vector E2 are obtained. The two walk paths are then merged to obtain the embedding vector .

5. The method for detecting anomalies in blockchain transaction behavior according to claim 1, characterized in that: The CNN contains two convolutional blocks, each of which consists of a convolutional layer, a maximum pooling layer, and a fully connected layer.

6. The method for detecting anomalies in blockchain transaction behavior according to claim 5, characterized in that: The convolution layers in the two convolution blocks are set to 3*3*32 and 3*3*64 respectively, the maximum pooling layer is set to 2*2 with a step size of 2, and the output size of the fully connected layer is 64*1.

Citation Information

Patent Citations

  • Network representation learning method for Ethernet fishing fraud

    CN111447179A