Virtual Currency Wallet Address Anomaly Detection Method and System Based on Adaptive Assortative Message Aggregation
By using adaptive hetero-aligned message aggregation operator and hetero-aligned perception of multi-task loss function in the virtual currency trading network, the graph neural network model is optimized, and the problem of poor detection of existing technology under hetero-aligned graph structure is solved, and more efficient virtual currency wallet address abnormal detection is achieved.
Patent Information
- Application Number
- CN202411578463.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-07
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2044-11-07
AI Technical Summary
The existing machine learning and graph neural network methods are not effective in virtual currency trading networks, especially under the different graph structure, making it difficult to effectively detect abnormal wallet addresses.
By modeling virtual currency transaction data into graph data, adaptive hetero-allocation message aggregation operator is used to transmit node information, consider the hetero-allocation properties of neighbor nodes, design a hetero-allocation perception multi-task loss function, and optimize the graph neural network model to improve detection effect.
It improves the accuracy and efficiency of abnormal detection of virtual currency wallet address, can more effectively identify the wallet address of illegal transactions, and provides it to regulatory authorities to achieve transaction control and risk prevention.
Smart Images

Figure CN119130652B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the fields of graph neural networks and virtual currency anti-fraud, and relates to a method and system for detecting abnormal virtual currency wallet addresses based on adaptive heterophilic message aggregation. Background Art
[0002] Due to its characteristics such as decentralization and non-tamperable transactions, blockchain technology has effectively improved the security, transparency, and efficiency of virtual currency transactions, promoting financial innovation and the development of the global economy. Thanks to its open and immutable transaction data, it can provide a unique and responsible channel for financial forensics. It is particularly important to detect transaction addresses with illegal behaviors in virtual currency transactions through known and publicly available transaction information.
[0003] With the development of machine learning, some common machine learning methods have been applied to the anomaly detection of virtual currency transactions, such as XGboost, RandomForest, etc. These methods use the transaction characteristics of transaction addresses to train anomaly detection models to detect abnormal addresses. However, this method often only uses the node characteristics of transactions and cannot effectively utilize the graph structure generated by transactions, resulting in unsatisfactory detection effects.
[0004] In order to make full use of the graph data generated by transactions between wallet addresses, graph anomaly detection methods based on Graph Neural Networks (GNN) have been applied to the task of detecting abnormal virtual currency wallet addresses. Common GNN methods usually combine the feature information of nodes with the feature information of their neighbor nodes, making full use of the topological structure and feature information between nodes to learn node representations, thereby enabling effective information propagation and learning in graph data. In many real-world networks, edges tend to connect similar nodes: users in social networks tend to connect with users with similar interests, and papers in citation networks mostly cite works from the same research field. This property is usually called homophily (the opposite is called heterophily). Early work on GNN mainly focused on homophilic graphs. However, GNNs that perform well on homophilic graphs often experience a sharp decline in performance on heterophilic graphs. This is because GNNs often do not consider the homophily of neighbor nodes when aggregating neighbor information. Directly aggregating nodes of different categories will result in information loss because nodes of different categories may have different features and meanings. In the virtual currency transaction network, fraudsters usually rarely establish connections with other fraudsters but are more inclined to establish connections with normal users. Therefore, the virtual currency transaction network is a typical heterophilic graph, which leads to poor performance of common machine learning and graph neural network methods in detecting abnormal virtual currency addresses. Summary of the Invention
[0005] To solve the above problems, the present invention provides a method and system for detecting abnormal virtual currency wallet addresses based on adaptive heterophilic message aggregation.
[0006] Considering the structural characteristics of the virtual currency trading network, the present invention models transaction data as graph data, obtains the node embeddings of the graph through an adaptive heterophilic message aggregation operator, and proposes a task of calculating the message heterophily on the graph based on the node anomaly detection task, so as to adaptively consider the information of different heterophilic neighbors when aggregating neighbors in the GNN. The technical solution of the invention is as follows:
[0007] The first aspect of the present invention relates to a method for detecting abnormal virtual currency wallet addresses based on adaptive heterophilic message aggregation, comprising the following steps:
[0008] 1. Preprocessing of node feature data;
[0009] According to the existing original transaction information, use pyspark to aggregate the data within a specific time window, and calculate various transaction characteristics of each address in different time windows;
[0010] 2. Constructing the transaction network graph data; using wallet addresses as nodes and transactions between wallet addresses as edges to obtain the original graph structure; performing random walk sampling on the original graph to obtain the training graph data of the model;
[0011] 3. Calculating the deep node embedding vectors on the graph; after initializing the node features in the graph, designing a graph neural network operator for adaptive heterophilic aggregation to perform information transmission between nodes, and considering different weights when the neighbor nodes are homophilic or heterophilic during the message transmission process;
[0012] 4. Calculating the heterophily-aware loss function; using multiple linear layers to obtain the final prediction result, inputting the node embedding vectors generated in step 3, outputting C-dimensional output scores, where C is the number of classification categories, and obtaining the probability scores of the nodes through softmax , for the calculation of heterophily and the prediction of node class probability scores, use the cross-entropy classification loss function and the mean squared error loss function for optimization respectively;
[0013] 5. Performing the node prediction task; dividing the nodes in the virtual currency transaction dataset into a training set, a validation set, and a test set; dividing the minibatch to batch the data and send it into the model for multiple Epoch training, using the stochastic gradient descent method to iteratively update the model parameters, recording the performance of the model in each Epoch, evaluating the performance of the model, and selecting the model parameters with the best average performance, and finally obtaining the virtual currency address anomaly detection model.
[0014] Preferably, for the random walk sampling of the original graph in step 2, the original thousands of abnormal wallet addresses are used as the original node set S for random walk sampling, and the sampling steps are as follows:
[0015] Step21: Select an abnormal node as the original node , starting from .
[0016] Step22: Starting from the current node, randomly select a neighbor node, select the next node, and move to that node. Repeat this step until the specified walk length is reached.
[0017] Step23: Record the nodes passed through during the random walk to obtain a point set.
[0018] Step24: Repeat the above steps to obtain multiple point sets, merge and deduplicate all the point sets, and finally retain these nodes and the edges related to these nodes from the original graph to obtain the subgraph required for model training.
[0019] Finally, the training graph data is obtained , where represents N nodes, and the node feature data represents the feature matrix, containing N nodes, and each node corresponds to d-dimensional features.
[0020] Preferably, step 3 specifically includes:
[0021] First, for the current node , sample its neighbor nodes. To balance the proportion of white and black samples among the neighbor nodes, downsample the white samples and upsample the black samples to obtain a balanced neighbor set of the node. Use the original features of the node and its neighbor nodes as the input, pass through the multi-layer perceptron MLP, and output the class probability of the node . Calculate the cosine similarity between the node and each of its neighbor nodes respectively as the heterophilicity measure. The calculation formula is as follows: , after obtaining the heterophilicity , perform information transfer between neighbor nodes. At the k-th layer of each GNN, the message passing function takes the embedding of the source node where and the heterophilicity between the source node and its neighbor nodes as the input: , where is the average aggregation function, is the heterophilicity measure calculated in the previous step, is the neighbor node of node .
[0022] The node embedding of the k-th layer is updated to: , where are trainable weights, is a vector concatenation function.
[0023] After iterative calculations, the final node embedding vector can be obtained to generate edge prediction input features;
[0024] Preferably, in the transaction anomaly detection model of step 4, C = 2, and the probability scores of the nodes are obtained through softmax . For the calculation of disassortativity measurement and the prediction of node class probability scores, the cross-entropy classification loss function and the mean squared error loss function are used for optimization respectively. The specific formulas are as follows: , where is the cross-entropy classification loss function, is the mean squared error loss function, is the true label of the node, is the predicted value of the model, is the true relationship between nodes. If and are nodes of the same class, the value is 1, otherwise it is -1, is the disassortativity calculated according to the model prediction results.
[0025] Preferably, in step 5, all nodes in the virtual currency transaction dataset are divided into a training set, a validation set, and a test set according to the ratio of 70%, 15%, and 15%; the performance of the Epoch model is evaluated using the performance of accuracy, precision, recall, and F1 value.
[0026] The second aspect of the present invention relates to a virtual currency wallet address anomaly detection system for adaptive disassortative message aggregation, including:
[0027] The node feature data preprocessing module includes: according to the existing original transaction information, using pyspark to aggregate the data within a specific time window, and calculating various transaction features of each address in different time windows;
[0028] The transaction network graph data construction module includes: using wallet addresses as nodes and transactions between wallet addresses as edges to obtain the original graph structure; performing random walk sampling on the original graph to obtain the training graph data of the model;
[0029] The deep node embedding vector module on the computational graph includes: after initializing the node features in the graph, designing a graph neural network operator for adaptive heterophilic aggregation to perform information transmission between nodes. During the message passing process, different weights are assigned when considering homophilic or heterophilic neighbor nodes.
[0030] The training loss function calculation module includes: using multiple linear layers to obtain the final prediction result, inputting the node embedding vectors generated in step 3, outputting C-dimensional output scores, where C is the number of classification categories, and obtaining the probability scores of the nodes through softmax. , for the calculation of heterophily and the prediction of node class probability scores, the cross-entropy classification loss function and the mean squared error loss function are respectively used for optimization;
[0031] The node prediction task module includes: dividing the nodes in the virtual currency transaction dataset into a training set, a validation set, and a test set; dividing the minibatch to batch the data and send it into the model for multiple Epoch training, using the stochastic gradient descent method to iteratively update the model parameters, recording the performance of the model in each Epoch, evaluating the performance of the model, selecting the model parameters with the best average performance, and finally obtaining the virtual currency address anomaly detection model.
[0032] The third aspect of the present invention relates to a virtual currency wallet address anomaly detection device based on adaptive heterophilic message aggregation, including a memory and one or more processors. Executable code is stored in the memory, and when the one or more processors execute the executable code, it is used to implement the virtual currency wallet address anomaly detection method based on adaptive heterophilic message aggregation of the present invention.
[0033] The fourth aspect of the present invention relates to a computer-readable storage medium, on which a program is stored. When the program is executed by a processor, it implements the virtual currency wallet address anomaly detection method based on adaptive heterophilic message aggregation of the present invention.
[0034] The advantages of the present invention are as follows: The virtual currency transaction data is modeled as graph data, and the transaction characteristics of the nodes are combined, thus making full use of the structural information of the transactions and the node feature information. Secondly, a disassortativity-aware multi-task loss function is adopted to simultaneously perform node anomaly detection and edge node disassortativity prediction tasks, improving the efficiency and generalization ability of the model. Aiming at the problem of the overly large original graph structure, a random walk sampling method is used to effectively reduce the scale of the graph and improve the computational efficiency. During the message passing process, the imbalance and disassortativity of neighbor nodes are considered to enhance the representation ability of the model. Finally, a flexible model evaluation method is adopted, comprehensively considering various metrics such as accuracy, precision, recall, and F1 value, which can comprehensively evaluate the performance of the model, and well complete the task of detecting abnormal wallet addresses. Through this anomaly detection model, the wallet addresses with illegal transactions in the virtual currency transaction network can be accurately identified, thus providing an effective tool for the regulatory authorities to achieve the control of transactions and the prevention of risks. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] Figure 1 is the flowchart of the method of the present invention.
[0036] Figure 2 is the schematic diagram of converting the original transaction data of the present invention into graph data.
[0037] Figure 3 is the schematic diagram of neighbor adaptive message aggregation of the present invention.
[0038] Figure 4 is the schematic diagram of the system structure of the present invention.
[0039] Figure 5 is the schematic diagram of the structure of the device of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0040] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0041] It should be noted that, without conflict, the features in the following embodiments and implementation manners can be combined with each other. Embodiment 1
[0042] Figure 1 is the flowchart of the virtual currency wallet address anomaly detection method based on adaptive disassortative message aggregation provided by an embodiment of the present invention. As Figure 1As shown in the figure, an abnormal detection method for virtual currency wallet addresses based on adaptive heterogamous message aggregation in this embodiment includes the following steps:
[0043] 1. Preprocessing of node feature data;
[0044] The original transaction data mainly includes the following fields: sender wallet address, recipient wallet address, transaction currency information, transaction amount, etc. According to the original transaction information of several months, such as Figure 2 As shown, use pyspark to aggregate the data within a specific time window, calculate various transaction features of each address in different time windows, and perform maximum-minimum normalization processing on the obtained features column by column.
[0045] 2. Constructing transaction network graph data;
[0046] The virtual currency transaction network is a natural graph structure. Using wallet addresses as nodes and transactions between wallet addresses as edges, the original graph structure is obtained. Due to the large size of the graph structure and the extremely uneven ratio of black and white samples, random walk sampling is performed on the original graph to obtain the training graph data of the model. Taking thousands of original abnormal wallet addresses as the original node set S for random walk sampling, the sampling steps are as follows:
[0047] Step 21: Select an abnormal node as the original node , starting from as the starting point.
[0048] Step 22: Starting from the current node, randomly select a neighbor node, select the next node, and move to that node. Repeat this step until the specified walk length is reached.
[0049] Step 23: Record the nodes passed during the random walk to obtain a point set.
[0050] Step 24: Repeat the above steps to obtain multiple point sets, merge and deduplicate all point sets, and finally retain these nodes and the edges related to these nodes from the original graph to obtain the subgraph required for model training.
[0051] Finally, the training graph data is obtained { }, where represents N nodes, and the node feature data represents the feature matrix, including N nodes, and each node corresponds to d-dimensional features.
[0052] 3. Calculating deep node embedding vectors on the graph;
[0053] After initializing the node features in the graph, such as Figure 3As shown, a graph neural network operator for adaptive disassortative aggregation is designed to perform information transmission between nodes. During the message passing process, different weights are assigned when considering assortative or disassortative neighbor nodes. The specific steps are as follows:
[0054] First, for the current node , sample its neighbor nodes. To balance the proportion of white and black samples among the neighbor nodes, downsample the white samples and upsample the black samples to obtain a balanced neighbor set of the node. Take the original features of this node and its neighbor nodes as inputs, and pass them through a multi-layer perceptron MLP to output the class probability of the node , for node and each of its neighbor nodes , calculate the cosine similarity respectively as the disassortativity measure. The calculation formula is as follows:
[0055] (1)
[0056] After obtaining the disassortativity , perform information transmission between neighbor nodes. At the k-th layer of each GNN, the message passing function takes the embedding of the source node where and the disassortativity between the source node and its neighbor nodes as inputs:
[0057] (2)
[0058] where is the average aggregation function, is the disassortativity calculated in the previous step, is node 's neighbor nodes.
[0059] The node embedding at the k-th layer is updated as:
[0060] (3)
[0061] where is the trainable weight, is the vector concatenation function.
[0062] After iterative calculations, the final node embedding vector can be obtained to generate the input features for edge prediction;
[0063] 4. Calculate the disassortativity-aware loss function;
[0064] Multiple linear layers are used to obtain the final prediction result. The input is the node embedding vector generated in step 3, and the output is the C-dimensional output score, where C is the number of classification categories. In the transaction anomaly detection model, C = 2. After passing through softmax, the probability score of the node is obtained. For the calculation of assortativity and the prediction of node class probability scores, the cross-entropy classification loss function and the mean squared error loss function are used for optimization respectively. The specific formulas are as follows:
[0065] (4)
[0066] Where is the cross-entropy classification loss function, is the mean squared error loss function, is the true label of the node, is the predicted value of the model, is the true relationship between nodes. If and are nodes of the same type, the value is 1; otherwise, it is -1. is the assortativity calculated based on the model prediction result.
[0067] 5. Perform the node prediction task;
[0068] All nodes in the virtual currency transaction dataset are divided into a training set, a validation set, and a test set according to the ratio of 70%, 15%, and 15%. The minibatch is divided to send the data into the model for multiple Epoch training. The stochastic gradient descent method is used to iteratively update the model parameters. During this process, the performance of the model in each Epoch is recorded. The performance of the model is evaluated using the accuracy, precision, recall, and F1 value. The model parameters with the best average performance are selected, and finally, the virtual currency address anomaly detection model is obtained. Using this anomaly detection model, the wallet addresses with illegal transactions in the virtual currency trading network can be accurately identified, providing an effective tool for the regulatory authorities to achieve transaction control and risk prevention. Example 2
[0069] This example relates to a virtual currency wallet address anomaly detection system with adaptive disassortative message aggregation, as Figure 4 shown. The system includes:
[0070] The node feature data preprocessing module includes: According to the existing original transaction information, pyspark is used to aggregate the data within a specific time window, and various transaction features of each address in different time windows are calculated;
[0071] The transaction network graph data construction module includes: using wallet addresses as nodes and transactions between wallet addresses as edges to obtain the original graph structure; performing random walk sampling on the original graph to obtain the training graph data of the model;
[0072] The module for calculating deep node embedding vectors on the graph includes: after initializing the node features in the graph, designing a graph neural network operator for adaptive heterophilic aggregation for information transfer between nodes. During the message passing process, different weights are assigned when considering homophilic or heterophilic neighbor nodes;
[0073] The training loss function calculation module includes: using multiple linear layers to obtain the final prediction result. Inputting the node embedding vectors generated in step 3, outputting C-dimensional output scores, where C is the number of classification categories, and obtaining the probability scores of the nodes through softmax For the calculation of heterophily and the prediction of node category probability scores, the cross-entropy classification loss function and the mean squared error loss function are used for optimization respectively;
[0074] The node prediction task module includes: dividing the nodes in the virtual currency transaction dataset into a training set, a validation set, and a test set; dividing the minibatch to batch the data and send it into the model for multiple Epoch training. The stochastic gradient descent method is used to iteratively update the model parameters, record the performance of the model for each Epoch, evaluate the performance of the model, select the model parameters with the best average performance, and finally obtain the virtual currency address anomaly detection model. Embodiment 3
[0075] As Figure 5 shown, this embodiment relates to a virtual currency wallet address anomaly detection device based on adaptive heterophilic message aggregation, including a memory and one or more processors. An executable code is stored in the memory. When the one or more processors execute the executable code, it is used to implement the virtual currency wallet address anomaly detection method based on adaptive heterophilic message aggregation in Embodiment 1.
[0076] At the hardware level, the device includes a processor, an internal bus, a network interface, a memory, and a non-volatile memory. Of course, there may also be other hardware required for other services. The processor reads the corresponding computer program from the non-volatile memory into the memory and then runs it to implement the above Figure 1 method. Of course, in addition to the software implementation method, the present invention does not exclude other implementation methods, such as logical devices or a combination of software and hardware. That is to say, the execution subject of the following processing flow is not limited to each logical unit, and can also be hardware or logical devices.
[0077] Improvements to a technology can be clearly distinguished as either hardware improvements (e.g., improvements to circuit structures such as diodes, transistors, switches, etc.) or software improvements (improvements to method flows). However, with the development of technology, many improvements to method flows today can be regarded as direct improvements to hardware circuit structures. Almost all designers obtain the corresponding hardware circuit structure by programming the improved method flow into the hardware circuit. Therefore, it cannot be said that an improvement to a method flow cannot be implemented using a hardware entity module. For example, a programmable logic device (PLD) (such as a field programmable gate array (FPGA)) is such an integrated circuit whose logical function is determined by the user programming the device. Designers can program themselves to "integrate" a digital system onto a single PLD without having to ask a chip manufacturer to design and fabricate a dedicated integrated circuit chip. Moreover, nowadays, instead of manually fabricating integrated circuit chips, this programming is mostly implemented using "logic compiler" software, which is similar to the software compiler used in program development and writing. The original code before compilation also has to be written in a specific programming language, which is called a hardware description language (HDL), and there is not just one kind of HDL, but many kinds, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc. Currently, the most commonly used are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should also be aware that by simply performing a little logical programming on the method flow using the above-mentioned several hardware description languages and programming it into the integrated circuit, it is easy to obtain the hardware circuit that implements the logical method flow.
[0078] The controller can be implemented in any suitable manner. For example, the controller can take the form of, for example, a microprocessor or a processor and a computer-readable medium storing computer-readable program code (such as software or firmware) executable by the (micro)processor, logic gates, switches, an application specific integrated circuit (ASIC), a programmable logic controller, and an embedded microcontroller. Examples of the controller include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicone Labs C8051F320. The memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art also know that in addition to implementing the controller in the form of pure computer-readable program code, it is entirely possible to make the controller implement the same function in the form of logic gates, switches, application specific integrated circuits, programmable logic controllers, embedded microcontrollers, etc. by logically programming the method steps. Therefore, such a controller can be considered a hardware component, and the devices included therein for implementing various functions can also be regarded as the structures within the hardware component. Or even, the devices for implementing various functions can be regarded as either software modules for implementing the method or structures within the hardware component.
[0079] The systems, devices, modules, or units illustrated in the above embodiments can be specifically implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer can be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or any combination of these devices.
[0080] For the convenience of description, when describing the above devices, they are described separately as various units according to their functions. Of course, when implementing the present invention, the functions of each unit can be implemented in the same or multiple software and / or hardware.
[0081] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program code.
[0082] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and combinations of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processors of general-purpose computers, special-purpose computers, embedded processors, or other programmable data processing devices to produce a machine, such that the instructions executed by the processors of the computer or other programmable data processing devices produce means for implementing the functions specified in one flow Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0083] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory produce a manufactured article including instruction means that implement the functions specified in one flow Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0084] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to produce a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one flow Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0085] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.
[0086] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM), and / or non-volatile memory such as read-only memory (ROM) or flash memory (flash RAM). The memory is an example of computer-readable media. Embodiment 4
[0087] This embodiment relates to a computer-readable storage medium having a program stored thereon, which when executed by a processor, implements the method for detecting abnormal virtual currency wallet addresses based on adaptive heterophilic message aggregation in Embodiment 1.
[0088] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.
[0089] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.
[0090] It should be understood by those skilled in the art that the embodiments of the present invention may be provided as methods, systems or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware aspects. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0091] The present invention may be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. The present invention may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage devices.
[0092] Each embodiment in the present invention is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other, and the differences between each embodiment and other embodiments are emphasized. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and reference can be made to the relevant parts of the method embodiment for the relevant content.
[0093] The above description is only for the embodiments of the present invention and is not intended to limit the present invention. For those skilled in the art, various modifications and changes can be made to the present invention. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the scope of the claims of the present invention.
Claims
1. A virtual currency wallet address anomaly detection method based on adaptive heterogeneous message aggregation includes the following steps: S1. Preprocessing of node feature data: Based on the existing original transaction information, use pyspark to aggregate the data within a specific time window and calculate the transaction features of each address in different time windows; S2. Construct transaction network graph data; use wallet addresses as nodes and transactions between wallet addresses as edges to obtain the original graph structure; perform random walk sampling on the original graph to obtain the training graph data of the model; S3. Calculate the deep node embedding vector on the graph; after initializing the node features in the graph, design a graph neural network operator with adaptive heterogeneity aggregation to transfer information between nodes. In the process of message transmission, different weights are assigned when considering whether neighbor nodes are homogeneous or heterogeneous, including: First, for the current node , sample its neighbor nodes, and in order to balance the ratio of black and white samples in the neighbor nodes, downsample the white samples and upsample the black samples to obtain a balanced neighbor set of the node; take the original features of the node and the neighbor nodes as input, pass through the multi-layer perceptron MLP, and output the category probability of the node , for nodes and each of its neighbor nodes The cosine similarity is calculated as a measure of heterogamy, and the calculation formula is as follows: , get heterogametic After that, information is transmitted between neighbor nodes. layer, the message passing function embeds the source node ,in , and the heterogeneity of the source node and its neighbor nodes As input: ,in is the average aggregation function, is the heterogamety calculated in the previous step, Is a node Neighbor nodes of No. Node embedding of layers Updated to: ,in are trainable weights, is the vector concatenation function; In passing After the iterative calculation, the final node embedding vector can be obtained to generate the edge prediction input features; S4. Calculate the loss function of heterogeneity perception; use multiple linear layers to get the final prediction result, input the node embedding vector generated in step S3, output the C-dimensional output score, C is the number of categories, and obtain the probability score of the node through softmax ,For the calculation of heterogamy and the prediction of node category probability scores, the cross entropy classification loss function and the mean square error loss function are used for optimization respectively; S5. Perform node prediction tasks; divide the nodes in the virtual currency transaction data set into training set, validation set and test set; divide the data into minibatches and send them into the model in batches for multiple Epoch training. Use the stochastic gradient descent method to iteratively update the model parameters, record the performance of each Epoch model, evaluate the performance of the model, select the model parameters with the best average performance, and finally obtain the virtual currency address anomaly detection model.
2. The method for detecting anomaly of virtual currency wallet addresses based on adaptive heterogeneous message aggregation according to claim 1, characterized in that: In step S2, the original graph is randomly sampled by random walk, and thousands of original abnormal wallet addresses are used as the original node set S for random walk sampling. The sampling steps are as follows: Step 21: Select an abnormal node as the original node ,by as a starting point; Step 22: Starting from the current node, randomly select a neighbor node, select the next node, and move to that node; repeat this step until the specified walk length is reached; Step 23: During the random walk, record the nodes passed through to obtain a point set; Step 24: Repeat the above steps to obtain multiple point sets, merge all point sets and remove duplicates, and finally retain these nodes and the edges related to these nodes from the original graph to obtain the subgraph required for model training; Finally, we get the training graph data ,in represents N nodes, and node feature data Represents a feature matrix, which contains N nodes, and each node corresponds to a d-dimensional feature.
3. The method for detecting anomaly of virtual currency wallet addresses based on adaptive heterogeneous message aggregation according to claim 1, characterized in that: In the transaction anomaly detection model of step S4, C = 2, and the probability score of the node is obtained through softmax , for the calculation of heterogeneity and the prediction of node category probability scores, the cross entropy classification loss function and the mean square error loss function are used for optimization respectively. The specific formulas are as follows: ,in is the cross entropy classification loss function, is the mean square error loss function, is the true label of the node, is the model's predicted value, is the true relationship between nodes, if and If they are the same type of nodes, the value is 1, otherwise -1. is the heterogamety calculated based on the model prediction results.
4. The method for detecting anomaly of virtual currency wallet addresses based on adaptive heterogeneous message aggregation according to claim 1, characterized in that: In step S5, all nodes in the virtual currency transaction data set are divided into a training set, a validation set, and a test set according to a ratio of 70%, 15%, and 15%.
5. The method for detecting anomaly of virtual currency wallet addresses based on adaptive heterogeneous message aggregation according to claim 1, characterized in that: In step S5, the performance of the Epoch model is expressed using the accuracy, precision, recall, and F1 value.
6. A virtual currency wallet address anomaly detection system based on adaptive heterogeneous message aggregation, characterized in that: include: The node feature data preprocessing module includes: based on the existing original transaction information, using pyspark to aggregate the data within a specific time window, and calculating the transaction features of each address in different time windows; The transaction network graph data construction module includes: using wallet addresses as nodes and transactions between wallet addresses as edges to obtain the original graph structure; performing random walk sampling on the original graph to obtain the training graph data of the model; The deep node embedding vector module on the computation graph includes: after initializing the node features in the graph, designing a graph neural network operator for adaptive heterogeneity aggregation to transmit information between nodes. In the process of message transmission, different weights are assigned when considering whether neighbor nodes are homogeneous or heterogeneous; The training loss function calculation module includes: using multiple linear layers to obtain the final prediction result, inputting the node embedding vector generated by the deep node embedding vector module on the calculation graph, outputting the C-dimensional output score, where C is the number of classification categories, and obtaining the probability score of the node through softmax. ,For the calculation of heterogamy and the prediction of node category probability scores, the cross entropy classification loss function and the mean square error loss function are used for optimization respectively; The node prediction task module includes: dividing the nodes in the virtual currency transaction data set into training set, validation set and test set; dividing the minibatch to send the data into the model in batches for multiple Epoch training, using the stochastic gradient descent method to iteratively update the model parameters, recording the performance of each Epoch model, evaluating the performance of the model, selecting the model parameters with the best average performance, and finally obtaining the virtual currency address anomaly detection model.
7. A virtual currency wallet address anomaly detection device based on adaptive heterogeneous message aggregation, characterized in that: It includes a memory and one or more processors, wherein the memory stores executable code, and when the one or more processors execute the executable code, it is used to implement the virtual currency wallet address anomaly detection method based on adaptive heterogeneous message aggregation as described in any one of claims 1-5.
Citation Information
Patent Citations
Abnormal virtual currency wallet address detection method based on graph neural network
CN115375480A
Heterogeneous graph anomaly detection method based on adaptive selection of multi-channel neighborhood nodes
CN118540239A