A method and system for detecting malicious Ethereum samples based on homogeneous enhanced compression modeling

By constructing and compressing the Ethereum interaction graph and using the pseudo-labeling mechanism and loss function training model, the problems of large transaction graph size and redundant information interference in Ethereum malicious sample detection are solved, and high-precision and efficient malicious account detection is achieved.

CN120546989BActive Publication Date: 2025-10-03ARTIFICIAL INTELLIGENCE INNOVATION RES INST OF ZHEJIANG UNIV OF TECH BINJIANG DISTRICT HANGZHOU
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510993239.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-18
Publication Date
2025-10-03
Estimated Expiration
2045-07-18

AI Technical Summary

Technical Problem

Existing Ethereum malicious sample detection methods have poor generalization capabilities and are unable to effectively identify complex malicious behaviors. In addition, the large scale of transaction graphs and redundant information interfere with model training, resulting in low detection accuracy and insufficient system robustness.

Method used

By constructing the initial Ethereum interaction graph, retaining key nodes and edges based on the message propagation mechanism, dividing the nodes into target nodes, bridge nodes and background nodes, aggregating the background node features, generating a compressed interaction graph, and using the pseudo-label mechanism to divide the homogeneous subgraphs. The detection model is trained by combining the pseudo-label loss function with the classification loss function.

Benefits of technology

It significantly reduces the node and edge scale of the Ethereum transaction graph, reduces the complexity of model training, enhances information dissemination between similar nodes, improves the accuracy and efficiency of malicious sample detection, and alleviates the problem of insufficient generalization ability caused by label sparsity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120546989B_ABST
    Figure CN120546989B_ABST
Patent Text Reader

Abstract

The present invention discloses a method and system for detecting malicious Ethereum samples based on homogeneous enhanced compression modeling, which belongs to the field of graph artificial intelligence and blockchain security technology. The present invention adopts the following technical solutions: extracting training label account interaction information to construct an initial Ethereum interaction graph; retaining key nodes and edges based on message propagation to generate a simplified graph; dividing target nodes, bridge nodes, and background nodes; aggregating background node features to the target node and deleting the node, aggregating similar bridge nodes to form new bridge nodes; deleting new bridge nodes with the same features and intersections with source bridge nodes to generate a compressed graph; generating pseudo labels through a fully connected layer and dividing homogeneous subgraphs, fusing the outputs after message transmission within the subgraph; and training the model with a combined pseudo label loss and classification loss. This method reduces computational complexity through graph compression, utilizes pseudo label homogeneous subgraphs to enhance similar information propagation, and improves the accuracy and efficiency of malicious behavior detection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of graph artificial intelligence and blockchain security technology, and in particular relates to an Ethereum malicious sample detection method and system based on homogeneous enhanced compression modeling. Background Art

[0002] With the continued development of blockchain technology and the widespread adoption of Ethereum smart contracts, the market for digital assets and decentralized applications has grown rapidly. However, Ethereum's open and anonymous nature also makes it a popular platform for illegal activities. Traditional malicious sample detection methods rely on rule matching, static address blacklists, or machine learning models based on single account characteristics. However, these methods suffer from poor generalization and inadequate modeling of complex malicious networks, making them difficult to meet practical application requirements.

[0003] Graph neural networks, with their powerful ability to model relationships within graph structures, have been widely used to detect malicious samples on Ethereum. Through a message-passing mechanism, graph neural networks can capture potential malicious behavior within the transaction graph. However, the exponential growth of Ethereum transaction volume has led to an excessively large transaction graph, and a large amount of redundant information interferes with model training. Furthermore, malicious samples often transfer funds through frequent interactions with legitimate accounts, resulting in significant heterogeneity in neighborhood information and weakening the ability of graph neural networks to effectively disseminate homogeneous information between similar nodes. Therefore, an efficient detection method that balances transaction graph compression and homogeneous information capture is urgently needed to improve the accuracy and robustness of identifying complex malicious behavior on the Ethereum platform. Summary of the Invention

[0004] To solve the above technical problems, the present invention proposes an Ethereum malicious sample detection method and system based on homogeneous enhanced compression modeling to solve the problems existing in the above-mentioned prior art.

[0005] In a first aspect, to achieve the above-mentioned objectives, the present invention provides a method for detecting malicious Ethereum samples using homogeneous enhanced compression modeling, comprising the following steps:

[0006] S1. Extract the neighborhood interaction information of the training label accounts and construct the initial Ethereum interaction graph with accounts as nodes and transactions as edges;

[0007] S2, based on the message propagation mechanism and the label account receptive field, retain key nodes and edges and generate a preliminary simplified interaction graph;

[0008] S3, dividing the nodes in the simplified graph into target nodes, bridge nodes connecting target node pairs, and background nodes that only interact with target nodes;

[0009] S4, aggregate background node features to corresponding target nodes and delete background nodes, aggregate bridge nodes connecting the same target node pair to form a new bridge node;

[0010] S5. Delete new bridge nodes with the same characteristics and intersections with the source bridge nodes to generate a compressed interaction graph;

[0011] S6. Generate pseudo labels through the fully connected layer, divide homogeneous subgraphs based on the pseudo labels, perform message passing within each subgraph, and then fuse the output;

[0012] S7. Combine the pseudo-label loss function and the classification loss function to train the detection model.

[0013] Optionally, in S1, the process of constructing the initial Ethereum interaction graph includes:

[0014] Accounts are considered as nodes, and transactions between accounts are considered as edges;

[0015] Extract feature representation based on account attributes and interaction behaviors;

[0016] Define the interaction graph structure including node set, edge set, node features and node labels;

[0017] The node labels are the actual malicious attributes of known labeled accounts.

[0018] Optionally, in S3, the node division process includes:

[0019] Accounts with known labels are used as target nodes;

[0020] The intermediate account connecting the two target nodes acts as a bridge node;

[0021] Only accounts directly connected to a single target node are used as background nodes;

[0022] The bridge nodes are divided into first-order bridge nodes and second-order bridge nodes according to the distance from the target node.

[0023] Optionally, in S4, the polymerization process includes:

[0024] Aggregate the feature mean of background nodes to the corresponding target node;

[0025] Aggregate the feature means of the same type of bridge nodes connecting the same target node pair into a new bridge node;

[0026] Delete the background nodes and original bridge nodes that have completed aggregation;

[0027] The bridge node types include first-order bridge, second-order left bridge and second-order right bridge.

[0028] Optionally, in S5, the conditions for deleting the new bridge node include:

[0029] The new bridge nodes have the same feature representation;

[0030] The source bridge node sets of the new bridge node have a non-empty intersection;

[0031] Only unique instances of redundant new bridge nodes that meet the conditions are retained.

[0032] Optionally, in S6, the process of dividing the homogeneous subgraphs includes:

[0033] Generate pseudo labels using two fully connected layers without aggregating neighbor features;

[0034] Split the graph into positive homogeneous subgraphs and negative homogeneous subgraphs based on pseudo-labels;

[0035] A positive homogeneous subgraph includes nodes and edges whose pseudo-labels are all malicious;

[0036] The negative homogeneous subgraph includes nodes and edges whose pseudo labels are normal.

[0037] In a second aspect, the present invention further provides an Ethereum malicious sample detection system based on homogeneous enhanced compression modeling, which is used to implement a method for detecting Ethereum malicious samples based on homogeneous enhanced compression modeling. The system includes:

[0038] The data acquisition module is used to extract the neighborhood interaction information of the training label accounts and construct the initial Ethereum interaction graph with accounts as nodes and transactions as edges;

[0039] The network compression module is used to retain key nodes and edges based on the message propagation mechanism to generate a preliminary simplified interaction graph, divide the target nodes / bridge nodes / background nodes, aggregate the background node features to the target nodes, and aggregate the same type of bridge nodes to form new bridge nodes. The new bridge nodes with the same features and intersections with the source bridge nodes are deleted to generate a compressed interaction graph;

[0040] The homogeneous enhancement module is used to generate pseudo labels through the fully connected layer, divide homogeneous subgraphs based on the pseudo labels, and perform message passing within each subgraph before fusion output;

[0041] Model optimization module, used to train the detection model by combining pseudo-label loss function and classification loss function;

[0042] The malicious sample detection module is used to input the interaction graph of the account to be detected into the trained detection model to output the classification results.

[0043] Optionally, the data acquisition module includes:

[0044] Node-edge definition unit, used to define accounts as nodes and transactions as edges;

[0045] Feature extraction unit, used to extract feature representation based on account attributes and interaction behaviors;

[0046] The graph structure building unit is used to define the interactive graph structure including node sets, edge sets, node features and real malicious labels.

[0047] In a third aspect, the present invention further provides a computer terminal device, comprising:

[0048] one or more processors;

[0049] a memory, coupled to the processor, for storing one or more programs;

[0050] When the one or more programs are executed by the one or more processors, the one or more processors implement an Ethereum malicious sample detection method based on homogeneous enhanced compression modeling.

[0051] In a fourth aspect, the present invention further provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, it implements a method for detecting malicious Ethereum samples based on homogeneous enhanced compression modeling.

[0052] Compared with the prior art, the present invention has the following advantages and technical effects:

[0053] This paper provides a method and system for detecting malicious Ethereum samples using homogeneous enhanced compression modeling. This method significantly reduces the node and edge size of the Ethereum transaction graph through graph compression, reducing model training complexity. It also utilizes a pseudo-labeling mechanism to partition homogeneous subgraphs, enhancing information dissemination between similar nodes and effectively suppressing heterogeneous information interference. Furthermore, it combines dual-loss function joint optimization to enhance the model's ability to capture malicious patterns. Ultimately, this method achieves high-precision and efficient detection of malicious Ethereum accounts while alleviating the generalization issues caused by label sparsity. BRIEF DESCRIPTION OF THE DRAWINGS

[0054] The accompanying drawings, which constitute part of the present invention, are provided to provide a further understanding of the present invention. The exemplary embodiments of the present invention and their descriptions are provided to explain the present invention and do not constitute an undue limitation of the present invention. In the accompanying drawings:

[0055] Figure 1 This is a flowchart of a training model for graph compression of training data and malicious sample detection according to an embodiment of the present invention;

[0056] Figure 2 This is a framework diagram of a graph compression method during training according to an embodiment of the present invention;

[0057] Figure 3 This is a framework diagram of a pseudo-label-guided homogeneous feature enhancement model according to an embodiment of the present invention;

[0058] Figure 4 This is a flowchart of malicious sample detection of a target account to be detected according to an embodiment of the present invention;

[0059] Figure 5 This is a framework diagram of a malicious sample detection system according to an embodiment of the present invention. DETAILED DESCRIPTION

[0060] It should be noted that, in the absence of conflict, the embodiments and features of the embodiments of the present invention can be combined with each other. The present invention will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.

[0061] It should be noted that the steps shown in the flowcharts of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and that, although a logical order is shown in the flowcharts, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0062] Example 1

[0063] like Figure 1 As shown, this embodiment provides an Ethereum malicious sample detection method based on homogeneous enhanced compression modeling, including:

[0064] S1. Extract the neighborhood interaction information of the training label accounts and construct the initial Ethereum interaction graph with accounts as nodes and transactions as edges;

[0065] S2, based on the message propagation mechanism and the label account receptive field, retain key nodes and edges and generate a preliminary simplified interaction graph;

[0066] S3, dividing the nodes in the simplified graph into target nodes, bridge nodes connecting target node pairs, and background nodes that only interact with target nodes;

[0067] S4, aggregate background node features to corresponding target nodes and delete background nodes, aggregate bridge nodes connecting the same target node pair to form a new bridge node;

[0068] S5. Delete new bridge nodes with the same characteristics and intersections with the source bridge nodes to generate a compressed interaction graph;

[0069] S6. Generate pseudo labels through the fully connected layer, divide homogeneous subgraphs based on the pseudo labels, perform message passing within each subgraph, and then fuse the output;

[0070] S7. Combine the pseudo-label loss function and the classification loss function to train the detection model.

[0071] Specifically, the following steps are included:

[0072] S1: Extract the neighborhood interaction information of the training label accounts and construct the initial Ethereum training interaction graph;

[0073] S2: Combining the graph message propagation mechanism and the receptive field of the labeled account, we identify and retain key nodes and edges that contribute to malicious sample detection and generate a preliminary simplified interaction graph.

[0074] S3: Based on the node structure relationship in the preliminary simplified interaction graph, the nodes are divided into target nodes to be detected, bridge nodes connecting target account pairs, and background nodes that only interact with target accounts;

[0075] S4: Perform graph compression based on the aggregation method, aggregate the background node features to the corresponding target account and remove the background node, and aggregate multiple bridge nodes connecting the same target node to form a new bridge node;

[0076] S5: According to the situation where the new bridge node has the same characteristics and the same source bridge node, the only similar bridge node is retained to avoid information redundancy;

[0077] S6: Introducing a pseudo-labeling mechanism to assign pseudo-labels to all nodes in the graph, and using the pseudo-labels to guide the generation of homogeneous subgraphs, using the homogeneous information transmission mechanism to enhance the common features between similar target accounts;

[0078] S7: Design an optimization objective function for malicious sample detection and a constraint objective function for pseudo-label generation, train the model in a targeted manner, and verify the performance in the test dataset.

[0079] As an implementation method in this embodiment, in S1, the process of constructing the initial Ethereum interaction graph includes:

[0080] Accounts are considered as nodes, and transactions between accounts are considered as edges;

[0081] Extract feature representation based on account attributes and interaction behaviors;

[0082] Define the interaction graph structure including node set, edge set, node features and node labels;

[0083] The node labels are the actual malicious attributes of known labeled accounts.

[0084] As an implementation in this embodiment, in S3, the node division process includes:

[0085] Accounts with known labels are used as target nodes;

[0086] The intermediate account connecting the two target nodes acts as a bridge node;

[0087] Only accounts directly connected to a single target node are used as background nodes;

[0088] The bridge nodes are divided into first-order bridge nodes and second-order bridge nodes according to the distance from the target node.

[0089] like Figure 2 As shown, the graph compression method is an implementation method in this embodiment. In S4, the aggregation process includes:

[0090] Aggregate the feature mean of background nodes to the corresponding target node;

[0091] Aggregate the feature means of the same type of bridge nodes connecting the same target node pair into a new bridge node;

[0092] Delete the background nodes and original bridge nodes that have completed aggregation;

[0093] The bridge node types include first-order bridge, second-order left bridge and second-order right bridge.

[0094] Specifically, step S4 includes:

[0095] S4.1: Aggregate background node features into target nodes. The aggregation process is recorded as , and delete the aggregated background nodes;

[0096] S4.2: The bridge nodes connecting the same target node pair have similar structural semantics. Aggregate these bridge node features to generate a new bridge node connecting the target node. The aggregation process is recorded as .

[0097] More specifically, the process includes:

[0098] S4.1: Target Node , aggregate the background node features within its domain, and the aggregation formula is as follows:

[0099]

[0100] in Target node Background nodes in the neighborhood, and Background nodes and target node The eigenvector representation of It is the feature vector representation of the target node after aggregating the background nodes. After aggregating the background nodes, the aggregated background nodes are deleted to reduce the graph size;

[0101] S4.2: Bridge nodes connecting the same target node pair have similar structural semantics. Using the order of the bridge node as a distinguishing metric, bridge nodes are divided into first-order bridges and second-order bridges. At the same time, second-order bridges are further divided into second-order left bridges and second-order right bridges based on their relative position to the target node, expressed as:

[0102]

[0103] in represents a second-order left bridge, Represents a second-order right bridge. Aggregate the features of these bridge nodes with similar structures to generate new bridge nodes to connect the end target nodes. The aggregation process formula is as follows:

[0104]

[0105] in Target node and The new bridge node after aggregation between Indicates the specific type of the bridge node.

[0106] As an implementation in this embodiment, in S5, the conditions for deleting the new bridge node include:

[0107] The new bridge nodes have the same feature representation;

[0108] The source bridge node sets of the new bridge node have a non-empty intersection;

[0109] Only unique instances of redundant new bridge nodes that meet the conditions are retained.

[0110] Specifically, the steps include:

[0111] S5.1: Count the new bridge nodes with the same feature representation and analyze their source bridge nodes. If the feature representation is the same and the source bridge nodes have an intersection, it means that the graph structure of these new bridge nodes is the same, that is, they connect to the same end target node;

[0112] S5.2: Delete redundant new bridge nodes and retain the only new bridge node to complete the graph compression process, and obtain the final compressed Ethereum interaction graph for training, denoted as .

[0113] The more specific process includes:

[0114] S5.1: If the new bridge nodes after aggregation have the same feature representation and the same semantic relationship at the feature level, then analyze the source bridge nodes of their aggregation. If the feature representation is the same and the source bridge nodes have an intersection, it means that the semantics and structural information of these new bridge nodes in the graph are the same, that is, the following conditions are met:

[0115]

[0116] in Indicates the target node and The set of bridge nodes between Indicates the target node and A set of bridge nodes between them.

[0117] S5.2: New bridge nodes that meet the above conditions are considered redundant nodes. By deleting redundant new bridge nodes and retaining the only new bridge node, the network structure is refined. The graph compression is achieved by combining graph node aggregation and network structure refinement, and the final compressed Ethereum interaction graph for training is obtained, which is denoted as .

[0118] like Figure 3 As shown, the homogeneous feature enhancement model is an implementation method in this embodiment. In S6, the process of dividing the homogeneous subgraphs includes:

[0119] Generate pseudo labels using two fully connected layers without aggregating neighbor features;

[0120] Split the graph into positive homogeneous subgraphs and negative homogeneous subgraphs based on pseudo-labels;

[0121] A positive homogeneous subgraph includes nodes and edges whose pseudo-labels are all malicious;

[0122] The negative homogeneous subgraph includes nodes and edges whose pseudo labels are normal.

[0123] Specifically, step S6 includes:

[0124] S6.1: After S5, we get the compressed training graph data. In order to suppress the interference of heterogeneous information, we use two fully connected layers to learn the characteristics of the account itself, denoted as ;

[0125] S6.2: Generate pseudo labels using the pseudo label generator, denoted as ,This process does not aggregate neighbor features, thus avoiding the introduction of domain heterogeneous information,interfering with the quality of pseudo-label generation;

[0126] S6.3: Based on the pseudo-labels of nodes, the training graph is divided into positive homogeneous subgraphs and negative homogeneous subgraphs, denoted as and , and retain the edges between nodes;

[0127] S6.4: Perform homogeneous message passing and feature updates in each subgraph, and finally fuse the output representations of the two subgraphs based on attention, adding the residual of the original features to obtain the final node representation.

[0128] More specifically, step S6 includes:

[0129] S6.1: Get compressed training graph data Afterwards, considering that heterogeneous information in malicious sample networks will harm the detection performance of graph neural networks based on homogeneity assumptions, in order to suppress the interference of heterogeneous information, two fully connected layers are used to learn the characteristics of the account itself and eliminate the interference of neighboring node attributes. The formula is as follows:

[0130]

[0131] in is the Gelu activation function, and as well as and are the learnable parameters of the fully connected layer, Represents the rich embedding representation obtained by mapping the initial features into a high-dimensional space.

[0132] S6.2: Generate pseudo labels using the pseudo label generator, denoted as ,in The fully connected layer is used as a classifier. The pseudo-label generation process does not aggregate neighbor features, thus avoiding the introduction of domain heterogeneous information that interferes with the quality of pseudo-label generation;

[0133] S6.3: After assigning pseudo labels to each node, the homogeneous association between nodes can be reflected, that is, nodes with the same label have stronger homogeneous associations. Based on this, the training graph is divided into positive homogeneous subgraphs and negative homogeneous subgraphs:

[0134]

[0135] in is a pseudo label, and represent normal labels and malicious labels respectively. and Heterogeneous information is separated based on pseudo labels, so that more homogeneous information is retained in the subgraph.

[0136] S6.4: Perform homogeneous message passing and feature update based on graph neural network in each subgraph, which can be expressed as:

[0137]

[0138] in Indicates that they come from different subgraphs, For nodes From the compressed graph The node embedding matrix learned in is the layer normalization function, Represents the aggregated feature representation. Layer normalization balances the differences between subgraphs, ensuring similar scales of feature representations across subgraphs, which facilitates subsequent fusion of multi-subgraph representations. Finally, the attention mechanism is designed to fuse the output representations of the two subgraphs, while adding the residuals of the original features to obtain the final node representation. The formula is as follows:

[0139]

[0140] in and To calculate the attention score The learnable parameters of and Represent the node representations in different homogeneous subgraphs, Represented in the subgraph Middle The attention weight of each sample, This is the node representation obtained after the final fusion. Residual connections are used to alleviate the over-smoothing problem of graph neural networks, while making the final representation contain network structure information and account attribute characteristics.

[0141] Specifically, step S7 includes:

[0142] S7.1: Design an objective function to optimize the quality of pseudo-labels and introduce a penalty factor to accelerate the efficiency and accuracy of pseudo-label generation. Combined with the cross-entropy loss function, it is expressed as follows:

[0143]

[0144] in, Indicates a larger value. Indicates the The pseudo-label cross entropy loss value of the round, represents the number of samples, The change in loss between two training rounds is used as a penalty term, Represents the pseudo-label prediction function to represent the node mapped to the label dimension, and Used to control the severity of punishment.

[0145] S7.2: Use cross entropy to optimize the detection performance of the final classification task, expressed as follows:

[0146]

[0147] in, Represents the classification mapping function for malicious sample detection, and the final node is represented by Mapped to the label dimension, Represents the cross entropy loss function for predicting node labels.

[0148] Considering that the objective function is homologous to the pseudo-label objective function, and in order to simplify the optimization strategy of the system, the two loss functions are fused in an average aggregation manner, as shown below:

[0149]

[0150] Refer to the attached Figure 4 As shown, Figure 4 For Figure 1 The flowchart shown in the figure is extended to use the training model obtained based on the compressed graph to complete the detection task for the account to be detected. The specific process is as follows:

[0151] According to step S1, domain interaction information of the account to be detected is extracted, and the account is regarded as a node, and the transaction between the accounts is regarded as an edge. Based on the account's own attributes and interaction behavior, the corresponding feature representation is designed and extracted, and the initial Ethereum interaction graph based on the account to be detected is constructed and recorded as ,in is a node in the graph, is the node feature, is the known label information of the node, are interaction edges in the graph.

[0152] According to step S2, the graph is initially filtered based on the receptive field of the account to be detected and the message transmission between accounts, retaining the key information propagation structure between the accounts to be detected, specifically including the first-order and second-order propagation structure between accounts, while retaining the locally valid transaction structure of the account to be detected. By removing the remaining nodes, a preliminary simplified Ethereum interaction graph is constructed, denoted as .

[0153] According to steps S4-S7, a malicious sample detection model trained on a compressed Ethereum interaction graph is obtained. This model is used to learn the Ethereum interaction graph to be detected. Malicious sample detection is achieved by classifying the accounts to be detected, demonstrating the generalization ability of the model and the effectiveness of graph compression training. The compressed graph-based detection method proposed in this patent can greatly reduce the graph size, thereby improving the training efficiency of downstream detection models. Specific graph size statistics are shown in Table 1.

[0154] Table 1

[0155]

[0156] Table 1 reports different interaction graphs based on the training sample and test sample architectures, and also reports the scale changes before and after the network structure is refined, showing that the refinement process can effectively further reduce the graph size.

[0157] At the same time, the final test results of the proposed model are shown in Table 2, which reflects the effectiveness of the method proposed in this patent through different base models and different training methods. The specific evaluation indicators include precision, recall rate, F1 score and accuracy.

[0158] Table 2

[0159]

[0160]

[0161] Table 2 compares different training methods, with the best detection performance indicated in bold. The original version directly trains the uncompressed graph using the base model, and then uses the model for testing; graph compression trains the compressed graph using the base model, and then uses the model for testing; the patented method uses the proposed pseudo-label-guided and graph-compressed training method, and then uses the carefully designed model for subsequent testing. By comparing the performance differences of different base models under different training methods, the method proposed in this patent achieves the best detection performance, demonstrating that graph compression can preserve the original structural information of the training graph, while the downstream pseudo-label-guided malicious sample detection method can alleviate the graph heterogeneity problem, thereby achieving the best detection performance.

[0162] Based on this, an embodiment of the present invention provides a method for detecting malicious Ethereum samples using homogeneous enhanced compression modeling. This method utilizes graph compression to address the high training complexity caused by the massive scale of the Ethereum transaction network. It also designs a pseudo-label generation algorithm to address the sparse label information in malicious sample detection scenarios. Finally, it proposes a disentangled learning paradigm based on homogeneous subgraph extraction to mitigate domain heterogeneity in malicious sample detection scenarios. Based on these advantages, the present invention designs an efficient Ethereum malicious sample detection system in five modules. The data acquisition module collects domain interaction data and constructs an initial interaction graph based on the annotations and accounts to be detected; the network compression module retains and compresses the key interaction structures related to the target account according to the domain interaction information of the training annotation data, reduces the graph size and obtains a streamlined compressed Ethereum interaction graph; the homogeneity enhancement module extracts homogeneous subgraphs guided by pseudo-labels, combines the homogeneous information enhancement method within the channel, strengthens the propagation of homogeneous information between accounts, and obtains highly discriminative account representations; the model optimization module designs optimization functions for pseudo-label generation and node classification, combines a simple multi-task optimization paradigm, sets convergence conditions to optimize the model, and obtains a malicious sample detection model with generalization ability; the malicious sample detection module uses an inductive learning method to use labeled compressed Ethereum interactions to train the detection model, learns the characteristics of the account to be detected in the original Ethereum of the account to be detected, and returns the detection results.

[0163] Example 2

[0164] Based on the same general inventive concept, the present invention also provides an Ethereum malicious sample detection system based on homogeneous enhanced compression modeling, such as Figure 5 The following describes the Ethereum malicious sample detection system based on homogeneous enhanced compression modeling provided by the present invention. The Ethereum malicious sample detection system based on homogeneous enhanced compression modeling described below and the Ethereum malicious sample detection method based on homogeneous enhanced compression modeling described above can be referenced to each other. The system includes:

[0165] The data acquisition module collects domain interaction data based on the annotations and accounts to be detected and constructs an initial interaction graph;

[0166] The network compression module addresses the problem of excessive graph size during training by retaining and compressing key interaction structures related to target accounts based on domain interaction information of training annotated data, thereby reducing the graph size to obtain a streamlined compressed Ethereum interaction graph.

[0167] The homogeneity enhancement module extracts homogeneous subgraphs guided by pseudo labels and combines it with the intra-channel homogeneous information enhancement method to enhance the propagation of homogeneous information between accounts and obtain highly discriminative account representations.

[0168] The model optimization module designs optimization functions for pseudo-label generation and node classification, combines a simple multi-task optimization paradigm, sets convergence conditions for optimizing the model, and obtains a malicious sample detection model with generalization capabilities.

[0169] The malicious sample detection module learns the account characteristics in the original Ethereum interaction graph to be detected in an inductive manner based on the detection model trained on the above-mentioned labeled compressed Ethereum interaction graph, and returns the detection results.

[0170] It should be understood that the Ethereum malicious sample detection system based on homogeneous enhanced compression modeling provided by the embodiment of the present invention has all the advantages of the Ethereum malicious sample detection method based on homogeneous enhanced compression modeling provided by the above-mentioned embodiment.

[0171] Example 3

[0172] In this embodiment, a computer terminal device is provided, including:

[0173] one or more processors;

[0174] a memory, coupled to the processor, for storing one or more programs;

[0175] When the one or more programs are executed by the one or more processors, the one or more processors implement the methods in the above embodiments.

[0176] In this embodiment, a computer-readable storage medium is further provided, on which a computer program is stored. When the computer program is executed by a processor, the method in the above embodiment is implemented.

[0177] In this embodiment, an electronic device is further provided, including a memory and a processor. The memory stores a computer program, and the processor is configured to run the computer program to execute the method in the above embodiment.

[0178] The above program can be executed in a processor or stored in a memory (or computer-readable medium). Computer-readable media includes both permanent and non-permanent, removable and non-removable media, and can be implemented using any method or technology to store information. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape, disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible by a computing device.

[0179] These computer programs can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for executing on the computer or other programmable device to implement the process. Figure 1 a process or multiple processes and / or boxes Figure 1 The steps of the functions specified in one or more blocks can be implemented by different modules corresponding to different steps.

[0180] This embodiment provides such a device or system. The system is called the Ethereum malicious sample detection system based on homogeneous enhanced compression modeling, and includes:

[0181] The data acquisition module is used to extract the neighborhood interaction information of the training label accounts and construct the initial Ethereum interaction graph with accounts as nodes and transactions as edges;

[0182] The network compression module is used to retain key nodes and edges based on the message propagation mechanism to generate a preliminary simplified interaction graph, divide the target nodes / bridge nodes / background nodes, aggregate the background node features to the target nodes, and aggregate the same type of bridge nodes to form new bridge nodes. The new bridge nodes with the same features and intersections with the source bridge nodes are deleted to generate a compressed interaction graph;

[0183] The homogeneous enhancement module is used to generate pseudo labels through the fully connected layer, divide homogeneous subgraphs based on the pseudo labels, and perform message passing within each subgraph before fusion output;

[0184] Model optimization module, used to train the detection model by combining pseudo-label loss function and classification loss function;

[0185] The malicious sample detection module is used to input the interaction graph of the account to be detected into the trained detection model to output the classification results.

[0186] As an implementation method of this embodiment, the data acquisition module includes:

[0187] Node-edge definition unit, used to define accounts as nodes and transactions as edges;

[0188] Feature extraction unit, used to extract feature representation based on account attributes and interaction behaviors;

[0189] The graph structure building unit is used to define the interactive graph structure including node sets, edge sets, node features and real malicious labels.

[0190] As an implementation method of this embodiment, the network compression module includes a node classification unit, which is configured to perform:

[0191] The target node designation unit uses accounts with known labels as target nodes;

[0192] The bridge node identification unit identifies the intermediate account connecting two target nodes as a bridge node, and divides it into first-order bridge nodes and second-order bridge nodes according to the distance;

[0193] The background node identification unit identifies an account that is directly connected to only a single target node as a background node.

[0194] As an implementation method of this embodiment, the network compression module includes a feature aggregation unit, which is configured to perform:

[0195] Background aggregation subunit, aggregates the feature mean of background nodes to the corresponding target node;

[0196] The bridge node aggregation subunit aggregates the feature means of the same type of bridge nodes connecting the same target node pair into a new bridge node, wherein the types include first-order bridge, second-order left bridge and second-order right bridge;

[0197] The node deletion subunit deletes the background nodes and original bridge nodes that have completed aggregation.

[0198] As an implementation method of this embodiment, the network compression module includes a redundancy elimination unit, which is configured to perform:

[0199] Feature comparison subunit, detects whether the new bridge node has the same feature representation;

[0200] The source verification subunit verifies that the source bridge node set of the new bridge node has a non-empty intersection;

[0201] The node prunes subunits and only retains the unique instance of the new bridge node that meets the conditions.

[0202] As an implementation manner in this embodiment, the homogeneous enhancement module includes:

[0203] Pseudo-label generation unit, which uses two fully connected layers to generate pseudo-labels without aggregating neighbor features;

[0204] The subgraph partitioning unit splits the graph into positive homogeneous subgraphs and negative homogeneous subgraphs according to the pseudo-labels. The positive homogeneous subgraph contains nodes and connecting edges whose pseudo-labels are all malicious, and the negative homogeneous subgraph contains nodes and connecting edges whose pseudo-labels are all normal.

[0205] The system or device is used to implement the functions of the method in the above-mentioned embodiment. Each module in the system or device corresponds to each step in the method, which has been explained in the method and will not be repeated here.

[0206] Through the above implementation, the problem of detecting malicious Ethereum samples using homogeneous enhanced compression modeling in the related art is solved, thereby ensuring that the problems existing in the existing technology are solved.

[0207] The above are merely preferred embodiments of the present invention, but the scope of protection of the present invention is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present invention should be included in the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be based on the scope of protection of the claims.

Claims

1. A method for detecting malicious Ethereum samples based on homogeneous enhanced compression modeling, characterized in that: The following steps are involved: S1. Extract the neighborhood interaction information of the training label accounts and construct the initial Ethereum interaction graph with accounts as nodes and transactions as edges; S2, based on the message propagation mechanism and the label account receptive field, retain key nodes and edges and generate a preliminary simplified interaction graph; S3, dividing the nodes in the simplified graph into target nodes, bridge nodes connecting target node pairs, and background nodes that only interact with target nodes; S4, aggregate background node features to corresponding target nodes and delete background nodes, aggregate bridge nodes connecting the same target node pair to form a new bridge node; S5. Delete new bridge nodes with the same characteristics and intersections with the source bridge nodes to generate a compressed interaction graph; S6. Generate pseudo labels through the fully connected layer, divide homogeneous subgraphs based on the pseudo labels, perform message passing within each subgraph, and then fuse the output; The S6 includes: S6.1: After S5, we get the compressed training graph data. In order to suppress the interference of heterogeneous information, we use two fully connected layers to learn the characteristics of the account itself, denoted as ; S6.2: Generate pseudo labels using the pseudo label generator, denoted as ,This process does not aggregate neighbor features, thus avoiding the introduction of domain heterogeneous information,interfering with the quality of pseudo-label generation; S6.3: Based on the pseudo-labels of nodes, the training graph is divided into positive homogeneous subgraphs and negative homogeneous subgraphs, denoted as and , and retain the edges between nodes; S6.4: Perform homogeneous message passing and feature updates in each subgraph, and finally fuse the output representations of the two subgraphs based on attention, adding the residual of the original features to obtain the final node representation; S7, training the detection model by combining the pseudo-label loss function and the classification loss function; The S7 includes: S7.1: Design an objective function to optimize the quality of pseudo-labels and introduce a penalty factor to accelerate the efficiency and accuracy of pseudo-label generation. Combined with the cross-entropy loss function, it is expressed as follows: in, Indicates a larger value. Indicates the The pseudo-label cross entropy loss value of the round, represents the number of samples, The change in loss between two training rounds is used as a penalty term, Represents the pseudo-label prediction function to represent the node mapped to the label dimension, and Used to control the severity of punishment; S7.2: Use cross entropy to optimize the detection performance of the final classification task, expressed as follows: in, Represents the classification mapping function for malicious sample detection, and the final node is represented by Mapped to the label dimension, represents the cross entropy loss function for predicting node labels; The two loss functions are fused in an average aggregation manner, as shown below: 。 2. The method according to claim 1, characterized in that In S1, the process of constructing the initial Ethereum interaction graph includes: Accounts are considered as nodes, and transactions between accounts are considered as edges; Extract feature representation based on account attributes and interaction behaviors; Define the interaction graph structure including node set, edge set, node features and node labels; The node labels are the actual malicious attributes of known labeled accounts.

3. The method according to claim 1, characterized in that In S3, the node division process includes: Accounts with known labels are used as target nodes; The intermediate account connecting the two target nodes acts as a bridge node; Only accounts directly connected to a single target node are used as background nodes; The bridge nodes are divided into first-order bridge nodes and second-order bridge nodes according to the distance from the target node.

4. The method according to claim 1, wherein In said S4, the polymerization process includes: Aggregate the feature mean of background nodes to the corresponding target node; Aggregate the feature means of the same type of bridge nodes connecting the same target node pair into a new bridge node; Delete the background nodes and original bridge nodes that have completed aggregation; The bridge node types include first-order bridge, second-order left bridge and second-order right bridge.

5. The method according to claim 1, wherein In S5, the conditions for deleting the new bridge node include: The new bridge nodes have the same feature representation; The source bridge node sets of the new bridge node have a non-empty intersection; Only unique instances of redundant new bridge nodes that meet the conditions are retained.

6. A homogeneous enhanced compression modeling Ethereum malicious sample detection system, characterized by: For implementing the method according to any one of claims 1 to 5, the system comprises: The data acquisition module is used to extract the neighborhood interaction information of the training label accounts and construct the initial Ethereum interaction graph with accounts as nodes and transactions as edges; The network compression module is used to retain key nodes and edges based on the message propagation mechanism to generate a preliminary simplified interaction graph, divide the target nodes / bridge nodes / background nodes, aggregate the background node features to the target nodes, and aggregate the same type of bridge nodes to form new bridge nodes. The new bridge nodes with the same features and intersections with the source bridge nodes are deleted to generate a compressed interaction graph; The homogeneous enhancement module is used to generate pseudo labels through the fully connected layer, divide homogeneous subgraphs based on the pseudo labels, and perform message passing within each subgraph before fusion output; Model optimization module, used to train the detection model by combining pseudo-label loss function and classification loss function; The malicious sample detection module is used to input the interaction graph of the account to be detected into the trained detection model to output the classification results.

7. The system according to claim 6, characterized in that The data acquisition module includes: Node-edge definition unit, used to define accounts as nodes and transactions as edges; Feature extraction unit, used to extract feature representation based on account attributes and interaction behaviors; The graph structure building unit is used to define the interactive graph structure including node sets, edge sets, node features and real malicious labels.

8. A computer terminal device, characterized in that: include: one or more processors; a memory, coupled to the processor, for storing one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the Ethereum malicious sample detection method based on homogeneous enhanced compression modeling as described in any one of claims 1-5.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the Ethereum malicious sample detection method based on homogeneous enhanced compression modeling as described in any one of claims 1 to 5 is implemented.

Citation Information

Patent Citations

  • Recommendation system anomaly detection method and device based on comparative learning optimization

    CN118520400A

  • Ethereum transaction user classification method and system based on semantic motif differentiation, medium and program product

    CN119939310A