Block chain phishing account detection method and device based on dynamic weight transaction subgraph

Through the combination of dynamic weight transaction sub-graph network and graph neural network, the problem of low detection accuracy of blockchain phishing account is solved, and more efficient phishing account identification and user security guarantee are achieved.

CN120258991AActive Publication Date: 2025-07-04HARBIN INSTITUTE OF TECHNOLOGY (SHENZHEN) (INSTITUTE OF SCIENCE AND TECHNOLOGY INNOVATION HARBIN INSTITUTE OF TECHNOLOGY SHENZHEN)
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510735233.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-04
Publication Date
2025-07-04
Estimated Expiration
2045-06-04

AI Technical Summary

Technical Problem

In the prior art, the blockchain phishing account detection method has a static method of calculating transaction sub-graph edge weights, resulting in low accuracy in recognition of phishing accounts, making it difficult to deal with phishing attacks in complex trading networks.

Method used

A dynamic weight transaction sub-graph network is adopted, combined with graph neural network and differentiable graph pooling technology, and a blockchain phishing account detection model is built through dynamic weight calculation and multi-layer feature extraction to enhance the perception of phishing behavior.

Benefits of technology

It improves the accuracy and efficiency of blockchain phishing account detection, enhances the security of user accounts, and can better identify phishing attacks in complex transaction scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120258991A_ABST
    Figure CN120258991A_ABST
Patent Text Reader

Abstract

The invention discloses a block chain phishing account detection method and device based on a dynamic weight transaction subgraph, and relates to the technical field of block chain security monitoring. The method comprises the following steps: constructing a dynamic weight transaction sub-graph network based on transaction information; obtaining a block chain phishing account detection model, wherein the block chain phishing account detection model comprises a first-stage graph neural network, a first-stage differentiable graph pooling layer, a second-stage graph neural network, a second-stage differentiable graph pooling layer, a third-stage graph neural network and a classifier module; inputting the dynamic weight transaction sub-graph network into a first-stage graph neural network, inputting an obtained first distribution matrix into a first-stage differentiable graph pooling layer, obtaining a first compression feature, inputting the first compression feature into a second-stage graph neural network, obtaining a second distribution matrix, inputting the second distribution matrix into a second-stage differentiable graph pooling layer, and inputting an obtained second compression feature into a third-stage graph neural network; and inputting the obtained global features of the graph into a classifier module to obtain a prediction result of the phishing account. By adopting the method and the device, the accuracy of block chain phishing account detection can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of blockchain security monitoring, and particularly to a method and device for detecting blockchain phishing accounts based on a dynamic weight transaction subgraph. Background Art

[0002] Due to characteristics such as decentralization and immutability, blockchain technology improves transaction transparency while also becoming a high-incidence scenario for phishing attacks due to its open anonymity. Traditional detection means rely on rule matching or shallow machine learning models and are difficult to cope with the hidden fraud behaviors implemented by attackers using complex transaction networks. In recent years, graph neural networks have been gradually applied to the field of blockchain security due to their powerful modeling ability for graph-structured data. For example, by constructing a transaction subgraph network to capture the interaction patterns between transactions and using graph convolutional networks and attention mechanisms to enhance the recognition ability for phishing attacks. However, in the current construction methods, the calculation method of the weights of the edges in the transaction subgraph network is relatively static, only considering the transaction amount quantity and not considering the amount mutation and time intensity of the transaction amount, resulting in insufficient flexibility of the subgraph network and a relatively low recognition accuracy for blockchain phishing accounts. Summary of the Invention

[0003] In order to solve the technical problem in the prior art that the edge weights of the transaction subgraph are only statically aggregated based on the transaction amount, resulting in a relatively low recognition accuracy for blockchain phishing accounts, embodiments of the present invention provide a method and device for detecting blockchain phishing accounts based on a dynamic weight transaction subgraph. The technical solutions are as follows:

[0004] On the one hand, a method for detecting blockchain phishing accounts based on a dynamic weight transaction subgraph is provided. This method is implemented by a device for detecting blockchain phishing accounts based on a dynamic weight transaction subgraph, and the method includes:

[0005] S1. Based on the original transaction information, construct a dynamic weight transaction subgraph network;

[0006] S2. Obtain a blockchain phishing account detection model, where the blockchain phishing account detection model includes a first-level graph neural network, a first-level differentiable graph pooling layer, a second-level graph neural network, a second-level differentiable graph pooling layer, a third-level graph neural network, and a classifier module;

[0007] S3. Input the dynamic weight transaction subgraph network into the first-level graph neural network to obtain a first assignment matrix;

[0008] S4. Input the first assignment matrix into the first-level differentiable graph pooling layer to obtain a first compressed feature;

[0009] S5. Input the first compressed feature into the second-level graph neural network to obtain a second assignment matrix;

[0010] S6. Input the second allocation matrix into the second-level differentiable graph pooling layer to obtain a second compressed feature;

[0011] S7. Input the second compressed feature into the third-level graph neural network to obtain a graph global feature;

[0012] S8. Input the graph global feature into the classifier module to obtain a prediction result of the blockchain phishing account.

[0013] On the other hand, a blockchain phishing account detection device based on a dynamic weight transaction subgraph is provided. The device is applied to a blockchain phishing account detection method based on a dynamic weight transaction subgraph, and the device includes:

[0014] A construction unit for constructing a dynamic weight transaction subgraph network based on the original transaction information;

[0015] An acquisition unit for acquiring a blockchain phishing account detection model, where the blockchain phishing account detection model includes a first-level graph neural network, a first-level differentiable graph pooling layer, a second-level graph neural network, a second-level differentiable graph pooling layer, a third-level graph neural network, and a classifier module;

[0016] A first processing unit for inputting the dynamic weight transaction subgraph network into the first-level graph neural network to obtain a first allocation matrix;

[0017] A second processing unit for inputting the first allocation matrix into the first-level differentiable graph pooling layer to obtain a first compressed feature;

[0018] A third processing unit for inputting the first compressed feature into the second-level graph neural network to obtain a second allocation matrix;

[0019] A fourth processing unit for inputting the second allocation matrix into the second-level differentiable graph pooling layer to obtain a second compressed feature;

[0020] A fifth processing unit for inputting the second compressed feature into the third-level graph neural network to obtain a graph global feature;

[0021] A classification unit for inputting the graph global feature into the classifier module to obtain a prediction result of the blockchain phishing account.

[0022] On the other hand, a blockchain phishing account detection device based on a dynamic weight transaction subgraph is provided. The blockchain phishing account detection device based on a dynamic weight transaction subgraph includes: a processor; a memory, and a computer-readable instruction is stored on the memory. When the computer-readable instruction is executed by the processor, any one of the methods in the above-mentioned blockchain phishing account detection method based on a dynamic weight transaction subgraph is implemented.

[0023] On the other hand, a computer-readable storage medium is provided, in which at least one instruction is stored, and the at least one instruction is loaded and executed by a processor to implement any one of the above-mentioned blockchain phishing account detection methods based on a dynamic weight transaction subgraph.

[0024] The beneficial effects brought by the technical solutions provided in the embodiments of the present invention at least include:

[0025] In the embodiments of the present invention, the dynamic weight transaction subgraph network considers the transaction frequency, perceives phishing behaviors through time decay and increased amount weights. As the weights, directions, and time attributes are retained layer by layer, the network information density and modeling accuracy are improved, and the sparsity is enhanced synchronously. A hierarchical feature extraction architecture is constructed based on DenseSAGEConv, and node-level feature abstraction is realized through a third-order graph convolutional layer. A cross-layer feature splicing strategy is adopted to fuse local and global information, and batch normalization and ReLU activation are combined to enhance the model stability. Secondly, the differentiable graph pooling technology is introduced, and a node assignment matrix and embedded features are dynamically generated through a two-branch GNN to realize hierarchical compression of the graph structure. The model constrains the pooling process through link prediction loss and entropy regularization to ensure the interpretability of topological relationships and node clustering. By combining the dynamic weight transaction subgraph network with the blockchain phishing account detection model, the perception ability of blockchain phishing accounts can be comprehensively improved, the detection efficiency and accuracy of blockchain phishing accounts can be increased, and the security of user accounts can be further ensured. Description of the Drawings

[0026] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the drawings required for the description of the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention, and those of ordinary skill in the art can also obtain other drawings based on these drawings without creative efforts.

[0027] Figure 1 is a flowchart of a blockchain phishing account detection method based on a dynamic weight transaction subgraph provided by an embodiment of the present invention;

[0028] Figure 2-1 is a schematic diagram of the process of constructing a transaction subgraph network from a transaction network provided by an embodiment of the present invention;

[0029] Figure 2-2 is a schematic diagram of the process of constructing a directed transaction subgraph network from a transaction network provided by an embodiment of the present invention;

[0030] Figure 2-3 is a schematic diagram of the process of constructing a temporal transaction subgraph network from a transaction network provided by an embodiment of the present invention;

[0031] Figure 2-4 It is a schematic diagram of the mapping strategy of a time - series trading sub - graph network provided by an embodiment of the present invention;

[0032] Figure 2-5 It is a schematic structural diagram of a blockchain phishing account detection model provided by an embodiment of the present invention;

[0033] Figure 2-6 It is a schematic structural diagram of a graph neural network provided by an embodiment of the present invention;

[0034] Figure 3 It is a block diagram of a blockchain phishing account detection device based on a dynamic - weight trading sub - graph provided by an embodiment of the present invention;

[0035] Figure 4 It is a schematic structural diagram of a blockchain phishing account detection device based on a dynamic - weight trading sub - graph provided by an embodiment of the present invention. Detailed implementation manners

[0036] Next, the technical solutions in the present invention will be described with reference to the accompanying drawings.

[0037] In the embodiments of the present invention, words such as "exemplarily" and "for example" are used to give examples, illustrations or explanations. Any embodiment or design solution described as an "example" in the present invention should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Exactly speaking, the use of the word "example" is intended to present concepts in a specific way. In addition, in the embodiments of the present invention, the meaning expressed by "and / or" can be both, or either one of the two.

[0038] In the embodiments of the present invention, "image" and "picture" can sometimes be used interchangeably. It should be noted that when not emphasizing their differences, the meanings they express are the same. "(of)", "corresponding", and "corresponding" can sometimes be used interchangeably. It should be noted that when not emphasizing their differences, the meanings they express are the same.

[0039] In the embodiments of the present invention, sometimes subscripts such as W1 may be written in a non - subscript form such as W1. When not emphasizing their differences, the meanings they express are the same.

[0040] To make the technical problems, technical solutions and advantages to be solved by the present invention clearer, the following will be described in detail with reference to the accompanying drawings and specific embodiments.

[0041] An embodiment of the present invention provides a method for detecting blockchain phishing accounts based on a dynamic weight transaction subgraph. This method can be implemented by a device for detecting blockchain phishing accounts based on a dynamic weight transaction subgraph, and this device for detecting blockchain phishing accounts based on a dynamic weight transaction subgraph can be a terminal or a server. As Figure 1 shown in the flowchart of the method for detecting blockchain phishing accounts based on a dynamic weight transaction subgraph, the processing flow of this method can include the following steps:

[0042] S1. Based on the original transaction information, construct a dynamic weight transaction subgraph network.

[0043] Optionally, S1, which constructs a dynamic weight transaction subgraph network based on the original transaction information, may include the following S11 - S13:

[0044] S11. Obtain the original transaction information, where the original transaction information includes transaction accounts, transactions between transaction accounts, transaction directions, transaction timestamps, and transaction amounts.

[0045] S12. According to the transaction accounts, transactions between transaction accounts, transaction directions, and transaction timestamps, construct the graph structure of the dynamic weight transaction subgraph network. The graph structure of the dynamic weight transaction subgraph network is the same as that of the time - series transaction subgraph network. The nodes of the graph structure of the dynamic weight transaction subgraph network represent transactions, and the edges are transaction relationships that satisfy the time sequence.

[0046] In a feasible implementation manner, first, introduce the subgraph network as follows:

[0047] The subgraph network represents the local sub - structure in the graph. Different from the traditional full - graph representation method, the subgraph network represents the relationship between nodes more refinedly, can better capture the features between nodes, and thus improve the performance of the model when processing complex data. Especially in the scenario of blockchain transactions, the subgraph network can well help detect abnormal patterns and threat perception.

[0048] The subgraph network first constructs a local subgraph according to the nodes in the graph and their connection relationships. These subgraphs not only include the information of the current node, but also contain the interaction information of the adjacent nodes, forming a local graph structure containing multi - layer information.

[0049] The propagation mechanism of the graph neural network can generate feature embeddings for each node in the subgraph network. The node embeddings are not only based on the features of the node itself, but also update the features of the node through the information propagation of adjacent nodes, so that each node can reflect its context relationship in the whole graph.

[0050] The features of the aggregated subgraph can effectively represent the global properties of the local structure. Aggregation operations usually use techniques such as graph convolution and pooling, enabling the model to extract richer graph structure information.

[0051] The subgraph network can be used for model training, helping researchers understand complex graph structures and discover potential patterns and regularities from them.

[0052] The dynamic weight trading subgraph network adopted in the embodiments of the present invention has a graph structure of the time-series trading subgraph network. The construction of the graph structure of the time-series trading subgraph network is improved on the basis of the directed trading subgraph network, and the directed trading subgraph network is improved on the basis of the trading subgraph network. Therefore, the following will introduce these three subgraph networks and their construction methods in sequence:

[0053] (1) Trading subgraph network:

[0054] The trading subgraph network is a mapping from G to T = (V’, E’), where V’ = {ei∈E} represents the node set of the trading subgraph network, ei represents the account node, and E’ = {(ei, ej, w’)} is the undirected edge set. w represents the weight. When ei and ej share the same account address in G, they will be connected.

[0055] The trading subgraph network is a variant of the subgraph network for the background of the trading ecosystem. Compared with the subgraph network, the trading subgraph network adds a weight mapping w’ = f(w), which can retain the transaction amount information in the trading network for subsequent phishing attack recognition tasks.

[0056] Figure 2-1 Shows the process of constructing the trading subgraph network: Given an original trading network composed of a central account address and its adjacent account addresses, first remove the directed attribute and retain the weight attribute to obtain an undirected trading network with weight values. Then, according to the definition of the trading network subgraph, map this trading network into the trading subgraph network structure space. The edges of the undirected trading network are mapped to the nodes of the trading subgraph network. Since the edges of the undirected trading network w1, w2, w3, w4, w5 share the central node, new edges are constructed between the nodes e1, e2, e3, e4, e5 of the trading subgraph network. The adjacent account addresses are also mapped into the trading subgraph network through the mapping mechanism, and e6, e7 are respectively mapped and new edges are constructed between e1, e5 and e2, e3.

[0057] (2) Directed trading subgraph network:

[0058] The transaction subgraph network cannot retain transaction direction information, which plays an important role in phishing attack recognition tasks. In addition, the transaction subgraph network is denser than the original transaction network, and its structure is more complex, and may even evolve into a complete graph. Based on the above problems, it is wrong to optimize the transaction subgraph network into a directed transaction subgraph network. The directed transaction subgraph network considers both transaction direction and transaction amount, which helps to extract the potential transaction patterns of the target address.

[0059] The directed transaction subgraph network is a mapping from G to where represents the node set of the directed transaction subgraph network, di represents a transaction, that is, a node of the directed transaction subgraph network, is the set of directed edges, When di and dj satisfy the following conditions, a directed edge will be formed between them:

[0060] (1) di and dj share the same account address in G;

[0061] (2) The termination node of di is the starting node of dj, and they can form a co-directional path of length two.

[0062] By comparing the transaction subgraph network and the directed transaction subgraph network, it can be found that the edges of the transaction subgraph network only represent a certain association between transactions, while the graph edges in the directed transaction subgraph network clearly represent the flow direction of transactions, enabling the directed transaction subgraph network to capture the direction relationship of fund flows. At the same time, the scale of the directed transaction subgraph network is smaller, and the information storage is more refined.

[0063] Figure 2-2 Shows the process of constructing a directed transaction subgraph network: Given the original transaction network, first retain the directed and weight attributes to obtain a directed transaction network with weight values. Then design a direction mapping strategy, and then map the directed transaction network to the structure space of the directed transaction subgraph network according to the definition of the directed transaction network subgraph.

[0064] The edges of the directed transaction network are mapped to the nodes d1, d2, d3, d4, d5, d6, d7 of the directed transaction subgraph network. The two red dashed directed lines indicate that the transactions d1, d2 and d3, d5 can be regarded as two consecutive transactions respectively, that is, the edges d1, d2 and the edges d3, d5 can form co-directional paths of length two respectively. According to the three direction mapping strategies, new edges are constructed in the directed transaction subgraph network. Since the (b) strategy in the direction mapping strategy does not meet the requirements for constructing edges, the directed transaction subgraph network can effectively limit the network scale, thus obtaining a relatively sparse graph.

[0065] (3) Temporal transaction subgraph network:

[0066] Transaction data is dynamic and becomes increasingly complex over time, which poses challenges to the analysis of transaction behavior using graph mining algorithms. In addition, phishing attacks usually have strong time perception characteristics. Based on the above problems, it is necessary to optimize the directed transaction subgraph network into a temporal transaction subgraph network. The temporal transaction subgraph network considers three attributes: transaction direction, transaction amount, and transaction time, which helps to extract the potential transaction patterns of the target address.

[0067] The temporal transaction subgraph network is a mapping from G to TT = (Vx, Ex), where Vx = {ti∈E} represents the node set of the temporal transaction subgraph network, ti is a node of the temporal transaction subgraph network, representing a transaction, and Ex = {(ti, tj,wx)} is the directed edge set, wx = f(w). When ti and tj satisfy the following conditions, a directed edge will be formed between them:

[0068] (1) ti and tj share the same account address in G;

[0069] (2) The destination node of ti is the source node of tj, and they can form a co-directional path of length two;

[0070] (3) li < lj, such that (ti, tj) shows the order of transactions. li is the time when the transaction ti occurs, and lj is the time when the transaction tj occurs.

[0071] By comparing the directed transaction subgraph network and the temporal transaction subgraph network, it can be found that the temporal transaction subgraph network changes the mapping strategy, can accurately capture the structural information of the temporal transaction flow, and at the same time further limits the scale of the network, and the information storage is more refined.

[0072] Figure 2-3 Shows the process of constructing a temporal directed transaction subgraph network: Given a constructed directed transaction subgraph network, then filter those edges that do not conform to the time order to obtain a temporal transaction subgraph network from the directed transaction subgraph network. The timestamps on the edges determine the order in which the transactions are generated. Here, it is assumed that t1 < t2 < t3 < t4 < t5 < t6 < t7. For ti and tj to be connected, i < j must be satisfied. At this time, the edges (t3, t2), (t6, t1), and (t7, t3) do not meet the formation conditions and are therefore deleted, resulting in a sparser graph.

[0073] Figure 2-4 Shows the mapping strategy of the temporal transaction subgraph network. Only when the three conditions for constructing the edges of the temporal transaction subgraph are met can a transaction chain of length 2 be constructed. Figure 2-4 The transaction chain in (a) can be successfully mapped to the temporal transaction subgraph network, Figure 2-4The transaction chain in (b) does not meet the second condition for constructing the edges of the time-series transaction subgraph. Figure 2-4 The transaction chain in (c) does not meet the third condition for constructing the edges of the time-series transaction subgraph. Figure 2-4 The transaction chain in (d) does not meet the second condition for constructing the edges of the time-series transaction subgraph.

[0074] S13. Determine the edge weights of the dynamic-weight transaction subgraph network according to the transaction timestamp, transaction amount, preset transaction amount weight coefficient, and preset time decay coefficient.

[0075] In a feasible implementation, phishing attacks often feature frequent small transactions and occasional large transactions. The time-series transaction subgraph network accurately depicts the sequential characteristics of the transaction flow through time-series constraints, but its edge weights are only based on the static aggregation of transaction amounts, making it difficult to distinguish potential risk patterns in complex transaction scenarios. In response to the above problems, the time-series transaction subgraph network is optimized into a dynamic-weight transaction subgraph network. On the basis of retaining the time-series constraints and graph structure of the time-series transaction subgraph network, the dynamic-weight transaction subgraph network designs a dynamic-weight calculation mechanism that integrates transaction amounts, time decay, and pattern features to enhance the sensitivity to abnormal transaction patterns.

[0076] Typical characteristics of phishing attacks include:

[0077] (1) Amount mutation: There may be small test transactions at the initial stage of the attack, followed by sudden large-scale fund transfers after success.

[0078] (2) Time intensity: The transaction frequency during the attack stage is significantly higher than that of normal accounts, and the transaction intervals are shorter.

[0079] Therefore, the edge weights of the dynamic-weight transaction subgraph network need to satisfy:

[0080] (1) Time-series decay: The timeliness of recent transactions is stronger, and the influence of historical transactions decays over time.

[0081] (2) Amount sensitivity: Amplify the weight differences of abnormal amounts (especially sudden large transactions).

[0082] Based on the above conditions, the embodiments of the present invention invent a calculation method for dynamic weights in a feasible implementation. Optionally, the edge weight calculation method of S13 may include the following S131-S133:

[0083] S131. Calculate the time decay according to the transaction timestamp and the following formula (1):

[0084] (1)

[0085] Among them, decay represents the time decay coefficient, and t1 and t2 represent the transaction timestamps of different transactions respectively;

[0086] Time decay is related to the time interval. The larger the time interval, the stronger the decay.

[0087] S132. Calculate the amount weight according to the transaction amount, the preset transaction amount weight coefficient, and the following formula (2):

[0088] (2)

[0089] Among them, represents the amount weight, and respectively represent the transaction amounts of different transactions, represents the preset transaction amount weight coefficient. The amount weight can increase the sensitivity to large transactions.

[0090] S133. Calculate the edge weight of the dynamic weight transaction subgraph network according to the transaction amount, time decay, amount weight, and the following formula (3):

[0091] (3)

[0092] Taking the logarithm of the transaction amount mean can avoid a single extreme value dominating the weight; the exponential decay function ensures that the weight of recent transactions is higher; the power function amplifies the marginal effect of the amount. The added time decay and power operation are both O(1) operations, and the overall complexity remains O(|E| 2 / |V|).

[0093] Comparing the time-series transaction subgraph network and the dynamic weight transaction subgraph network, it can be found that the dynamic weight transaction subgraph network shows advantages in reflecting the characteristics of phishing attacks through a two-stage weight optimization mechanism (time decay, enhanced amount weight):

[0094] (1)Fine-grained capture of frequent small transactions:

[0095] In the initial stage of a phishing attack, there are often high-frequency small test transactions, which are used to verify the activity of the target account. The time-series transaction subgraph network uses static logarithmic weights, resulting in the weights of such transactions being concentrated in a narrow range and making it difficult to distinguish the small transfer behaviors of normal users. The dynamic weight transaction subgraph network strengthens the weight decay effect of intensive transactions through the time decay factor.

[0096] (2)Differentiated amplification of sudden large transactions:

[0097] After a phishing attack is successful, the attacker usually quickly transfers a large amount of funds. The linear weight calculation of the time-series transaction subgraph network results in a high degree of weight overlap between such transactions and normal large transactions. The dynamic weight transaction subgraph network strengthens the weight difference of large transactions through the amount weight.

[0098] In summary, the dynamic weight transaction subgraph network considers the transaction frequency and increases the perception of phishing behavior through time decay and amount weight. The comparison shows that with the gradual retention of weight, direction, and time attributes, the network information density and modeling accuracy are improved, but the sparsity is enhanced synchronously.

[0099] S2. Obtain a blockchain phishing account detection model, which includes a first-level graph neural network, a first-level differentiable graph pooling layer, a second-level graph neural network, a second-level differentiable graph pooling layer, a third-level graph neural network, and a classifier module.

[0100] Among them, the structures of the first-level graph neural network, the second-level graph neural network, and the third-level graph neural network are the same, but the network parameters are different.

[0101] The first-level differentiable graph pooling layer and the second-level differentiable graph pooling layer have the same structure, but different network parameters.

[0102] In a feasible implementation manner, the embodiment of the present invention combines the method of graph neural network (GNN) and differentiable graph pooling (DiffPool) to design a blockchain phishing account detection model for blockchain threat perception. GNN is a type of deep learning model specifically used to process graph-structured data. Graph data consists of nodes and edges. GNN can effectively extract information from the graph structure by learning the features of the nodes and edges in the graph. Diffpool can generate a hierarchical representation of the graph through a differentiable graph pooling strategy and can be used in combination with GNN, thus solving the problem that the traditional GNN method has a flat structure and cannot learn the hierarchical representation of the graph. The model structure is as Figure 2-5 shown, and the pooling and embedding layer configurations are shown in Table 1-1, and the fully connected layer configurations are shown in Table 1-2.

[0103] Table 1-1 Pooling and Embedding Layer Configuration Table

[0104]

[0105] Table 1-2 Fully Connected Layer Configuration Table

[0106]

[0107] S3. Input the dynamic weight transaction subgraph network into the first-level graph neural network to obtain a first assignment matrix.

[0108] Optionally, the structures of the first-level graph neural network, the second-level graph neural network, and the third-level graph neural network all include a first convolutional layer, a second convolutional layer, and a third convolutional layer. Taking the first convolutional layer as an example, the operation execution process of the graph neural network is described in detail. The first convolutional layer is responsible for the initial feature extraction and pooling preparation of the original input graph. It contains two parallel branches: the pooling branch generates a node assignment matrix to define how to cluster the original nodes into supernodes, and the feature branch extracts the local structural features of the original graph. The dynamic weight trading subgraph network is used as the input, and its feature dimension includes the in-degree weight and the out-degree weight, as well as the adjacency matrix of the corresponding trading subgraph network. Its structure is as Figure 2-6 shown. The convolutional layer is DenseSAGEConv, which is suitable for dense graphs and can learn node representations based on the features of the neighbor nodes of the node and the graph structure information. The output of each convolutional layer passes through the ReLU activation function to introduce non-linearity. A batch normalization operation is introduced at the output end of each convolutional layer. By normalizing the intermediate feature distribution, the abnormal fluctuation of the gradient during training is significantly alleviated, thereby accelerating the model convergence speed and improving the overall training stability. The specific operations of S3 can include S31 - S34:

[0109] S31: Input the dynamic weight trading subgraph network into the first convolutional layer, perform feature transformation through the DenseSAGEConv graph convolution operation to obtain the first initial convolutional feature, process the first initial convolutional feature through the ReLU activation function, and optimize the first initial convolutional feature after processing through batch normalization to obtain the first convolutional feature.

[0110] In a feasible implementation manner, the first convolutional layer is responsible for extracting the basic trading pattern features from the original in-degree and out-degree weights. x0 performs feature transformation through the DenseSAGEConv graph convolution operation, and the output dimension is mapped to hidden_channels. This layer is followed by the ReLU activation function to introduce non-linear expression ability, and the gradient propagation stability is optimized through batch normalization. The output dimension of the first convolutional layer is hidden_channels.

[0111] S32: Input the first convolutional feature into the second convolutional layer to obtain the first initial high-order feature, process the first initial high-order feature through the ReLU activation function, and optimize the first initial high-order feature after processing through batch normalization to obtain the first high-order feature.

[0112] In a feasible implementation manner, the output dimension of the second convolutional layer is hidden_channels.

[0113] S33. Input the first high-order feature into the third convolutional layer to obtain the second initial high-order feature. Process the second initial high-order feature through the ReLU activation function and optimize the processed second initial high-order feature through batch normalization to obtain the second high-order feature.

[0114] In a feasible implementation, high-order features are abstracted layer by layer through the second and third convolutional layers to identify complex patterns. The subsequent convolutional layer inherits the output of the previous layer as the input and maintains a unified hidden dimension hidden_channels. Each layer sequentially performs graph convolution, ReLU activation, and batch normalization. The output dimension of the third convolutional layer is out_channels.

[0115] The mathematical expression of convolution is as shown in formula (4), where x k is the output feature tensor, x k-1 is the input feature tensor, A is the adjacency matrix, and BN represents batch normalization.

[0116] (4)

[0117] S34. Concatenate the first convolutional feature, the first high-order feature, and the second high-order feature along the channel dimension to obtain a fused feature, that is, obtain the first allocation matrix.

[0118] In a feasible implementation, by integrating local transaction features (i.e., the first convolutional feature, which can be represented by x1), middle-layer interaction patterns (i.e., the first high-order feature, which can be represented by x2), and global fund flow topologies (i.e., the second high-order feature, which can be represented by x3), the representation ability for blockchain phishing account behaviors is enhanced. That is, the output x3 of the third convolutional layer is concatenated with the intermediate-layer features x1, x2 along the channel dimension to generate a fused feature x fused , whose dimension is hidden_channels×2 + out_channels.

[0119] Optionally, a fully connected layer can also be added after the third convolutional layer. After feature fusion, the fused feature is input into the fully connected layer and mapped to a 2D probability distribution (non-blockchain phishing account probability, blockchain phishing account probability) through a fully connected operation, directly serving account risk determination.

[0120] The above graph convolutional network takes into account both feature abstraction and information retention. Through the cooperation of normalization operations and non-linear activation, it effectively alleviates the gradient vanishing problem in graph data. At the same time, the multi-scale fusion strategy improves the modeling robustness of the model for complex transaction patterns.

[0121] S4. Input the first allocation matrix into the first-level differentiable graph pooling layer to obtain the first compressed feature.

[0122] In a feasible implementation, the graph structure is first compressed according to the allocation matrix generated by the first-level graph neural network, reducing the number of nodes to about 25% of the original graph while preserving the key topological structure information, and ensuring semantic consistency between the pooled graph and the original graph through a specific loss function.

[0123] Optionally, the first-level differentiable graph pooling layer includes a node embedding generator, an allocation matrix learner, and a hierarchical pooling layer.

[0124] In a feasible implementation, in a blockchain transaction network, threat behaviors such as phishing attacks often exhibit multi-level topological features: abnormal account behaviors at the micro level (such as high-frequency small transfers) are intertwined with cross-account fund flows at the macro level. Traditional graph neural networks can effectively capture node-level features through neighborhood information aggregation, but their flat information transmission structure is difficult to model complex hierarchical transaction patterns. The embodiment of the present invention adopts a differentiable graph pooling (DiffPool) mechanism to construct a hierarchical transaction representation system through dynamic coarsening and semantic abstraction, breaking through the limitations of traditional methods. DiffPool maps the original graph structure G (l) = (A (l) , X (l) ) gradually into a series of coarse-grained graphs G (l+1) , G (l+2) , …, where A is the adjacency matrix and X is the node feature matrix. Its core innovation lies in transforming the discrete graph pooling process into a differentiable matrix operation. The specific operations of S4 can include S41 - S43:

[0125] S41: Input the first allocation matrix into the node embedding generator to extract high-order node representations through multi-layer graph convolution.

[0126] In a feasible implementation, the input is the graph structure G (l) = (A (l) , X (l) ) output by the previous layer, where A (l) and X (l) are the results after information aggregation and pooling operations of the previous layer of GNN. The output is Z (l) = GNNembed(A (l) , X (l) ). This module extracts high-order node representations Z (l) ∈R nl ×d through multi-layer graph convolution, where nl is the number of nodes in the current layer and d is the embedding dimension. The high-order semantic abstraction of the topological and feature information passed from the previous layer reflects the dynamic behavior patterns of transaction nodes.

[0127] S42. Input the first assignment matrix into the assignment matrix learner, and generate a soft assignment matrix from nodes to supernodes through an independent GNN module.

[0128] In a feasible implementation, the input also depends on the graph structure G output by the previous layer (l) = (A (l) , X (l) ). The output is S (l) = softmax(GNNpool(A (l) , X (l) ))), and generate a soft assignment matrix S from nodes to supernodes through an independent GNN module (l) ∈R nl×nl’ , where nl’ (nl’ < nl) is the number of nodes in the next layer. Through softmax normalization, S (l) maps the local transaction features learned by the previous layer of the graph neural network into a probability distribution from nodes to supernodes, thus defining the clustering boundary of suspicious account clusters. This process directly inherits the encoding ability of the previous layer for the complexity of the transaction network.

[0129] S43. Input the high-order node representation and the soft assignment matrix into the hierarchical pooling layer, retain the key transaction paths, aggregate the nodes with high-frequency interactions into supernodes, and abstract the node features to obtain the first compressed feature.

[0130] In a feasible implementation, the granularity adjacency matrix A (l+1) is obtained by multiplying three matrices S (l)T , A (l) , and S (l) . In this way, the key transaction paths can be retained, the nodes with high-frequency interactions can be aggregated into supernodes, and abnormal patterns such as fund collection and chain diffusion can be effectively identified. Abstract the node feature X (l+1) = S (l)T Z (l) weightedly fuses the original node semantics, enabling the model to perceive local transaction details and global fund flow rules across levels. This process is dynamically optimized through end-to-end training, so that the assignment matrices of adjacent levels can not only meet the topological sparsity constraint (minimizing the link prediction loss), but also improve the clustering confidence (entropy regularization term constraint).

[0131] DiffPool ensures the effectiveness of hierarchical representation through the following mechanisms:

[0132] (1) Hierarchical parameter sharing: Different pooling layers share GNN parameters to avoid over-parameterization problems caused by increasing the number of layers.

[0133] (2) Regularization constraints: Introduce link prediction loss and entropy regularization terms to respectively constrain the sparsity of the assignment matrix and the clustering confidence.

[0134] (3) Multi-scale feature fusion: Skip connections are used to aggregate the pooling results of each layer, enhancing the model's ability to jointly perceive local and global features.

[0135] S5. Input the first compressed feature into the second-level graph neural network to obtain the second assignment matrix.

[0136] In a feasible implementation, working on the coarsened graph after the first pooling, its pooling branch further generates a more compact assignment matrix, and the feature branch learns higher-order graph features and the interaction patterns between subgraphs.

[0137] S6. Input the second assignment matrix into the second-level differentiable graph pooling layer to obtain the second compressed feature.

[0138] In a feasible implementation, perform the second graph compression, further reducing the number of nodes to approximately 6.25% of the original graph, generating a highly abstract global graph representation. The representation at this level can capture the overall properties and macroscopic semantic features of the graph.

[0139] S7. Input the second compressed feature into the third-level graph neural network to obtain the graph global feature.

[0140] In a feasible implementation, perform pure feature extraction and transformation on the finally compressed hypergraph, and generate a fixed-size 64-dimensional graph-level global representation through mean pooling.

[0141] S8. Input the graph global feature into the classifier module to obtain the prediction result of the blockchain phishing account.

[0142] In a feasible implementation, perform high-dimensional semantic compression on the global graph feature, filter redundant information and strengthen discriminative patterns, output a general embedding vector with both generalization and interpretability; subsequently, project this embedding vector into the target classification space and generate a prediction label through probability normalization.

[0143] In summary, adopting a three-level graph neural network structure can achieve an optimal balance between hierarchical feature abstraction and computational efficiency: the first level focuses on the extraction of local features of the original graph and preliminary pooling, the second level models the interaction patterns of subgraphs, and the third level integrates global semantics. Progressive pooling can not only retain key topological information but also avoid semantic distortion caused by over-compression; compared with the two-level structure, the three-level design enhances the modeling ability for nested hierarchical graphs, while more than three levels are prone to cause training instability and over-abstraction of features.

[0144] In the embodiments of the present invention, the dynamic weight trading subgraph network considers the trading frequency and perceives phishing behaviors through time decay and increased amount weights. A hierarchical feature extraction architecture is constructed based on DenseSAGEConv. Node-level feature abstraction is achieved through a third-order graph convolutional layer. A cross-layer feature splicing strategy is adopted to fuse local and global information, and batch normalization and ReLU activation are combined to enhance the model stability. Secondly, the differentiable graph pooling technology is introduced, and a node assignment matrix and embedded features are dynamically generated through a two-branch GNN to achieve hierarchical compression of the graph structure. The model constrains the pooling process through link prediction loss and entropy regularization to ensure the interpretability of topological relationships and node clustering. By combining the dynamic weight trading subgraph network with the blockchain phishing account detection model, the perception ability of blockchain phishing accounts can be comprehensively improved, the detection efficiency and accuracy of blockchain phishing accounts can be increased, and the security of users can be further ensured.

[0145] Figure 3 FIG. is a block diagram of a blockchain phishing account detection device based on a dynamic weight trading subgraph provided by an embodiment of the present invention. This device is used for the blockchain phishing account detection method based on the dynamic weight trading subgraph. Referring to Figure 3 , the device includes a construction unit 310, an acquisition unit 320, a first processing unit 330, a second processing unit 340, a third processing unit 350, a fourth processing unit 360, a fifth processing unit 370, and a classification unit 380. Among them:

[0146] The construction unit 310 is configured to construct a dynamic weight trading subgraph network based on the original transaction information;

[0147] The acquisition unit 320 is configured to acquire a blockchain phishing account detection model, where the blockchain phishing account detection model includes a first-level graph neural network, a first-level differentiable graph pooling layer, a second-level graph neural network, a second-level differentiable graph pooling layer, a third-level graph neural network, and a classifier module;

[0148] The first processing unit 330 is configured to input the dynamic weight trading subgraph network into the first-level graph neural network to obtain a first assignment matrix;

[0149] The second processing unit 340 is configured to input the first assignment matrix into the first-level differentiable graph pooling layer to obtain a first compressed feature;

[0150] The third processing unit 350 is configured to input the first compressed feature into the second-level graph neural network to obtain a second assignment matrix;

[0151] The fourth processing unit 360 is configured to input the second assignment matrix into the second-level differentiable graph pooling layer to obtain a second compressed feature;

[0152] The fifth processing unit 370 is configured to input the second compressed feature into the third-level graph neural network to obtain a graph global feature;

[0153] The classification unit 380 is configured to input the graph global feature into a classifier module to obtain a prediction result of the blockchain phishing account.

[0154] Figure 4 FIG. is a schematic structural diagram of a blockchain phishing account detection device based on a dynamic weight transaction subgraph provided by an embodiment of the present invention. As Figure 4 shown, the blockchain phishing account detection device based on a dynamic weight transaction subgraph may include the above-mentioned Figure 3 shown blockchain phishing account detection device based on a dynamic weight transaction subgraph. Optionally, the blockchain phishing account detection device 410 based on a dynamic weight transaction subgraph may include a first processor 2001.

[0155] Optionally, the blockchain phishing account detection device 410 based on a dynamic weight transaction subgraph may further include a memory 2002 and a transceiver 2003.

[0156] Wherein, the first processor 2001, the memory 2002, and the transceiver 2003 may be connected through a communication bus, for example.

[0157] Next, in conjunction with Figure 4 each component of the blockchain phishing account detection device 410 based on a dynamic weight transaction subgraph will be specifically introduced:

[0158] Wherein, the first processor 2001 is the control center of the blockchain phishing account detection device 410 based on a dynamic weight transaction subgraph, and may be a processor or a collective term for multiple processing elements. For example, the first processor 2001 is one or more central processing units (CPUs), or may be an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present invention, such as: one or more digital signal processors (DSPs), or one or more field programmable gate arrays (FPGAs).

[0159] Optionally, the first processor 2001 may execute various functions of the blockchain phishing account detection device 410 based on a dynamic weight transaction subgraph by running or executing software programs stored in the memory 2002 and calling data stored in the memory 2002.

[0160] In a specific implementation, as an example, the first processor 2001 may include one or more CPUs, such as Figure 4 the CPU0 and CPU1 shown in

[0161] In a specific implementation, as an example, the blockchain phishing account detection device 410 based on the dynamic weight trading subgraph may also include multiple processors, such as Figure 4 the first processor 2001 and the second processor 2004 shown in. Each of these processors may be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). The processor here may refer to one or more devices, circuits, and / or processing cores for processing data (such as computer program instructions).

[0162] Among them, the memory 2002 is used to store the software program for implementing the solution of the present invention and is controlled by the first processor 2001 to execute. The specific implementation manner can refer to the above method embodiment and will not be elaborated here.

[0163] Optionally, the memory 2002 may be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM), or other optical disc storage (including compressed optical discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), a magnetic storage medium or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 2002 may be integrated with the first processor 2001 or exist independently and be coupled to the first processor 2001 through an interface circuit ( Figure 4 not shown in) of the blockchain phishing account detection device 410 based on the dynamic weight trading subgraph. The embodiments of the present invention do not make specific limitations on this.

[0164] The transceiver 2003 is used to communicate with a network device or with a terminal device.

[0165] Optionally, the transceiver 2003 may include a receiver and a transmitter ( Figure 4(not shown separately). Among them, the receiver is used to implement the receiving function, and the transmitter is used to implement the sending function.

[0166] Optionally, the transceiver 2003 can be integrated with the first processor 2001 or exist independently, and is coupled to the first processor 2001 through an interface circuit ( Figure 4 (not shown) of the blockchain phishing account detection device 410 based on the dynamic weight trading subgraph. The embodiments of the present invention do not make specific limitations on this.

[0167] It should be noted that Figure 4 the structure of the blockchain phishing account detection device 410 based on the dynamic weight trading subgraph shown in does not constitute a limitation on the router. The actual knowledge structure recognition device may include more or fewer components than those shown, or combine certain components, or have different component arrangements.

[0168] In addition, the technical effects of the blockchain phishing account detection device 410 based on the dynamic weight trading subgraph can refer to the technical effects of the blockchain phishing account detection method based on the dynamic weight trading subgraph described in the above method embodiments, and will not be elaborated here.

[0169] It should be understood that the first processor 2001 in the embodiments of the present invention may be a central processing unit (CPU), and this processor may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), off-the-shelf programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or this processor may also be any conventional processor, etc.

[0170] It should also be understood that the memory in the embodiments of the present invention can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), or a flash memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of random access memory (RAM) are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM).

[0171] The above embodiments can be implemented in whole or in part by software, hardware (such as circuits), firmware, or any combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions described in the embodiments of the present invention are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wired (such as infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or a data center that contains one or more collections of available media. The available media can be magnetic media (such as floppy disks, hard disks, magnetic tapes), optical media (such as DVDs), or semiconductor media. The semiconductor media can be a solid-state drive.

[0172] It should be understood that the term "and / or" in this document is merely a description of the association relationship between associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. Here, A and B can be singular or plural. In addition, the character " / " in this document generally represents an "or" relationship between the associated objects before and after, but it may also represent an "and / or" relationship, which can be specifically understood by referring to the context before and after.

[0173] In the present invention, "at least one" means one or more, and "a plurality" means two or more. "At least one of the following" or its similar expressions refer to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c can represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c can be single or multiple.

[0174] It should be understood that in various embodiments of the present invention, the magnitudes of the sequence numbers of the above processes do not mean the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present invention.

[0175] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of the present invention.

[0176] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the above-described devices, apparatuses, and units can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.

[0177] In several embodiments provided by the present invention, it should be understood that the disclosed devices, apparatuses, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of the devices or units can be in an electrical, mechanical, or other form.

[0178] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0179] In addition, the functional units in various embodiments of the present invention can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit.

[0180] When the above-mentioned functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The foregoing storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs.

[0181] As described above, the above are only specific implementation manners of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of changes or substitutions, which should all be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.

Claims

1. A blockchain phishing account detection method based on a dynamic weight trading subgraph, characterized in that, The method includes: S1. Based on the original transaction information, construct a dynamic weight transaction subgraph network; S2. Obtain a blockchain phishing account detection model, where the blockchain phishing account detection model includes a first-level graph neural network, a first-level differentiable graph pooling layer, a second-level graph neural network, a second-level differentiable graph pooling layer, a third-level graph neural network, and a classifier module; S3. Input the dynamic weight transaction subgraph network into the first-level graph neural network to obtain a first assignment matrix; S4. Input the first assignment matrix into the first-level differentiable graph pooling layer to obtain a first compressed feature; S5. Input the first compressed feature into the second-level graph neural network to obtain a second assignment matrix; S6. Input the second assignment matrix into the second-level differentiable graph pooling layer to obtain a second compressed feature; S7. Input the second compressed feature into the third-level graph neural network to obtain a graph global feature; S8. Input the graph global feature into the classifier module to obtain the prediction result of the blockchain phishing account.

2. The blockchain phishing account detection method based on a dynamically weighted trading subgraph according to claim 1, wherein The construction of the dynamic weight transaction subgraph network based on the original transaction information in S1 includes: S11. Obtain the original transaction information, where the original transaction information includes transaction accounts, transactions between transaction accounts, transaction directions, transaction timestamps, and transaction amounts; S12. According to the transaction accounts, transactions between transaction accounts, transaction directions, and transaction timestamps, construct the graph structure of the dynamic weight transaction subgraph network. The graph structure of the dynamic weight transaction subgraph network is the same as that of the time-series transaction subgraph network. The nodes of the graph structure of the dynamic weight transaction subgraph network represent transactions, and the edges are transaction relationships that satisfy the time series; S13. Determine the edge weights of the dynamic weight transaction subgraph network according to the transaction timestamp, transaction amount, a preset transaction amount weight coefficient, and a preset time decay coefficient.

3. The blockchain phishing account detection method based on a dynamic weight trading subgraph according to claim 2, wherein, The determination of the edge weights of the dynamic weight transaction subgraph network according to the transaction timestamp, transaction amount, a preset transaction amount weight coefficient, and a preset time decay coefficient in S13 includes: S131. Calculate the time decay according to the transaction timestamp and the following formula (1): (1) where decay represents the time decay coefficient, and t1 and t2 respectively represent the transaction timestamps of different transactions; S132. Calculate the amount weight according to the transaction amount, the preset transaction amount weight coefficient, and the following formula (2): (2) Among them, represents the amount weight, and respectively represent the transaction amounts of different transactions, represents the preset transaction amount weight coefficient; S133. Calculate the edge weights of the dynamic weight transaction subgraph network according to the transaction amount, time decay, amount weight, and the following formula (3): (3)。 4. The blockchain phishing account detection method based on a dynamically weighted trading subgraph according to claim 1, characterized in that The structures of the first-level graph neural network, the second-level graph neural network, and the third-level graph neural network are the same, but the network parameters are different; The structures of the first-level graph neural network, the second-level graph neural network, and the third-level graph neural network all include a first convolutional layer, a second convolutional layer, and a third convolutional layer; The input of the dynamic weight transaction subgraph network into the first-level graph neural network in S3 to obtain a first assignment matrix includes: S31. Input the dynamic weight trading subgraph network into the first convolutional layer, perform feature transformation through DenseSAGEConv graph convolution operation to obtain the first initial convolutional feature, process the first initial convolutional feature through the ReLU activation function, and optimize the processed first initial convolutional feature through batch normalization to obtain the first convolutional feature; S32. Input the first convolutional feature into the second convolutional layer to obtain the first initial high-order feature, process the first initial high-order feature through the ReLU activation function, and optimize the processed first initial high-order feature through batch normalization to obtain the first high-order feature; S33. Input the first high-order feature into the third convolutional layer to obtain the second initial high-order feature, process the second initial high-order feature through the ReLU activation function, and optimize the processed second initial high-order feature through batch normalization to obtain the second high-order feature; S34. Concatenate the first convolutional feature, the first high-order feature, and the second high-order feature along the channel dimension to obtain the fused feature, that is, obtain the first assignment matrix.

5. The blockchain phishing account detection method based on a dynamic weight trading subgraph according to claim 1, wherein The structures of the first-level differentiable graph pooling layer and the second-level differentiable graph pooling layer are the same, but the network parameters are different; The first-level differentiable graph pooling layer includes a node embedding generator, an assignment matrix learner, and a hierarchical pooling layer; The step of inputting the first assignment matrix into the first-level differentiable graph pooling layer in S4 to obtain the first compressed feature includes: S41. Input the first assignment matrix into the node embedding generator to extract high-order node representations through multi-layer graph convolution; S42. Input the first assignment matrix into the assignment matrix learner to generate a soft assignment matrix from nodes to supernodes through an independent GNN module; S43. Input the high-order node representation and the soft assignment matrix into the hierarchical pooling layer, retain the key trading paths, aggregate the nodes with high-frequency interactions into supernodes, and abstract the node features to obtain the first compressed feature.

6. A blockchain phishing account detection device based on a dynamic weight trading subgraph, the blockchain phishing account detection device based on the dynamic weight trading subgraph is used to implement the blockchain phishing account detection method according to any one of claims 1-5, characterized in that, The device includes: A construction unit for constructing a dynamic weight trading subgraph network based on the original trading information; An acquisition unit for acquiring a blockchain phishing account detection model, where the blockchain phishing account detection model includes a first-level graph neural network, a first-level differentiable graph pooling layer, a second-level graph neural network, a second-level differentiable graph pooling layer, a third-level graph neural network, and a classifier module; A first processing unit for inputting the dynamic weight trading subgraph network into the first-level graph neural network to obtain the first assignment matrix; A second processing unit for inputting the first assignment matrix into the first-level differentiable graph pooling layer to obtain the first compressed feature; A third processing unit for inputting the first compressed feature into the second-level graph neural network to obtain the second assignment matrix; A fourth processing unit for inputting the second assignment matrix into the second-level differentiable graph pooling layer to obtain the second compressed feature; A fifth processing unit for inputting the second compressed feature into the third-level graph neural network to obtain the graph global feature; A classification unit for inputting the graph global feature into the classifier module to obtain the prediction result of the blockchain phishing account.

7. The blockchain phishing account detection device based on the dynamically weighted trading subgraph according to claim 6, wherein, The construction unit is used for: S11. Obtain the original transaction information, where the original transaction information includes transaction accounts, transactions between transaction accounts, transaction directions, transaction timestamps, and transaction amounts; S12. Construct the graph structure of the dynamic weighted transaction sub-graph network according to the transaction accounts, transactions between transaction accounts, transaction directions, and transaction timestamps. The graph structure of the dynamic weighted transaction sub-graph network is the same as that of the time-series transaction sub-graph network. The nodes of the graph structure of the dynamic weighted transaction sub-graph network represent transactions, and the edges are transaction relationships that satisfy the time series; S13. Determine the edge weights of the dynamic weighted transaction sub-graph network according to the transaction timestamp, transaction amount, preset transaction amount weight coefficient, and preset time decay coefficient.

8. The blockchain phishing account detection device based on the dynamic weight trading subgraph according to claim 7, characterized in that, The construction unit is used for: S131. Calculate the time decay according to the transaction timestamp and the following formula (1): (1) where decay represents the time decay coefficient, and t1 and t2 respectively represent the transaction timestamps of different transactions; S132. Calculate the amount weight according to the transaction amount, preset transaction amount weight coefficient, and the following formula (2): (2) Among them, represents the amount weight, and respectively represent the transaction amounts of different transactions, represents the preset transaction amount weight coefficient; S133. Calculate the edge weights of the dynamic weighted transaction sub-graph network according to the transaction amount, time decay, amount weight, and the following formula (3): (3)。 9. A blockchain phishing account detection device based on a dynamic weight trading subgraph, characterized in that, The blockchain phishing account detection device based on the dynamic weighted sub-graph includes: A processor; A memory, on which computer-readable instructions are stored. When the computer-readable instructions are executed by the processor, the method described in any one of claims 1 to 5 is implemented.

10. A computer-readable storage medium, characterized in that, Program code is stored in the computer-readable storage medium, and the program code can be called by the processor to execute the method described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Machine learning to determine domain reputation, content classification, phishing sites, and command and control sites

    EP3965362A1

  • Ethereum phishing scam detection method and apparatus based on graph classification

    WO2022121145A1