Ethereum Phishing Account Detection Method and System Based on Multi-Dimensional Contrastive Learning
By using a multi-dimensional comparison learning method in Ethereum phishing account detection, the spatial, timing, and transaction attribute features are extracted, and the Siamese triplet model and the multi-head attention mechanism are used for detection, the problems of model generalization ability deviation and insufficient feature extraction in the existing technology are solved, and higher detection accuracy and explanatory ability are achieved.
Patent Information
- Application Number
- CN202510096644.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-22
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2045-01-22
AI Technical Summary
The existing Ethereum phishing account detection methods have problems such as model generalization capability bias and insufficient feature extraction, resulting in distortion of accuracy indicators and insufficient model interpretation.
A multi-dimensional contrast learning method is adopted to extract features from three dimensions: space, timing, and transaction attributes, and compare learning is used using the Siamese triplet model, and feature fusion and detection are performed in combination with the multi-head attention mechanism.
It improves the generalization ability and accuracy of the model, fully extracts features, enhances the interpretability of the model, and can more effectively detect Ethereum phishing accounts.
Smart Images

Figure CN119538013B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and specifically to an Ethereum phishing account detection method and system based on multi-dimensional contrast learning. Background Art
[0002] With the popularization of the Ethereum platform, phishing attacks have become increasingly rampant, posing a major threat to the security of users' assets. Currently, for the detection methods of Ethereum phishing accounts, they mainly perform inference, analysis, and detection based on the natural graph structure of the Ethereum transaction network. The existing methods have the following problems:
[0003] 1. The imbalance in the number of transaction data of phishing accounts will lead to a deviation in the generalization ability of the model and distortion of the accuracy index;
[0004] 2. Insufficient feature extraction and lack of model interpretability caused by the lack of data differentiation processing during feature embedding and over-reliance on embedding models such as graph convolutional networks.
[0005] Therefore, there is an urgent need for an Ethereum phishing account detection method and system based on multi-dimensional contrast learning to solve the above problems. Summary of the Invention
[0006] The purpose of the present invention is to provide an Ethereum phishing account detection method and system based on multi-dimensional contrast learning, which can improve the generalization ability and accuracy of the model while fully extracting the features in the model and enhancing the model interpretability.
[0007] To achieve the above object, the present invention is realized through the following technical solutions:
[0008] On the one hand, the present invention provides an Ethereum phishing account detection method based on multi-dimensional contrast learning, including the following steps:
[0009] Obtain the transaction addresses of normal accounts and phishing accounts according to the labeled data set open-sourced on GitHub, and at the same time crawl the transaction records of the transaction accounts in the Ethereum browser Ethereum;
[0010] According to the transaction records of the transaction accounts, set a transaction quantity threshold, and for the transaction account data with a transaction quantity less than the threshold, perform a time-longitudinal data augmentation algorithm based on the transaction cycle characteristics of the Ethereum phishing accounts;
[0011] Extract features from the transaction accounts in three dimensions: space, time series, and transaction attributes;
[0012] According to the characteristics of the transaction accounts, construct an Ethereum transaction graph, and perform contrast learning on the weighted sample groups based on the Siamese triplet model to obtain enhanced features in three dimensions: space, time series, and transaction attributes;
[0013] The multi-head attention mechanism is adopted for feature fusion, and the fused feature embeddings are detected.
[0014] Preferably, the transaction records of the trading account include: transaction time, sender, recipient, and transaction amount information.
[0015] Preferably, the time longitudinal data enhancement based on the transaction cycle characteristics of Ethereum phishing accounts includes:
[0016] The transaction records of each crawled account are evenly divided into 10 time periods. Based on the collected trading accounts, the proportion of account transaction quantities in each time period is obtained. By calculating the ratio difference between the sample to be enhanced and the statistic, it is judged whether the sample is incomplete and whether data enhancement is required in each time period. The generative adversarial model is used to generate simulated transaction data in these time periods. If a transaction data needs to be added in the second time period, the statistical data in the second time period is input into the generative adversarial model for the construction of new data.
[0017] Preferably, the feature extraction of the trading account from three dimensions of space, time sequence, and transaction attributes is specifically as follows:
[0018] Feature extraction of the trading account from the space dimension: The obtained phishing transaction records are converted into a directed transaction graph according to the transaction direction, and the edges of the network are weighted according to the transaction amount, transaction times, and transaction frequency. The weighted graph is input into the generative adversarial model to obtain its feature embedding vector;
[0019] Feature extraction of the trading account from the time sequence dimension: The transaction records of the account are divided into 10 time periods according to time, and the transaction data of each time period is respectively input into the bidirectional LSTM model to obtain the time sequence features of the entire transaction life cycle of the account;
[0020] Feature extraction of the trading account from the transaction attribute dimension: The in-degree, out-degree, in-degree to out-degree ratio, in-value, out-value, in-value to out-value ratio, average in-value, average out-value, minimum in-value, minimum out-value, maximum in-value, and maximum out-value of the trading account are counted.
[0021] Preferably, the construction of the Ethereum transaction graph is specifically as follows: The graph is constructed according to the natural graph structure of the transaction network. The nodes in the graph represent trading accounts, the edges represent transaction relationships, and the edges are weighted according to the transaction characteristics between the nodes.
[0022] Preferably, the contrastive learning of the weighted sample group based on the Siamese triplet model includes:
[0023] Construct positive and negative sample groups according to the transaction characteristics of the account, and calculate the distances between different samples;
[0024] Set a threshold to distinguish similar samples and different samples, and obtain enhanced features of three-dimensional features after contrastive learning:
[0025]
[0026] Among them, represents the distance between the anchor sample and the positive sample , represents the distance between the anchor sample and the negative sample , is the set interval.
[0027] Preferably, it is characterized in that the multi-head attention mechanism is used for feature fusion, including:
[0028]
[0029] Among them, respectively represent the query vector, key vector and value vector, is a learnable weight matrix for linearly transforming the concatenated output. The calculation formula for each head is as follows:
[0030]
[0031] Among them, , are respectively the query, key and value transformation matrices of the th head. Attention is the attention calculation function, and scaled dot-product attention is used. The specific calculation formula is as follows:
[0032]
[0033] Among them, is the dimension of the key vector, used to scale the dot-product result, The function is used to normalize the dot-product result to obtain the attention weight.
[0034] Preferably, the detection of the fused feature embedding is specifically:
[0035] Construct a deep neural network to detect the fused feature embedding obtained by the multi-head attention mechanism, and classify the detection samples as normal or malicious.
[0036] On the other hand, a ground fault line identification system is also provided, including:
[0037] The grounding test-pulling line experience sorting module is used for: pre-generating a grounding line test-pulling sequence table and sorting the test-pulling lines;
[0038] The phase current dynamic comparison module is used for: generating the maximum value of the sudden change of the fault phase current according to the occurrence time of the fault phase current;
[0039] The grounding fault line determination module: determines the grounding fault line according to the maximum value of the sudden change of the fault phase current.
[0040] On the other hand, a detection system based on the above-mentioned Ethereum phishing account detection method based on multi-dimensional contrast learning is provided, including:
[0041] The data acquisition module is used for: obtaining the transaction addresses of normal accounts and phishing accounts according to the labeled data set open-sourced in GitHub, and at the same time crawling the transaction records of the transaction accounts in the Ethereum browser Ethereum;
[0042] The data processing module is used for: setting a transaction quantity threshold according to the transaction records of the transaction accounts, and performing a time-longitudinal data enhancement algorithm on the transaction account data with the transaction quantity less than the threshold based on the transaction cycle characteristics of Ethereum phishing accounts; extracting features of the transaction accounts from three dimensions of space, time series, and transaction attributes; constructing an Ethereum transaction graph according to the features of the transaction accounts, and performing contrast learning on the weighted sample group based on the Siamese triplet model to obtain enhanced features in three dimensions of space, time series, and transaction attributes;
[0043] The feature detection module is used for: performing feature fusion by adopting a multi-head attention mechanism and detecting the fused feature embedding.
[0044] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0045] 1. Effectively solve the long-tail problem of transaction data: By designing a time-longitudinal data enhancement module, the technical solution of the present invention can effectively enhance the account data with too few transactions, solve the long-tail problem existing in Ethereum transaction data, which not only improves the quality and integrity of the data, but also provides a richer and more reliable data basis for subsequent feature extraction and model training;
[0046] 2. Accurately capture the attack cycle characteristics of phishing accounts: The technical solution of the present invention considers the feature differences of phishing accounts in the entire attack cycle. By evenly dividing time periods and applying the adversarial generation model (GAN), it can simulate and supplement the missing transaction data, so as to more accurately reflect the attack behavior of phishing accounts. This innovation makes the model have higher sensitivity and accuracy in detecting phishing accounts;
[0047] 3. Achieve effective extraction and fusion of multi-dimensional features: Through feature extraction in three dimensions of space, time series, and transaction attributes, this technical solution can comprehensively capture the multi-dimensional features of trading accounts. At the same time, the multi-head attention mechanism is used for feature fusion, enabling features in different dimensions to complement each other and improving the representation ability of feature embeddings. Compared with traditional single-dimensional feature extraction methods, this method has stronger feature expression ability and higher detection performance.
[0048] 4. Construct a weighted sample group for contrastive learning: This technical solution conducts contrastive learning on the weighted sample group based on the Siamese triplet model, differentiating similar samples and dissimilar samples by calculating the distances between different samples and setting thresholds. This method can further extract and enhance the differential information in feature representations, improving the model's ability to identify phishing accounts.
[0049] 5. Improve the model's detection performance and generalization ability: Through the comprehensive application of the above innovation points, this technical solution constructs a deep neural network model that can effectively detect the fused feature embeddings obtained by the multi-head attention mechanism, classifying the detection samples as normal or malicious. Compared with the existing technology, this model has higher accuracy, sensitivity, and generalization ability in detecting Ethereum phishing accounts. BRIEF DESCRIPTION OF THE DRAWINGS
[0050] Figure 1 is the flowchart of the method of the present invention;
[0051] Figure 2 is the overall model structure diagram of the present invention;
[0052] Figure 3 is the schematic diagram of the system structure of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0053] The present invention will be further described below in conjunction with specific embodiments. It should be understood that these embodiments are only used to illustrate the present invention and not to limit the scope of the present invention. In addition, it should be understood that after reading the content taught by the present invention, those skilled in the art can make various changes or modifications to the present invention, and these equivalent forms also fall within the scope defined by this application.
[0054] In the present invention, terms such as "upper", "lower", "left", "right", "front", "rear", "vertical", "horizontal", "side", "bottom", etc. indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings. They are only relational terms determined to facilitate the description of the structural relationship of each component or element of the present invention, and do not specifically refer to any component or element of the present invention. It should not be construed as a limitation of the present invention.
[0055] Embodiment:
[0056] The trading volume of Ethereum trading accounts shows a long-tail phenomenon, that is, there are few accounts with high trading volumes and many accounts with low trading volumes. This phenomenon exists in both normal trading accounts and phishing accounts. Currently, some structure-based methods, such as random walk and graph representation methods like GNN, need to extract potential structural features based on a sufficiently rich trading structure. Some work directly discards the account data with too little trading volume, which is obviously very unreasonable. In addition, some work uses autoregression for data supplementation. Through testing and analysis, it is found that each phishing attack account has a different attack cycle. Regressing through high-volume accounts will mix the transactions in different periods together, resulting in an insignificant autoregression effect. To solve this problem, based on the phishing attack trading cycle, the attack times of different phishing accounts are set to the same scale, the trading occurrences in the entire cycle are calculated and divided into different time periods. Through the vertical trading situation in the same time period, an adversarial generation model is designed, and the transactions in this time period are input to generate corresponding simulated transaction data. For the overall accounts, a minimum trading volume threshold is set. For accounts that do not meet the minimum threshold, analyze the trading volume difference between this account and the overall accounts, and obtain the time period with the least number of transactions. For example, the overall data has the most trading volume in the first time period, but the account with low trading volume only has one transaction in the first time period. Use the adversarial generation model to generate the data for this time period. After adding this data, calculate and generate again. Due to the complexity of Ethereum phishing transactions, using the overall time series for some VAE generations shows very poor performance. Therefore, the choice is to change from the horizontal cycle to the vertical time.
[0057] In addition to the differences in the number of Ethereum account transactions, there are significant differences in the characteristics of phishing accounts throughout the entire attack cycle. Previous work has pointed out that in the early and middle stages of phishing account nodes, there are more incoming transactions, and in the later stage, there are more outgoing transactions. Although many accounts follow this pattern, there are also many accounts with very balanced incoming and outgoing transactions throughout the cycle because they transfer out the received amount directly after receiving it. Some accounts will make large-scale transfers, but some accounts will make multiple small-scale transfers. This kind of differential transaction will cause the loss of high-dimensional features with high differences when represented in a conventional graph. To solve this problem, a multi-modal triplet siamese model is designed during feature extraction, which extracts features from three dimensions: space, time series, and attributes. Taking space as an example, the distances between the sample to be detected and positive and negative samples are calculated respectively to extract unique features. However, in order to calculate the distances between differential samples, the processing work of positive and negative samples is carried out in advance, the distances between different samples are calculated, and a threshold is set. Samples smaller than this threshold are recognized as similar samples and fused, and samples larger than the threshold are retained. Finally, a sample group with differences in transaction patterns can be obtained. The sample to be detected is compared with the positive and negative sample groups to obtain the feature embedding of the space module. After obtaining the embeddings of the three modules, a multi-head attention mechanism is added for feature fusion to enhance the representation ability of the feature embedding.
[0058] As Figure 1 shown, this embodiment provides an Ethereum phishing account detection method based on multi-dimensional contrast learning, including the following steps:
[0059] Obtain the transaction addresses of normal accounts and phishing accounts according to the labeled dataset open-sourced on GitHub, and at the same time crawl the transaction records of transaction accounts in the Ethereum browser Ethereum;
[0060] According to the transaction records of transaction accounts, set a transaction quantity threshold, and for the transaction account data with the transaction quantity less than the threshold, perform a time longitudinal data augmentation algorithm based on the transaction cycle characteristics of Ethereum phishing accounts;
[0061] Extract features from the three dimensions of space, time series, and transaction attributes for transaction accounts;
[0062] According to the characteristics of transaction accounts, construct an Ethereum transaction graph, and perform contrast learning on the sample group with weights based on the Siamese triplet model to obtain enhanced features in the three dimensions of space, time series, and transaction attributes;
[0063] Adopt a multi-head attention mechanism for feature fusion, and detect the fused feature embedding.
[0064] Among them, the transaction records of the trading account include: transaction time, sender, recipient, and transaction amount information.
[0065] The specific model building is as Figure 2 shown.
[0066] For account data with too few transactions, a time longitudinal data enhancement module based on the transaction cycle characteristics of Ethereum phishing accounts is used to solve the long-tail problem of Ethereum transaction data:
[0067] First, evenly divide the transaction records of each account into 10 time periods. Based on the previously collected trading accounts, obtain the proportion of account transactions in each time period. By calculating the ratio difference between the sample to be enhanced and the statistic, determine whether the sample is incomplete and whether data enhancement is required in each time period;
[0068] Then use the generative adversarial network (GAN) to generate simulated transaction data in these time periods. For example, if a transaction data needs to be added in the second time period, input part of the statistical data in the second time period into the GAN to construct new data.
[0069] To extract multi-dimensional features of the trading account, feature extraction is carried out from three dimensions: space, time series, and transaction attributes:
[0070] In the spatial dimension, convert the obtained phishing transaction records into a directed transaction graph according to the transaction direction, and weight the edges of the network according to the transaction amount, transaction times, transaction frequency, etc. Then input the weighted graph into the GCN to obtain its feature embedding vector;
[0071] In the time dimension, divide the transaction records of the account into 10 time periods according to time, and input the transaction data of each time period into the bidirectional LSTM model respectively to obtain the time series features of the entire transaction life cycle of the account;
[0072] In the transaction attribute dimension, count the in-degree, out-degree, in-degree to out-degree ratio, in-value, out-value, in-value to out-value ratio, average in-value, average out-value, minimum in-value, minimum out-value, maximum in-value, and maximum out-value of the trading account. Through the feature extraction of these three dimensions, a more comprehensive and accurate account feature representation can be obtained.
[0073] After obtaining the transaction data, construct an Ethereum transaction graph:
[0074] First, construct a graph according to the natural graph structure of the transaction network. Nodes in the graph represent transaction accounts, edges represent transaction relationships, and the edges are weighted according to the transaction characteristics between the nodes. To represent the interactions between accounts more comprehensively, multiple types of edges are introduced, such as direct transactions, indirect transactions, similar transaction patterns, etc. However, in order to obtain representative data samples in sample contrast learning, the acquired dataset is embedded with multi-dimensional data and the similarity is compared to obtain more representative metadata.
[0075] To further improve the representation ability of feature embedding, contrast learning of weighted sample groups is performed based on the Siamese triplet model:
[0076] Construct positive and negative sample groups according to the transaction characteristics of the accounts, and calculate the distances between different samples;
[0077] Set a threshold to distinguish similar samples and different samples. After contrast learning, enhanced features of three-dimensional features are obtained. The formula is as follows:
[0078]
[0079] Among them, represents the distance between the anchor sample and the positive sample , represents the distance between the anchor sample and the negative sample , is the set interval. This loss function is used to minimize the distance between the anchor and the positive sample, while maximizing the distance between the anchor and the negative sample and maintaining a certain interval.
[0080] After obtaining the feature embeddings of the three modules, a multi-head attention mechanism is used for feature fusion:
[0081] The multi-head attention mechanism can simultaneously focus on the importance of different features and perform weighted summation according to their weights, so as to obtain a more representative feature representation. Through feature fusion, the features of the three dimensions of space, time series, and attributes can be effectively combined to improve the detection performance of the model. The specific formula is as follows:
[0082]
[0083] Among them respectively represent the query vector (query), key vector (key), and value vector (value), is a learnable weight matrix used for linear transformation of the concatenated output. The calculation formula for each head is as follows:
[0084]
[0085] Among them , , are the query, key, and value transformation matrices of the -th head respectively, is the attention calculation function, which uses scaled dot-product attention. The specific calculation formula is as follows:
[0086]
[0087] is the dimension of the key vector, which is used to scale the dot-product result to avoid the score being too large or too small, The
[0088] function is used to normalize the dot-product result to obtain the attention weights.
[0089] To detect Ethereum phishing accounts as early as possible and minimize property losses, early detection is performed on accounts with a short trading history period and few trading records. Specifically:
[0090] Perform a timestamp-based early transaction random walk on the meta-sample set in the knowledge base to obtain the early transaction behavior patterns of normal accounts and phishing accounts, and detect the topological transaction subgraph obtained by the random walk through the previously constructed multi-dimensional Siamese triplet model.
[0091] As Figure 3 shown, this embodiment also provides a detection system based on the above-mentioned Ethereum phishing account detection method based on multi-dimensional contrast learning, including:
[0092] A data acquisition module, which is used to: obtain the transaction addresses of normal accounts and phishing accounts according to the labeled data set open-sourced on GitHub, and at the same time crawl the transaction records of the transaction accounts in the Ethereum browser Ethereum;
[0093] A data processing module, which is used to: set a transaction quantity threshold according to the transaction records of the transaction accounts, and perform a time-longitudinal data augmentation algorithm on the transaction account data with a transaction quantity less than the threshold based on the transaction cycle characteristics of Ethereum phishing accounts; extract features from the three dimensions of space, time series, and transaction attributes; construct an Ethereum transaction graph according to the features of the transaction accounts, and perform contrast learning on the weighted sample groups based on the Siamese triplet model to obtain enhanced features in the three dimensions of space, time series, and transaction attributes;
[0094] A feature detection module, configured to: perform feature fusion using a multi-head attention mechanism and detect the fused feature embeddings.
[0095] The above is a specific description of the preferred embodiment of the present invention. However, the present invention is not limited to the described embodiment. Those skilled in the art can make various equivalent deformations or substitutions without departing from the spirit of the present invention. These equivalent deformations or substitutions are all included in the scope defined by the claims of this application.
Claims
1. An Ethereum phishing account detection method based on multi-dimensional contrastive learning, characterized in that: The following steps are involved: Obtain the transaction addresses of normal accounts and phishing accounts based on the open source labeled dataset in GitHub, and crawl the transaction records of transaction accounts in the Ethereum browser; According to the transaction records of the trading accounts, a transaction quantity threshold is set, and for the transaction account data with a transaction quantity less than the threshold, a time-based data enhancement algorithm is performed based on the transaction cycle characteristics of the Ethereum phishing account; The features of trading accounts are extracted from three dimensions: space, time series, and transaction attributes. Specifically: Extract features of transaction accounts from the spatial dimension: convert the acquired phishing transaction records into a directed transaction graph according to the transaction direction, weight the edges of the network according to the transaction amount, number of transactions and transaction frequency, and input the weighted graph into the adversarial generative model to obtain its feature embedding vector; Extract features of trading accounts from the time series dimension: Divide the account's transaction records into 10 time periods, input the transaction data of each time period into the bidirectional LSTM model, and obtain the time series features of the account's entire transaction life cycle; Extract features from the transaction account from the transaction attribute dimension: count the transaction account's in-degree, out-degree, in-degree-out-degree ratio, in-value, out-value, in-value-out-value ratio, average in-value, average out-value, minimum in-value, minimum out-value, maximum in-value, and maximum out-value; According to the characteristics of the transaction account, the Ethereum transaction graph is constructed, and comparative learning of the weighted sample group is performed based on the Siamese Triplet model to obtain enhanced features in three dimensions: space, time series, and transaction attributes; The Ethereum transaction graph is constructed as follows: the graph is constructed according to the natural graph structure of the transaction network, the nodes in the graph represent transaction accounts, the edges represent transaction relationships, and the edges are weighted according to the transaction characteristics between the nodes; Use multi-head attention mechanism to perform feature fusion and detect the fused feature embedding; The time-based data enhancement based on the transaction cycle characteristics of the Ethereum phishing account includes: The transaction records of each crawled account are equally divided into 10 time periods. Based on the collected transaction accounts, the proportion of account transactions in each time period is obtained. By calculating the ratio difference between the sample to be enhanced and the statistic, it is determined whether the sample is incomplete and whether data enhancement is needed in each time period. The adversarial generative model is used to generate simulated transaction data in these time periods. If a transaction data needs to be added in the second time period, the statistical data of the second time period is input into the adversarial generative model to construct new data.
2. The Ethereum phishing account detection method based on multi-dimensional contrastive learning according to claim 1 is characterized in that: The transaction record of the transaction account includes: transaction time, sender, receiver and transaction amount information.
3. The Ethereum phishing account detection method based on multi-dimensional contrastive learning according to claim 1 is characterized in that: The comparative learning of the weighted sample group based on the Siamese Triplet model includes: Construct positive and negative sample groups based on the transaction characteristics of the account, and calculate the distance between different samples; A threshold is set to distinguish similar samples from different samples, and enhanced features of three dimensional features are obtained through comparative learning: in, Represents anchor point samples With positive samples The distance between Represents anchor point samples With negative samples The distance between is the set interval.
4. The Ethereum phishing account detection method based on multi-dimensional contrastive learning according to claim 3 is characterized in that: The multi-head attention mechanism is used for feature fusion, including: in, denote the query vector, key vector and value vector respectively, is a learnable weight matrix used to perform a linear transformation on the concatenated output. The calculation formula for each head is as follows: in, , They are The query, key, and value transformation matrices of the head. Attention is the attention calculation function, using scaled dot product attention. The specific calculation formula is as follows: in, is the dimension of the key vector, used to scale the dot product result, The function is used to normalize the dot product result to obtain the attention weight.
5. The Ethereum phishing account detection method based on multi-dimensional contrastive learning according to claim 4 is characterized in that: The detection of the fused feature embedding is specifically as follows: A deep neural network is constructed to detect the fused feature embedding obtained by the multi-head attention mechanism and classify the detected samples as normal or malicious.
6. A detection system based on the Ethereum phishing account detection method based on multi-dimensional contrastive learning as claimed in claim 1, characterized in that: include: The data acquisition module is used to obtain the transaction addresses of normal accounts and phishing accounts based on the open source labeled data set in GitHub, and crawl the transaction records of transaction accounts in the Ethereum browser Ethereum; The data processing module is used to: set a transaction quantity threshold according to the transaction records of the transaction account, and perform a time-longitudinal data enhancement algorithm based on the transaction cycle characteristics of the Ethereum phishing account for the transaction account data whose transaction quantity is less than the threshold; extract features of the transaction account from three dimensions: space, time sequence, and transaction attributes; construct an Ethereum transaction graph based on the characteristics of the transaction account, and perform comparative learning of the authorized sample group based on the Siamese triplet model to obtain enhanced features in three dimensions: space, time sequence, and transaction attributes; The feature detection module is used to: use the multi-head attention mechanism to fuse features and detect the fused feature embeddings.
Citation Information
Patent Citations
Method, device and apparatus for detecting transaction exception group
CN111538869A
Financial anti-fraud transaction data enhancement method and device based on model residual error
CN117494798A
Ethereum account identity recognition method and system based on data enhancement
CN117689386A