Block chain gambling risk identification method based on time graph attention mechanism

Through the combination of the time graph attention mechanism and the MLP model, the problem of small impact on time patterns and difficult to capture key transaction information in blockchain gambling risk identification is solved, and more efficient gambling risk identification is achieved.

CN120509896APending Publication Date: 2025-08-19BEIJING INST OF TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411484745.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-10-23
Publication Date
2025-08-19

AI Technical Summary

Technical Problem

In the prior art, in the identification of blockchain gambling risks, time patterns have little impact on identification, and it is difficult to effectively capture and analyze key transaction information.

Method used

Using a method based on the time graph attention mechanism, we use the cosine function to encode the transaction timestamp by obtaining the node characteristics and transaction characteristics of neighbor accounts, and combine the attention mechanism and the MLP model to identify gambling risks.

Benefits of technology

It improves the accuracy and efficiency of gambling risk identification, can effectively capture the evolutionary process and cyclical laws of transactions, and enhances the model's sensitivity to transaction time information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120509896A_ABST
    Figure CN120509896A_ABST
Patent Text Reader

Abstract

The invention provides a blockchain gambling risk identification method based on a time graph attention mechanism, and the method comprises the steps: firstly obtaining a statistical feature of a to-be-detected account, of which each Pearson coefficient is smaller than a set threshold value, as a node feature, carrying out the coding conversion of the time sequence information of a transaction through employing a time coding technology, and obtaining a time graph attention mechanism; the transaction evolution process and the transaction periodicity rule between the accounts are captured, and the transaction characteristics of the accounts are obtained; according to the method, node features and transaction features are integrated, learning focuses are adjusted by means of an attention mechanism according to each node feature, each transaction feature and the relative importance of the node features and the transaction features in the whole network, finally, an aggregation feature matrix is input into an MLP model, and whether the account to be detected has the gambling risk or not is automatically identified. And the accuracy and the recognition efficiency of gambling risk recognition are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the interdisciplinary technical field of network information security and machine learning, and in particular relates to a blockchain gambling risk identification method based on a time graph attention mechanism. Background Art

[0002] Blockchain technology is the underlying core technology behind numerous cryptocurrencies, including Bitcoin and Ethereum. It boasts anonymity, decentralization, immutability, and data transparency. This means that no single individual or organization can control the entire blockchain network by simply controlling one or a few nodes. Once data is stored on the blockchain, it cannot be modified or deleted. Users conduct transactions using pseudonyms, and the transfer of value between anonymous participants does not rely on reliable third-party institutions. Due to the anonymity of blockchain, criminals are increasingly targeting it for various fraudulent activities.

[0003] Currently, research on gambling risk in Ethereum is insufficient, with most existing studies relying solely on handcrafted features for analysis. This approach faces two major issues. First, temporal patterns are crucial for identifying gambling risk. Older transactions may have less influence on current gambling risk identification, while more recent transactions have a more significant impact on the network's current topology and node representation. Second, given the varying importance of different transactions, effectively capturing and analyzing key transaction information presents a challenge. Summary of the Invention

[0004] In order to solve the problem that traditional solutions are insufficient in identifying gambling fraud risks, the present invention provides a blockchain gambling risk identification method based on a time graph attention mechanism, which can improve the accuracy and efficiency of gambling risk identification.

[0005] A blockchain gambling risk identification method based on a time graph attention mechanism includes the following steps:

[0006] S1: Perform node feature acquisition operations on neighboring accounts that have transacted with the tested account to obtain node features of each neighboring account. The node feature acquisition operation is as follows:

[0007] All transaction information since the current neighbor account was registered is divided into three categories: Category I transactions where the current neighbor account is only the receiver, Category II transactions where the current neighbor account is only the sender, and Category III transactions where the current neighbor account is both the receiver and the sender.

[0008] The average amount, total amount, standard deviation of amount, entropy of amount, average timestamp, sum of timestamps, standard deviation of timestamp, entropy of timestamps, average gas, sum of gas, standard deviation of gas, entropy of gas, average gasPrice, maximum gasPrice, and sum of gasPrice of Category I transactions; the maximum amount, entropy of amount, average timestamp, maximum timestamp, entropy of timestamp, average gas, minimum gas, maximum gas, sum of gas, entropy of gas, average gasPrice, maximum gasPrice, and sum of gasPrice of Category II transactions; the total amount, maximum gas, entropy of gasPrice, and minimum gasPrice of Category III transactions are used as node features. The Pearson coefficient between any two features in the node features is less than the set threshold.

[0009] S2: The transaction timestamps of each transaction information of the account to be tested are encoded and converted using the cosine function. Then, the converted transaction timestamps, transaction amounts, gas consumed by the transaction, gasPrice (the amount of ether paid per unit of gas), and transaction direction flags of each transaction information of the account to be tested are concatenated in ascending order of timestamps to form transaction features. Among them, the transaction direction flag of the transaction information of the account to be tested as the receiver is 1, and the transaction direction flag of the transaction information of the account to be tested as the receiver is 0;

[0010] S3: Concatenate the node features of each neighboring account of the account to be tested and the transaction features of the account to be tested to obtain the input feature matrix;

[0011] S4: Input the input features into the trained attention model for feature fusion to obtain the aggregated feature matrix;

[0012] S5: Input the aggregated feature matrix into the trained MLP model to obtain the result of whether the account to be tested has gambling risk.

[0013] Furthermore, the joint training method of the attention model and the MLP model is:

[0014] Step 1: Obtain the Ethereum transaction containing the sending address, receiving address, transaction timestamp, transaction amount, the amount of gas consumed by the transaction, and the amount of Ether paid per unit of gas (gasPrice) on the Ethereum network, and construct the Ethereum multilateral transaction directed graph G;

[0015] Step 2: Select addresses marked with gambling risk labels and an equal number of addresses not marked with gambling risk labels from the Ethereum multilateral transaction directed graph G as target nodes; each address corresponds to an account;

[0016] Step 3: Obtain all transactions of the account corresponding to each target node since registration, and sort all transactions of each target node in ascending order according to timestamps to obtain the transaction sequence diagram of each target node;

[0017] Step 4: Take each target node as the current target node and perform the input feature matrix acquisition operation to obtain the input feature matrix corresponding to each target node. The input feature matrix acquisition operation is:

[0018] Perform node feature acquisition operations on the neighboring accounts corresponding to the neighboring nodes that have traded with the account corresponding to the current target node, and obtain the node features of each neighboring account;

[0019] The transaction timestamps of each transaction information of the account corresponding to the current target node are encoded and converted using the cosine function. Then, the converted transaction timestamps, transaction amounts, gas consumed, gasPrice (the amount of ether paid per unit of gas), and transaction direction flags of each transaction information of the account corresponding to the current target node are concatenated in ascending order of timestamps to form transaction features.

[0020] The node features of each neighbor account corresponding to the current target node and the transaction features of the account corresponding to the current target node are concatenated to obtain the input feature matrix corresponding to the current target node;

[0021] Step 5: Input the input feature matrix corresponding to each target node into the attention model for feature fusion to obtain the aggregated feature matrix corresponding to each target node;

[0022] Step 6: Input the aggregate feature matrix corresponding to each target node into the MLP model to obtain the gambling risk prediction value corresponding to each target node;

[0023] Step 7: Construct a loss function using the gambling risk prediction value corresponding to each target node and the gambling risk label corresponding to each target node, and determine whether the loss function is less than the set value. If yes, obtain the trained attention model and MLP model. If not, proceed to step 8.

[0024] Step 8: Adjust the model parameters of the attention model and the MLP model, and re-execute steps 5 to 7 until the loss function is less than the set value.

[0025] Furthermore, the node feature screening method is:

[0026] The six different statistical features of Category I, Category II, and Category III transactions on four different transaction attributes are used as candidate basic features. The total number of candidate basic features is the product of the number of transaction categories, the number of transaction attributes, and the number of statistical features, which is 72 in total. Among them, the four different transaction attributes are transaction timestamp, transaction amount, amount of gas consumed by the transaction, and gasPrice (the amount of ether paid per unit of gas); the six different statistical features are sum, maximum, minimum, average, standard deviation, and entropy.

[0027] Obtain the Pearson coefficient between any two candidate basic features. For candidate basic feature combinations whose Pearson coefficient is greater than the set threshold, only one of them is randomly selected and retained as the node feature. For candidate basic feature combinations whose Pearson coefficient is less than the set threshold, both candidate basic features are retained as node features.

[0028] Furthermore, the transaction timestamp of any transaction information is encoded and converted through the cosine function as follows:

[0029] tp m =(cos(ω1(tt m )+b1),cos(ω2(tt m )+b2),…,cos(ω d (tt m )+b d ))

[0030] Among them, tp m is the transaction timestamp of the mth transaction information after encoding, t m is the transaction timestamp of the mth transaction information, ω1,ω2,…,ω d and b1,b2,…,b d are the d-dimensional period and d-dimensional phase of the cosine function, respectively, and d is a set constant.

[0031] Beneficial effects:

[0032] 1. The present invention provides a blockchain gambling risk identification method based on a time graph attention mechanism. First, the statistical features of each Pearson coefficient of the account to be tested that are all less than a set threshold are obtained as node features. Then, time coding technology is used to encode and convert the timing information of the transaction, thereby capturing the transaction evolution process and periodic laws between accounts and obtaining the transaction features of the account. The present invention integrates the node features and transaction features, and uses the attention mechanism to adjust the learning focus according to each node feature and transaction feature and their relative importance in the entire network. Finally, the aggregated feature matrix is input into the MLP model to automatically identify whether the account to be tested has gambling risks, thereby improving the accuracy and efficiency of gambling risk identification.

[0033] 2. The present invention provides a blockchain gambling risk identification method based on a time graph attention mechanism. For the target node, a time-series transaction graph is extracted, and the basic feature information of the node is obtained by extracting multi-dimensional manual features and screening the Pearson coefficient. Then, for the transaction sequence of the target node, the time information is encoded by introducing a time function and spliced with the transaction features and account features as the input data of the attention mechanism model. Finally, an attention model and an MLP model are obtained for identifying whether an account has gambling risks, thereby solving the problem that traditional solutions are insufficient in identifying gambling fraud risks.

[0034] 3. The present invention provides a blockchain gambling risk identification method based on a time graph attention mechanism. The method uses the Pearson coefficient technical analysis to evaluate and screen feature information. Given the excessive number of extracted transaction features, and the observation that features extracted for a single transaction attribute have a stronger correlation with each other than features across attributes, the present invention calculates the Pearson correlation coefficient between each statistical feature based on four attributes to analyze the feature relationship within each transaction attribute, thereby screening out appropriate statistical features as node features, thereby improving model efficiency while ensuring model accuracy.

[0035] 4. The present invention provides a blockchain gambling risk identification method based on a time graph attention mechanism. For any transaction in a transaction sequence graph, the time cosine function is used to map the timestamp of each transaction to a multi-dimensional space, so as to effectively capture the time information and periodicity of node-related transactions, thereby increasing the model's sensitivity to transaction time information. At the same time, the present invention combines node feature information, time coding information, and transaction feature information, and uses the attention mechanism to train them, thereby capturing important transaction information. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] Figure 1 A flowchart of a blockchain gambling risk identification method based on a time graph attention mechanism provided by the present invention;

[0037] Figure 2 The present invention provides a system framework for a blockchain gambling risk identification method based on a time graph attention mechanism;

[0038] Figure 3 This is the basic feature screening process provided by the present invention. DETAILED DESCRIPTION

[0039] In order to enable people skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application.

[0040] In order to address the shortcomings of traditional solutions in identifying gambling fraud risks, the present invention extracts the time-series transaction graph for the target node, and obtains the basic feature information of the node by extracting multi-dimensional manual features and screening the Pearson coefficient; finally, for the transaction sequence of the target node, the time information is encoded by introducing a time function, and spliced with the transaction features and account features as the input data of the attention mechanism model.

[0041] Specifically, such as Figure 1 As shown in FIG, a blockchain gambling risk identification method based on a time graph attention mechanism includes the following steps:

[0042] S1: Perform node feature acquisition operations on neighboring accounts that have transacted with the tested account to obtain node features of each neighboring account. The node feature acquisition operation is as follows:

[0043] All transaction information since the current neighbor account was registered is divided into three categories: Category I transactions where the current neighbor account is only the receiver, Category II transactions where the current neighbor account is only the sender, and Category III transactions where the current neighbor account is both the receiver and the sender.

[0044] The average amount, total amount, standard deviation of amount, entropy of amount, average timestamp, sum of timestamps, standard deviation of timestamp, entropy of timestamp, average gas, sum of gas, standard deviation of gas, entropy of gas, average gasPrice, maximum gasPrice, and sum of gasPrice of category I transactions; the maximum amount, entropy of amount, average timestamp, maximum timestamp, entropy of timestamp, average gas, minimum gas, maximum gas, sum of gas, entropy of gas, average gasPrice, maximum gasPrice, and sum of gasPrice of category II transactions; the total amount, maximum gas, entropy of gasPrice, and minimum gasPrice of category III transactions are used as node features.

[0045] Among them, the Pearson coefficient between any two features in the node features is less than the set threshold;

[0046] It should be noted that the node feature screening method is:

[0047] The six different statistical features of Category I, Category II, and Category III transactions on four different transaction attributes are used as candidate basic features. The total number of candidate basic features is the product of the number of transaction categories, the number of transaction attributes, and the number of statistical features, which is 72 in total. Among them, the four different transaction attributes are transaction timestamp, transaction amount, amount of gas consumed by the transaction, and gasPrice (the amount of ether paid per unit of gas); the six different statistical features are sum, maximum, minimum, average, standard deviation, and entropy.

[0048] That is to say, for the above three categories, a set of functions F are defined to carefully calculate and analyze the characteristic values of each of the four attributes: transaction time, stamp value, gas, and gas Price.

[0049] F in (x)={sum(x),max(x),min(x),mean(x),std(x),ent(x)}

[0050] F out (x)={sum(x),max(x),min(x),mean(x),std(x),ent(x)}

[0051] F all (x)={sum(x),max(x),min(x),mean(x),std(x),ent(x)}

[0052] Among them, F in (x), F out (x), F all (x) represents the F-function corresponding to Class I transactions, Class II transactions, and Class III transactions, respectively; sum(x) represents the sum, max(x) represents the maximum value, min(x) represents the minimum value, mean(x) represents the mean value, std(x) represents the standard deviation, and ent(x) represents the entropy.

[0053] Obtain the Pearson coefficient between any two candidate basic features. For candidate basic feature combinations whose Pearson coefficient is greater than the set threshold, only one of them is randomly selected and retained as the node feature. For candidate basic feature combinations whose Pearson coefficient is less than the set threshold, both candidate basic features are retained as node features.

[0054] In other words, the present invention uses the Pearson coefficient to quantitatively analyze the extracted transaction features, revealing the potential interactions or dependencies between different transaction attributes. This step plots four Pearson correlation coefficient graphs based on the four attributes to analyze the characteristic relationships within each transaction attribute. The correlation coefficient threshold is set at 0.7. If the correlation coefficient exceeds 0.7, redundancy is considered, and only one feature is retained to improve the generalization ability of the subsequent model. In other words, the present invention retains 32 node feature information from the 72 node feature information. The resulting node features after screening are shown in Table 1.

[0055] Table 1

[0056] Feature Name Feature Description Feature Name Feature Description avg_w_in Average transaction amount received std_gas_in Standard deviation of transaction gas received sum_w_in The total value of the transaction amount received ent_gas_in Receive transaction gas entropy std_w_in Standard deviation of transaction amounts received avg_gas_out Average gas cost of sending transactions ent_w_in Entropy of the received transaction amount min_gas_out Minimum gas value for sending transactions max_w_out Maximum transaction amount to be sent max_gas_out The maximum gas value for sending transactions ent_w_out Entropy of the transaction amount sent sum_gas_out The total amount of gas for sending transactions sum_w_all The total amount of all transactions ent_gas_out Entropy of sending transaction gas avg_t_in Average of the timestamps of received transactions max_gas_all The maximum gas value for all transactions sum_t_in Accept the sum of transaction timestamps avg_gasPrice_in Average gasPrice of receiving transactions std_t_in Standard deviation of transaction timestamps accepted max_gasPrice_in The maximum gasPrice of the receiving transaction ent_t_in Accepts entropy of transaction timestamps sum_gasPrice_in The sum of gasPrices of receiving transactions avg_t_out The average value of the transaction timestamp avg_gasPrice_out Average gasPrice of sending transactions max_t_out The maximum value of the transaction timestamp max_gasPrice_out The maximum gasPrice of a sending transaction ent_t_out Entropy of the sent transaction timestamp sum_gasPrice_out The sum of the gasPrices of sending transactions avg_gas_in Average gas cost of receiving transactions ent_gasPrice_all Entropy of all transaction gasPrices sum_gas_in The total amount of gas for receiving transactions min_gasPrice_all The minimum gasPrice of all transactions

[0057] S2: The transaction timestamps of each transaction information of the account to be tested are encoded and converted using the cosine function. Then, the converted transaction timestamps, transaction amounts, gas consumed by the transaction, gasPrice (the amount of ether paid per unit of gas), and transaction direction flags of each transaction information of the account to be tested are concatenated in ascending order of timestamps to form transaction features. Among them, the transaction direction flag of the transaction information of the account to be tested as the receiver is 1, and the transaction direction flag of the transaction information of the account to be tested as the receiver is 0;

[0058] Furthermore, the transaction timestamp of any transaction information is encoded and converted through the cosine function as follows:

[0059] tp m =(cos(ω1(tt m )+b1),cos(ω2(tt m )+b2),…,cos(ω d (tt m )+b d ))

[0060] Among them, tp m is the transaction timestamp of the mth transaction information after encoding, t m is the transaction timestamp of the mth transaction information, ω1,ω2,…,ω d and b1,b2,…,b d are the d-dimensional period and d-dimensional phase of the cosine function, respectively, and d is a set constant.

[0061] S3: Concatenate the node features of each neighboring account of the account to be tested and the transaction features of the account to be tested to obtain the input feature matrix;

[0062] S4: Input the input features into the trained attention model for feature fusion to obtain the aggregated feature matrix;

[0063] S5: Input the aggregated feature matrix into the trained MLP model to obtain the result of whether the account to be tested has gambling risks, so as to identify the difference between gambling accounts and normal accounts.

[0064] like Figure 2 As shown in Figure 2, the joint training method of the attention model and the MLP model is:

[0065] Step 1: Obtain the Ethereum transaction containing the sending address, receiving address, transaction timestamp, transaction amount, the amount of gas consumed by the transaction, and the amount of Ether paid per unit of gas (gasPrice) on the Ethereum network, and construct the Ethereum multilateral transaction directed graph G;

[0066] It should be noted that the present invention constructs a sequential transaction graph based on Ethereum's transaction information, thereby forming a sequential transaction network. Specifically, the present invention obtains transaction data from Ethereum's official website etherscan. The transaction includes twelve attributes: hash block address (TxHash), hash block height (BlockHeight), transaction timestamp (TimeStamp), transaction sending node (From), transaction receiving node (To), transaction amount (Value), transaction gas consumption (gas), amount of ether paid per unit of gas (gasPrice), transaction contract address (ContractAddress), output (Input) and whether the transaction is wrong (isError). Only six attributes are retained: transaction sending node (From), transaction receiving node (To), transaction amount (Value) and transaction timestamp (TimeStamp), transaction gas consumption (gas) and amount of ether paid per unit of gas (gasPrice).

[0067] Step 2: Select addresses marked with gambling risk labels and an equal number of addresses not marked with gambling risk labels from the Ethereum multilateral transaction directed graph G as target nodes; each address corresponds to an account;

[0068] Because Ethereum's transaction data is too large, this paper selects only 2,000 gambling addresses and 2,000 non-gambling addresses as central nodes to build a small-scale transaction network. The central node is used as the target node. If the sending address or receiving address of a transaction is the target node, all relevant transaction data is captured to construct a large-scale Ethereum multilateral transaction directed graph G.

[0069] For any target node k∈G, the temporal transaction network graph g is extracted k =(V k ,E k ,X k ,Ck ), and finally created the time series transaction network dataset D G Specifically, if the sending address or receiving address of the transaction is the target node and the transaction amount is not zero, the transaction is added to the transaction sequence diagram. Finally, the transaction information is sorted in descending order according to the timestamp to construct the transaction sequence diagram of the target node. k , N k is the set of neighbor nodes of node k, X k is the feature set of neighbor nodes. Due to the anonymity of Ethereum, the node itself does not have any attributes, so this section selects the basic feature information after screening as the node feature. k is the transaction set related to node k, C k is their corresponding transaction feature set.

[0070] Step 3: Obtain all transactions of the account corresponding to each target node since registration, and sort all transactions of each target node in ascending order according to timestamps to obtain the transaction sequence diagram of each target node;

[0071] Step 4: Take each target node as the current target node and perform the input feature matrix acquisition operation to obtain the input feature matrix corresponding to each target node, where Figure 3 As shown, the input feature matrix acquisition operation is:

[0072] Perform node feature acquisition operations on the neighboring accounts corresponding to the neighboring nodes that have been traded with the account corresponding to the current target node, and obtain the node features of each neighboring account; that is, for the above transaction sequence network diagram g k , the present invention extracts three main categories of feature information; first, the feature information of all target nodes as sending nodes is obtained, and their respective feature values are calculated based on the four attributes of transaction timestamp, transaction amount, gas required for transaction, and gasPrice; then, the feature information of all target nodes as receiving nodes is obtained in the same way; finally, the feature information of all target nodes that are both receiving nodes and sending nodes is obtained in the same way.

[0073] The transaction timestamps of each transaction information of the account corresponding to the current target node are encoded and converted using the cosine function. Then, the converted transaction timestamps, transaction amounts, gas consumed, gasPrice (the amount of ether paid per unit of gas), and transaction direction flags of each transaction information of the account corresponding to the current target node are concatenated in ascending order of timestamps to form transaction features.

[0074] The node features of each neighbor account corresponding to the current target node and the transaction features of the account corresponding to the current target node are concatenated to obtain the input feature matrix corresponding to the current target node;

[0075] For example, for the time series transaction network graph g k First, the transaction information E is sorted according to the timestamp information k Sort in ascending order and create a position index numbered from 0 to M. Then set X k and C k Finally, in order to distinguish whether the transaction direction is a receiving transaction or a sending transaction, this section assigns a constant value to represent it: if it is a receiving transaction, the constant value is 1; if it is a sending transaction, the constant value is 0. Assume that the mth sending transaction (k,u) of the target node k can be represented as:

[0076] h m (k) = E[h u ||h ku ||d m ]

[0077] Among them, h m (k) represents node v k The feature representation of the mth transaction obtained through embedding learning. h u is the characteristic information of neighbor node u, h ku is the characteristic information of the transaction, and d m is the direction information of the transaction. E is the embedding function, which is used to transform the input fusion features into feature information that is easier for the model to process.

[0078] After obtaining the representation of each transaction, the feature matrix H(k) of node k is formed by stacking:

[0079] H(k)={h0(k),h1(k),…,h M (k)}

[0080] A time function is used to convert E k The timestamp of each transaction in E is mapped to a multi-dimensional space, making the model more sensitive to the time information of the transaction. Specifically, for the target node k, E k The timestamp information of the first transaction is recorded as t, and the timestamp information of the mth transaction is recorded as t m , then convert these timestamps using the following time encoding function:

[0081] tp m (k)=(cos(ω1(tt m )+b1),cos(ω2(tt m )+b2),…,cos(ωd (tt m )+b d ))

[0082] where ω1,ω2,…,ω d and b1,b2,…,b d By adjusting these parameters, each dimension can represent transactions at different time intervals with different periods and phases, thus providing a unique vector representation for each time difference.

[0083] After obtaining the time representation of each transaction, the time feature matrix TP(k) of node k is formed by stacking:

[0084] TP(k)={tp0(k),tp1(k),…,tp M (k)}

[0085] The transaction feature H(k) is precisely concatenated with the position code TP(k) to obtain new input feature information. In this way, the model not only captures the basic characteristics of each transaction, but also understands the relative position of each transaction in the entire sequence:

[0086] X emb (k)=H(k)+TP(k)

[0087] ={x0(k),x1(k),…,x M (k)}

[0088] ={tp0(k)||h0(k),tp1(k)||h1(k),…,tp M (k)||h M (k)}

[0089] It can be seen that the method for obtaining the input feature matrix of the present invention can be summarized as follows:

[0090] For the time-series transaction network diagram, the transaction information is first sorted in ascending order according to the timestamp information, and a position index is created for numbering. Then, the node features and transaction features are binned. At the same time, in order to distinguish whether the transaction direction is a receiving transaction or a sending transaction, the transaction feature is also assigned a constant value to represent it: if it is a receiving transaction, the constant value is 1; if it is a sending transaction, the constant value is 0. The features of the neighboring nodes and the transaction features themselves are spliced to obtain a fused feature representation.

[0091] Step 5: Input the input feature matrix corresponding to each target node into the attention model for feature fusion to obtain the aggregated feature matrix corresponding to each target node;

[0092] The attention feature extraction stage of the gambling account recognition model consists of two key submodules: a multi-head attention module and a feedforward neural network. These two submodules are combined and stacked into multiple layers. The output of each layer immediately becomes the input for the next layer, ensuring the continuous flow and in-depth processing of information within the model.

[0093] For each layer’s input feature information, different weight matrices are used: query matrix, key matrix, and value matrix to transform it into a new embedded feature representation. Then the output features of the self-attention layer are concatenated with the original features and the results are normalized. Specifically, assuming that the input features of layer l are The formula for the attention step is expressed as follows:

[0094] The input data Through the different weight matrices of layer l is converted into a new embedding representation. Then the layer normalization is applied to convert the output of the self-attention layer Original input embedding Directly add them together, and then perform layer normalization on the result. The specific formula is as follows:

[0095]

[0096] Next comes the operation of the feedforward neural network. For the input feature information of each layer, this sublayer applies the same transformation independently to each position, which can be regarded as an independent neural network that processes each element in the sequence one by one. Specifically, this step performs two linear transformations. The first is to multiply the output information of the self-attention layer by the weight matrix and add a bias vector, and then process the result with a nonlinear activation function. The second time is to multiply the result of the first step by the weight matrix again and add a bias vector. The specific formula is as follows:

[0097]

[0098] Among them, GELU represents a linear function, and is the weight matrix in the network, and is the bias vector.

[0099] After the calculation, normalization is also used. The specific formula is as follows:

[0100]

[0101] Step 6: Input the aggregate feature matrix corresponding to each target node into the MLP model to obtain the gambling risk prediction value corresponding to each target node;

[0102] Step 7: Construct a loss function using the gambling risk prediction value corresponding to each target node and the gambling risk label corresponding to each target node, and determine whether the loss function is less than the set value. If yes, obtain the trained attention model and MLP model. If not, proceed to step 8.

[0103] Step 8: Adjust the model parameters of the attention model and the MLP model, and re-execute steps 5 to 7 until the loss function is less than the set value.

[0104] It can be seen from this that the present invention has the following advantages:

[0105] (1) The gambling fraud risk identification scheme GTGAM based on the time graph attention mechanism proposed in this paper adopts time coding technology to learn the timing information of transactions, which can capture the transaction evolution process between accounts and the periodic laws of transactions.

[0106] (2) The present invention integrates time coding information, transaction coding information and account coding information, and uses the attention mechanism to adjust the learning focus according to the characteristics of each node and transaction and their relative importance in the entire network.

[0107] Of course, the present invention may have many other embodiments. Without departing from the spirit and essence of the present invention, those skilled in the art may of course make various corresponding changes and modifications based on the present invention, but these corresponding changes and modifications should all fall within the scope of protection of the claims attached to the present invention.

Claims

1. A blockchain gambling risk identification method based on a time graph attention mechanism, characterized in that: The following steps are involved: S1: Perform node feature acquisition operations on neighboring accounts that have transacted with the tested account to obtain node features of each neighboring account. The node feature acquisition operation is as follows: All transaction information since the current neighbor account was registered is divided into three categories: Category I transactions where the current neighbor account is only the receiver, Category II transactions where the current neighbor account is only the sender, and Category III transactions where the current neighbor account is both the receiver and the sender. The average amount, total amount, standard deviation of amount, entropy of amount, average timestamp, sum of timestamps, standard deviation of timestamp, entropy of timestamps, average gas, sum of gas, standard deviation of gas, entropy of gas, average gasPrice, maximum gasPrice, and sum of gasPrice of Category I transactions; the maximum amount, entropy of amount, average timestamp, maximum timestamp, entropy of timestamp, average gas, minimum gas, maximum gas, sum of gas, entropy of gas, average gasPrice, maximum gasPrice, and sum of gasPrice of Category II transactions; the total amount, maximum gas, entropy of gasPrice, and minimum gasPrice of Category III transactions are used as node features. The Pearson coefficient between any two features in the node features is less than the set threshold. S2: The transaction timestamps of each transaction information of the account to be tested are encoded and converted using the cosine function. Then, the converted transaction timestamps, transaction amounts, gas consumed by the transaction, gasPrice (the amount of ether paid per unit of gas), and transaction direction flags of each transaction information of the account to be tested are concatenated in ascending order of timestamps to form transaction features. Among them, the transaction direction flag of the transaction information of the account to be tested as the receiver is 1, and the transaction direction flag of the transaction information of the account to be tested as the receiver is 0; S3: Concatenate the node features of each neighboring account of the account to be tested and the transaction features of the account to be tested to obtain the input feature matrix; S4: Input the input features into the trained attention model for feature fusion to obtain the aggregated feature matrix; S5: Input the aggregated feature matrix into the trained MLP model to obtain the result of whether the account to be tested has gambling risk.

2. A blockchain gambling risk identification method based on a time graph attention mechanism as claimed in claim 1, characterized in that: The joint training method of the attention model and the MLP model is: Step 1: Obtain the Ethereum transaction containing the sending address, receiving address, transaction timestamp, transaction amount, the amount of gas consumed by the transaction, and the amount of Ether paid per unit of gas (gasPrice) on the Ethereum network, and construct the Ethereum multilateral transaction directed graph G; Step 2: Select addresses marked with gambling risk labels and an equal number of addresses not marked with gambling risk labels from the Ethereum multilateral transaction directed graph G as target nodes; each address corresponds to an account; Step 3: Obtain all transactions of the account corresponding to each target node since registration, and sort all transactions of each target node in ascending order according to timestamps to obtain the transaction sequence diagram of each target node; Step 4: Take each target node as the current target node and perform the input feature matrix acquisition operation to obtain the input feature matrix corresponding to each target node. The input feature matrix acquisition operation is: Perform node feature acquisition operations on the neighboring accounts corresponding to the neighboring nodes that have traded with the account corresponding to the current target node, and obtain the node features of each neighboring account; The transaction timestamps of each transaction information of the account corresponding to the current target node are encoded and converted using the cosine function. Then, the converted transaction timestamps, transaction amounts, gas consumed, gasPrice (the amount of ether paid per unit of gas), and transaction direction flags of each transaction information of the account corresponding to the current target node are concatenated in ascending order of timestamps to form transaction features. The node features of each neighbor account corresponding to the current target node and the transaction features of the account corresponding to the current target node are concatenated to obtain the input feature matrix corresponding to the current target node; Step 5: Input the input feature matrix corresponding to each target node into the attention model for feature fusion to obtain the aggregated feature matrix corresponding to each target node; Step 6: Input the aggregate feature matrix corresponding to each target node into the MLP model to obtain the gambling risk prediction value corresponding to each target node; Step 7: Construct a loss function using the gambling risk prediction value corresponding to each target node and the gambling risk label corresponding to each target node, and determine whether the loss function is less than the set value. If yes, obtain the trained attention model and MLP model. If not, proceed to step 8. Step 8: Adjust the model parameters of the attention model and the MLP model, and re-execute steps 5 to 7 until the loss function is less than the set value.

3. A blockchain gambling risk identification method based on a time graph attention mechanism as claimed in claim 1, characterized in that: The node feature screening method is: The six different statistical features of Category I, Category II, and Category III transactions on four different transaction attributes are used as candidate basic features. The total number of candidate basic features is the product of the number of transaction categories, the number of transaction attributes, and the number of statistical features, which is 72 in total. Among them, the four different transaction attributes are transaction timestamp, transaction amount, amount of gas consumed by the transaction, and gasPrice (the amount of ether paid per unit of gas); the six different statistical features are sum, maximum, minimum, average, standard deviation, and entropy. Obtain the Pearson coefficient between any two candidate basic features. For candidate basic feature combinations whose Pearson coefficient is greater than the set threshold, only one of them is randomly selected and retained as the node feature. For candidate basic feature combinations whose Pearson coefficient is less than the set threshold, both candidate basic features are retained as node features.

4. A blockchain gambling risk identification method based on a time graph attention mechanism as claimed in claim 1, characterized in that: The transaction timestamp of any transaction information is encoded and converted through the cosine function as follows: tp m =(cos(ω1(t-t m )+b1),cos(ω2(t-t m )+b2),…,cos(ω d (t-t m )+b d )) Among them, tp m is the transaction timestamp of the mth transaction information after encoding, t m is the transaction timestamp of the mth transaction information, ω1, ω2, ..., ω d and b1, b2, ..., b d are the d-dimensional period and d-dimensional phase of the cosine function, respectively, and d is a set constant.