A method and related products for detecting abnormal blockchain transactions
By extracting structural features and data features from the blockchain transaction graph and combining with the network representation learning algorithm, the problem of poor detection of blockchain transaction abnormalities is solved, and higher detection accuracy is achieved.
Patent Information
- Application Number
- CN202211215287.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-30
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2042-09-30
AI Technical Summary
The existing blockchain transaction anomaly detection methods have poor results and it is difficult to effectively identify abnormal transaction behaviors in the blockchain network.
By extracting the structural features and transaction data features of the transaction network from the blockchain transaction graph, combining the abnormal detection model for detection, network representation learning algorithms such as deep walk and second-order attribute network embedding to extract a more comprehensive feature set to perform abnormal detection.
It significantly improves the accuracy of blockchain transaction anomaly detection, can more accurately capture changes in transaction network structure, and improves the accuracy of abnormal analysis.
Smart Images

Figure CN115567224B_ABST
Abstract
Description
Technical Field
[0001] The present invention generally relates to the field of blockchain technology. More specifically, the present invention relates to a method for detecting abnormal blockchain transactions, a device for detecting abnormal blockchain transactions, and a computer-readable storage medium. Background Art
[0002] A blockchain is a distributed encrypted ledger that provides a platform for non-trusting members to conduct transactions securely, enabling decentralized, low-cost, peer-to-peer transactions, and has been widely applied in fields such as finance, healthcare, logistics, and the Internet of Things. The blockchain uses distributed storage and collective maintenance to achieve decentralization, and uses asymmetric encryption algorithms such as SHA-256 and reliable storage technologies to complete credit endorsement, ensuring the openness, publicity, and security of the system. However, due to characteristics such as the huge circulating market value, large number of users, and account anonymity of the blockchain, transactions on the blockchain are frequently threatened by abnormal behaviors such as theft.
[0003] The most successful practice of the blockchain is the cryptocurrency represented by Bitcoin. Cryptocurrencies are also increasingly entering the financial market. Cryptocurrencies have the characteristic of anonymity and do not require users to undergo real-name authentication. Therefore, more and more criminals use cryptocurrencies as tools for crime, committing network and financial crimes.
[0004] Blockchain transaction records are distributed and stored on a public chain, which provides a significant advantage for researching and detecting abnormal blockchain transactions. However, the huge capacity of the blockchain poses a challenge to further exploring it. Due to the large number of users and transactions in the blockchain system, manual detection of abnormalities is impossible, which also brings great difficulties to the detection of abnormal blockchain transaction behaviors.
[0005] Regarding abnormal blockchain transactions, the current common detection methods are feature-based classification methods, clustering-based detection methods, statistical analysis model-based detection methods, etc. By detecting behaviors such as illegal addresses, deviations in transaction amounts, and abnormalities in transaction speeds in Bitcoin transactions, it is determined whether an abnormality has occurred. However, these blockchain transaction anomaly detection methods mainly focus on problems such as the identification and classification of addresses and the judgment of abnormal amounts, and their detection effects are not ideal.
[0006] In view of this, how to solve the problem that the current detection methods for abnormal blockchain transaction behaviors have poor effects is of great significance for improving the security of blockchain network transactions. Summary of the Invention
[0007] To solve the above one or more technical problems, the present invention proposes to extract the structural features of the transaction network from the blockchain transaction graph, and add the structural features to the data features for joint detection of transaction abnormal behaviors, thereby effectively improving the accuracy of detecting blockchain transaction abnormal behaviors. For this purpose, the present invention provides solutions in the following aspects.
[0008] In a first aspect, the present invention provides a method for detecting blockchain transaction anomalies, including: obtaining a blockchain transaction graph; extracting the structural features and transaction data features of the transaction network from the blockchain transaction graph; merging the structural features and transaction data features of the transaction network to obtain a merged feature set; and using an anomaly detection model to detect the merged feature set to determine whether there are transaction abnormal behaviors in the blockchain.
[0009] In one embodiment, the blockchain transaction graph includes nodes, edges, and marking information of transactions, the edges include Bitcoin transfer information between transactions, and the marking information includes attributes of transactions. Among them, extracting the structural features and transaction data features of the transaction network from the blockchain transaction graph includes: extracting the structural features of the transaction network from the blockchain transaction graph according to a network representation method; and extracting transaction data features from the nodes, edges, and marking information in the blockchain transaction graph.
[0010] In one embodiment, extracting the structural features of the transaction network from the blockchain transaction graph according to the network representation method includes: performing feature extraction on the blockchain transaction graph based on a network representation learning algorithm of deep walk to obtain the structural features of the transaction network; and / or using a second-order attribute network to embed the blockchain transaction graph for feature extraction to obtain the structural features of the transaction network.
[0011] In one embodiment, performing feature extraction on the blockchain transaction graph based on the network representation learning algorithm of deep walk to obtain the structural features of the transaction network includes: converting the blockchain transaction graph into a network graph; obtaining a sampling sequence of the nodes by using a set walking method; and performing vector learning on the sampling sequence of the nodes according to a neural network model to use the obtained representation vector of the nodes as the structural features of the transaction network.
[0012] In one embodiment, using a second-order attribute network to embed the blockchain transaction graph for feature extraction to obtain the structural features of the transaction network includes: extracting the association information between nodes and attributes from the information of the edges from adjacent nodes to the target node to obtain a structural information matrix and an attribute information matrix; and using a neural network model to learn the structural information matrix and the attribute information matrix respectively to obtain the representation vector of the nodes.
[0013] In one embodiment, obtaining the sampling sequence of the node by using the set walking method includes: obtaining the sampling sequence of the node by using the random walk method; and / or accessing adjacent nodes by using the biased random walk method based on the total transaction amount to obtain the sampling sequence of the node.
[0014] In one embodiment, accessing adjacent nodes by using the biased random walk method based on the total transaction amount includes accessing adjacent nodes with a set probability after the starting node; the set probability includes:
[0015]
[0016] where A(v i ,v j ) represents the trading volume between node v i and v j , represents the set of nodes connected to node v i .
[0017] In one embodiment, detecting the merged feature set by using the anomaly detection model to determine whether there is an abnormal transaction behavior in the blockchain includes: normalizing and sampling the merged feature set to obtain a balanced transaction feature data set; and detecting the transaction feature data set by using the anomaly detection model to determine whether an abnormal transaction occurs.
[0018] In a second aspect, the present invention further provides a device for detecting abnormal blockchain transactions, including: a processor; and a memory that stores computer instructions for detecting abnormal blockchain transactions, and when the computer instructions are run by the processor, the device executes the method according to one or more of the foregoing and following embodiments.
[0019] In a third aspect, the present invention further provides a computer-readable storage medium, on which computer-readable instructions for detecting abnormal blockchain transactions are stored, and when the computer-readable instructions are executed by one or more processors, the method according to one or more of the foregoing and following embodiments is implemented.
[0020] According to the technical solution of the present invention, by learning the network structure and attribute information of blockchain transactions, it is possible to mine implicit information from the neighborhood structure of transactions and perform anomaly detection together with data information, so as to accurately capture changes in the blockchain network structure features and effectively improve the accuracy of transaction anomaly detection. Further, in the present invention, the network representation method for extracting structure features is also improved, and based on the biased random walk strategy of transaction summary, accurate capture of transaction nodes with larger trading volumes is achieved, which is beneficial to improving the accuracy of anomaly analysis results. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] By reading the following detailed description with reference to the accompanying drawings, the above and other objects, features, and advantages of the exemplary embodiments of the present invention will become readily understandable. In the drawings, several embodiments of the present invention are shown by way of illustration and not limitation, and like or corresponding reference numerals indicate like or corresponding parts, wherein:
[0022] Figure 1 is a schematic diagram schematically showing a scenario for detecting abnormal blockchain transactions according to an embodiment of the present invention;
[0023] Figure 2 is a flowchart schematically showing a method for detecting abnormal blockchain transactions according to an embodiment of the present invention;
[0024] Figure 3 is a flowchart schematically showing a method for obtaining the structural features of a transaction network according to an embodiment of the present invention;
[0025] Figure 4 is a schematic diagram schematically showing the extraction of structural features using a second-order attribute network according to an embodiment of the present invention;
[0026] Figure 5 is a flowchart schematically showing a method for anomaly detection using a combined feature set according to an embodiment of the present invention;
[0027] Figure 6 is a distribution diagram of transactions at different intervals schematically showing according to an embodiment of the present invention;
[0028] Figure 7 is a schematic distribution diagram of normal and abnormal samples in a dataset before and after sampling schematically showing according to an embodiment of the present invention;
[0029] Figure 8 is a schematic diagram of a device for detecting abnormal blockchain transactions according to an embodiment of the present invention. Detailed Embodiments
[0030] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0031] Existing blockchain abnormal transaction detection mainly focuses on the transaction amount, transaction address, etc. when an abnormal event occurs, and only extracts features from the transaction itself, that is, extracts features from transaction data for abnormal transaction analysis. This method actually regards transactions as isolated nodes, only extracts features from the transactions themselves, and does not deeply mine the transaction network structure information. Through the comparative analysis of the transaction network structure in the normal state and the abnormal state, the inventor found that the blockchain network generally maintains a stable state during normal operation, while when an attack anomaly occurs, the network structure will change greatly. By detecting the changes in the blockchain network structure, the accuracy of abnormal transaction detection can be effectively improved.
[0032] Based on this, in the present invention, starting from the network structure features, network representation learning is used to mine the hidden information in the blockchain transaction network structure and extract a more accurate and comprehensive feature set. By combining the structural features and data features of the transaction network, abnormal transactions are comprehensively detected, thereby effectively improving the accuracy of abnormal transaction event detection in the blockchain.
[0033] The following will describe in detail the specific implementation manners of the present invention with reference to the accompanying drawings.
[0034] Figure 1 FIG. 100 is a schematic diagram schematically showing a scenario 100 for detecting blockchain transaction anomalies according to an embodiment of the present invention. In the context of the present invention, this scenario 100 can be used for detecting various transaction anomaly events in the blockchain, such as attacks, etc.
[0035] As Figure 1 shown, the blockchain abnormal detection in the present invention mainly includes three parts: obtaining structural features by a network representation learning algorithm, feature merging, and abnormal detection analysis. In some embodiments, abnormal analysis is performed through a transaction graph composed of a Bitcoin transaction dataset. This transaction graph contains nodes, edges, and marking information of transactions. Among them, the nodes represent transactions, and the edges include the Bitcoin transfer information between transactions, that is, the output of a certain transaction representing a transaction is spent as an input by the next transaction. The marking information includes the attributes of the transactions, such as 3 values: "normal", "abnormal", and "unknown".
[0036] Use network representation learning methods to learn blockchain transaction graph data, obtaining representation vectors of transaction nodes in a low-dimensional space as the features of transactions. In some embodiments, DeepWalk and Binarized attributed network embedding (BANE) can be used to extract structural features from Bitcoin transaction graphs. At the same time, traditional methods are used to obtain transaction data features. Then, by combining the structural features and data features, a more comprehensive and accurate feature set can be obtained to achieve more accurate anomaly detection. In some embodiments, transaction data features include information directly related to transactions and aggregated information. Aggregated information includes transaction information obtained by taking one hop backward or forward from the central node, and information directly related to transactions includes one or more of the following: time interval, the number of input and output transactions, and the average Bitcoin value of input and output transactions.
[0037] Meanwhile, in order to obtain more accurate detection results, the dataset can also be preprocessed, for example, using random oversampling and Synthetic Minority Oversampling Technique (SMOTE), two oversampling methods, as well as random undersampling to process the imbalanced dataset.
[0038] Next, unsupervised and supervised machine learning algorithms are used for anomaly detection. After obtaining the representation vectors of blockchain transaction nodes using the network representation learning method, they are added as features to the feature set of the original data, and the dataset is processed by Z-score normalization, oversampling, and undersampling to obtain a more balanced transaction feature dataset. In the anomaly detection stage, supervised and unsupervised algorithms can be used in the present invention to detect the feature set. Supervised algorithms can be, for example, Logistic Regression (LR), Random Forest (RF), Adaptive boosting (AdaBoost), Multi-Layer Perception (MLP), and support vector machines (SVM), and the unsupervised algorithm can be K-means.
[0039] Figure 2 It is a flowchart schematically showing a method 200 for detecting blockchain transaction anomalies according to an embodiment of the present invention.
[0040] As Figure 2As shown, at step S201, a blockchain transaction graph is obtained. In some embodiments, the blockchain transaction graph includes nodes, edges, and marking information of transactions.
[0041] At step S202, the structural features and transaction data features of the transaction network are extracted from the blockchain transaction graph. In some embodiments, a network graph can be generated based on the transaction graph, and then the structural features of the transaction network are extracted from the blockchain transaction graph according to the network representation method, and the transaction data features are extracted from the node, edge, and marking information in the blockchain transaction graph.
[0042] At step S203, the structural features and transaction data features of the transaction network are merged to obtain a merged feature set. In some embodiments, after merging the structural features and data features of the transaction network, a more comprehensive and accurate feature set can be obtained, which is convenient for analyzing the hidden information in the transaction network and improving the accuracy of detecting abnormal blockchain transaction behaviors.
[0043] At step S204, an anomaly detection model is used to detect the merged feature set to determine whether there are abnormal transaction behaviors in the blockchain. In some embodiments, after obtaining the structural features of the blockchain transaction by using the network representation learning method, they are added as features to the feature set of the original data, and the dataset is subjected to Z-score standardization, oversampling, and undersampling processes to obtain a more balanced transaction feature dataset. In the anomaly detection stage, 5 supervised algorithms and 1 unsupervised algorithm can be used in the present invention to detect the feature set.
[0044] Figure 3 It is a flowchart schematically showing a method 300 for obtaining the structural features of a transaction network according to an embodiment of the present invention. It should be noted that steps S301 to S303 in the method 300 for obtaining the structural features of the transaction network represent the way of obtaining the structural features of the transaction network by using deep walk, and steps S304 to S305 represent the way of obtaining the structural features by using the second-order attribute network. Therefore, steps S301 to S303 and steps S304 to S305 are two parallel ways of obtaining the structural features.
[0045] In some embodiments, the structural features of the transaction network can be obtained by performing feature extraction on the blockchain transaction graph based on the deep walk network representation learning algorithm, or the structural features of the transaction network can be obtained by using the second-order attribute network to embed the blockchain transaction graph for feature extraction. It is also possible to comprehensively adopt the two methods respectively for feature extraction, and detect the structural features obtained by the two methods respectively, or add them to the same feature set for anomaly detection.
[0046] As Figure 3As shown, at step S301, the blockchain transaction graph is converted into a network graph. In some embodiments, the information in the transaction is represented by the structure of the network graph. For example, the features between nodes in the network can represent transaction information.
[0047] At step S302, a sampling sequence of nodes is obtained using a set wandering method. In some embodiments, multiple different wandering methods can be used to obtain the sampling sequence of nodes. For example, 3 network representation learning algorithms, DeepWalk, DeepWalk-Ba (DeepWalk Based on Amount), and Binarized attributed network embedding (BANE), are used to extract features from the Bitcoin transaction graph. DeepWalk is an algorithm for learning the latent representation of network nodes. DeepWalk-Ba is an improvement of the DeepWalk algorithm, which will be described in detail below. BANE is an attributed network representation learning algorithm that analyzes the attribute information of nodes and edges while learning nodes and edges.
[0048] At step S303, vector learning is performed on the sampling sequence of nodes according to the neural network model to use the obtained representation vector of the nodes as the structural feature of the transaction network. In some embodiments, by learning the structure and attribute information of the transaction network, the representation vector of the nodes is obtained. The representation vector of the nodes can represent the structural feature of the transaction network.
[0049] In some embodiments, obtaining the sampling sequence of the nodes by the above wandering method includes obtaining the sampling sequence of the nodes by using a random walk method; and / or accessing neighboring nodes in a biased random walk manner based on the total transaction amount to obtain the sampling sequence of the nodes.
[0050] When obtaining the sampling sequence of nodes by using a random walk method, it can be implemented in 3 steps. The first step is network generation: Use transaction data to generate a network graph G=(V, E), where V represents the set of vertices and E represents the set of edges. The second step is to obtain the node sampling sequence using a random walk. The third step is to use the skip-gram model to learn the sampling sequence to obtain the representation vector of the nodes. During the random walk process, the depth-first traversal algorithm for randomly accessing nodes (RandomWalk) can be used to traverse the nodes. For a given starting node v i , randomly select a node v i+1 from its neighbor nodes for access and repeat this process until the node sequence {v i , v i+1, …} reach a certain length. After obtaining sequences of sufficient length for each node in the network, skip-gram vector learning is performed on the obtained set of node sequences to represent discrete network nodes as vectors, thereby obtaining the representation vectors of the nodes.
[0051] When accessing neighboring nodes in a biased random walk manner based on the total transaction amount, in the above second step, the starting node v i After that, access the neighboring node v with a set probability j . The set probability includes:
[0052]
[0053] where A(v i , v j ) represents the transaction volume between node v i and v j , represents the set of nodes connected to node v i .
[0054] The following is an example to illustrate the information of the blockchain transaction network. The blockchain transaction network can be represented by G=(V, E), where V={v1, v2, …, v n} is the node set, v i , i∈{1, 2, …, n} represents transactions, E={(v i , v j )|i≠j} represents the edge set, (v i , v j ) represents the transfer of tokens between two transactions. Use G l =(V, E, X, Y) to represent the network with node features and labels, where X∈R |v|×d is the feature matrix of the node set, d is the dimension of the node features, Y={y1, y2, …, y n} represents the label set of the nodes, and the value of y i , i∈{0, 1, …, n} is 0 and 1, 0 represents that the node is a normal transaction, and 1 represents that the node is an abnormal transaction. Blockchain abnormal transaction detection can be regarded as a graph classification task. By learning from the training data set, a classifier f: is used to predict the labels of blockchain transactions. For node v i , if f(v i ) = 0, then v i is a normal transaction. If f(v i ) = 1, v i is an abnormal transaction.
[0055] The process of extracting structural features using the DeepWalk-Ba algorithm is as follows:
[0056]
[0057] The input of the algorithm is a graph G = (V, E), parameters such as the dimension d of representation learning, the number of walks γγ for each vertex, and the random walk length t, and the output is a vertex representation matrix φ ∈ R |V|×d For the input graph G = (V, E), shuffle the node set V into O, and randomly select v from O i as the starting node, select the next node according to the biased random walk, and finally obtain γ sequences W with a maximum length of t vi Then use skip-gram to learn the expression vectors of the nodes.
[0058] The algorithm for extracting structural features using the biased random walk strategy of nodes is as follows:
[0059]
[0060]
[0061] For the current node curr of the walk sequence walk, its next node is the node V closest to it determined according to the total transaction amount curr .
[0062] In some embodiments, when using a second-order attribute network to embed the blockchain transaction graph for feature extraction, at step S304, the association information between nodes and attributes is extracted from the information of the edges from adjacent nodes to the target node to obtain a structure information matrix and an attribute information matrix. In some embodiments, an adjacency matrix is defined in the BANE algorithm, and the association information between nodes and attributes is captured by aggregating node attributes in a layer-by-layer manner and the information of the edges from adjacent nodes to the target node.
[0063] At step S305, a neural network model is used to learn the structure information matrix and the attribute information matrix respectively to obtain the representation vectors of the nodes. In some embodiments, by learning the two matrices of network structure and network attribute respectively, and then combining the two matrices, the representation vector of the attribute network is obtained. As an example, as Figure 4 shown, by using a second-order attribute network to embed the blockchain transaction graph for feature extraction, the representation vector C of the nodes is obtained. The network structure matrix A is an n×n matrix, the attribute information matrix B is an n×d matrix, and the learned network representation matrix C is an n×k matrix.
[0064] The transaction network structure features and data features are shown in the following table:
[0065]
[0066]
[0067] The above structural features 1, 2, and 3 are the node representation vectors obtained by the DeepWalk, DeepWalk-Ba, and BANE network representation learning methods respectively after learning the blockchain transaction network. Among them, DeepWalk and DeepWalk-Ba obtain 128-dimensional features for each node, and BANE obtains 64-dimensional features.
[0068] For the data features, each transaction node has 166-dimensional features, among which the first 94 dimensions are information directly related to the transaction, including the transaction time interval, the number of input and output transactions, the average Bitcoin value of input and output transactions, etc. The remaining 72 features are aggregated features obtained by using the transaction information to jump one hop backward or forward from the central node, that is, the features of second-order transaction information.
[0069] When the above structural features and data features are combined to obtain the combined feature set, it can be seen that each node in the transaction network has 166-dimensional data features. After using the network representation learning method to learn the transaction network, DeepWalk and DeepWalk-Ba obtain 128-dimensional features for each node, and BANE obtains 64-dimensional features. The data features of the original dataset nodes are 166-dimensional. After feature combination (that is, adding 128-dimensional or 64-dimensional structural features to the 166-dimensional features of each node), the node features become 294 and 230 dimensions respectively.
[0070] Figure 5 It is a flowchart schematically showing a method 500 for anomaly detection using the combined feature set according to an embodiment of the present invention.
[0071] In step S501, the combined feature set is standardized. In some embodiments, the influence of the data scale on the detection result can be reduced through standardization.
[0072] In step S502, the combined feature set is sampled to obtain a balanced transaction feature dataset. In some embodiments, the problem of data imbalance can be reduced through oversampling and undersampling. The processes of standardization and oversampling will be described in detail in the following content.
[0073] At step S503, the transaction feature dataset is detected using an anomaly detection model to determine whether a transaction anomaly has occurred. In an application scenario, anomaly transaction detection can be regarded as a binary classification problem, with only two categories: normal and abnormal. Generally, the positive class (P) represents abnormal, and the negative class (N) represents normal. True (T) and false (F) are for the comparison result between prediction and actual. T means correct matching, that is, predicting positive and the actual is positive. Predicting negative and the actual is also negative. Correspondingly, F means mismatch, that is, incorrect prediction.
[0074] Precision, recall, and F1 value are used as evaluation indicators for anomaly transaction detection. Among them, precision (P) represents the proportion of correctly predicted data among the data predicted as positive examples; recall (R) represents the proportion of correctly predicted data among the data that are actually positive examples; the F1 value is the harmonic mean of precision and recall. The calculation methods of precision, recall, and F1 value are as follows:
[0075]
[0076]
[0077]
[0078] By using the original feature set, the combined feature set after adding the features extracted by network representation learning, and the combined feature set after standardization and sampling as the input of the detection model, and randomly selecting 70% of the input set as the training set and the remaining 30% as the test set for anomaly detection. Set the number of clusters k of K-means to be from 2 to 13. After the test, check the detection effects under different numbers of clusters k, select the sample clusters under the k value with the best classification effect for clustering, and calculate the detection indicators such as precision accordingly.
[0079] In the three groups of experiments, compared with the first group of experiments that detect the features in the original data, the detection effect of the second group of experiments based on network representation learning has been greatly improved, proving the effectiveness of network representation learning in extracting features from blockchain transaction graphs. For the three network representation learning methods, the DeepWalk-Ba model has a better detection effect than DeepWalk, proving that the biased random walk can better reflect the characteristics of the network and contribute more information to feature extraction. Among the three methods, the detection method using BANE to extract features has the best detection effect, indicating that representing learning is carried out simultaneously on the transaction network structure features and attribute information, and more accurate and comprehensive feature information is obtained.
[0080] Figure 6 It schematically shows the distribution diagram of transactions at different intervals according to an embodiment of the present invention. Figure 7It is a schematic diagram showing the distribution of normal and abnormal samples in the dataset before and after sampling according to an embodiment of the present invention.
[0081] As Figure 6 shown, the blockchain transaction graph shows the transaction distributions of three different labels at different time intervals. The dataset in this graph contains 203,769 nodes and 234,355 edges. Each transaction node has 166 features. The first 94 features represent information directly related to the transaction, including the time interval, the number of input and output transactions, the average Bitcoin values of input and output transactions, etc. The time interval represents the time when the transaction is broadcast to the Bitcoin transaction network. The remaining 72 features are aggregated features obtained by taking one hop backward or forward from the central node using transaction information.
[0082] In the present invention, the Z-Score method is selected to standardize the feature data. The Z-Score standardization method transforms data of different orders of magnitude into the same order of magnitude using the standard deviation and variance of the original data and measures it using the Z-Score value, making different feature data comparable. The standardization process is as follows:
[0083] Assume that the original data sequence with n features is: {x1, x2, ……, x n}, and perform the transformation on it: where, After standardization, the sequence becomes {y1, y2, ……, y n}, and the mean of the new sequence is 0 and the variance is 1.
[0084] Next, oversampling and undersampling of the data are required.
[0085] In the dataset after screening, the proportion of abnormal samples to normal samples is approximately 11%. Since the output categories of many anomaly detection models are based on thresholds, when the proportion of normal and abnormal samples in the training data is unbalanced, the existence of the threshold will cause the model output to tend to the category with a higher proportion. Based on this, for the data imbalance problem in such binary classification problems, generally, methods such as adjusting the model threshold or sampling the dataset are adopted to solve it.
[0086] In the present invention, two oversampling methods, namely random oversampling and Synthetic Minority Oversampling Technique (SMOTE), and random undersampling are used to process the imbalanced dataset. Random oversampling is the replication sampling of minority class samples, while random undersampling is the random sampling of majority class samples. The basic idea of the SMOTE algorithm is to interpolate and synthesize new samples from minority class samples and add them to the dataset. That is, for a minority class sample a, a minority class sample b is selected from its adjacent samples, and then a new sample c is randomly generated on the line connecting a and b. As Figure 7 shows the distribution of normal and abnormal samples in the dataset before and after being processed by the three sampling methods. It can be seen that the dataset after sampling processing is more balanced. By improving the balance of the dataset in the input anomaly detection model, it can help improve the accuracy of the results of transaction anomaly detection.
[0087] Figure 8 is a schematic diagram showing a device 800 for detecting blockchain transaction anomalies according to an embodiment of the present invention. The device 800 may include a device 801 according to an embodiment of the present invention, as well as its peripheral devices and external networks. As described above, the device 801 realizes operations such as obtaining a blockchain transaction graph, extracting structural features, data features, and detecting using an anomaly detection model, so as to implement the foregoing combination Figure 2 , Figure 3 or Figure 4 the solution of the present invention described above.
[0088] As Figure 8 shown, the device 801 may include a CPU 8011, which may be a general-purpose CPU, a dedicated CPU, or other information processing and program execution units. Further, the device 801 may also include a large-capacity memory 8012 and a read-only memory ROM 8013. The large-capacity memory 8012 may be configured to store various types of data and various required programs, and the ROM 8013 may be configured to store data required for the power-on self-test of the device 801, the initialization of each functional module in the system, the driver for the basic input / output of the system, and the data for booting the operating system.
[0089] Furthermore, the device 801 further includes other hardware platforms or components, such as the illustrated TPU (Tensor Processing Unit) 8014, GPU (Graphic Processing Unit) 8015, FPGA (Field Programmable Gate Array) 8016, and MLU (Memory Logic Unit) 8017. It can be understood that although various hardware platforms or components are illustrated in the device 801, they are merely exemplary rather than restrictive, and those skilled in the art can add or remove corresponding hardware according to actual needs. For example, the device 801 may include only a CPU as a well-known hardware platform and another hardware platform as the test hardware platform of the present invention.
[0090] The device 801 of the present invention further includes a communication interface 8018, so that it can be connected to a local area network / wireless local area network (LAN / WLAN) 805 through the communication interface 8018, and then can be connected to a local server 806 or connected to the Internet ("Internet") 807 through the LAN / WLAN. Alternatively or additionally, the device 801 of the present invention can also be directly connected to the Internet or a cellular network based on wireless communication technology through the communication interface 8018, such as based on the third generation ("3G"), fourth generation ("4G"), or fifth generation ("5G") wireless communication technology. In some application scenarios, the device 801 of the present invention can also access a server 808 of an external network and a possible database 809 as needed.
[0091] The peripheral devices of the device 801 may include a display device 802, an input device 803, and a data transmission interface 804. In one embodiment, the display device 802 may include, for example, one or more speakers and / or one or more visual displays. The input device 803 may include, for example, a keyboard, a mouse, a microphone, a gesture capture camera, or other input buttons or controls, which are configured to receive data input or user instructions. The data transmission interface 804 may include, for example, a serial interface, a parallel interface, or a universal serial bus interface ("USB"), a small computer system interface ("SCSI"), serial ATA, FireWire, PCI Express, and a high-definition multimedia interface ("HDMI"), etc., which are configured for data transmission and interaction with other devices or systems.
[0092] The above-mentioned CPU 8011, large-capacity memory 8012, read-only memory ROM 8013, TPU 8014, GPU 8015, FPGA 8016, MLU 8017, and communication interface 8018 of the device 801 of the present invention can be interconnected through the bus 8019, and data interaction with peripheral devices can be achieved through this bus. In one embodiment, through this bus 8019, the CPU 8011 can control other hardware components and their peripheral devices in the device 801.
[0093] During operation, the processor CPU 8011 of the device 801 of the present invention can obtain media data packets through the input device 803 or the data transmission interface 804, and retrieve computer program instructions or codes stored in the memory 8012 to process the obtained information, so as to complete the filling of detection information in the media data packets or determine the network status.
[0094] According to the fourth aspect of the present invention, the present invention also provides a computer-readable storage medium, on which computer-readable instructions for detecting abnormal blockchain transactions are stored. When the computer-readable instructions are executed by one or more processors, the methods described in one or more of the foregoing embodiments are implemented.
[0095] From the above description of the modular design of the present invention, it can be seen that the device of the present invention can be flexibly arranged according to application scenarios or requirements and is not limited to the architecture shown in the drawings. Further, it should also be understood that any module, unit, component, server, computer, or device that executes operations in the examples of the present invention can include or otherwise access a computer-readable medium, such as a storage medium, a computer storage medium, or a data storage device (removable) and / or non-removable), such as a magnetic disk, an optical disk, or a magnetic tape. The computer storage medium can include volatile and non-volatile, removable and non-removable media implemented by any method or technology for storing information, such as computer-readable instructions, data structures, program modules, or other data. Based on this, the present invention also discloses a computer-readable storage medium, on which computer-readable instructions for identifying the status of a split and merge sign are stored. When the computer-readable instructions are executed by one or more processors, the methods and operations described in combination with the foregoing drawings are implemented.
[0096] Although this specification has shown and described multiple embodiments of the present invention, it will be apparent to those skilled in the art that such embodiments are provided by way of example only. Many variations, changes, and alternative ways will occur to those skilled in the art without departing from the spirit and scope of the present invention. It should be understood that various alternatives to the embodiments of the present invention described herein may be employed in practicing the present invention. The appended claims are intended to define the scope of the present invention and thus cover component parts, equivalents, or alternatives within the scope of these claims.
Claims
1. A method for detecting anomalies in blockchain transactions, characterized in that, Comprising: Obtain a blockchain transaction graph; Extract the structural features and transaction data features of the transaction network from the blockchain transaction graph; Merge the structural features and transaction data features of the transaction network to obtain a merged feature set; And Use an anomaly detection model to detect the merged feature set to determine whether there is any abnormal transaction behavior in the blockchain; The blockchain transaction graph includes nodes, edges and marking information of transactions, the edges include Bitcoin transfer information between transactions, and the marking information includes attributes of transactions. Among them, extracting the structural features and transaction data features of the transaction network from the blockchain transaction graph includes: Extract the structural features of the transaction network from the blockchain transaction graph according to the network representation method; and Extract transaction data features from the nodes, edges and marking information in the blockchain transaction graph; The extracting the structural features of the transaction network from the blockchain transaction graph according to the network representation method includes: Perform feature extraction on the blockchain transaction graph based on the network representation learning algorithm of deep walk to obtain the structural features of the transaction network; and / or Use the second-order attribute network to embed the blockchain transaction graph for feature extraction to obtain the structural features of the transaction network; Wherein, the blockchain transaction graph is a Bitcoin transaction graph; The network representation learning algorithm based on deep walk adopts DeepWalk-Ba.
2. The method according to claim 1, wherein The performing feature extraction on the blockchain transaction graph based on the network representation learning algorithm of deep walk to obtain the structural features of the transaction network includes: Convert the blockchain transaction graph into a network graph; Obtain the sampling sequence of the nodes by using a set walking method; and Perform vector learning on the sampling sequence of the nodes according to the neural network model, and use the obtained representation vector of the nodes as the structural features of the transaction network.
3. The method according to claim 1, wherein The using the second-order attribute network to embed the blockchain transaction graph for feature extraction to obtain the structural features of the transaction network includes: Extract the association information between nodes and attributes from the information of the edges from adjacent nodes to the target node to obtain a structural information matrix and an attribute information matrix; and Use the neural network model to learn the structural information matrix and the attribute information matrix respectively to obtain the representation vector of the nodes.
4. The method according to claim 2, wherein The obtaining the sampling sequence of the nodes by using a set walking method includes: Obtain the sampling sequence of the nodes by using the random walk method; and / or Access adjacent nodes based on the biased random walk method based on the total transaction amount to obtain the sampling sequence of the nodes.
5. The method according to claim 4, wherein The accessing adjacent nodes based on the biased random walk method based on the total transaction amount includes accessing adjacent nodes with a set probability after the starting node; The set probability includes: where \(A(v i ,v j )\) represents the trading volume between nodes \(v i and \(v j \), represents the set of nodes connected to node \(v i \).
6. The method according to any one of claims 1-5, characterized in that, The using the anomaly detection model to detect the merged feature set to determine whether there is any abnormal transaction behavior in the blockchain includes: Perform normalization and sampling processing on the merged feature set to obtain a balanced transaction feature data set; and use the anomaly detection model to detect the transaction feature data set to determine whether a transaction anomaly occurs.
7. A device for detecting anomalies in blockchain transactions, characterized in that, Comprising: A processor; And A memory stores computer instructions for detecting anomalies in blockchain transactions. When the computer instructions are run by the processor, the device is caused to execute the method according to any one of claims 1-6.
8. A computer-readable storage medium, characterized in that, Computer-readable instructions for detecting anomalies in blockchain transactions are stored thereon. When the computer-readable instructions are executed by one or more processors, the method according to any one of claims 1-6 is implemented.
Citation Information
Patent Citations
Block chain transaction behavior-oriented anomaly detection method
CN114862588A