Cryptocurrency money laundering transaction detection method, device and equipment, medium and product

By constructing a directed weighted graph and using traffic analysis and community detection to extract suspicious subgraphs, combined with the GraphSAGE model, the problem of insufficient accuracy and detection rate of cryptocurrency money laundering transaction detection in the existing technology is solved, and more efficient transaction detection is achieved.

CN120509961APending Publication Date: 2025-08-19BEIJING UNIV OF CHEM TECH +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510522979.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-24
Publication Date
2025-08-19

AI Technical Summary

Technical Problem

The existing cryptocurrency money laundering transaction detection methods have insufficient detection rate and accuracy of illegal transactions and cannot meet regulatory needs.

Method used

By constructing a directed weighted graph, suspicious subgraphs are extracted from it using traffic analysis and community detection, and node features are represented as splicing formats of transaction features and address features, and input them into the cryptocurrency money laundering transaction detection model based on the GraphSAGE model for analysis.

Benefits of technology

It improves the detection rate of illegal transactions and the accuracy of cryptocurrency money laundering transaction detection to meet regulatory needs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120509961A_ABST
    Figure CN120509961A_ABST
Patent Text Reader

Abstract

The invention provides a cryptocurrency money laundering transaction detection method and device, equipment, a medium and a product, and the method comprises the steps: constructing a directed weighted graph according to transaction data to be detected; extracting suspicious sub-graphs from the directed weighted graph through flow analysis and community detection; for each node in the suspicious sub-graph, forming a feature representation of the node; inputting the feature representations of all the nodes and the suspicious sub-graphs into a cryptocurrency money laundering transaction detection model to obtain a cryptocurrency money laundering transaction detection result output by the cryptocurrency money laundering transaction detection model; wherein the cryptocurrency money laundering transaction detection result comprises an illegal transaction behavior or a legal transaction behavior; the cryptocurrency money laundering transaction detection model is pre-constructed based on a GraphSAGE model and is obtained through training. According to the scheme, the detection rate of illegal transactions and the accuracy of cryptocurrency money laundering transaction detection are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security and financial crime detection technology, and in particular to a method, device, equipment, medium and product for detecting cryptocurrency money laundering transactions. Background Art

[0002] In recent years, digital cryptocurrencies have rapidly gained popularity worldwide thanks to their advantages, including fast peer-to-peer transactions, low costs, high transparency, strong security, and immutability. However, due to their decentralized and anonymous nature, Bitcoin and other cryptocurrencies are also widely used for illegal activities such as money laundering, dark web transactions, and ransomware attacks, posing a serious threat to financial security and social stability.

[0003] To curb the abuse of cryptocurrencies in illegal financial activities, governments and financial regulators have stepped up transaction monitoring, promoted the implementation of Anti-Money Laundering (AML) and Know Your Customer (KYC) regulations, and widely applied blockchain analysis, transaction monitoring, and risk assessment technologies to track and identify suspicious transactions, curb illegal capital flows, and maintain the security and stability of the financial system.

[0004] Existing methods for detecting cryptocurrency money laundering transactions fall into four main categories. 1) Rule-based methods rely on pre-set rules, typically combining historical transaction data, social networks, laws and regulations, and expert knowledge to formulate detection strategies. These methods are primarily suitable for large financial institutions but are less applicable to transactions by ordinary users. 2) Machine learning-based methods extract rich transaction features and combine them with common machine learning classification algorithms, such as support vector machines (SVMs), random forests (RFs), and eXtreme Gradient Boosting (XGBoost), to identify illegal transactions. However, these methods typically focus only on suspicious features of individual transactions and struggle to effectively extract and utilize structural information at the transaction network level, resulting in limitations in detection efficiency. 3) Graph-based methods model transaction relationships as graphs and employ deep learning models, such as graph convolutional networks (GCNs) and graph attention networks (GATs), to aggregate node information and capture contextual dependencies. However, due to the heterogeneity of transaction networks, these methods often introduce significant noise, diluting key features and thus affecting classification accuracy. 4) Network analysis-based methods focus on global or local analysis of transaction networks (such as network metrics, subgraph patterns, and path analysis) to extract important structural features for illegal transaction detection. However, accurately capturing and interpreting this network structure information remains a major challenge.

[0005] However, with the increasing sophistication of illicit account disguise methods, local information from a single transaction is no longer sufficient to effectively identify anomalous behavior. Analysis must rely on the global structure of the transaction network. However, due to the sparsity and heterogeneity of the Bitcoin network, existing money laundering detection methods struggle to extract key transaction network structures from the vast volume of legitimate transactions, resulting in a low detection rate for illegal transactions and failing to meet regulatory requirements.

[0006] It can be seen from this that the existing solutions have poor detection rates for illegal transactions and poor accuracy in detecting cryptocurrency money laundering transactions, and cannot meet regulatory requirements. Summary of the Invention

[0007] The present invention provides a method, device, equipment, medium and product for detecting cryptocurrency money laundering transactions, which are used to address the defects of the existing technology in that the detection rate of illegal transactions and the accuracy of cryptocurrency money laundering transaction detection are poor and cannot meet regulatory requirements, and realize efficient and accurate cryptocurrency money laundering transaction detection.

[0008] The present invention provides a method for detecting cryptocurrency money laundering transactions, comprising: Constructing a directed weighted graph based on the transaction data to be detected; wherein the nodes in the directed weighted graph include multiple address nodes and multiple transaction nodes, each transaction node representing a transaction; the edges in the directed weighted graph represent the flow of funds between the address nodes, and the weights of the edges represent the amount of the fund flow; Extracting suspicious subgraphs from the directed weighted graph through traffic analysis and community detection; For each node in the suspicious subgraph, a feature representation corresponding to the node is formed, where the feature representation is a concatenation of transaction features and address features; The feature representations of all nodes in the suspicious subgraph and the suspicious subgraph are input into a cryptocurrency money laundering transaction detection model to obtain a cryptocurrency money laundering transaction detection result output by the cryptocurrency money laundering transaction detection model; wherein the cryptocurrency money laundering transaction detection result includes: illegal transaction behavior or legal transaction behavior; the cryptocurrency money laundering transaction detection model is pre-built based on the GraphSAGE model and obtained through training.

[0009] According to a cryptocurrency money laundering transaction detection method provided by the present invention, extracting a suspicious subgraph from the directed weighted graph through traffic analysis and community detection includes: Select at least one target address node from the plurality of address nodes; For each target address node, apply the Dinic algorithm to calculate the maximum flow from the target address node to each transaction address node; wherein the transaction address node is an address node other than the target address node among the multiple address nodes that has a direct or indirect transaction with the target address node; Eliminating transaction address nodes whose maximum traffic in the directed weighted graph is lower than a preset traffic threshold, to obtain an updated directed weighted graph; Applying the Louvain algorithm to perform community detection on the updated directed weighted graph to identify community structures with dense capital flows and obtain multiple communities; Calculate the sum of the maximum traffic from the target address node to all transaction address nodes in each community to obtain the total traffic corresponding to each community; From the multiple communities, a community with the largest total traffic volume is selected as a suspicious subgraph.

[0010] According to a cryptocurrency money laundering transaction detection method provided by the present invention, for each target address node, applying the Dinic algorithm to calculate the maximum flow from the target address node to each transaction address node includes: For each target address node, use the target address node as the source node, and use each transaction address node as the sink node; Setting the flow between the source node and the sink node to 0; For each edge in the directed weighted graph, the residual capacity of the edge is set to the original capacity of the edge, and an adjacency list storage network is constructed; Calculate the shortest path hierarchy from the source node by a breadth-first search algorithm, and construct a hierarchical graph based on the shortest path hierarchy; Using a depth-first search algorithm, in the hierarchical graph, starting from the source node, searching for an augmenting path; Traversing each edge in the augmenting path, calculating the minimum residual capacity of the augmenting path, and obtaining the flow increment; Based on the flow increment, updating the flow between the source node and the sink node and the residual capacity of each edge in the directed weighted graph along the augmented path; If no augmenting path can be found in the current hierarchical graph, the process returns to the step of calculating the shortest path hierarchy from the source node through the breadth-first search algorithm, and constructing a hierarchical graph based on the shortest path hierarchy; otherwise, the current flow between the source node and the sink node is used as the maximum flow from the target address node to the transaction address node.

[0011] According to a cryptocurrency money laundering transaction detection method provided by the present invention, the Louvain algorithm is applied to perform community detection on the updated directed weighted graph to identify community structures with dense capital flows, and multiple communities are obtained, including: Initializing each address node in the updated directed weighted graph as an independent community to obtain multiple initial communities; Based on the adjacency table storage network, the modularity gain after each address node is moved to the community where its neighbor address node is located is calculated; For each address node, if the modularity gain is greater than a preset gain threshold, the address node is moved to the community where the neighboring address node is located, to obtain multiple updated communities; Treating each updated community as an address node, constructing a new directed weighted graph, and returning to execute the step of initially treating each address node in the updated directed weighted graph as an independent community to obtain the initial multiple communities, until the modularity gain is no greater than a preset gain threshold.

[0012] According to a cryptocurrency money laundering transaction detection method provided by the present invention, for each node in a suspicious subgraph, forming a feature representation corresponding to the node includes: For transaction nodes in the suspicious subgraph, the transaction features corresponding to the transaction nodes are extracted and normalized; the address features corresponding to the transaction nodes are constructed with all values being 0; the transaction features and address features corresponding to the transaction nodes are concatenated to obtain the feature representation corresponding to the transaction nodes; For the address nodes in the suspicious subgraph, the address features corresponding to the address nodes are extracted and normalized; the transaction features corresponding to the address nodes with all values being 0 are constructed; the transaction features and address features corresponding to the address nodes are concatenated to obtain the feature representation corresponding to the address nodes.

[0013] According to a cryptocurrency money laundering transaction detection method provided by the present invention, before constructing a directed weighted graph based on the transaction data to be detected, the method further includes: Constructing a dataset and dividing the dataset into a training set, a validation set, and a test set; the training set includes: multiple suspicious subgraphs and a reference cryptocurrency money laundering transaction detection result corresponding to each suspicious subgraph; Build an initial cryptocurrency money laundering transaction detection model based on the GraphSAGE model; Based on the training set, the validation set, and the test set, the initial cryptocurrency money laundering transaction detection model is trained to obtain the cryptocurrency money laundering transaction detection model.

[0014] The present invention also provides a cryptocurrency money laundering transaction detection system, comprising the following modules: A construction module is configured to construct a directed weighted graph based on the transaction data to be detected; wherein the nodes in the directed weighted graph include multiple address nodes and multiple transaction nodes, each transaction node representing a transaction; the edges in the directed weighted graph represent the flow of funds between the address nodes, and the weights of the edges represent the amount of the fund flow; An extraction module, configured to extract suspicious subgraphs from the directed weighted graph through traffic analysis and community detection; A splicing module, configured to generate a feature representation corresponding to each node in the suspicious subgraph, wherein the feature representation is a splicing format of transaction features and address features; A processing module is configured to input the feature representations of all nodes in a suspicious subgraph and the suspicious subgraph into a cryptocurrency money laundering transaction detection model to obtain a cryptocurrency money laundering transaction detection result output by the cryptocurrency money laundering transaction detection model; wherein the cryptocurrency money laundering transaction detection result includes: illegal transaction behavior or legal transaction behavior; the cryptocurrency money laundering transaction detection model is pre-built and trained based on the GraphSAGE model.

[0015] The present invention also provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and running on the processor, wherein when the processor executes the computer program, it implements any of the above-described methods for detecting cryptocurrency money laundering transactions.

[0016] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements any of the above-described methods for detecting cryptocurrency money laundering transactions.

[0017] The present invention also provides a computer program product, comprising a computer program, which, when executed by a processor, implements any of the above-described methods for detecting cryptocurrency money laundering transactions.

[0018] The cryptocurrency money laundering transaction detection method, apparatus, device, medium, and product provided by this invention deeply explore valuable financial relationships and community structures through traffic analysis and community detection. Suspicious subgraphs are extracted from directed weighted graphs, effectively retaining key suspicious nodes and important network structures with high financial interaction density with the target address. Furthermore, the cryptocurrency money laundering transaction detection problem is transformed into a suspicious subgraph classification problem. For each node in the suspicious subgraph, a feature representation of the node is generated. The feature representations of all nodes and the suspicious subgraph are input into a cryptocurrency money laundering transaction detection model, and the cryptocurrency money laundering transaction detection model outputs a cryptocurrency money laundering transaction detection result. This solution improves the detection rate of illegal transactions and the accuracy of cryptocurrency money laundering transaction detection. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] In order to more clearly illustrate the technical solutions in the present invention or the prior art, a brief introduction is given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0020] Figure 1 Schematic diagram of the process of detecting cryptocurrency money laundering transactions provided by the present invention.

[0021] Figure 2 It is a schematic diagram of the characteristic representation of the node provided by the present invention.

[0022] Figure 3 Schematic diagram of the cryptocurrency money laundering transaction detection model provided by the present invention.

[0023] Figure 4 It is a structural diagram of the cryptocurrency money laundering transaction detection device provided by the present invention.

[0024] Figure 5 It is a structural schematic diagram of the electronic device provided by the present invention. DETAILED DESCRIPTION

[0025] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the embodiments described are only some of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.

[0026] It should be noted that the brief descriptions of terms in this application are only for the purpose of facilitating the understanding of the embodiments described below, and are not intended to limit the embodiments of this application. Unless otherwise specified, these terms should be understood according to their ordinary and usual meanings.

[0027] In the specification and claims of this application, as well as in the accompanying drawings, the terms "first," "second," and the like are used to distinguish similar or similar objects or entities, and are not necessarily intended to limit a particular order or precedence, unless otherwise indicated. It should be understood that such terms are interchangeable where appropriate, e.g., embodiments of this application can be implemented in an order other than that shown or described in the drawings or descriptions.

[0028] In addition, the terms "including" and "having" and any variations thereof are intended to cover, but not exclude, inclusion. For example, a product or device comprising a list of components is not necessarily limited to those components explicitly listed, but may include other components not explicitly listed or inherent to such products or devices. The term "module" as used in this application refers to any known or later developed hardware, software, firmware, artificial intelligence, fuzzy logic, or combination of hardware and / or software code that is capable of performing the functions associated with the element.

[0029] The following specific embodiments are used to describe in detail the technical solution of the present application and how the technical solution of the present application solves the above technical problems. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. Figure 1-Figure 3 The present invention describes a method for detecting cryptocurrency money laundering transactions.

[0030] Figure 1 This is one of the flow charts of the cryptocurrency money laundering transaction detection method provided by the present invention, such as Figure 1 As shown, the method includes the following: Step 101: Construct a directed weighted graph based on the transaction data to be detected.

[0031] The nodes in the directed weighted graph include multiple address nodes and multiple transaction nodes, each transaction node represents a transaction; the edges in the directed weighted graph represent the flow of funds between address nodes, and the weight of the edge represents the amount of fund flow.

[0032] Step 102: Extract suspicious subgraphs from the directed weighted graph through traffic analysis and community detection.

[0033] Step 103: For each node in the suspicious subgraph, a feature representation corresponding to the node is formed. The feature representation is a concatenation format of transaction features and address features.

[0034] Step 104: Input the feature representations of all nodes and the suspicious subgraphs into the cryptocurrency money laundering transaction detection model to obtain the cryptocurrency money laundering transaction detection results output by the cryptocurrency money laundering transaction detection model.

[0035] Among them, the cryptocurrency money laundering transaction detection results include: illegal transaction behavior or legal transaction behavior; the cryptocurrency money laundering transaction detection model is pre-built based on the GraphSAGE model and obtained through training.

[0036] In practical applications, the execution entity of the cryptocurrency money laundering transaction detection method can be a cryptocurrency money laundering transaction detection device. There are many ways to implement a cryptocurrency money laundering transaction detection device. For example, it can be implemented through a computer program, such as application software, or a chip. It can also be implemented as a medium storing the relevant computer program, such as a USB flash drive or cloud storage device. Alternatively, it can be implemented through a physical device that integrates or installs the relevant computer program, such as a server or smart device.

[0037] In practical applications, the cryptocurrency money laundering transaction detection device acquires the transaction data to be detected in real time. For example, comprehensive and real-time transaction data can be acquired by combining blockchain node data, API calls, crawler technology, user reports, and other methods. Furthermore, a directed weighted graph is constructed based on the transaction data to be detected.

[0038] Specifically, step 101 includes: constructing a directed weighted graph based on the transaction data to be detected.

[0039] The nodes in the directed weighted graph include multiple address nodes and multiple transaction nodes, each transaction node represents a transaction; the edges in the directed weighted graph represent the flow of funds between address nodes, and the weight of the edge represents the amount of fund flow.

[0040] It should be noted that the directed weighted graph constructed in this application is a graph of fund flows originating from labeled address nodes. Labeled address nodes are labeled addresses. The address-transaction graph originating from labeled address nodes is distinct from other transaction graphs originating from labeled transactions. In practical applications, starting from labeled address nodes, the fund flows of multiple transactions paid to an address are tracked to construct a directed weighted graph. This allows for the discovery of connections between multiple funds from the same address node, yielding richer network structure information.

[0041] Optionally, in a possible implementation manner, the above step 101 includes: Determine the label address node, which is the starting address node of the transaction to be detected; Extract multiple transaction records that the tag address node has participated in historically to track the whereabouts of funds sent by the tag address node and construct a transaction path that reflects the flow of funds; The transaction path is represented as a heterogeneous graph constructed by address nodes and transaction nodes, resulting in a directed weighted graph.

[0042] In this example, a directed weighted graph is used to model the graph structure of a cryptocurrency transaction network, known as a fund flow graph, to track the flow of funds from output transactions to a target address. By analyzing the structure and characteristics of the fund flow graph, money laundering in cryptocurrency transactions can be detected.

[0043] For example, based on the transaction data to be detected, a directed weighted graph G is constructed. The directed weighted graph G is a weighted directed address transaction heterogeneous graph, which can be expressed as .in, V Represents a set of nodes in the graph, including two types of nodes: address nodes and transaction nodes ; E Represents the edge set in the graph, including two types of edges: edges from addresses to transactions and the edge of the transaction to the address ; W Represents the weight of the edge, indicating the amount of money the address node participates in a transaction or the amount of money the transaction sends to a certain address node.

[0044] Furthermore, step 102 includes extracting suspicious subgraphs from the directed weighted graph through traffic analysis and community detection.

[0045] A suspicious subgraph refers to a local network structure extracted from a directed weighted graph (the entire transaction network) that is highly suspected of money laundering. This subgraph includes key nodes and their network relationships with a high density of financial interactions with the target address. Extracting a suspicious subgraph from a directed weighted graph effectively identifies key nodes and their network relationships with a high density of financial interactions with the target address, providing a crucial analytical foundation for subsequent money laundering detection and significantly improving detection accuracy and efficiency.

[0046] In light of the above description, a directed weighted graph consists of address nodes and transaction nodes. During transactions, funds flow along specific paths, forming a directed flow network with capacity constraints. In this embodiment, flow analysis involves calculating the maximum flow rate from source nodes to sink nodes in the network, i.e., the maximum amount of tradable funds. It can be understood that by calculating the maximum flow rate from source nodes to sink nodes, the intensity of fund interactions between address nodes can be quantified, thereby identifying high-risk transaction paths, abnormal fund aggregation points, and potential illegal trading activities.

[0047] In this example, community analysis involves optimizing modularity to identify tightly connected groups of nodes within a graph, thereby revealing communities with dense capital flows. Modularity is a measure of the quality of community segmentation; higher modularity indicates stronger internal connections and fewer cross-community connections within the network. By optimizing modularity, community analysis can effectively aggregate addresses with dense capital flows, thereby identifying key transaction paths and potential illegal trading activity.

[0048] For example, traffic analysis can be performed based on the Dinic algorithm to calculate the maximum traffic between the target address node and the transaction address node. Furthermore, transaction address nodes with maximum traffic below a threshold are eliminated. Furthermore, community detection based on the Louvain algorithm is performed to identify multiple communities. Furthermore, the sum of traffic corresponding to each community is calculated, and the community with the largest sum of traffic is identified as a suspicious subgraph.

[0049] Optionally, in a possible implementation, the above step 102 includes: Select at least one target address node from a plurality of address nodes; For each target address node, the Dinic algorithm is applied to calculate the maximum flow from the target address node to each transaction address node. A transaction address node is an address node other than the target address node that has a direct or indirect transaction with the target address node. Eliminate transaction address nodes whose maximum traffic in the directed weighted graph is lower than the preset traffic threshold to obtain an updated directed weighted graph; Apply the Louvain algorithm to perform community detection on the updated directed weighted graph to identify community structures with dense capital flows and obtain multiple communities; Calculate the sum of the maximum traffic from the target address node to all transaction address nodes in each community to obtain the total traffic corresponding to each community; From multiple communities, the community with the largest total traffic volume is selected as the suspicious subgraph.

[0050] In this implementation, selecting multiple target address nodes from multiple address nodes is the first step in the suspicious subgraph extraction process. This step aims to identify the address nodes that require focused analysis, allowing subsequent traffic analysis and community detection to identify suspicious transactions associated with these target address nodes.

[0051] It should be noted that this application does not specifically limit the method for selecting the target address node. In one example, the target address node can be selected based on the transaction characteristics of the address node. For example, an address node with a large transaction amount, a high transaction frequency, or an abnormal transaction pattern is selected as the target address node. In another example, the target address node can be selected based on the risk label of the address node. For example, an address node that has been marked as high-risk or suspicious is selected as the target address node. In another example, the target address node can be selected based on a user report. For example, an address node that has been reported by a user or marked as suspicious by a regulatory agency is selected as the target address node. In another example, the target address node can be randomly sampled. For example, in some cases, a portion of the address nodes can also be randomly selected for analysis as the target address node to evaluate the health of the overall network. In another example, the above-mentioned label address node is used as the target address node.

[0052] Furthermore, for each target address node, the Dinic algorithm is applied to calculate the maximum flow from the target address node to each transaction address node.

[0053] The Dinic algorithm is an efficient graph-theoretic algorithm for solving the maximum flow problem in directed graphs. It gradually increases the flow by constructing a hierarchical graph and augmenting paths until the maximum value is reached.

[0054] In this implementation, the maximum flow between the target address node and the transaction address node is calculated using the Dinic algorithm. Specifically, in a directed weighted graph G The weight of each edge Represents the maximum capacity of the edge. The target address node is regarded as the source node s , and use the transaction address node as the sink node t , calculate from the source node s Arrive tThe maximum flow between.

[0055] Specifically, for the calculation process of the maximum flow, in one example, for each target address node, the Dinic algorithm is applied to calculate the maximum flow from the target address node to each transaction address node, including: For each target address node, use the target address node as the source node and each transaction address node as the sink node; Set the flow between the source node and the sink node to 0; For each edge in the directed weighted graph, the residual capacity of the edge is set to the original capacity of the edge, and an adjacency table storage network is constructed; By using the breadth-first search algorithm, the shortest path hierarchy from the source node is calculated, and a hierarchical graph is constructed based on the shortest path hierarchy; Using the depth-first search algorithm, we search for augmenting paths starting from the source node in the hierarchical graph. Traverse each edge in the augmenting path, calculate the minimum residual capacity of the augmenting path, and obtain the flow increment; Based on the flow increment, the flow between the source node and the sink node along the augmenting path and the residual capacity of each edge in the directed weighted graph are updated; If no augmenting path can be found in the current hierarchical graph, then return to the step of calculating the shortest path hierarchy from the source node through the breadth-first search algorithm, and constructing the hierarchical graph based on the shortest path hierarchy; otherwise, the flow between the current source node and the sink node is used as the maximum flow from the target address node to the transaction address node.

[0056] Specifically, traffic analysis based on the Dinic algorithm can be divided into the following three steps: Step 1: Initialize the residual network.

[0057] Among them, the residual network is used to represent the remaining capacity of the current network in the maximum flow algorithm (such as Dinic algorithm). In the maximum flow algorithm, the residual network is used to support the search of augmenting paths. Through the residual network, the source node can be found. s To the sink node t By initializing the residual network, the maximum flow algorithm can efficiently perform flow calculation and path search, and finally find the path from the source node s To the sink node t Maximum flow rate.

[0058] First, for each target address node, take the target address node as the source node s , and use the transaction address node as the sink node t . The source nodes Sink Node t Traffic between Set to 0, that is, .

[0059] Furthermore, the remaining capacity is defined as , for each edge in the directed weighted graph, the residual capacity of the edge is set to the original capacity of the edge, that is, .

[0060] Furthermore, an adjacency table storage network is constructed. It is understood that the purpose of constructing an adjacency table storage network is to provide efficient data structure support for subsequent traffic analysis and community detection. Specifically, on the one hand, the adjacency table storage network supports fast traffic analysis. When calculating the maximum flow, it is necessary to frequently access a node's neighbor nodes and their edge weights. The adjacency table storage network can quickly provide this information, thereby improving the efficiency of traffic calculation. During traffic updates, the adjacency table storage network supports fast edge weight updates, enabling the algorithm to efficiently perform traffic adjustment and path search. On the other hand, the adjacency table storage network facilitates community detection. Community detection algorithms (such as the Louvain algorithm) require frequent access to a node's neighbor nodes and their connections. The adjacency table storage network can quickly provide this information, thus supporting efficient community detection. Through the adjacency table storage network, the connectivity between nodes can be quickly calculated, thereby optimizing modularity and identifying community structures with dense capital flows.

[0061] Step 2: Construct a hierarchical diagram.

[0062] First, calculate the number of nodes from the source node using the Breadth-First Search (BFS) algorithm. s Starting shortest path level , so that it meets the following conditions: in, Source node s level, For nodes level, From the source node s Starting shortest path level , Represents the source node s The level is 0. Representation node The level is equal to the node The level of the node is increased by 1. v At the node u The next layer. For each edge in the graph All belong to the edge set E . Represents an edge The residual capacity is greater than 0, which means that this edge can still transmit traffic.

[0063] Furthermore, according to the shortest path hierarchy Construct a hierarchical graph. Specifically, construct a hierarchical graph , only retain the edges of the hierarchical relationship so that they meet the following conditions: in, Representation hierarchy diagram By node collection V and edge sets composition. Representation hierarchy diagram The edge set in , which contains all edges that satisfy the following conditions : 、 、 ,in, For each edge in the graph . Represents an edge The residual capacity is greater than 0, which means that this edge can still transmit traffic. Representation node v The level is equal to the node u The level of plus 1, that is v exist u The next layer.

[0064] Step 3: Augmented path search and traffic update.

[0065] When the hierarchy diagram Sink nodes are still included , do the following: First, through the Depth-First Search (DFS) algorithm, in the hierarchical graph, from the source node s Start by finding the augmenting path P , augmenting path P The following conditions must be met: in, Represents a line from the source node s To the sink node t The path contains a series of nodes. Indicates that for the path P Each edge in . Represents an edge The residual capacity is greater than 0, which means that this edge can still transmit traffic.

[0066] Furthermore, traverse the augmenting path P For each edge in , calculate the augmenting path P The minimum residual capacity is obtained to obtain the flow increment : Furthermore, based on the flow increment, along the augmented path P Update source node s Sink Node t Traffic between And the residual capacity of each edge in the directed weighted graph: in, is the flow increment, Represents an edge The residual capacity minus the flow rate increase . Represents an edge The residual capacity increases .

[0067] Furthermore, continue to search for augmenting paths and update the flow until no new augmenting paths can be found. If no augmenting path can be found in the current hierarchical graph, return to the step of calculating the shortest path hierarchy from the source node through the breadth-first search algorithm, and construct the hierarchical graph based on the shortest path hierarchy; otherwise, the flow between the current source node and the sink node is used as the maximum flow from the target address node to the transaction address node, and the maximum flow The calculation is complete.

[0068] It can be understood that the maximum flow reflects the intensity of fund interaction between the target address node and the transaction address node. Low-flow address nodes usually have only weak or occasional fund interaction and contribute little to the analysis. Furthermore, in order to effectively remove irrelevant or noise nodes, the maximum flow in the directed weighted graph is removed. The transaction address nodes with a traffic flow below the preset threshold F are used to obtain the updated directed weighted graph. In practice, the traffic flow threshold F can be adaptively adjusted according to the specific network environment and experimental scenario to ensure the reliability and accuracy of the analysis results.

[0069] Furthermore, the Louvain algorithm is applied to perform community detection on the updated directed weighted graph to identify community structures with dense capital flows and obtain multiple communities.

[0070] Specifically, the Louvain algorithm uses modularity optimization to identify densely connected groups of nodes in a directed weighted graph, thereby revealing communities with dense capital flows. Modularity is a measure of the quality of community segmentation; higher modularity indicates stronger internal connections and fewer cross-community connections within the network. By optimizing modularity, the Louvain algorithm can effectively aggregate addresses with dense capital flows, thereby identifying key transaction paths and potential illegal trading activities.

[0071] Optionally, in one example, the Louvain algorithm is applied to perform community detection on the updated directed weighted graph to identify community structures with dense capital flows, and multiple communities are obtained, including: Each address node in the updated directed weighted graph is initially treated as an independent community, thus obtaining multiple initial communities; Based on the adjacency table storage network, the modularity gain after each address node is moved to the community where its neighbor address node is located is calculated; For each address node, if the modularity gain is greater than the preset gain threshold, the address node is moved to the community where the neighboring address node is located, and multiple updated communities are obtained; Treat each updated community as an address node, construct a new directed weighted graph, and return to execute the step of initially treating each address node in the updated directed weighted graph as an independent community to obtain the initial multiple communities until the modularity gain is no greater than the preset gain threshold.

[0072] In this example, community detection based on the Louvain algorithm is mainly divided into three stages: initialization, modularity optimization, and community aggregation.

[0073] Specifically, in the initialization phase, each node , initially an independent community ,Right now ,in, V Represents a collection of nodes in a graph.

[0074] Further, we enter the modularity optimization phase and calculate the nodes v Classified as neighbor nodes u Community Modularity gain after , as shown below: in, Representing the community The sum of the weights of the edges between the internal nodes and node v. It is half the sum of the weights of all edges in the graph. Representing the community The sum of the weights of all edges within a node, Then the weight of the edge of node v is .

[0075] In practice, when When the node v Move to neighbor node u Community Otherwise, the node v Remain in the original community. Repeat this process until all nodes are stably assigned to their corresponding communities, thus forming a new community distribution.

[0076] Furthermore, we enter the community aggregation stage and treat each community as a new super node to construct a new graph. , new picture The edge weight can be expressed as follows: Among them, when hour, Representative super node The self-loop weight of hour, Representative super node and The weight of the edge between them. Representation node u Belongs to supernode . Representation node v Belongs to supernode . Representation node u and nodes v The weight of the edge between them.

[0077] Repeat modularity optimization and community aggregation until modularity converges. Finally, output the final community division: Furthermore, the maximum traffic from the target address node to all transaction address nodes in each community is calculated to obtain the total traffic volume for each community. Among multiple communities, the community with the largest total traffic volume is selected as the suspicious subgraph.

[0078] It is understandable that communities with the largest total traffic are retained as suspicious subgraphs to extract key nodes and their network structures with the highest density of fund interactions with the target address, thereby exploring the interaction patterns and organizational characteristics between key nodes. It should be noted that if the extracted suspicious subgraph cannot form an address transaction heterogeneous graph, the subgraph containing the target address's first-hop transaction node and its output address node is used as the suspicious subgraph instead.

[0079] Through the above steps, a suspicious subgraph can be obtained, and further, money laundering transaction detection can be performed based on the suspicious subgraph.

[0080] In practical applications, the label of a suspicious subgraph is defined as the label of the target address node, thereby converting the money laundering transaction detection problem into a suspicious subgraph classification problem. Suspicious subgraphs have a unique bipartite graph structure, that is, address nodes can only be connected through transaction nodes, and transaction nodes can only be connected through address nodes. However, traditional heterogeneous graph models rely on direct multiple relationships between different node types for information dissemination, which makes it difficult for heterogeneous graph models based on multiple relationships to be effectively applied to address transaction heterogeneous graphs. To solve this problem, this application proposes a new feature combination strategy, which represents the features of each node as a splicing of transaction features and address features, thereby converting the heterogeneous graph into a homogeneous graph, realizing the independent aggregation of address features and transaction features, and effectively improving the ability to disseminate information and integrate multiple information.

[0081] Specifically, step 103 includes: for each node in the suspicious subgraph, forming a feature representation corresponding to the node, where the feature representation is a concatenation format of transaction features and address features.

[0082] Optionally, in a possible implementation manner, the above step 103 includes: For transaction nodes in the suspicious subgraph, the transaction features corresponding to the transaction nodes are extracted and normalized; the address features corresponding to the transaction nodes with all values ​​zero are constructed; the transaction features and address features corresponding to the transaction nodes are spliced together to obtain the feature representation corresponding to the transaction nodes; For the address nodes in the suspicious subgraph, the address features corresponding to the address nodes are extracted and normalized; the transaction features corresponding to the address nodes with all values ​​zero are constructed; the transaction features and address features corresponding to the address nodes are spliced together to obtain the feature representation corresponding to the address nodes.

[0083] The transaction characteristics corresponding to the transaction node include but are not limited to the transaction amount, transaction fee, transaction timestamp, number of input addresses, and number of output addresses. The address characteristics corresponding to the address node include but are not limited to the address node's historical transaction count, cumulative received amount, cumulative sent amount, and the address node's active duration.

[0084] It is understandable that the feature representation of each node can be obtained through step 103. The feature representation of each node is a concatenation of transaction features and address features. The node at this time can be used as a pseudo-feature enhancement node to keep the transaction node and the address node consistent in feature dimension, thereby converting the original heterogeneous graph structure into a homogeneous graph structure for training or reasoning with the graph neural network model. The feature vector of the pseudo-feature enhancement node is formed by sequentially concatenating the real feature vector and the pseudo-feature vector. The concatenated pseudo-feature enhancement node is used to construct a homogeneous graph so that it can be trained and reasoned using homogeneous graph neural network models such as GraphSAGE, GCN, or GAT.

[0085] Figure 2 This is a schematic diagram of the characteristic representation of the node provided by the present invention, such as Figure 2 As shown in the figure, first, appropriate transaction features and address features are selected for transaction nodes and address nodes respectively according to different transaction environments, and normalized. Then, in order to aggregate transaction features and address features separately, transaction features and address features are concatenated and padded with 0. Figure 2 As shown in the figure, for transaction nodes, address features with all zero feature values in the same dimension are appended to the normalized transaction features. Similarly, for address nodes, transaction features with all zero feature values in the same dimension are appended to the normalized address features. In this way, the initial features of each node are a combination of transaction features and address features in the same dimension, forming the feature representation of the node.

[0086] Furthermore, step 104 includes: inputting the feature representations and suspicious subgraphs of all nodes into the cryptocurrency money laundering transaction detection model, and obtaining the cryptocurrency money laundering transaction detection results output by the cryptocurrency money laundering transaction detection model.

[0087] Among them, the cryptocurrency money laundering transaction detection results include: illegal transaction behavior or legal transaction behavior; the cryptocurrency money laundering transaction detection model is pre-built based on the GraphSAGE model and obtained through training.

[0088] In this embodiment, GraphSAGE (Graph Sample and Aggregation) is an inductive graph neural network model. Through neighborhood sampling and feature aggregation, it learns node embeddings using only local information, enabling inductive reasoning on new nodes or graphs without relying on training the entire graph structure. Therefore, the extraction of suspicious subgraphs can be viewed as the neighborhood sampling process in the GraphSAGE model, with the extracted subgraphs corresponding to the sampling results. The aggregation process is implemented using the convolution kernel SAGEConv.

[0089] Specifically, in one possible implementation, the cryptocurrency money laundering transaction detection model includes: an input layer, multiple convolutional layers, layer normalization, a nonlinear activation function, a random dropout mechanism, a global average pooling layer, and an output layer; The input layer is used to receive the feature representations of all nodes and transmit the feature representations of all nodes to the convolutional layer; Multiple convolutional layers are used to capture complex relationships and high-order interactions in suspicious subgraphs based on the feature representation of all nodes, thereby obtaining more expressive node embeddings. After each convolutional layer, layer normalization, nonlinear activation function, and random dropout mechanism are introduced; layer normalization is used to stabilize feature distribution and prevent gradient explosion or disappearance; nonlinear activation function is used to introduce nonlinear transformation to increase the expressive power of the model; random dropout mechanism is used to randomly drop features of some nodes to prevent overfitting; A global average pooling layer is set after the last convolutional layer to aggregate the feature representations of all nodes into a graph-level representation; The output layer is used to output the cryptocurrency money laundering transaction detection results based on the graph-level representation through logarithmic normalization and maximum value processing.

[0090] In one example, Figure 3 This is a schematic diagram of the architecture of the cryptocurrency money laundering transaction detection model provided by the present invention. Figure 3 As shown in the figure, L-layer convolution (SAGEConv) is used to capture the complex relationships and high-order interactions in the suspicious subgraph, thereby obtaining more expressive node embeddings. The first convolution layer maps the input features to the hidden layer, the middle convolution layer aggregates neighbor information to extract higher-order feature interactions, and the last convolution layer maps the hidden layer features to the output layer for the final classification task.

[0091] The aggregation process of the convolutional layer (SAGEConv) is as follows: in, is a nonlinear activation function, Representation node The neighbor set of is the selected aggregation function (such as mean, LSTM or pooling), Represents feature splicing. For the Layer Node The hidden representation of Represents the feature matrix of the input. For the The trainable weight matrix of the layer.

[0092] Specifically, after each convolutional layer, layer normalization (LayerNorm) is introduced to stabilize feature distribution, and nonlinear transformations are introduced through the activation function (ReLU). Furthermore, a random dropout mechanism (dropout) is used to prevent overfitting. After the final convolutional layer, node features are aggregated into a graph-level representation through global mean pooling. Subsequently, the output layer undergoes log-softmax and maximum (max) operations to obtain the final subgraph classification label, which is the result of cryptocurrency money laundering transaction detection.

[0093] In this example, traffic analysis and community detection were used to deeply explore valuable financial relationships and community structures, extracting suspicious subgraphs from a directed weighted graph. These subgraphs effectively retained key suspicious nodes and important network structures with high financial interaction density with the target address. Furthermore, the problem of detecting cryptocurrency money laundering transactions was transformed into a suspicious subgraph classification problem. For each node in the suspicious subgraph, a feature representation was generated. The feature representations of all nodes and the suspicious subgraph were then input into a cryptocurrency money laundering transaction detection model, which then outputted a cryptocurrency money laundering transaction detection result. This demonstrates that the solution of this example improves both the detection rate of illegal transactions and the accuracy of cryptocurrency money laundering transaction detection.

[0094] Furthermore, in one possible implementation, before step 101, the cryptocurrency money laundering transaction detection method further includes: Construct a dataset and divide it into a training set, a validation set, and a test set. The training set includes: multiple suspicious subgraphs and the reference cryptocurrency money laundering transaction detection results corresponding to each suspicious subgraph. Build an initial cryptocurrency money laundering transaction detection model based on the GraphSAGE model; Based on the training set, validation set and test set, the initial cryptocurrency money laundering transaction detection model is trained to obtain the cryptocurrency money laundering transaction detection model.

[0095] The following uses specific examples to illustrate the construction and training process of the cryptocurrency money laundering transaction detection model of this application.

[0096] Specifically, we conducted experiments on Bitcoin Core network data, obtaining a dataset from WalletExplorer.com, a leading platform for blockchain and cryptocurrency wallet analysis that provides widely recognized and well-known wallet labels. To reduce the potential overlap between addresses within the same wallet in the transaction network, we selected multiple wallets and screened a small number of labeled addresses from each wallet to construct the final labeled dataset.

[0097] Specifically, we selected 829 addresses from 23 top wallets (covering Exchanges, Pools, and Services) from WalletExplorer.com as senders of legitimate transactions, and 644 addresses from 20 top gambling wallets as senders of illicit transactions to form a labeled dataset. Subsequently, by tracking the flow of funds from outgoing transactions of labeled addresses, we constructed an address-transaction graph dataset, comprising 132,870 address nodes and 38,322 transaction nodes. The address-transaction data for this experiment was obtained using the Bitcoin Core network interface provided by Blockstream.com.

[0098] Based on the suspicious subgraph extraction method proposed in this paper, suspicious subgraphs were extracted from the Bitcoin address transaction graph and a corresponding dataset was constructed. Next, the GraphSAGE model based on subgraph sampling was used to construct an initial cryptocurrency money laundering transaction detection model, performing adaptive learning and classification. First, 16 key transaction features and 19 address features were selected, and new node representations were constructed based on these features. Next, the subgraph label was defined as the label of the target address, and the suspicious subgraph dataset and the label dataset were divided into training, validation, and test sets in a ratio of 7:2:1. Finally, the final result of the suspicious subgraph classification is the classification result of the address output transaction.

[0099] During model training, this solution employs mini-batch training with a cross-entropy loss function as the objective function and an optimizer (Adam) for parameter updates. To accelerate convergence, a learning rate scheduler (StepLR) is introduced to reduce the learning rate after a fixed number of steps. Furthermore, to prevent overfitting and save training time, an early stopping mechanism is employed. Training is terminated early if performance on the training set fails to improve within five consecutive iterations. Finally, to reduce experimental randomness, each experiment is repeated 10 times, and the average result is taken as the final result.

[0100] For example, the feature selection is as follows: transaction features include 16 indicators: transaction time, lock time, transaction size, weight, transaction fee, transaction amount, input number, output number, and the minimum, maximum, mean and standard deviation of the input and output amount series.

[0101] Address features include: five transaction statistics, the minimum, maximum, mean, and variance of the transaction fee series, and 10 time series-related features, for a total of 19 features. The five transaction statistics include: number of transactions, number of incoming transactions, number of outgoing transactions, total incoming funds, and total outgoing funds. The 10 time series-related features include: total transaction time, the minimum, maximum, mean, and variance of the time interval series between adjacent transactions, and the minimum, maximum, mean, variance, and time aggregation of the time required to complete a forwarding transaction (receiving and subsequently sending the same unspent transaction output UTXO).

[0102] The parameters were set as follows: the input dimension of the graph model was 35, the dimension of the new node representation, and the output dimension was 2, the final number of categories. Through grid search, this approach determined the following hyperparameters: the GraphSAGE model contained two convolutional layers, the hidden layer dimension was 128, the dropout rate was set to 0.4, and the batch size was 32. The initial learning rate of the Adam optimizer was 0.01, the step size of the learning rate scheduler (StepLR) was 20, and the decay factor (gamma) was 0.5. Furthermore, based on the experimental dataset, the traffic threshold was set to 0.001 Bitcoin.

[0103] To validate the effectiveness of our solution, we conducted experiments comparing it with traditional machine learning models and common graph models to assess its effectiveness in detecting illegal transactions. We also compared the performance differences between different transaction network representations.

[0104] In this experiment, six evaluation metrics were considered: accuracy, precision, recall, F1 score, illegal transaction miss rate (ERillegal), and total runtime. The experimental results demonstrate that this solution, by extracting suspicious subgraphs and applying the GraphSAGE model, achieves optimal classification results. Specifically, recall reached 93.1%, while accuracy, precision, and F1 score reached 92.0%, 89.3%, and 91.0%, respectively. Furthermore, the illegal transaction miss rate was reduced to 7.1‰, while the total runtime of the graph model was shortened to 18.1 seconds, fully demonstrating the dual advantages of this solution in performance and efficiency.

[0105] Compared to traditional machine learning detection methods (such as MLP, RF, and XGB), this solution achieves at least 6% improvements in accuracy, precision, recall, and F1 score, breaking through the performance bottlenecks of traditional methods based on transaction features. Compared to the full-graph GCN (addr-tx graph) detection method, this solution improves recall by 16.7%, reduces the missed detection rate of illegal transactions from 23.7‰ to 7.1‰, and shortens the total runtime from 49.2s to 18.1s. This not only effectively alleviates the problem of missed detection of illegal transactions caused by the sparsity and heterogeneity of cryptocurrency networks, but also significantly reduces the computational overhead of graph models, improving detection efficiency and applicability.

[0106] In addition, compared with the node-weighted GAT and GraphTransformer and the node-selection-based FastGCN graph model, this scheme reduced the missed detection rate of illegal transactions by 6‰, 12‰ and 7‰, respectively, further verifying that the extracted suspicious subgraph can effectively capture the key transaction network structure, thereby significantly improving the detection effect of illegal transactions.

[0107] Finally, under the same GraphSAGE model, the detection performance of transaction homogeneous graphs (tx-tx graphs), transaction heterogeneous graphs (tx-addr graphs), and address transaction graphs (addr-tx graphs) was compared. The results show that the address transaction graph significantly improves the recall rate and F1 score, verifying its effectiveness in characterizing transaction networks and complex transaction relationships.

[0108] In summary, the cryptocurrency money laundering transaction detection method provided in this embodiment, through traffic analysis and community detection, deeply explores valuable financial relationships and community structures, extracting suspicious subgraphs from directed weighted graphs. These subgraphs effectively retain key suspicious nodes and important network structures with high financial interaction density with the target address. Furthermore, the cryptocurrency money laundering transaction detection problem is transformed into a suspicious subgraph classification problem. For each node in the suspicious subgraph, a feature representation is generated. The feature representations of all nodes and the suspicious subgraph are then input into the cryptocurrency money laundering transaction detection model, which then outputs the cryptocurrency money laundering transaction detection results. This solution improves the detection rate of illegal transactions and the accuracy of cryptocurrency money laundering transaction detection.

[0109] The following describes the cryptocurrency money laundering transaction detection device provided by the present invention. The cryptocurrency money laundering transaction detection device described below and the cryptocurrency money laundering transaction detection method described above can be referenced to each other.

[0110] Figure 4This is a schematic diagram of the structure of the cryptocurrency money laundering transaction detection device provided by the present invention. Figure 4 As shown, the cryptocurrency money laundering transaction detection device includes: a construction module 41, an extraction module 42, a splicing module 43 and a processing module 44.

[0111] Construction module 41 is used to construct a directed weighted graph based on the transaction data to be detected; wherein the nodes in the directed weighted graph include multiple address nodes and multiple transaction nodes, and each transaction node represents a transaction; the edges in the directed weighted graph represent the flow of funds between address nodes, and the weight of the edge represents the amount of the fund flow.

[0112] The extraction module 42 is configured to extract suspicious subgraphs from the directed weighted graph through traffic analysis and community detection.

[0113] The splicing module 43 is used to form a feature representation corresponding to each node in the suspicious subgraph, where the feature representation is a splicing format of transaction features and address features.

[0114] Processing module 44 is configured to input the feature representations of all nodes and the suspicious subgraphs into a cryptocurrency money laundering transaction detection model to obtain a cryptocurrency money laundering transaction detection result output by the cryptocurrency money laundering transaction detection model; wherein the cryptocurrency money laundering transaction detection result includes: illegal transaction behavior or legal transaction behavior; the cryptocurrency money laundering transaction detection model is pre-built and trained based on the GraphSAGE model.

[0115] Optionally, in a possible implementation, the extraction module 42 is specifically configured to: Select at least one target address node from a plurality of address nodes; For each target address node, the Dinic algorithm is applied to calculate the maximum flow from the target address node to each transaction address node. A transaction address node is an address node other than the target address node that has a direct or indirect transaction with the target address node. Eliminate the target address nodes whose maximum flow rate in the directed weighted graph is lower than a preset flow threshold, and obtain an updated directed weighted graph; Apply the Louvain algorithm to perform community detection on the updated directed weighted graph to identify community structures with dense capital flows and obtain multiple communities; Calculate the sum of the maximum traffic from the target address node to all transaction address nodes in each community to obtain the total traffic corresponding to each community; From multiple communities, the community with the largest total traffic volume is selected as the suspicious subgraph.

[0116] Optionally, in one embodiment, the extraction module 42 is configured to apply the Dinic algorithm to each target address node to calculate the maximum flow corresponding to the target address node, specifically to: For each target address node, the target address node is used as the source node, and multiple transaction address nodes are used as sink nodes; Set the flow between the source node and the sink node to 0; For each edge in the directed weighted graph, the residual capacity of the edge is set to the original capacity of the edge, and an adjacency table storage network is constructed; By using the breadth-first search algorithm, the shortest path hierarchy from the source node is calculated, and a hierarchical graph is constructed based on the shortest path hierarchy; Using the depth-first search algorithm, we search for augmenting paths starting from the source node in the hierarchical graph. Traverse each edge in the augmenting path, calculate the minimum residual capacity of the augmenting path, and obtain the flow increment; Based on the flow increment, the flow between the source node and the sink node along the augmenting path and the residual capacity of each edge in the directed weighted graph are updated; If no augmenting path can be found in the current hierarchical graph, then return to the step of calculating the shortest path hierarchy from the source node through the breadth-first search algorithm, and constructing the hierarchical graph based on the shortest path hierarchy; otherwise, the flow between the current source node and the sink node is used as the maximum flow from the target address node to the transaction address node.

[0117] Optionally, in one embodiment, the extraction module 42 is configured to apply the Louvain algorithm to perform community detection on the updated directed weighted graph to identify community structures with dense capital flows. When multiple communities are obtained, the extraction module 42 is specifically configured to: Each address node in the updated directed weighted graph is initially treated as an independent community, thus obtaining multiple initial communities; Based on the adjacency table storage network, the modularity gain after each address node is moved to the community where its neighbor address node is located is calculated; For each address node, if the modularity gain is greater than the preset gain threshold, the address node is moved to the community where the neighboring address node is located, and multiple updated communities are obtained; Treat each updated community as an address node, construct a new directed weighted graph, and return to execute the step of initially treating each address node in the updated directed weighted graph as an independent community to obtain the initial multiple communities until the modularity gain is no greater than the preset gain threshold.

[0118] Optionally, in a possible implementation manner, the splicing module 43 is specifically configured to: For transaction nodes in the suspicious subgraph, the transaction features corresponding to the transaction nodes are extracted and normalized; the address features corresponding to the transaction nodes with all values ​​zero are constructed; the transaction features and address features corresponding to the transaction nodes are spliced together to obtain the feature representation corresponding to the transaction nodes; For the address nodes in the suspicious subgraph, the address features corresponding to the address nodes are extracted and normalized; the transaction features corresponding to the address nodes with all values ​​zero are constructed; the transaction features and address features corresponding to the address nodes are spliced together to obtain the feature representation corresponding to the address nodes.

[0119] Optionally, in one possible implementation, the cryptocurrency money laundering transaction detection model includes: an input layer, multiple convolutional layers, layer normalization, a nonlinear activation function, a random dropout mechanism, a global average pooling layer, and an output layer; The input layer is used to receive the feature representations of all nodes and transmit the feature representations of all nodes to the convolutional layer; Multiple convolutional layers are used to capture complex relationships and high-order interactions in suspicious subgraphs based on the feature representation of all nodes, thereby obtaining more expressive node embeddings. After each convolutional layer, layer normalization, nonlinear activation function, and random dropout mechanism are introduced; layer normalization is used to stabilize feature distribution and prevent gradient explosion or disappearance; nonlinear activation function is used to introduce nonlinear transformation to increase the expressive power of the model; random dropout mechanism is used to randomly drop features of some nodes to prevent overfitting; A global average pooling layer is set after the last convolutional layer to aggregate the feature representations of all nodes into a graph-level representation; The output layer is used to output the cryptocurrency money laundering transaction detection results based on the graph-level representation through logarithmic normalization and maximum value processing.

[0120] Optionally, in a possible implementation, the cryptocurrency money laundering transaction detection device further includes: a training module; the training module is configured to: Construct a dataset and divide it into a training set, a validation set, and a test set. The training set includes: multiple suspicious subgraphs and the reference cryptocurrency money laundering transaction detection results corresponding to each suspicious subgraph. Build an initial cryptocurrency money laundering transaction detection model based on the GraphSAGE model; Based on the training set, validation set and test set, the initial cryptocurrency money laundering transaction detection model is trained to obtain the cryptocurrency money laundering transaction detection model.

[0121] The cryptocurrency money laundering transaction detection device provided by this invention uses traffic analysis and community detection to deeply explore valuable financial relationships and community structures, extracting suspicious subgraphs from directed weighted graphs. These subgraphs effectively retain key suspicious nodes and important network structures with high financial interaction density with the target address. Furthermore, the cryptocurrency money laundering transaction detection problem is transformed into a suspicious subgraph classification problem. For each node in the suspicious subgraph, a feature representation is generated. The feature representations of all nodes and the suspicious subgraph are then input into a cryptocurrency money laundering transaction detection model, which then outputs the cryptocurrency money laundering transaction detection results. This embodiment improves the detection rate of illegal transactions and the accuracy of cryptocurrency money laundering transaction detection.

[0122] Figure 5 Schematic diagram of the structure of the electronic device provided by the present invention, such as Figure 5 As shown, the electronic device may include: a processor (processor) 510, a communication interface (Communications Interface) 520, a memory (memory) 530 and a communication bus 540, wherein the processor 510, the communication interface 520, and the memory 530 communicate with each other through the communication bus 540. The processor 510 can call the logic instructions in the memory 530 to execute the cryptocurrency money laundering transaction detection method, which includes: constructing a directed weighted graph based on the transaction data to be detected; wherein the nodes in the directed weighted graph include multiple address nodes and multiple transaction nodes, and each transaction node represents a transaction; the edges in the directed weighted graph represent the flow of funds between the address nodes, and the weight of the edge represents the amount of the fund flow; through traffic analysis and community detection, a suspicious subgraph is extracted from the directed weighted graph; for each node in the suspicious subgraph, a feature representation corresponding to the node is formed, and the feature representation is a splicing format of transaction features and address features; the feature representations of all nodes in the suspicious subgraph and the suspicious subgraph are input into the cryptocurrency money laundering transaction detection model to obtain the cryptocurrency money laundering transaction detection results output by the cryptocurrency money laundering transaction detection model; wherein the cryptocurrency money laundering transaction detection results include: illegal transaction behavior or legal transaction behavior; the cryptocurrency money laundering transaction detection model is pre-built based on the GraphSAGE model and is obtained through training.

[0123] Furthermore, the logic instructions in the aforementioned memory 530 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the portion that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, a mobile hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0124] On the other hand, the present invention also provides a computer program product, which includes a computer program, which can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the cryptocurrency money laundering transaction detection method provided by the above methods, the method including: constructing a directed weighted graph based on the transaction data to be detected; wherein the nodes in the directed weighted graph include multiple address nodes and multiple transaction nodes, and each transaction node represents a transaction; the edges in the directed weighted graph represent the flow of funds between the address nodes, and the weight of the edge represents the amount of the fund flow; extracting a suspicious subgraph from the directed weighted graph through traffic analysis and community detection; for each node in the suspicious subgraph, forming a feature representation corresponding to the node, the feature representation is a splicing format of transaction features and address features; inputting the feature representations of all nodes in the suspicious subgraph and the suspicious subgraph into a cryptocurrency money laundering transaction detection model to obtain the cryptocurrency money laundering transaction detection result output by the cryptocurrency money laundering transaction detection model; wherein the cryptocurrency money laundering transaction detection result includes: illegal transaction behavior or legal transaction behavior; the cryptocurrency money laundering transaction detection model is pre-built based on the GraphSAGE model and obtained through training.

[0125] On the other hand, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, is implemented to execute the cryptocurrency money laundering transaction detection method provided by the above-mentioned methods, the method comprising: constructing a directed weighted graph based on the transaction data to be detected; wherein the nodes in the directed weighted graph include multiple address nodes and multiple transaction nodes, and each transaction node represents a transaction; the edges in the directed weighted graph represent the flow of funds between the address nodes, and the weight of the edge represents the amount of the fund flow; extracting a suspicious subgraph from the directed weighted graph through traffic analysis and community detection; for each node in the suspicious subgraph, forming a feature representation corresponding to the node, the feature representation is a splicing format of transaction features and address features; inputting the feature representations of all nodes in the suspicious subgraph and the suspicious subgraph into a cryptocurrency money laundering transaction detection model to obtain the cryptocurrency money laundering transaction detection result output by the cryptocurrency money laundering transaction detection model; wherein the cryptocurrency money laundering transaction detection result includes: illegal transaction behavior or legal transaction behavior; the cryptocurrency money laundering transaction detection model is pre-constructed based on the GraphSAGE model and obtained through training.

[0126] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e., they may be located in one location or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of the present embodiment. Persons of ordinary skill in the art will be able to understand and implement the present invention without inventive effort.

[0127] Through the above description of the embodiments, those skilled in the art will clearly understand that each embodiment can be implemented using software plus a necessary general-purpose hardware platform, or of course, hardware. Based on this understanding, the essence of the above technical solution, or the portion that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a magnetic disk, or an optical disk, and includes a number of instructions for causing a computer device (such as a personal computer, server, or network device) to execute the methods described in each embodiment or certain portions of the embodiments.

[0128] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.

Claims

1. A method for detecting money laundering transactions using cryptocurrency, characterized in that: include: Constructing a directed weighted graph based on the transaction data to be detected; wherein the nodes in the directed weighted graph include multiple address nodes and multiple transaction nodes, each transaction node representing a transaction; the edges in the directed weighted graph represent the flow of funds between the address nodes, and the weights of the edges represent the amount of the fund flow; Extracting suspicious subgraphs from the directed weighted graph through traffic analysis and community detection; For each node in the suspicious subgraph, a feature representation corresponding to the node is formed, where the feature representation is a concatenation of transaction features and address features; The feature representations of all nodes in the suspicious subgraph and the suspicious subgraph are input into a cryptocurrency money laundering transaction detection model to obtain a cryptocurrency money laundering transaction detection result output by the cryptocurrency money laundering transaction detection model; wherein the cryptocurrency money laundering transaction detection result includes: illegal transaction behavior or legal transaction behavior; the cryptocurrency money laundering transaction detection model is pre-built based on the GraphSAGE model and obtained through training.

2. The cryptocurrency money laundering transaction detection method according to claim 1, characterized in that: Extracting suspicious subgraphs from the directed weighted graph through traffic analysis and community detection includes: Select at least one target address node from the plurality of address nodes; For each target address node, apply the Dinic algorithm to calculate the maximum flow from the target address node to each transaction address node; wherein the transaction address node is an address node other than the target address node among the multiple address nodes that has a direct or indirect transaction with the target address node; Eliminating transaction address nodes whose maximum traffic in the directed weighted graph is lower than a preset traffic threshold, to obtain an updated directed weighted graph; Applying the Louvain algorithm to perform community detection on the updated directed weighted graph to identify community structures with dense capital flows and obtain multiple communities; Calculate the sum of the maximum traffic from the target address node to all transaction address nodes in each community to obtain the total traffic corresponding to each community; From the multiple communities, a community with the largest total traffic volume is selected as a suspicious subgraph.

3. The cryptocurrency money laundering transaction detection method according to claim 2, characterized in that: For each target address node, the Dinic algorithm is applied to calculate the maximum flow from the target address node to each transaction address node, including: For each target address node, use the target address node as the source node, and use each transaction address node as the sink node; Setting the flow between the source node and the sink node to 0; For each edge in the directed weighted graph, the residual capacity of the edge is set to the original capacity of the edge, and an adjacency list storage network is constructed; Calculate the shortest path hierarchy from the source node by a breadth-first search algorithm, and construct a hierarchical graph based on the shortest path hierarchy; Using a depth-first search algorithm, in the hierarchical graph, starting from the source node, searching for an augmenting path; Traversing each edge in the augmenting path, calculating the minimum residual capacity of the augmenting path, and obtaining the flow increment; Based on the flow increment, updating the flow between the source node and the sink node and the residual capacity of each edge in the directed weighted graph along the augmented path; If no augmenting path can be found in the current hierarchical graph, the process returns to the step of calculating the shortest path hierarchy from the source node through the breadth-first search algorithm, and constructing a hierarchical graph based on the shortest path hierarchy; otherwise, the current flow between the source node and the sink node is used as the maximum flow from the target address node to the transaction address node.

4. The cryptocurrency money laundering transaction detection method according to claim 3, characterized in that: The Louvain algorithm is applied to perform community detection on the updated directed weighted graph to identify community structures with dense capital flows, and multiple communities are obtained, including: Initializing each address node in the updated directed weighted graph as an independent community to obtain multiple initial communities; Based on the adjacency table storage network, the modularity gain after each address node is moved to the community where its neighbor address node is located is calculated; For each address node, if the modularity gain is greater than a preset gain threshold, the address node is moved to the community where the neighboring address node is located, to obtain multiple updated communities; Treating each updated community as an address node, constructing a new directed weighted graph, and returning to execute the step of initially treating each address node in the updated directed weighted graph as an independent community to obtain the initial multiple communities, until the modularity gain is no greater than a preset gain threshold.

5. The cryptocurrency money laundering transaction detection method according to claim 1, characterized in that: For each node in the suspicious subgraph, forming a feature representation corresponding to the node includes: For transaction nodes in the suspicious subgraph, the transaction features corresponding to the transaction nodes are extracted and normalized; the address features corresponding to the transaction nodes are constructed with all values being 0; the transaction features and address features corresponding to the transaction nodes are concatenated to obtain the feature representation corresponding to the transaction nodes; For the address nodes in the suspicious subgraph, the address features corresponding to the address nodes are extracted and normalized; the transaction features corresponding to the address nodes with all values being 0 are constructed; the transaction features and address features corresponding to the address nodes are concatenated to obtain the feature representation corresponding to the address nodes.

6. The cryptocurrency money laundering transaction detection method according to any one of claims 1 to 5, characterized in that: Before constructing the directed weighted graph based on the transaction data to be detected, the method further includes: Constructing a dataset and dividing the dataset into a training set, a validation set, and a test set; the training set includes: multiple suspicious subgraphs and a reference cryptocurrency money laundering transaction detection result corresponding to each suspicious subgraph; Build an initial cryptocurrency money laundering transaction detection model based on the GraphSAGE model; Based on the training set, the validation set, and the test set, the initial cryptocurrency money laundering transaction detection model is trained to obtain the cryptocurrency money laundering transaction detection model.

7. A cryptocurrency money laundering transaction detection device, characterized in that: include: A construction module is configured to construct a directed weighted graph based on the transaction data to be detected; wherein the nodes in the directed weighted graph include multiple address nodes and multiple transaction nodes, each transaction node representing a transaction; the edges in the directed weighted graph represent the flow of funds between the address nodes, and the weights of the edges represent the amount of the fund flow; An extraction module, configured to extract suspicious subgraphs from the directed weighted graph through traffic analysis and community detection; A splicing module, configured to generate a feature representation corresponding to each node in the suspicious subgraph, wherein the feature representation is a splicing format of transaction features and address features; A processing module is configured to input the feature representations of all nodes in a suspicious subgraph and the suspicious subgraph into a cryptocurrency money laundering transaction detection model to obtain a cryptocurrency money laundering transaction detection result output by the cryptocurrency money laundering transaction detection model; wherein the cryptocurrency money laundering transaction detection result includes: illegal transaction behavior or legal transaction behavior; the cryptocurrency money laundering transaction detection model is pre-built and trained based on the GraphSAGE model.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that: When the processor executes the computer program, the method for detecting cryptocurrency money laundering transactions according to any one of claims 1 to 6 is implemented.

9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method for detecting cryptocurrency money laundering transactions according to any one of claims 1 to 6 is implemented.

10. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the method for detecting cryptocurrency money laundering transactions according to any one of claims 1 to 6 is implemented.