Mining behavior real-time monitoring method and system, medium and equipment
By building a data acquisition network and model training, the multi-dimensional data characteristics of blockchain are extracted, and the real-time and accuracy problems of selfish mining behavior detection in the existing technology are solved, dynamic monitoring and rapid response are achieved, and fairness and stability of the blockchain network are improved.
Patent Information
- Application Number
- CN202510351380.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-24
- Publication Date
- 2025-07-22
Smart Images

Figure CN120354296A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of blockchain security, and relates to a real-time monitoring method, system, medium and device for mining behavior. Background Art
[0002] In blockchain technology, the Proof of Work (PoW) mechanism is widely used in the consensus process due to its decentralization and high security. However, selfish mining attacks, by means of hiding private chains, delaying block broadcasts, etc., disrupt the fair competition among miners and steal profits, damaging the fairness of the PoW mechanism and the stability of the blockchain network.
[0003] However, existing detection technologies mainly make judgments based on post-event analysis or single-dimensional metrics. For example, by listening to the block broadcast status or setting fixed thresholds to identify suspicious behaviors. The setting of fixed thresholds cannot adapt to the influence of network latency fluctuations or transaction peak periods, resulting in a high false positive rate. The post-event analysis mechanism, on the other hand, cannot achieve real-time response and often triggers an alarm only after the attack has caused damage. Such methods have limitations in a dynamic and complex blockchain network environment. Summary of the Invention
[0004] Aiming at the deficiencies of the prior art, the present application provides a real-time monitoring method, system, medium and device for mining behavior, realizing real-time and high-precision detection of selfish mining behavior.
[0005] To achieve the above object, in a first aspect, the present invention provides a real-time monitoring method for mining behavior, including:
[0006] Obtaining historical multi-dimensional data of the blockchain through a data acquisition network;
[0007] Extracting and fusing the transaction behavior characteristics and block generation mode characteristics corresponding to each mining behavior in the historical multi-dimensional data to obtain historical comprehensive characteristics; wherein, the transaction behavior characteristics include: transaction time interval characteristics, average block transaction fee characteristics, and transaction address correlation characteristics; the block generation mode characteristics include: block generation time interval characteristics, block generation size characteristics, and parent-child relationship characteristics between blocks; the historical comprehensive characteristics are equipped with discriminant result labels corresponding to the mining behavior.
[0008] Training a preset original model according to each of the historical comprehensive characteristics to obtain a behavior monitoring model;
[0009] Confirming whether there is selfish mining behavior in the current blockchain according to the behavior monitoring model and the current multi-dimensional data of the blockchain.
[0010] Compared with the prior art, the embodiments of the present application have the following beneficial effects: By constructing a data acquisition network to obtain multi-dimensional blockchain historical data, a comprehensive data basis is provided for subsequent analysis; Extract and fuse the transaction behavior characteristics and block generation mode characteristics to form historical comprehensive characteristics. Among them, the transaction behavior characteristics include transaction time interval, average transaction fee per block, and transaction address correlation characteristics, which can accurately depict abnormal transaction behaviors; Combining the block generation time interval, size, and parent-child relationship characteristics can comprehensively capture abnormal block generation patterns and enhance the comprehensiveness of the characteristics in reflecting mining behaviors; Training a model based on the historical comprehensive characteristics and the corresponding mining behavior discrimination results can improve the model's recognition ability for different mining behaviors; Combining real-time data input and model prediction output can achieve dynamic monitoring and rapid response, effectively reducing detection latency.
[0011] In some embodiments of the first aspect of the present application, the extracting and fusing the transaction behavior characteristics and block generation mode characteristics corresponding to each mining behavior in the historical multi-dimensional data to obtain historical comprehensive characteristics includes:
[0012] Extract the transaction behavior characteristics corresponding to each mining behavior in the historical multi-dimensional data;
[0013] Extract the block generation mode characteristics corresponding to each mining behavior in the historical multi-dimensional data;
[0014] According to the weighted fusion algorithm, fuse the transaction behavior characteristics and block generation mode characteristics to obtain historical comprehensive characteristics.
[0015] Compared with the prior art, the above embodiments have the following beneficial effects: Using the weighted fusion algorithm to dynamically integrate the two types of characteristics can avoid the deviation of a single feature dimension and improve the characterization ability of the comprehensive characteristics for mining behaviors.
[0016] In some embodiments of the first aspect of the present application, the extracting the transaction behavior characteristics corresponding to each mining behavior in the historical multi-dimensional data includes:
[0017] Calculate the corresponding transaction time interval characteristic based on the average value of all transaction times within the block at the same height in the historical multi-dimensional data;
[0018] Calculate the average transaction fee within the same block in the historical multi-dimensional data as the corresponding average transaction fee characteristic per block.
[0019] Compared with the prior art, the above embodiments have the following beneficial effects: Calculating and generating the transaction time interval characteristic through the average value of transaction times within the block at the same height can eliminate the interference of single transaction time fluctuations and enhance the stability of time dimension analysis; Based on the average transaction fee characteristic per block, it directly reflects the miner's fee preference for packing transactions and provides a quantitative basis for identifying abnormally high-fee transactions.
[0020] In some embodiments of the first aspect of the present application, the extraction of the transaction behavior characteristics corresponding to each mining behavior in the historical multi-dimensional data further includes:
[0021] Taking each miner address and the corresponding historical frequent trading address in the historical multi-dimensional data as nodes, and taking the transaction quantity between addresses as edges, to construct each transaction graph;
[0022] Respectively according to each of the transaction graphs, calculating a first topological feature vector of the node corresponding to each miner address, and a second topological feature vector of the node corresponding to each historical frequent trading address;
[0023] According to the correlation degree of each of the first topological feature vectors and each of the second topological feature vectors, calculating the transaction address correlation characteristics corresponding to each transaction address.
[0024] Compared with the prior art, the above embodiments have the following beneficial effects: By constructing a transaction graph to associate miner addresses with historical frequent trading addresses, visually presenting the topological structure of the transaction network; Based on the node degree and clustering coefficient to construct topological feature vectors, quantifying the interaction intensity between miners and associated addresses; Identifying high-frequency associated transactions through correlation degree calculation, effectively capturing the selfish behavior of miners preferentially packing associated transactions.
[0025] In some embodiments of the first aspect of the present application, the step of respectively calculating a first topological feature vector of the node corresponding to each miner address, and a second topological feature vector of the node corresponding to each historical frequent trading address according to each of the transaction graphs includes:
[0026] According to the transaction graph, respectively calculating the degree and clustering coefficient of each node;
[0027] Respectively according to the degree and clustering coefficient corresponding to each node, constructing the corresponding topological feature vector; wherein, the topological feature vector of the node corresponding to the miner address is the first topological feature vector, and the topological feature vector of the node corresponding to each historical frequent trading address is the second topological feature vector.
[0028] Compared with the prior art, the above embodiments have the following beneficial effects: By calculating the degree and clustering coefficient of nodes, the interaction pattern between the miner address and the associated addresses can be quantified from the transaction network topology; among them, the node degree directly reflects the trading activity of the miner with a specific address and can identify high-frequency associated transactions; the clustering coefficient reveals whether a tight sub-network is formed among the associated addresses (such as a hidden trading circle where the miner frequently interacts with fixed partners), and this structural feature is particularly significant in selfish mining behavior (for example, the miner preferentially packages transactions of its own associated addresses). Compared with other features (such as simple transaction amount or time interval), the combination of the node degree and the clustering coefficient can more accurately capture the structural anomalies of the transaction network (such as the formation of a dense star structure or a closed small group between the miner address and the associated addresses), avoiding misjudgments caused by relying solely on transaction frequency or amount (such as the confusion between normal high-frequency transactions and malicious associated transactions), thereby improving the detection specificity of selfish mining behavior.
[0029] In some embodiments of the first aspect of the present application, calculating the transaction address correlation feature corresponding to each transaction address according to the correlation degree between each first vector of the topological features and each second vector of the topological features includes:
[0030] Calculate the cosine similarity between the first vector of the topological features and each second vector of the topological features in each transaction graph respectively;
[0031] Calculate the corresponding transaction address correlation feature according to each cosine similarity, a preset mixing adjustment coefficient, and the mixing transaction ratio.
[0032] Compared with the prior art, the above embodiments have the following beneficial effects: Quantify the topological feature correlation between the miner address and the historical frequently traded addresses through cosine similarity to avoid a single index deviation; combine the mixing adjustment coefficient and the mixing transaction ratio to dynamically correct the correlation threshold to adapt to different network environments (such as the mixing service interference scenario), and improve the robustness of the transaction address correlation feature.
[0033] In some embodiments of the first aspect of the present application, obtaining the historical multi-dimensional data of the blockchain through the data acquisition network includes:
[0034] Obtain the original historical multi-dimensional data of the blockchain through the data acquisition network;
[0035] Preprocess the original historical multi-dimensional data to obtain the historical multi-dimensional data; wherein, the preprocessing includes any one or a combination of the following methods: invalid value removal, format unification, and standardization processing.
[0036] Compared with the prior art, the above embodiments have the following beneficial effects: By removing invalid values, unifying formats, and standardizing processing, noise and format differences in the original data are eliminated, ensuring data quality; the preprocessed data can be directly used for feature extraction and model training, reducing the interference of abnormal data on the detection results.
[0037] In a second aspect, the present invention also provides a real-time monitoring system for mining behaviors, including: a data acquisition module, a comprehensive feature acquisition module, a training module, and a result output module;
[0038] Among them, the data acquisition module is used to obtain historical multi-dimensional data of the blockchain through a data acquisition network;
[0039] The comprehensive feature acquisition module is used to extract and fuse the transaction behavior features and block generation mode features corresponding to each mining behavior in the historical multi-dimensional data to obtain historical comprehensive features; among them, the transaction behavior features include: transaction time interval feature, average block transaction fee feature, and transaction address correlation feature; the block generation mode features include: block generation time interval feature, block generation size feature, and parent-child relationship feature between blocks; the historical comprehensive features are equipped with discriminant result labels corresponding to the mining behaviors.
[0040] The training module is used to train a preset original model according to each of the historical comprehensive features to obtain a behavior monitoring model;
[0041] The result output module is used to confirm whether there is selfish mining behavior in the current blockchain according to the behavior monitoring model and the current multi-dimensional data of the blockchain.
[0042] Compared with the prior art, the embodiments of the present application have the following beneficial effects: By constructing a data acquisition network to obtain historical multi-dimensional data of the blockchain, a comprehensive data basis is provided for subsequent analysis; extracting and fusing transaction behavior features and block generation mode features to form historical comprehensive features, among which the transaction behavior features include transaction time interval, average block transaction fee, and transaction address correlation features, which can accurately depict abnormal transaction behaviors; combining the block generation time interval, size, and parent-child relationship features can comprehensively capture abnormal block generation modes and enhance the comprehensiveness of the features reflecting mining behaviors; training the model based on historical comprehensive features and corresponding discriminant results of mining behaviors can improve the model's recognition ability for different mining behaviors; combining real-time data input and model prediction output can achieve dynamic monitoring and rapid response, effectively reducing detection latency.
[0043] Thirdly, the present invention also provides a real-time monitoring device for mining behavior, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the computer program is loaded into the processor, the steps of the real-time monitoring method for mining behavior are implemented.
[0044] Fourthly, an embodiment of the present application also provides a computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, the steps of the real-time monitoring method for mining behavior are implemented. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] Figure 1 : It is a schematic flowchart of a real-time monitoring method for mining behavior provided in some embodiments of the present invention.
[0046] Figure 2 : It is a schematic structural diagram of a real-time monitoring system for mining behavior provided in some embodiments of the present invention.
[0047] Figure 3 : It is a structural diagram of a real-time monitoring device for mining behavior provided in some embodiments of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0048] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without making creative efforts belong to the scope of protection of the present invention.
[0049] Embodiment 1:
[0050] Please refer to Figure 1 , which is a real-time monitoring method for mining behavior provided in an embodiment of the present invention, including steps S1 to S4:
[0051] Step S1: Obtain historical multi-dimensional data of the blockchain through a data collection network;
[0052] In specific implementation, a distributed data collection network can be constructed. By establishing a stable connection with blockchain nodes, data can be obtained in real time to prepare for subsequent feature extraction. The collected multi-dimensional data includes basic data such as block height, block generation timestamp, transaction quantity, transaction fee, transaction time, transaction address, and a list of miners' historical frequently traded addresses. Among them, the miners' historical frequently traded addresses can select transaction data within 10 days and addresses with 5 or more fund transactions with miners. Here, the number of days and the number of times can be customarily set according to different situations and are not limited herein.
[0053] Further, step S1 can be implemented through the following preferred embodiments, including steps S11 - S12, specifically as follows:
[0054] S11: Obtain the original historical multi - dimensional data of the blockchain through the data acquisition network;
[0055] S12: Pre - process the original historical multi - dimensional data to obtain historical multi - dimensional data; wherein, the pre - processing includes any one or a combination of the following methods: invalid value removal, format unification, and standardization processing.
[0056] In this preferred embodiment, steps S11 - S12 eliminate the noise and format differences in the original data through invalid value removal, format unification, and standardization processing, ensure the data quality. The pre - processed data can be directly used for feature extraction and model training, reducing the interference of abnormal data on the detection results.
[0057] Step S2: Extract and fuse the transaction behavior features and block generation mode features corresponding to each mining behavior in the historical multi - dimensional data to obtain historical comprehensive features; wherein, the transaction behavior features include: transaction time interval feature, average block transaction fee feature, and transaction address correlation feature; the block generation mode features include: block generation time interval feature, block generation size feature, and parent - child relationship feature between blocks; the historical comprehensive features are equipped with discriminant result labels corresponding to the mining behaviors.
[0058] Further, step S2 can be implemented through the following preferred embodiments, including steps S21 - S23, specifically as follows:
[0059] S21: Extract the transaction behavior features corresponding to each mining behavior in the historical multi - dimensional data.
[0060] Further, step S21 can be implemented through the following preferred embodiments, including steps S211 - S215, specifically as follows:
[0061] S211: Calculate and generate the corresponding transaction time interval feature according to the average value of all transaction times within the blocks at the same height in the historical multi - dimensional data.
[0062] In specific implementation, the calculation method of the transaction time interval is as follows:
[0063] TD b = tx_time i - T b ; where tx_time i represents
[0064] The transaction time of the i-th transaction, tx_num i Indicates the number of transactions in the j-th block in the block set of the same height, T b Indicates the average value of all transaction times in the block set of the same height, TD b Indicates the transaction time interval corresponding to the i-th transaction.
[0065] S212: Calculate the average transaction fee within the same block in the historical multi-dimensional data as the corresponding block average transaction fee feature.
[0066] For the blocks with selfish mining, the transaction information therein has the following characteristics: First, selfish miners will preferentially select transactions with higher transaction fees when packing transactions; second, the number of transactions is small. This is to accelerate the propagation speed of the block in the network, and reducing the block size is the only way to achieve this goal. Therefore, they will try to reduce the number of transactions in the block. It should be noted that the number of transactions is at least 1, and this transaction is used to record the block reward for the miner. These two characteristics will lead to an increase in the average payment fee of the transactions in the block. Therefore, the increase in the average transaction fee within the block is an obvious feature for judging whether there is selfish mining behavior.
[0067] In specific implementation, the calculation method of the block average transaction fee is as follows:
[0068] Among them, tx_gasFee represents the block average transaction fee, gasFee represents the transaction fee, and tx_num represents the number of transactions.
[0069] In this preferred embodiment, steps S211 - S212 calculate and generate the transaction time interval feature through the average value of the transaction times within the block of the same height, eliminate the interference of the single transaction time fluctuation, and enhance the stability of the time dimension analysis; based on the block average transaction fee feature, directly reflect the fee preference of the miner for packing transactions, and provide a quantitative basis for identifying abnormally high-fee transactions.
[0070] In addition, selfish miners may preferentially pack transactions associated with themselves (such as transactions of cooperation parties or transactions initiated by themselves). The receiving addresses of these transactions may have a high-frequency association with the miner's historical transaction address list. Therefore, we can identify the mining behavior by extracting the transaction address correlation feature, and the specific method is as follows:
[0071] S213: Respectively use each miner address and the corresponding historical frequent transaction address in the historical multi-dimensional data as nodes, and use the number of transactions between the addresses as edges to construct each transaction graph.
[0072] S214: Calculate the first topological feature vector of the nodes corresponding to each miner address and the second topological feature vector of the nodes corresponding to each historical frequent trading address respectively according to each of the trading graphs.
[0073] S215: Calculate the trading address correlation features corresponding to each trading address according to the correlation degrees of each of the first topological feature vectors and each of the second topological feature vectors.
[0074] In this preferred embodiment, steps S213 - S215 associate miner addresses with historical frequent trading addresses by constructing trading graphs, visually presenting the topological structure of the trading network; construct topological feature vectors based on node degrees and clustering coefficients to quantify the interaction intensity between miners and associated addresses; identify high-frequency associated transactions through correlation degree calculation, effectively capturing the selfish behavior of miners preferentially packing associated transactions.
[0075] Furthermore, step S214 can be implemented through the following preferred implementation manners, including steps S2141 - S2142, specifically as follows:
[0076] S2141: Calculate the degree and clustering coefficient of each node respectively according to the trading graph.
[0077] In specific implementation, the calculation method of the degree degree of a node is as follows:
[0078] degree i = ∑ j A ij ; where A ij represents the number of historical transactions between node i and node j.
[0079] The calculation method of the clustering coefficient is as follows: where c i represents the clustering coefficient of node i.
[0080] S2142: Construct corresponding topological feature vectors respectively according to the degree and clustering coefficient corresponding to each node; among them, the topological feature vector of the node corresponding to the miner address is the first topological feature vector, and the topological feature vectors of the nodes corresponding to each historical frequent trading address are the second topological feature vectors.
[0081] In specific implementation, the topological feature vector of each node i can be expressed as: [degree i , c i .
[0082] In this preferred embodiment, steps S2141 - S2142 can quantify the interaction patterns between miner addresses and associated addresses from the transaction network topology by calculating the node degree and clustering coefficient. Among them, the node degree directly reflects the trading activity of miners with specific addresses and can identify high-frequency associated transactions. The clustering coefficient, on the other hand, reveals whether a tight sub-network is formed among the associated addresses (such as a hidden trading circle where miners interact frequently with fixed partners). Such structural features are particularly significant in selfish mining behavior (for example, miners preferentially package transactions of their associated addresses). Compared with other features (such as simple transaction amounts or time intervals), the combination of node degree and clustering coefficient can more accurately capture structural anomalies in the transaction network (such as the formation of a dense star structure or a closed small group between miner addresses and associated addresses), avoiding misjudgments caused by relying solely on transaction frequency or amount (such as the confusion between normal high-frequency transactions and malicious associated transactions), thereby improving the detection specificity of selfish mining behavior.
[0083] Further, step S215 can be implemented through the following preferred implementation methods, including steps S2151 - S2152, specifically as follows:
[0084] S2151: Calculate the cosine similarity between the first vector of the topological features and each second vector of the topological features in each transaction graph.
[0085] In specific implementation, the algorithm for calculating the cosine similarity X is:
[0086] where V miner represents the first vector of topological features, and V i represents the second vector of topological features.
[0087] S2152: Calculate the corresponding transaction address correlation features based on each cosine similarity, a preset mixing adjustment coefficient, and the mixing transaction ratio.
[0088] In specific implementation, the calculation method of the transaction address correlation addr_relation is as follows:
[0089] addr_relation = X - θ0·(1 + βρ); where θ0 represents the base threshold, β represents the mixing adjustment coefficient, ρ represents the mixing transaction ratio, and ρ ∈ [0, 1].
[0090] In this preferred embodiment, S2151 - S2152 quantify the topological feature correlation between miner addresses and historically frequent transaction addresses through cosine similarity, avoiding the deviation of a single indicator. Combining the mixing adjustment coefficient and the mixing transaction ratio to dynamically correct the correlation threshold, adapting to different network environments (such as the mixing service interference scenario), and improving the robustness of the transaction address correlation features.
[0091] S22: Extract the block generation mode features corresponding to each mining behavior in the historical multi-dimensional data.
[0092] In specific implementation, the block header of each block contains the hash value of the previous block. Based on this, the parent block of this block can be found, so as to determine the parent-child relationship and obtain the parent-child relationship features between blocks.
[0093] S23: According to the weighted fusion algorithm, fuse the transaction behavior features and the block generation mode features to obtain the historical comprehensive features.
[0094] In specific implementation, the transaction behavior feature f tx , the block generation mode feature f block and the historical comprehensive feature F can be expressed as follows respectively:
[0095] f tx = [TD b , tx_gasFee, addr_relation]; f block = [t b , B, H];
[0096] F = αf tx + (1 - α)f block ; where, t b represents the block generation time interval feature, B represents the block generation size feature, H represents the parent-child relationship feature between blocks, and α represents the weight coefficient.
[0097] After obtaining the above historical comprehensive features, each feature included therein can be compared with the cases of normal mining behavior and selfish mining behavior in advance, set the evaluation criteria corresponding to various features, and then evaluate the obtained features to obtain the discrimination results of the corresponding mining behavior.
[0098] In this preferred embodiment, steps S21 - S23 adopt the weighted fusion algorithm to dynamically integrate the two types of features, avoid the deviation of a single feature dimension, and improve the characterization ability of the comprehensive features for mining behavior.
[0099] Step S3: Train the preset original model according to each of the historical comprehensive features to obtain a behavior monitoring model.
[0100] In specific implementation, machine learning algorithms (such as support vector machines, random forests, convolutional neural networks or recurrent neural networks, etc.) can be used to train the historical comprehensive features, and the model is not limited here.
[0101] In this embodiment, step S3 trains the model based on the historical comprehensive features and the corresponding mining behavior discrimination results, and improves the recognition ability of the model for different mining behaviors.
[0102] Step S4: Based on the behavior monitoring model and the current multi-dimensional data of the blockchain, confirm whether there is selfish mining behavior in the current blockchain.
[0103] In specific implementation, in addition to confirming whether there is selfish mining behavior currently, after confirming the existence of selfish mining behavior, an alarm system can be connected for alarm subsequently, and sent to the blockchain network administrator and relevant users through multiple channels, such as text messages, emails, and blockchain node notifications. At the same time, more functions can be added, such as automatically taking corresponding response measures, temporarily freezing some permissions of suspicious miners, restricting their activity scope in the network, and marking and reviewing relevant transactions, etc.
[0104] In this embodiment, Step S4 combines real-time data input and model prediction output to achieve dynamic monitoring and rapid response, effectively reducing detection latency.
[0105] In summary, compared with the prior art, the above embodiments of the present application have the following beneficial effects: By constructing a data acquisition network to obtain historical multi-dimensional data of the blockchain, a comprehensive data foundation is provided for subsequent analysis; Extracting and fusing transaction behavior characteristics and block generation mode characteristics to form historical comprehensive characteristics, among which, transaction behavior characteristics include transaction time interval, average transaction fee of the block, and transaction address correlation characteristics, which can accurately depict abnormal transaction behavior; Combining block generation time interval, size, and parent-child relationship characteristics can comprehensively capture abnormal block generation modes, enhancing the comprehensiveness of the characteristics reflecting mining behavior; Training a model based on historical comprehensive characteristics and corresponding mining behavior discrimination results to improve the model's recognition ability for different mining behaviors; Combining real-time data input and model prediction output to achieve dynamic monitoring and rapid response, effectively reducing detection latency.
[0106] Embodiment 2:
[0107] Please refer to Figure 2 , based on the same inventive concept, a real-time monitoring system for mining behavior disclosed in an embodiment of the present invention includes: a data acquisition module M1, a comprehensive feature acquisition module M2, a training module M3, and a result output module M4;
[0108] Among them, the data acquisition module M1 is used to obtain historical multi-dimensional data of the blockchain through a data acquisition network.
[0109] Further, the data acquisition module M1 includes: a raw data acquisition sub-module and a preprocessing sub-module;
[0110] Among them, the raw data acquisition sub-module is used to obtain the original historical multi-dimensional data of the blockchain through a data acquisition network;
[0111] The preprocessing sub-module is used to preprocess the original historical multi-dimensional data to obtain historical multi-dimensional data; wherein, the preprocessing includes any one or a combination of the following methods: invalid value removal, format unification, and standardization processing.
[0112] In this preferred embodiment, the data acquisition module M1 eliminates noise and format differences in the original data through invalid value removal, format unification, and standardization processing to ensure data quality; the preprocessed data can be directly used for feature extraction and model training, reducing the interference of abnormal data on the detection results.
[0113] The comprehensive feature acquisition module M2 is used to extract and fuse the transaction behavior features and block generation mode features corresponding to each mining behavior in the historical multi-dimensional data to obtain historical comprehensive features; wherein, the transaction behavior features include: transaction time interval feature, average block transaction fee feature, and transaction address correlation feature; the block generation mode features include: block generation time interval feature, block generation size feature, and parent-child relationship feature between blocks; the historical comprehensive features are equipped with discriminant result labels corresponding to the mining behaviors.
[0114] Further, the comprehensive feature acquisition module M2 includes: a transaction feature extraction sub-module, a block feature extraction sub-module, and a feature fusion sub-module;
[0115] Among them, the transaction feature extraction sub-module is used to extract the transaction behavior features corresponding to each mining behavior in the historical multi-dimensional data;
[0116] The block feature extraction sub-module is used to extract the block generation mode features corresponding to each mining behavior in the historical multi-dimensional data;
[0117] The feature fusion sub-module is used to fuse the transaction behavior features and block generation mode features according to the weighted fusion algorithm to obtain historical comprehensive features.
[0118] In this preferred embodiment, the comprehensive feature acquisition module M2 dynamically integrates the two types of features using the weighted fusion algorithm, avoiding single feature dimension deviation and enhancing the characterization ability of the comprehensive features for mining behaviors.
[0119] Further, the transaction feature extraction sub-module includes a transaction time interval feature extraction unit and an average block transaction fee feature extraction unit.
[0120] Among them, the transaction time interval feature extraction unit is used to calculate and generate the corresponding transaction time interval feature according to the average value of all transaction times in the blocks at the same height in the historical multi-dimensional data;
[0121] The block average transaction fee feature extraction unit is used to calculate the average transaction fee within the same block in the historical multi-dimensional data as the corresponding block average transaction fee feature.
[0122] In this preferred embodiment, the transaction time interval feature extraction unit calculates and generates the transaction time interval feature through the average value of the transaction times within the blocks at the same height, eliminates the interference of the single transaction time fluctuation, and enhances the stability of the time dimension analysis; the block average transaction fee feature extraction unit directly reflects the fee preference of the miners for packing transactions based on the average transaction fee feature within the block, and provides a quantitative basis for identifying abnormally high-fee transactions.
[0123] Furthermore, the transaction feature extraction sub-module further includes: a transaction graph construction unit, a vector calculation unit, and a transaction address correlation feature calculation unit;
[0124] Among them, the transaction graph construction unit is used to construct each transaction graph by taking each miner address and the corresponding historical frequent transaction address in the historical multi-dimensional data as nodes and the transaction quantity between the addresses as edges.
[0125] The vector calculation unit is used to calculate the first topological feature vector of the node corresponding to each miner address and the second topological feature vector of the node corresponding to each historical frequent transaction address respectively according to each transaction graph.
[0126] The transaction address correlation feature calculation unit is used to calculate the transaction address correlation feature corresponding to each transaction address according to the correlation degree between each first topological feature vector and each second topological feature vector.
[0127] In this preferred embodiment, the transaction feature extraction sub-module associates the miner address with the historical frequent transaction address by constructing a transaction graph, visually presents the topological structure of the transaction network; constructs topological feature vectors based on the node degree and clustering coefficient to quantify the interaction intensity between the miner and the associated addresses; identifies high-frequency associated transactions through correlation degree calculation, and effectively captures the selfish behavior of the miner preferentially packing associated transactions.
[0128] Furthermore, the vector calculation unit includes: a first calculation sub-unit and a vector construction sub-unit;
[0129] Among them, the first calculation sub-unit is used to calculate the degree and clustering coefficient of each node respectively according to the transaction graph.
[0130] The vector construction sub-unit is used to construct the corresponding topological feature vector respectively according to the degree and clustering coefficient corresponding to each node; among them, the topological feature vector of the node corresponding to the miner address is the first topological feature vector, and the topological feature vectors of the nodes corresponding to each historical frequent transaction address are the second topological feature vectors.
[0131] In this preferred embodiment, the vector calculation unit can quantify the interaction pattern between the miner address and the associated address from the transaction network topology by calculating the degree and clustering coefficient of the nodes; among them, the node degree directly reflects the trading activity of the miner with a specific address and can identify high-frequency associated transactions; the clustering coefficient reveals whether a tight sub-network is formed among the associated addresses (such as a hidden trading circle where the miner interacts frequently with fixed partners), and this structural feature is particularly significant in selfish mining behavior (for example, the miner preferentially packages the transactions of its associated addresses). Compared with other features (such as simple transaction amount or time interval), the combination of the node degree and the clustering coefficient can more accurately capture the structural anomalies in the transaction network (such as the formation of a dense star structure or a closed small group between the miner address and the associated address), avoiding misjudgment caused by relying solely on transaction frequency or amount (such as the confusion between normal high-frequency transactions and malicious associated transactions), thereby improving the detection specificity of selfish mining behavior.
[0132] Furthermore, the transaction address relevance feature calculation unit includes: a similarity calculation sub-unit and a second calculation sub-unit;
[0133] Among them, the similarity calculation sub-unit is used to calculate the cosine similarity between the first topological feature vector and each of the second topological feature vectors in each transaction graph respectively;
[0134] The second calculation sub-unit is used to calculate the corresponding transaction address relevance feature according to each of the cosine similarities, a preset mixing adjustment coefficient, and the mixing transaction ratio.
[0135] In this preferred embodiment, the similarity calculation sub-unit quantifies the topological feature relevance between the miner address and the historical frequently traded addresses through cosine similarity, avoiding the deviation of a single indicator; the second calculation sub-unit dynamically corrects the relevance threshold by combining the mixing adjustment coefficient and the mixing transaction ratio to adapt to different network environments (such as the mixing service interference scenario), improving the robustness of the transaction address relevance feature.
[0136] The training module M3 is used to train a preset original model according to each of the historical comprehensive features to obtain a behavior monitoring model.
[0137] In this embodiment, the training module M3 trains the model based on the historical comprehensive features and the corresponding mining behavior discrimination results, improving the model's recognition ability for different mining behaviors.
[0138] The result output module M4 is used to confirm whether there is selfish mining behavior in the blockchain currently according to the behavior monitoring model and the current multi-dimensional data of the blockchain.
[0139] In this embodiment, the result output module M4 combines real-time data input with model prediction output to achieve dynamic monitoring and rapid response, effectively reducing detection latency.
[0140] For example, as an implementation, an Ethereum selfish mining monitoring system is constructed. In addition to the above modules, a data storage module is added to store data, an alarm module is added to issue alarms, a visualization module is added to display the system status, and a system management module is added to be responsible for managing and configuring the entire system, including system parameter settings, user permission management, data backup and recovery.
[0141] First, multiple widely distributed nodes are selected in the Ethereum network as data collection nodes. These nodes cover different geographical locations and network environments and collect data at a frequency of once every 5 seconds through the JSON-RPC interface, including block height, timestamp, transaction quantity, transaction fee, transaction address, miner computing power information, and network topology. The data storage module pre-initializes a distributed database, creates data tables and an index structure based on timestamps and block heights. The comprehensive feature acquisition module sets initial thresholds. For example, the normal transaction time interval is 1 - 60 seconds, and the normal block generation time interval is 12 - 20 seconds. The training module selects a convolutional neural network as the machine learning algorithm and initializes model parameters such as convolutional kernel size, number of layers, and learning rate.
[0142] During the data collection process, the collection nodes perform preliminary cleaning on the data, filter records with incorrect formats or missing key fields (such as empty transaction amounts), and the processed data is transmitted to the database for storage through a security protocol. After the comprehensive feature acquisition module reads the transaction data, if it detects that a certain address initiates transactions frequently within a short period (interval less than 1 second) and the transaction amounts are concentrated near specific values, it marks them as abnormal transactions. At the same time, for example, if it is found that the block generation time interval of a certain miner fluctuates to 5 seconds and the block size is abnormal, it is marked as a suspicious block. The extracted features are fused into a comprehensive feature vector and input into the convolutional neural network model, which is trained using historical normal transaction data and known selfish mining cases, and the model accuracy is improved by adjusting parameters.
[0143] During the real-time detection stage, the model continuously analyzes the input data. When it detects the simultaneous occurrence of abnormal transactions and suspicious blocks, the system determines it as a selfish mining behavior. The alarm module immediately sends a text message alarm to the administrator, publishes a warning message on the Ethereum node, and at the same time automatically freezes the block production permission of the suspicious miner and marks the relevant transactions.
[0144] The system regularly analyzes the attack data, discovers that selfish mining behaviors exhibit characteristics such as specific transaction patterns or concentration during network congestion periods, optimizes the feature extraction rules accordingly, and retrains the model by supplementing data during network congestion periods.
[0145] The visualization module displays the network status, abnormal behavior detection results, and trend analysis in the form of charts. For example, it shows the change in the number of suspicious transactions through a line chart and the distribution of abnormal types through a pie chart. Administrators adjust the monitoring parameters and security policies based on the visualized information, such as modifying the alert threshold or strengthening the monitoring during specific periods. The entire system forms a closed loop from data collection to response measures, continuously improving the detection ability through feature fusion and model iteration.
[0146] In summary, compared with the prior art, the embodiments of the present application have the following beneficial effects: By constructing a data collection network to obtain multi-dimensional historical data of the blockchain, it provides a comprehensive data basis for subsequent analysis; extracting and fusing transaction behavior features and block generation mode features to form historical comprehensive features. Among them, the transaction behavior features include transaction time intervals, average transaction fees of blocks, and transaction address correlation features, which can accurately depict abnormal transaction behaviors; combining features such as block generation time intervals, sizes, and parent-child relationships can comprehensively capture abnormal block generation modes and enhance the comprehensiveness of features reflecting mining behaviors; training a model based on historical comprehensive features and corresponding mining behavior discrimination results to improve the model's recognition ability for different mining behaviors; combining real-time data input and model prediction output to achieve dynamic monitoring and rapid response, effectively reducing detection latency.
[0147] The division of the above-described modules is only a logical function division. In actual implementation, there may be other division methods. For example, multiple modules can be combined or integrated into another system.
[0148] Embodiment 3:
[0149] Figure 3 The structure diagram of a real-time monitoring device for a mining behavior of the present application is presented. As Figure 3 shown, the real-time monitoring device for the mining behavior may include: a processor N1, a memory N2, a data interface N3, and a communication bus N4.
[0150] Among them: The processor N1, the memory N2, and the data interface N3 complete mutual communication through the communication bus N4; the data interface N3 is used for data communication with other devices such as input devices or output devices; the processor N1 is used to execute a program N5, and specifically can execute the relevant steps in the embodiment of the real-time monitoring method for a mining behavior described above.
[0151] Specifically, the program N5 may include program code, and the program code includes computer-executable instructions.
[0152] The processor N1 may be a central processing unit (CPU), or an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application. The one or more processors included in the real-time monitoring device for mining behaviors may be of the same type, such as one or more CPUs, or of different types, such as one or more CPUs and one or more ASICs.
[0153] The memory N2 is used to store the program N5. The memory N2 may include a high-speed RAM memory, and may also include a non-volatile memory, such as at least one disk memory.
[0154] The algorithms or displays provided herein are not inherently related to any particular computer, virtual system, or other device. In addition, the embodiments of the present application are not directed to any particular programming language.
[0155] Embodiment 4:
[0156] The embodiments of the present invention further provide a computer-readable storage medium. The storage medium stores at least one executable instruction. When the executable instruction runs on the real-time monitoring device / system for mining behaviors, the real-time monitoring device / system for mining behaviors is enabled to execute the real-time monitoring method for mining behaviors in any of the above method embodiments.
[0157] In the specification provided herein, a large number of specific details are set forth. However, it can be understood that the embodiments of the present application can be practiced without these specific details. Similarly, in order to streamline the present application and assist in understanding one or more of the various inventive aspects, in the above description of the exemplary embodiments of the present application, the various features of the embodiments of the present application are sometimes grouped together in a single embodiment, figure, or description thereof. Among them, the claims following the specific implementation manners are hereby expressly incorporated into the specific implementation manners, and each claim itself serves as a separate embodiment of the present application.
[0158] Those skilled in the art can understand that the modules in the devices in the embodiments can be adaptively changed and disposed in one or more devices different from the embodiments. The modules or units or components in the embodiments can be combined into one module or unit or component, and in addition, they can be divided into multiple sub-modules or sub-units or sub-components. Except that at least some of such features and / or processes or units are mutually exclusive.
Claims
1. A real-time monitoring method for mining behavior, characterized in that, Including: Obtain the historical multi-dimensional data of the blockchain through a data collection network; Extract and fuse the transaction behavior characteristics and block generation mode characteristics corresponding to each mining behavior in the historical multi-dimensional data to obtain historical comprehensive characteristics; wherein, the transaction behavior characteristics include: transaction time interval characteristics, average block transaction fee characteristics, and transaction address correlation characteristics; the block generation mode characteristics include: block generation time interval characteristics, block generation size characteristics, and parent-child relationship characteristics between blocks; the historical comprehensive characteristics are equipped with discriminant result labels corresponding to the mining behaviors; Train a preset original model according to each of the historical comprehensive characteristics to obtain a behavior monitoring model; Confirm whether there is selfish mining behavior in the blockchain currently according to the behavior monitoring model and the current multi-dimensional data of the blockchain.
2. The real-time monitoring method of a mining behavior according to claim 1, characterized in that, The extracting and fusing the transaction behavior characteristics and block generation mode characteristics corresponding to each mining behavior in the historical multi-dimensional data to obtain historical comprehensive characteristics includes: Extract the transaction behavior characteristics corresponding to each mining behavior in the historical multi-dimensional data; Extract the block generation mode characteristics corresponding to each mining behavior in the historical multi-dimensional data; Fuse the transaction behavior characteristics and block generation mode characteristics according to a weighted fusion algorithm to obtain historical comprehensive characteristics.
3. The real-time monitoring method of a mining behavior according to claim 2, wherein, The extracting the transaction behavior characteristics corresponding to each mining behavior in the historical multi-dimensional data includes: Calculate and generate corresponding transaction time interval characteristics according to the average value of all transaction times in the block at the same height in the historical multi-dimensional data; Calculate the average transaction fee in the same block in the historical multi-dimensional data as the corresponding average block transaction fee characteristic.
4. The real-time monitoring method for a mining behavior according to claim 2, wherein The extracting the transaction behavior characteristics corresponding to each mining behavior in the historical multi-dimensional data further includes: Respectively use each miner address and the corresponding historical frequent transaction address in the historical multi-dimensional data as nodes, and use the transaction quantity between addresses as edges to construct each transaction graph; Respectively calculate the first topological feature vector of the node corresponding to each miner address and the second topological feature vector of the node corresponding to each historical frequent transaction address according to each of the transaction graphs; Calculate the transaction address correlation characteristics corresponding to each transaction address according to the correlation degree between each of the first topological feature vectors and each of the second topological feature vectors.
5. The real-time monitoring method of a mining behavior according to claim 4, characterized in that, The respectively calculating the first topological feature vector of the node corresponding to each miner address and the second topological feature vector of the node corresponding to each historical frequent transaction address according to each of the transaction graphs includes: Calculate the degree and clustering coefficient of each node according to the transaction graph; Respectively construct corresponding topological feature vectors according to the degree and clustering coefficient corresponding to each node; wherein, the topological feature vector of the node corresponding to the miner address is the first topological feature vector, and the topological feature vectors of the nodes corresponding to each historical frequent transaction address are the second topological feature vectors.
6. The real-time monitoring method of a mining behavior according to claim 4, characterized in that, The calculating the transaction address correlation characteristics corresponding to each transaction address according to the correlation degree between each of the first topological feature vectors and each of the second topological feature vectors includes: Calculate the cosine similarity between the first topological feature vector and each of the second topological feature vectors in each transaction graph respectively; Calculate the corresponding transaction address correlation features based on each of the cosine similarities, a preset coin mixing adjustment coefficient, and the coin mixing transaction ratio.
7. A real-time monitoring method for a mining behavior according to any one of claims 1-6, characterized in that, The historical multi-dimensional data of the blockchain is obtained through the data collection network, including: Obtain the original historical multi-dimensional data of the blockchain through the data collection network; Preprocess the original historical multi-dimensional data to obtain historical multi-dimensional data; wherein, the preprocessing includes any one or a combination of the following methods: invalid value removal, format unification, and standardization processing.
8. A real-time monitoring system for mining behavior, characterized in that, Including: A data collection module, a comprehensive feature acquisition module, a training module, and a result output module; Among them, the data collection module is used to obtain the historical multi-dimensional data of the blockchain through the data collection network; The comprehensive feature acquisition module is used to extract and fuse the transaction behavior features and block generation mode features corresponding to each mining behavior in the historical multi-dimensional data to obtain historical comprehensive features; wherein, the transaction behavior features include: transaction time interval feature, block average transaction fee feature, and transaction address correlation feature; the block generation mode features include: block generation time interval feature, block generation size feature, and parent-child relationship feature between blocks; the historical comprehensive features are equipped with discriminant result labels corresponding to the mining behaviors; The training module is used to train a preset original model according to each of the historical comprehensive features to obtain a behavior monitoring model; The result output module is used to confirm whether there is selfish mining behavior in the blockchain currently according to the behavior monitoring model and the current multi-dimensional data of the blockchain.
9. A real-time monitoring device for mining behavior, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the computer program is loaded into the processor, it implements the steps of a real-time monitoring method for a mining behavior according to any one of claims 1-7.
10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the steps of a real-time monitoring method for a mining behavior according to any one of claims 1-7.