High-order semantic subspace learning enhanced block chain illegal transaction detection method

Through high-order semantic subspace learning and dynamic feature fusion methods, the problems of insufficient feature utilization and insufficient model robustness in blockchain illegal transaction detection are solved, and efficient recognition and accurate detection of complex transaction patterns are achieved.

CN120598673AInactive Publication Date: 2025-09-05XIANGTAN UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510696279.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-28
Publication Date
2025-09-05
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing technologies for detecting illegal transactions on the blockchain suffer from insufficient feature utilization, insufficient model robustness, and data imbalance, resulting in limited ability to identify complex nonlinear feature interactions.

Method used

A high-order semantic subspace learning method is adopted to train the base classifier through random subspace sampling and dynamic weight adjustment to construct a spatiotemporal feature pyramid structure. Combined with a distributed ensemble classifier, the feature importance and model parameters are dynamically adjusted to achieve cross-granularity feature enhancement.

Benefits of technology

The model's ability to identify illegal transactions has been improved, and it can automatically focus on key features, reduce the risk of overfitting, adapt to the dynamic changes of blockchain transaction data, improve detection efficiency and accuracy, and reduce hardware costs and energy consumption.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120598673A_ABST
    Figure CN120598673A_ABST
Patent Text Reader

Abstract

The invention discloses a high-order semantic subspace learning enhanced block chain illegal transaction detection method, and relates to the technical field of block chain illegal transaction detection, and the method comprises the steps: obtaining block chain transaction data, and forming an initial feature matrix; initializing a sampling weight based on the importance of the basic statistical features, carrying out multiple times of random subspace sampling on the feature space, training a corresponding base classifier for each time of sampling, and dynamically adjusting the sampling weight according to the performance of a base model on a verification set; collecting prediction probability outputs of all the base models, organizing the prediction probability outputs into a semantic meta-feature matrix, performing multi-modal fusion on semantic meta-features and original features, constructing a spatial-temporal feature pyramid structure, realizing cross-granularity feature enhancement through a dynamic weight distribution mechanism, and further constructing a distributed integrated classifier. And outputting a probability prediction result of the illegal transaction. The detection accuracy and generalization ability are improved through high-order semantic subspace learning and multi-level feature fusion.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of blockchain illegal transaction detection, and specifically to a high-order semantic subspace learning-enhanced blockchain illegal transaction detection method. Background Art

[0002] The rapid development of blockchain technology has driven the widespread adoption of cryptocurrency systems, such as Bitcoin, which offer users greater autonomy and privacy in financial transactions. However, their decentralization and anonymity also facilitate illegal activities, including money laundering, fraud, and difficult-to-trace payments. Against this backdrop, effectively identifying illegal transactions within cryptocurrency networks has become a critical issue that needs to be addressed.

[0003] Currently, methods for detecting illegal cryptocurrency transactions primarily rely on traditional machine learning models and deep learning models. Traditional shallow learning models such as decision trees, logistic regression, and random forests are typically based on manually designed statistical features, such as transaction frequency, time interval, and clustering coefficient. These methods are somewhat effective in capturing simple linear relationships, but they rely heavily on domain knowledge and manual feature engineering, have limited generalization capabilities, and perform poorly in dealing with complex nonlinear feature interactions. Furthermore, blockchain transaction data typically exists in the form of flat, low-dimensional tables, lacking clear temporal or spatial dependency structures, making it challenging for deep learning models to process such data. While methods such as convolutional neural networks and graph neural networks have performed well in modeling image, text, and sequence data, their application to flattened cryptocurrency data is more limited, and their computational complexity is high, requiring additional preprocessing.

[0004] Therefore, to address the above issues, a high-order semantic subspace learning-enhanced blockchain illegal transaction detection method is urgently needed. Summary of the Invention

[0005] In response to the shortcomings of the existing technology, the present invention provides a high-order semantic subspace learning-enhanced blockchain illegal transaction detection method, which solves the problems of insufficient feature utilization, insufficient model robustness and data imbalance in blockchain illegal transaction detection.

[0006] To achieve the above objectives, the present invention is implemented through the following technical solutions: a high-order semantic subspace learning enhanced blockchain illegal transaction detection method, comprising the following steps: step S1, obtaining blockchain transaction data, cleaning and standardizing the blockchain transaction data, extracting basic statistical features, and forming an initial feature matrix; step S2, initializing sampling weights based on the importance of basic statistical features, performing multiple random subspace samplings on the feature space, selecting a feature subset according to the current weight for each sampling, training a corresponding base classifier for each sampling, and dynamically adjusting the sampling weights according to the performance of the base model on the validation set; step S3, collecting the predicted probability outputs of all base models, organizing the predicted probability outputs into a semantic meta-feature matrix, wherein each meta-feature in the semantic meta-feature matrix corresponds to the predicted probability of a base model for a certain category; step S4, performing multimodal fusion of the semantic meta-features with the original features, constructing a spatiotemporal feature pyramid structure, and realizing cross-granular feature enhancement through a dynamic weight allocation mechanism; step S5, constructing a distributed ensemble classifier on the fused enhanced feature space, adopting an adaptive enhancement strategy to improve detection efficiency, and outputting a probability prediction result of illegal transactions.

[0007] Furthermore, the specific analysis of training the corresponding base classifier is as follows: when new blockchain transaction data is added, a feature subset of the new data is extracted, fast sampling is performed based on the current sampling weight, a new base model is automatically generated for the feature combination in the new data that is not covered by the existing base model, the subspace coverage range is expanded, all base models are jointly retrained based on the update cycle, and the model parameters are updated using the new data in the update cycle to ensure that the model adapts to the dynamic changes of blockchain transaction patterns.

[0008] Furthermore, the sampling weight initialization based on the importance of basic statistical features specifically includes: using the random forest algorithm to determine the average Gini impurity reduction of each feature of the initial feature matrix, and taking the average Gini impurity reduction of each feature as the initial importance score; normalizing the importance score to obtain a feature sampling weight vector, and evaluating the base model performance under the initial weight through 5-fold cross validation. If the accuracy of the validation set is lower than the baseline, the weight distribution is adjusted to increase the sampling probability of low-frequency features.

[0009] Furthermore, the semantic meta-feature matrix is ​​obtained by collecting the probability outputs of a preset number of base models for each sample to form a semantic meta-feature tensor, flattening the semantic meta-feature tensor into a one-dimensional vector, where each element corresponds to the prediction probability of a base model for a specific category; the meta-feature vector captures the classification confidence under different subspaces, reflecting the potential risk of the sample, and introduces an attention mechanism to weightedly amplify the meta-features corresponding to the subspaces where the base model performs well on the validation set.

[0010] Furthermore, step S4 is specifically analyzed as follows: the standardized original features are spliced ​​with the flattened meta-feature vectors at the channel level to form basic fusion features, and a three-dimensional feature pyramid is constructed, which includes three spatial dimensions: transaction granularity, address particle and network granularity. A learnable spatiotemporal attention module is set in each spatial dimension, and the cross-granularity fusion weight is calculated through the multi-head self-attention mechanism. The residual dense connection structure is used to nonlinearly fuse the low-level feature map with the high-level semantic features, and the spatiotemporal gating mechanism is introduced to dynamically adjust the conduction weights of features of different granularities according to the importance of the features.

[0011] Furthermore, the three-dimensional feature pyramid construction method is as follows: the original features are multimodally fused with the meta-feature vectors to construct a dynamic and scalable semantic pyramid structure, which includes a bottom transaction detail layer, a middle address association layer and a top semantic decision layer; local mutation features and global temporal evolution features are extracted in the bottom transaction detail layer, and a multi-head self-attention mechanism is used to capture cross-transaction correlations; a graph convolutional network module is constructed in the middle address association layer, and the receptive field is expanded through void convolution to capture the hidden topological relationship between addresses; a multi-scale feature fusion module is deployed in the top semantic decision layer, and text descriptions, numerical statistics and graph structure features are fused through a cross-granularity attention mechanism; a cross-modal aggregator is set at the top level of the pyramid, and the transmission weights of features at different levels are dynamically adjusted through a spatiotemporal gating mechanism to eliminate redundant feature interference.

[0012] Furthermore, step S5 is specifically analyzed as follows: designing a phased feature screening architecture, adopting a Transformer-based abnormal pattern capture module in the first phase, identifying high-frequency abnormal transaction fragments through the self-attention mechanism, deploying an adaptive integrated decision engine in the second phase, dynamically allocating base classifier weights based on feature importance, and optimizing the voting mechanism through reinforcement learning strategy; setting a dynamic routing layer between feature screening and decision fusion, selecting shallow fast reasoning paths or deep refined analysis paths in real time according to sample confidence, introducing an online incremental learning mechanism, actively labeling boundary samples and triggering base classifier parameter fine-tuning, synchronously updating feature importance evaluation results, adopting a federated learning framework to realize multi-party data collaborative training, protecting transaction privacy through a secure aggregation protocol, and ensuring model convergence consistency.

[0013] The present invention has the following beneficial effects:

[0014] This high-order semantic subspace learning method enhances blockchain illegal transaction detection. It initializes sampling weights based on the importance of basic statistical features and dynamically adjusts weights based on the performance of base classifiers on the validation set. It can automatically focus on the feature subset that contributes most to illegal transaction detection, avoid interference from invalid features, and improve the model's ability to recognize complex transaction patterns. For example, in cryptocurrency money laundering scenarios, it can prioritize capturing key features such as abnormal fund flows and sudden changes in transaction frequency. Multiple random subspace samplings generate multiple base classifiers, and ensemble learning is used to reduce the overfitting risk of a single model while maintaining the ability to capture diverse illegal transaction behaviors. The predicted probability of the base classifier is organized into a semantic meta-feature matrix, where each meta-feature reflects the confidence of the base model in a certain category, forming a probabilistic semantic description of the transaction behavior. The semantic meta-features are combined with the original features through multimodal fusion to construct a spatiotemporal feature pyramid structure, achieving local-level classification. Multi-granularity feature enhancement from local (single transaction) to global (transaction network); constructing a distributed ensemble classifier on the enhanced feature space, supporting parallel processing of massive blockchain transaction data, significantly improving detection efficiency; by dynamically adjusting the weights of the base classifier (such as the AdaBoost mechanism), focusing on difficult-to-classify samples (such as illegal behaviors disguised as normal transactions), continuously improving detection accuracy; dynamic weight adjustment and multimodal fusion mechanisms enable the model to adapt to the dynamic changes of blockchain transaction data, avoiding performance degradation due to data distribution drift; the semantic meta-feature matrix and spatiotemporal feature pyramid structure provide an intermediate representation of the model decision, which facilitates tracing the identification basis of illegal transactions by analyzing the distribution of the base model prediction probability; reducing feature dimensions through random subspace sampling, and combining distributed ensemble classifiers to reduce the computing load of a single node, it is suitable for resource-constrained environments, while ensuring detection accuracy, reducing hardware costs and energy consumption. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] Figure 1 This is a flow chart of the method for detecting illegal transactions on blockchain using high-order semantic subspace learning enhanced by the present invention. DETAILED DESCRIPTION

[0016] The embodiment of the present application enhances the blockchain illegal transaction detection method through a high-order semantic subspace learning, thereby improving the detection accuracy and generalization ability through the fusion of high-order semantic subspace learning and multi-level features.

[0017] The overall idea of ​​the embodiments of the present application is: to clean and process blockchain transaction data and extract basic features, train the base classifier through random subspace sampling and dynamic weight adjustment, convert the base model prediction probability into semantic meta-features and fuse them with the original features, construct a spatiotemporal feature pyramid to enhance the features, and use a distributed integrated classifier to output the illegal transaction detection results.

[0018] See also Figure 1The embodiment of the present invention provides a technical solution: a high-order semantic subspace learning-enhanced blockchain illegal transaction detection method, comprising the following steps: step S1, obtaining blockchain transaction data, cleaning and standardizing the blockchain transaction data, extracting basic statistical features, and forming an initial feature matrix; step S2, initializing sampling weights based on the importance of basic statistical features, performing multiple random subspace samplings on the feature space, selecting a feature subset based on the current weight for each sampling, training a corresponding base classifier for each sampling, and dynamically adjusting the sampling weights based on the performance of the base model on the validation set; step S3, collecting the predicted probability outputs of all base models, organizing the predicted probability outputs into a semantic meta-feature matrix, wherein each meta-feature in the semantic meta-feature matrix corresponds to the predicted probability of a base model for a certain category; step S4, performing multimodal fusion of the semantic meta-features with the original features to construct a spatiotemporal feature pyramid structure, and achieving cross-granular feature enhancement through a dynamic weight allocation mechanism; step S5, constructing a distributed ensemble classifier on the fused enhanced feature space, adopting an adaptive enhancement strategy to improve detection efficiency, and outputting a probability prediction result for illegal transactions.

[0019] Specifically, the specific steps of step S1 are: real-time synchronization or batch pulling of original transaction data from the blockchain network to construct an original transaction data set. The original transaction data includes but is not limited to the following Table 1:

[0020]

[0021]

[0022] Table 1

[0023] In this implementation plan, the original transaction data is pulled from the blockchain network in real time or in batches, covering multiple dimensions such as basic transaction information, address information, network topology information, and smart contract information, which can fully record the full picture of blockchain transactions; basic statistical features are extracted and an initial feature matrix is ​​formed to convert the original transaction data into a structured and computable feature representation, which is convenient for subsequent model processing. These basic statistical features can characterize transaction characteristics from multiple angles, such as the mean and variance of the transaction amount reflect the fluctuation of the transaction amount, and the in-degree and out-degree of the address reflect the activity and importance of the address in the network. The rich and representative feature matrix provides sufficient information for subsequent subspace sampling and base classifier training. Sufficient information helps to explore potential patterns and regularities in the data and improve the model's ability to express illegal transaction characteristics; as the starting step of the entire detection method, the initial feature matrix it outputs is the basis for subsequent steps. An accurate initial feature matrix can make the sampling weight initialization based on feature importance in step S2 more reasonable and improve the effectiveness of random subspace sampling; it provides a reliable source of original data for the construction of the semantic meta-feature matrix in step S3, thereby affecting the quality of multimodal fusion and the construction of spatiotemporal feature pyramids; ultimately determines the input quality of the distributed ensemble classifier, plays a key role in the accuracy and efficiency of illegal transaction detection, and ensures that the entire detection method can run stably and efficiently.

[0024] Specifically, the specific steps of step S2 are: using the random forest algorithm to train the initial feature matrix generated in step S1, and determining the contribution of each feature to the classification result by calculating the Gini impurity reduction of each feature in each decision tree of the random forest; taking the average of the Gini impurity reduction of the same feature in all decision trees to obtain the average Gini impurity reduction of each feature as the initial importance score; normalizing the average Gini impurity reduction of all features so that the sum of all weights is 1 to form a feature sampling weight vector; each element in the weight vector corresponds to the sampling probability of a feature, and the feature with a higher importance score has a greater probability of being selected in the sampling; setting the number of base models and the proportion of subspace features (such as selecting 50% of the features each time sampling), based on the current sampling weight vector, using the roulette method to perform multiple random samplings on the feature space, and generating a feature subset each time sampling; for each feature subset, using the gradient boosting algorithm (such as LightGBM) to train a base classifier, the base classifier The input is the feature subset obtained by sampling, and the output is the probability prediction result of the transaction category; when there is new blockchain transaction data, the feature subset of the new data is extracted, and rapid sampling is performed based on the current sampling weight to determine whether the feature combination of the new data has been covered by the existing base model; for the uncovered feature combination (such as the feature combination corresponding to the new transaction mode), a new base classifier is automatically generated to expand the coverage of the feature subspace; an update cycle is set (such as weekly), and at the end of the update cycle, all base models are jointly retrained using the new data within the cycle; by re-inputting the new data, the parameters of the base model are adjusted to ensure that the model can adapt to the dynamic changes of the blockchain transaction mode, such as the emergence of new illegal transaction methods; after each training is completed, the performance of each base model is evaluated using the validation set. If the performance of the base model on the validation set is better than the average level, the sampling weight of its corresponding feature subset is increased. If the performance is lower than the average level, the sampling probability of the corresponding feature is reduced, forming a closed loop of "sampling-training-feedback-adjustment".

[0025] The specific analysis of training the corresponding base classifier is as follows: when new blockchain transaction data is added, the feature subset of the new data is extracted, and fast sampling is performed based on the current sampling weight. A new base model is automatically generated for the feature combination in the new data that is not covered by the existing base model, and the subspace coverage is expanded. All base models are jointly retrained based on the update cycle, and the model parameters are updated using the new data in the update cycle to ensure that the model adapts to the dynamic changes of blockchain transaction patterns.

[0026] Initializing sampling weights based on basic statistical feature importance specifically includes: using the random forest algorithm to determine the average Gini impurity reduction of each feature in the initial feature matrix, and taking the average Gini impurity reduction of each feature as the initial importance score; normalizing the importance score to obtain the feature sampling weight vector, and evaluating the performance of the base model under the initial weights through 5-fold cross-validation. If the accuracy of the validation set is lower than the baseline, the weight distribution is adjusted to increase the sampling probability of low-frequency features.

[0027] In this implementation, a base classifier refers to a single classification model trained on a feature subset obtained through random sampling. Each base classifier focuses on learning a subdomain of the feature space (such as the "transaction amount anomaly" subspace or the "address interaction pattern" subspace). By inputting differentiated feature subsets, it captures illegal transaction patterns of different dimensions. The base model and base classifier have the same meaning, specifically referring to an independent model trained on a specific feature subset. The probability distribution of its output is used to construct semantic meta-features. The combination of different base models forms a multi-angle coverage of the original feature space.

[0028] The specific steps for dynamically adjusting sampling weights are as follows: Evaluate the classification performance of each base model on the validation set, collecting metrics such as accuracy, recall, and F1 score, with a focus on detecting illegal transactions; correlate the performance of the base model with the corresponding feature subsets, and analyze which feature subsets contribute most to improving model performance (e.g., a base model achieves an F1 score of 0.92 on the "address creation time + transaction frequency" subset); for base models with excellent performance, proportionally increase the sampling weight of their feature subsets (e.g., by 10%-15%) to increase the probability of appearance of this subspace in subsequent sampling; for base models with poor performance, reduce the sampling weight of their feature subsets (e.g., by 5%-10%) to reduce the sampling frequency of invalid subspaces; for low-frequency features (e.g., "smart contract call parameters"), maintain a certain sampling probability (e.g., no less than 5%) even if the corresponding base model has average performance to avoid missing new risk patterns due to sampling bias; and after adjustment, normalize the sampling weights of all features to ensure that the sum of the weight vectors is 1, maintaining a reasonable sampling probability.

[0029] The steps of using the random forest algorithm to evaluate feature importance are as follows: use the initial feature matrix to train the random forest model, set the number of trees (such as 100 trees), and randomly select some samples and features for splitting each decision tree during training to form a diversified decision path; in the process of splitting each node of each decision tree, calculate the sum of the Gini impurity of the node before the split and the Gini impurity of the child node after the split, and the difference between the two is the reduction in the Gini impurity of the feature at the current node; accumulate the Gini impurity reduction of each feature in each decision tree to obtain the importance contribution of the feature in the entire tree; calculate the average importance contribution of the same feature in all decision trees as the average Gini impurity reduction of the feature; sort the features according to the average Gini impurity reduction, identify the key features that have the greatest impact on the classification results (such as "transaction amount abnormality" and "address in-degree"), and provide a basis for subsequent sampling weight setting.

[0030] The average Gini impurity reduction measures the contribution of a feature to the classification results. Specifically, it is expressed as the average reduction in sample class confusion caused by using that feature in the splitting process of the random forest decision tree. A larger value indicates that the feature is more capable of distinguishing illegal transactions from legitimate ones. For example, a high average Gini impurity reduction for "the shortest path length between an address and a known illegal address" indicates that this feature effectively helps the model identify risky transactions associated with illegal addresses.

[0031] Through random subspace sampling, different base models are forced to focus on differentiated feature combinations, and high-order semantic feature interactions that are difficult to design manually are automatically discovered, such as the combined risk of "large transfers at 3 a.m. + new addresses + counterparties with multiple unfamiliar addresses"; dynamic adjustment of sampling weights enables the model to adaptively strengthen effective subspaces (such as the recently frequently appearing "cross-chain bridge transaction" feature subset), suppress invalid subspaces, and reduce overfitting risks; a new data-triggered base model automatic generation mechanism can quickly expand the coverage of feature subspaces when new illegal transaction patterns (such as new currency mixing protocols) emerge; through weight-guided sampling, priority is given to important feature subsets to reduce invalid calculations of redundant features; a regular joint retraining mechanism enables the model to track changes in the distribution of blockchain transaction data, avoiding degradation of detection performance due to data drift.

[0032] Specifically, the specific steps of step S3 are as follows: for each base model trained in step S2, the sample feature subset processed in step S1 is input to obtain the predicted probability of each base model for the sample belonging to each transaction category; for each sample, the predicted probabilities of all base models are arranged in order according to the base model number and category number to form a two-dimensional semantic meta-feature tensor, in which rows correspond to base models and columns correspond to transaction categories; the two-dimensional semantic meta-feature tensor is flattened into a one-dimensional vector according to the row-first principle, where each element corresponds to the predicted probability of a base model for a specific category, forming a meta-feature vector; the length of the meta-feature vector is "number of base models × number of transaction categories", for example, the predicted probabilities of 25 base models for three categories of transactions are flattened to form a 75-dimensional meta-feature vector; the meta-feature vector is denoised by removing low-contribution dimensions through principal component analysis (PCA) or singular value decomposition (SVD), retaining feature dimensions that can reflect differences in the confidence of the main classification; the meta-feature vector of each sample is associated with its unique identifier (such as the transaction hash value) and stored to form a sample-meta-feature mapping table, which is convenient for subsequent fusion with the original features and model training call.

[0033] The semantic meta-feature matrix is ​​obtained as follows: for each sample, the probability outputs of a preset number of base models are collected to form a semantic meta-feature tensor, and the semantic meta-feature tensor is flattened into a one-dimensional vector, where each element corresponds to the prediction probability of a base model for a specific category; the meta-feature vector captures the classification confidence in different subspaces, reflecting the potential risk of the sample, and by introducing the attention mechanism, the meta-features corresponding to the subspaces where the base model performs well on the validation set are weighted and amplified.

[0034] In this embodiment, the steps of capturing classification confidence by the meta-feature vector are as follows: each base model corresponds to a feature subspace (such as the "transaction amount abnormality subspace" and the "address interaction subspace"), and its predicted probability reflects the confidence level that the sample in the subspace belongs to a certain type of transaction. For example, the base model A predicts the illegal transaction class of a certain sample in the "large transfer subspace" with a probability of 0.85, indicating that the subspace believes that there is an 85% probability that the sample is an illegal transaction; the meta-feature vector linearly combines the subspace confidences of all base models to form a multi-angle description of the sample risk. For example, the meta-feature vector of sample X is 0.85. Among them, the illegal transaction probability of base model A (large transfer subspace) is 0.85, the illegal transaction probability of base model B (new address subspace) is 0.72, and the normal transaction probability of base model C (normal transaction subspace) is 0.90. By combining these confidence levels, the risk level of sample X can be comprehensively judged. The distribution of each element in the meta-feature vector is analyzed to identify subspace combinations with high confidence. For example, if the illegal transaction prediction probabilities of multiple base models (such as large transfer, new address, and abnormal time subspaces) are all higher than a threshold (such as 0.7), then the sample is judged to have a composite risk pattern and requires special attention.

[0035] The steps of weighted amplification of the attention mechanism are as follows: quantitatively evaluate the performance of each base model on the validation set, calculate its detection index for illegal transactions, and identify base models with excellent performance; rank the importance of the corresponding subspaces according to the performance indicators of the base models. For example, the F1 score of base model D in the "dark web address interaction subspace" is 0.92, ranking in the top 10%, and its corresponding subspace is marked as a high-importance subspace; assign higher attention weights to the meta-features corresponding to the high-importance subspaces. For example, the weight of the meta-feature corresponding to base model D is increased from the default 1. 0 to 1.5 to enhance its influence in feature fusion; regularly (such as after each round of training) re-evaluate the performance of the base model, adjust the attention weight according to the latest results, if the performance of a base model declines (such as the F1 score is lower than the threshold of 0.8), reduce the weight of its corresponding meta-feature; if the performance of the new base model is outstanding, increase its weight; before concatenating the meta-feature vector with the original feature, multiply each element in the meta-feature vector by its corresponding attention weight to form a weighted meta-feature vector, so that the classification confidence of the high-importance subspace occupies a larger proportion in the final feature space.

[0036] By converting the subspace prediction probability of the base model into a structured meta-feature vector and using the attention mechanism to enhance the confidence of the key subspace, we achieve "multi-perspective capture and key enhancement" of blockchain transaction risks. This not only retains the differentiated judgment of each subspace, but also dynamically focuses on high-value subspaces through the attention mechanism, solving the problem of difficulty in capturing risk patterns in flat data, and providing rich semantic information support for subsequent multi-level feature fusion and classification decisions.

[0037] Specifically, step S4 is analyzed as follows: the standardized original features are spliced ​​with the flattened meta-feature vectors at the channel level to form basic fusion features, and a three-dimensional feature pyramid is constructed, which includes three spatial dimensions: transaction granularity, address particle and network granularity. A learnable spatiotemporal attention module is set in each spatial dimension, and the cross-granularity fusion weight is calculated through the multi-head self-attention mechanism. The residual dense connection structure is used to nonlinearly fuse the low-level feature map with the high-level semantic features, and the spatiotemporal gating mechanism is introduced to dynamically adjust the conduction weights of features of different granularities according to the importance of the features.

[0038] The three-dimensional feature pyramid construction method is as follows: the original features are multimodally fused with the meta-feature vectors to construct a dynamic and scalable semantic pyramid structure, which includes a bottom-level transaction details layer, a middle-level address association layer, and a top-level semantic decision layer; local mutation features and global temporal evolution features are extracted in the bottom-level transaction details layer, and a multi-head self-attention mechanism is used to capture cross-transaction correlations; a graph convolutional network module is constructed in the middle-level address association layer, and the receptive field is expanded through void convolution to capture the hidden topological relationship between addresses; a multi-scale feature fusion module is deployed in the top-level semantic decision layer, and text descriptions, numerical statistics, and graph structure features are integrated through a cross-granularity attention mechanism; a cross-modal aggregator is set at the top level of the pyramid, and the transmission weights of features at different levels are dynamically adjusted through a spatiotemporal gating mechanism to eliminate redundant feature interference.

[0039] In this implementation plan, transaction granularity mainly focuses on the individual details of blockchain transactions, corresponding to the bottom transaction details layer in the three-dimensional feature pyramid, covering the specific attributes and dynamic changes of a single transaction, such as transaction amount, transaction timestamp, transaction type (transfer, contract call, etc.), handling fee and other information. It is used to capture the local mutation characteristics of each transaction (such as a sudden surge in amount) and global temporal evolution characteristics (such as the changing trend of transaction frequency over a period of time), to help identify abnormal behavior in a single transaction.

[0040] Address particles focus on the correlation between blockchain addresses, corresponding to the middle address correlation layer in the three-dimensional feature pyramid. Blockchain addresses are regarded as nodes in the network. By analyzing information such as the flow of funds, transaction frequency, and common counterparties between addresses, an address correlation network is constructed. Using technologies such as graph convolutional networks, hidden topological relationships between addresses are captured, such as discovering address clusters and core control addresses, thereby identifying illegal transactions involving the coordination of multiple addresses, such as the fund transfer network of money laundering gangs.

[0041] Network granularity describes the characteristics of the entire blockchain network from a macro perspective, corresponding to the top-level semantic decision layer in the three-dimensional feature pyramid. It integrates the information of transaction granularity and address particles, and combines the global properties of the blockchain network, such as the total transaction volume of the entire network, average transaction fees, on-chain activity and other statistical features, as well as multimodal information such as transaction-related text descriptions (such as smart contract code semantics). Through the multi-scale feature fusion module and cross-modal aggregator, it analyzes transaction patterns and trends from the perspective of the entire network and identifies illegal behaviors that affect the security of the entire network, such as large-scale network attacks or systematic fraud.

[0042] The specific analysis of calculating the cross-granularity fusion weight through the multi-head self-attention mechanism is as follows: the features of the three spatial dimensions of transaction granularity, address granularity and network granularity are linearly transformed and mapped to different feature subspaces to obtain the query vector (Query), key vector (Key) and value vector (Value); in multiple independent "heads", the attention score of each dimension feature is calculated separately. For each "head", the attention score is obtained by calculating the dot product of the query vector and the key vector, and then dividing it by the scaling factor (to prevent the dot product from being too large and causing the gradient to disappear); then the attention score is normalized using the softmax function to obtain the attention weight; finally, the attention weight is multiplied by the value vector and summed to obtain the output of each "head"; the outputs of multiple "heads" are spliced ​​and mapped back to the original feature dimension through linear transformation to obtain the fused feature representation; based on the fused feature representation, the contribution of each granularity feature to the final result is calculated to generate the cross-granularity fusion weight for subsequent weighted fusion of features of different granularities.

[0043] The specific analysis of the residual dense connection structure and spatiotemporal gating mechanism is as follows: In the network structure, low-level feature maps are directly connected to the input or intermediate layers of the high-level network through skip connections, forming residual connection paths. At the same time, dense connections are established between feature maps at different levels. That is, the input of each layer contains not only the output of the previous layer, but also the feature maps of all previous layers. This allows low-level features to participate more directly in the calculation of high-level features, enhances the network's ability to reuse features, and prevents gradients from disappearing during propagation. For each spatial dimension and level of feature map, the feature map is compressed into a one-dimensional vector through operations such as global average pooling. The importance score of each feature is calculated through a fully connected layer and activation function, reflecting the degree of influence of the feature on the final illegal transaction detection results. Based on the feature importance score, the spatiotemporal gating weight is calculated for each feature, combining information from the temporal and spatial dimensions. Based on the calculated spatiotemporal gating weight, features of different granularities and levels are weighted. Highly important features are given larger weights to make them dominate the feature transmission process. Unimportant features are given lower weights to reduce their impact on subsequent calculations. In this way, the conduction paths and intensities of features with different granularity are dynamically adjusted to achieve adaptive screening and enhancement of features.

[0044] The construction of a three-dimensional feature pyramid and the analysis of operations at each layer are as follows: a dynamic and extensible semantic pyramid structure is constructed, which includes a bottom-level transaction detail layer, a middle-level address association layer, and a top-level semantic decision layer. The hierarchical relationship and data flow between the layers are clarified. The bottom-level features are gradually transferred to the upper layers after processing, and the upper-level features can also be used as feedback to adjust the calculations of the lower layers.

[0045] The operational analysis of the underlying transaction details layer is as follows: for the standardized raw transaction data, sliding windows and local feature extraction algorithms are used to extract the local mutation features of each transaction (such as sudden changes in transaction amounts, abnormal transaction time intervals) and global temporal evolution features (such as trends in transaction amounts over a period of time, periodic changes in transaction frequency); the extracted transaction features are input into the multi-head self-attention mechanism, and by calculating the attention weights between different transaction features, the correlation between cross-transactions is captured, such as discovering multiple transactions with similar transaction patterns and exploring potential illegal transaction gang behavior.

[0046] The operation analysis of the middle-level address association layer is as follows: based on the transaction relationship between blockchain addresses, an address association graph is constructed, with addresses as nodes and transactions as edges, and weights are assigned to edges (such as transaction amount, number of transactions, etc.); a graph convolutional network is deployed on the address association graph, and appropriate graph convolution operations are designed to update the feature representation of nodes by aggregating the feature information of node neighbors; using the void convolution technology, the receptive field of the graph convolutional network is expanded without increasing too much computational effort, so that it can capture hidden topological relationships between addresses at longer distances, such as discovering money laundering paths that transfer funds through multiple intermediate addresses.

[0047] The top-level semantic decision-making layer operation analysis is as follows: the transaction detail features from the bottom layer, the address association features from the middle layer, as well as additional text description features (such as smart contract code semantics), numerical statistical features (such as the total transaction volume and average fee of the entire network) and graph structure features (such as the topological properties of the address network) are input into the multi-scale feature fusion module. Through the cross-granularity attention mechanism, the attention weights between features of different scales and types are calculated, and the features are weightedly fused according to the weights to highlight the feature combinations that are more important for illegal transaction detection and form a high-level semantic feature representation.

[0048] The cross-modal aggregator at the top of the pyramid operates as follows: The fused features output by the top semantic decision layer, along with features from other modalities (such as text, numerical values, and graph structures), are fed into the cross-modal aggregator. Based on the importance of features at each level and the spatiotemporal information of the current transaction, spatiotemporal gating weights are calculated to assess the contribution of features at different levels to illegal transaction detection in the current scenario. Based on the spatiotemporal gating weights, features at different levels are weighted and aggregated to enhance the impact of key features and suppress interference from redundant features. In this way, the feature transmission path is dynamically adjusted, so that the final output feature representation is more focused on core information related to illegal transactions, improving detection accuracy and efficiency.

[0049] By constructing a three-dimensional feature pyramid including transaction granularity, address particles and network granularity, the blockchain transaction data is structured and expressed from different angles, which can fully capture transaction details (such as fluctuations in the amount of a single transaction), relationships between addresses (such as the fund transfer network) and overall network characteristics (such as the transaction pattern of the entire network). Compared with single-dimensional feature analysis, it improves information utilization and effectively mines the patterns behind complex illegal transactions; the spatiotemporal attention module and spatiotemporal gating mechanism, based on the multi-head self-attention mechanism and feature importance evaluation, can dynamically adjust the weights and transmission paths of features of different granularities. When processing massive transaction data, it can automatically focus on key features and suppress noise interference. For example, when identifying money laundering transactions, it can quickly locate illegal transactions. The combination of relevant core features reduces the impact of irrelevant information on detection results and improves detection accuracy; the use of multi-head self-attention mechanism, graph convolutional network and void convolution and other technologies can effectively capture the long-range dependency between spatiotemporal features and the hidden topological relationship between addresses. For complex illegal transaction scenarios involving multiple addresses and multiple transactions, the semantic logic behind the transaction can be fully mined; the residual dense connection structure enhances the network's ability to reuse features at different levels, avoids the gradient vanishing problem, and enables the model to maintain stable performance when facing newly emerging illegal transaction patterns; the dynamically scalable semantic pyramid structure can adapt to changes in data scale and feature dimension, improve model generalization, and reduce detection errors in different blockchain network scenarios.

[0050] Specifically, step S5 is analyzed as follows: design a phased feature screening architecture. In the first phase, a Transformer-based abnormal pattern capture module is adopted to identify high-frequency abnormal transaction fragments through the self-attention mechanism. In the second phase, an adaptive integrated decision engine is deployed to dynamically allocate base classifier weights based on feature importance, and the voting mechanism is optimized through reinforcement learning strategy. A dynamic routing layer is set between feature screening and decision fusion to select shallow and fast reasoning paths or deep and refined analysis paths in real time according to sample confidence. An online incremental learning mechanism is introduced to actively label boundary samples and trigger base classifier parameter fine-tuning. The feature importance evaluation results are updated synchronously. A federated learning framework is used to realize multi-party data collaborative training. Transaction privacy is protected through a secure aggregation protocol to ensure model convergence consistency.

[0051] The specific analysis of the phased feature screening architecture is as follows: In the first phase of the Transformer-based abnormal pattern capture module, the basic fusion features are divided into fixed-length segments according to the transaction time series, and input into the multi-head self-attention mechanism. By calculating the attention weights between different transaction segments, key segments containing high-frequency abnormal behaviors (such as high-frequency small transfers in a short period of time, abnormal fund flows between addresses) are identified; at the same time, position encoding technology is used to retain transaction timing information, and the key segments are enhanced with the feedforward neural network to output the abnormal pattern feature vector.

[0052] The adaptive integrated decision engine in the second phase calculates the contribution of each base classifier to different types of transaction samples based on the Shapley value and dynamically adjusts the voting weight of the base classifier. For complex transaction scenarios, a reinforcement learning algorithm is used to build a policy network, with detection accuracy and false alarm rate as reward functions to optimize the combination strategy of the base classifier. When a new illegal transaction pattern is detected, a dynamic weight adjustment mechanism is triggered to increase the weight of the base classifier with strong recognition ability of the pattern.

[0053] The dynamic routing layer analyzes the abnormal pattern feature vector through the gated recurrent unit (GRU) and calculates the prediction confidence of the sample. If the confidence is higher than the preset threshold, the shallow fast inference path is selected to directly output the voting result of the base classifier. If the confidence is lower than the threshold, the sample is sent to the deep and refined analysis path and a secondary judgment is made based on the high-level semantic features of the three-dimensional feature pyramid.

[0054] The online incremental learning mechanism calculates the uncertainty of samples based on entropy values ​​and prioritizes boundary samples with high uncertainty for active labeling. The labeled samples are added to the training set, triggering parameter fine-tuning of the base classifier and updating the feature weights in the feature importance evaluation module. During the parameter update process, gradient truncation technology is used to prevent gradient explosion and ensure model stability.

[0055] In the federated learning framework, a secure multi-party computing protocol is designed to realize the encrypted interaction of data among all participants, and homomorphic encryption technology is used to aggregate model parameters in the ciphertext state. A model consistency verification mechanism is introduced to eliminate abnormal model updates by calculating the cosine similarity of the model parameters of each participant, thereby ensuring the consistency and reliability of the global model convergence.

[0056] In this implementation plan, the specific analysis of dynamically allocating weights based on feature importance is as follows: for each base classifier, the Shapley value is used to calculate the contribution of each feature to the final decision in the classification process of different transaction samples (such as normal transactions, known illegal transactions, and new suspicious transactions), forming a feature importance score matrix; according to the feature importance score, an initial voting weight is assigned to each base classifier. For example, a base classifier that is good at identifying "abnormal address associations" is given a higher weight when processing transactions involving complex address networks. The prediction performance of the base classifier on real-time transaction data is continuously monitored, and indicators such as prediction accuracy and false alarm rate are recorded. If a base classifier continuously misjudges a specific type of transaction (such as large-scale cross-border transfers), its voting weight is reduced; conversely, if the performance is excellent, the weight is increased to achieve dynamic adaptation of the weight.

[0057] The specific analysis of optimizing the voting mechanism through reinforcement learning strategy is as follows: all base classifiers and their current voting weights, transaction samples to be classified, and historical detection results are used as the reinforcement learning environment; the state space is constructed with the base classifier weight vector, sample feature vector, historical detection accuracy and false alarm rate as state variables; it is defined as a set of operations to adjust the voting weight of the base classifier, such as "increase the weight of base classifier A by 0.1" and "reduce the weight of base classifier B by 0.05", etc.; if the classification result is correct and the false alarm rate is reduced, a positive reward (such as +10 points) is given; if the classification result is wrong or the false alarm rate increases, a negative reward is given. (e.g., -20 points); a deep neural network (e.g., a multilayer perceptron) is used to construct a policy network, with state variables as input and the output being the execution probability of each action; by continuously interacting with the environment (i.e., classifying transaction samples and receiving reward feedback), the policy network parameters are updated using Q-learning or the Deep Q Network (DQN) algorithm to maximize the cumulative reward; based on the trained policy network, the optimal action is selected when processing new transaction samples, and the voting weights of the base classifiers are dynamically adjusted; as new transaction data flows in, the policy network is continuously trained to adapt to changes in transaction patterns and optimize the voting mechanism.

[0058] In the first stage, the Transformer-based abnormal pattern capture module uses the self-attention mechanism to quickly locate high-frequency abnormal transaction fragments, such as identifying suspicious patterns such as "high-frequency small-amount transfers across regions in a short period of time"; in the second stage, the adaptive integrated decision engine dynamically adjusts the weights of the base classifiers to make refined judgments on complex transactions and improve the accuracy of illegal transaction detection; the dynamic routing layer intelligently selects the inference path according to the sample confidence, directly outputs the results for high-confidence samples, and reduces the consumption of computing resources; for low-confidence samples, it combines in-depth analysis of the three-dimensional feature pyramid to avoid missed detection and improve the overall inference efficiency; the entropy value is used to quantify the sample inaccuracy. Deterministically, it actively labels boundary samples and fine-tunes base classifier parameters to quickly adapt to new illegal transaction patterns; it evaluates the contribution of base classifiers based on Shapley values, and combines reinforcement learning to optimize voting strategies guided by detection accuracy and false alarm rate, automatically enhancing the ability to identify emerging risk patterns and reducing manual intervention costs; through secure multi-party computing protocols and homomorphic encryption technology, it achieves multi-party data collaborative training while protecting data privacy, breaking down data silos; the model consistency verification mechanism detects abnormal parameter updates through cosine similarity, preventing malicious node attacks or data deviations from causing model failure, and ensuring global model convergence stability.

[0059] In summary, this application has at least the following effects:

[0060] Through data cleaning and standardization, data quality is guaranteed, laying the foundation for subsequent analysis; random subspace sampling and dynamic weight adjustment mechanism enhance the model's generalization ability and avoid overfitting; semantic meta-feature matrix and multimodal fusion mine high-order semantic information of data and improve feature expression ability; spatiotemporal feature pyramid structure and dynamic weight allocation effectively integrate features of different granularity; distributed integrated classifiers and adaptive enhancement strategies improve detection efficiency and accuracy, and can quickly and accurately identify illegal blockchain transactions, reducing missed detection and false detection rates.

[0061] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0062] The present invention is described with reference to flowcharts of methods according to embodiments of the present invention. It should be understood that each combination of processes in the flowcharts can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts. Figure 1 A device that specifies functions in a process or multiple processes.

[0063] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A function specified in a process or multiple processes.

[0064] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 The steps of a specified function in a process or multiple processes.

[0065] Although the preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present invention.

[0066] Obviously, those skilled in the art may make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if such changes and modifications fall within the scope of the claims and their equivalents, the present invention is intended to include such changes and modifications.

Claims

1. A high-order semantic subspace learning-enhanced blockchain illegal transaction detection method, characterized by: The following steps are involved: Step S1: Obtain blockchain transaction data, clean and standardize the blockchain transaction data, extract basic statistical features, and form an initial feature matrix; Step S2: Initialize sampling weights based on the importance of basic statistical features, perform multiple random subspace samplings on the feature space, select feature subsets based on the current weights for each sampling, train a corresponding base classifier for each sampling, and dynamically adjust the sampling weights based on the performance of the base model on the validation set; Step S3: Collect the predicted probability outputs of all base models and organize the predicted probability outputs into a semantic meta-feature matrix, where each meta-feature in the semantic meta-feature matrix corresponds to the predicted probability of a base model for a certain category; Step S4: Multimodally fuse the semantic meta-features with the original features to construct a spatiotemporal feature pyramid structure, and achieve cross-granularity feature enhancement through a dynamic weight allocation mechanism; In step S5, a distributed ensemble classifier is constructed on the fused enhanced feature space, an adaptive enhancement strategy is adopted to improve detection efficiency, and a probability prediction result of illegal transactions is output.

2. The method for detecting illegal transactions in blockchain using high-order semantic subspace learning enhancement according to claim 1 is characterized in that: The specific analysis of training the corresponding base classifier is as follows: when new blockchain transaction data is added, a feature subset of the new data is extracted, fast sampling is performed based on the current sampling weight, a new base model is automatically generated for the feature combination in the new data that is not covered by the existing base model, the subspace coverage range is expanded, all base models are jointly retrained based on the update cycle, and the model parameters are updated using the new data in the update cycle to ensure that the model adapts to the dynamic changes of blockchain transaction patterns.

3. The high-order semantic subspace learning-enhanced blockchain illegal transaction detection method according to claim 1 is characterized in that: Initializing the sampling weights based on the importance of basic statistical features specifically includes: using a random forest algorithm to determine the average Gini impurity reduction of each feature on the initial feature matrix, and using the average Gini impurity reduction of each feature as the initial importance score; The importance scores are normalized to obtain the feature sampling weight vector. The performance of the base model under the initial weights is evaluated through 5-fold cross-validation. If the accuracy of the validation set is lower than the baseline, the weight distribution is adjusted to increase the sampling probability of low-frequency features.

4. The method for detecting illegal transactions in blockchain using high-order semantic subspace learning enhancement according to claim 1 is characterized in that: The semantic meta-feature matrix is ​​obtained by collecting the probability outputs of a preset number of base models for each sample to form a semantic meta-feature tensor, flattening the semantic meta-feature tensor into a one-dimensional vector, where each element corresponds to the predicted probability of a certain base model for a specific category; The meta-feature vector captures the classification confidence in different subspaces and reflects the potential risk of the sample. By introducing the attention mechanism, the meta-features corresponding to the subspaces where the base model performs well on the validation set are weighted and amplified.

5. The high-order semantic subspace learning-enhanced blockchain illegal transaction detection method according to claim 1 is characterized in that: The specific analysis of step S4 is as follows: the standardized original features are spliced ​​with the flattened meta-feature vectors at the channel level to form basic fusion features, and a three-dimensional feature pyramid is constructed, which includes three spatial dimensions: transaction granularity, address particle and network granularity. A learnable spatiotemporal attention module is set in each spatial dimension, and the cross-granularity fusion weight is calculated through the multi-head self-attention mechanism. The residual dense connection structure is used to nonlinearly fuse the low-level feature map with the high-level semantic features. The spatiotemporal gating mechanism is introduced to dynamically adjust the conduction weights of features of different granularities according to the importance of the features.

6. The high-order semantic subspace learning-enhanced blockchain illegal transaction detection method according to claim 5 is characterized in that: The three-dimensional feature pyramid construction method is as follows: the original features are multimodally fused with the meta-feature vectors to construct a dynamic and scalable semantic pyramid structure, which includes a bottom transaction detail layer, a middle address association layer, and a top semantic decision layer; At the bottom transaction detail layer, local mutation features and global temporal evolution features are extracted, and a multi-head self-attention mechanism is used to capture cross-transaction correlations. A graph convolutional network module is constructed at the middle address association layer, and the receptive field is expanded through void convolution to capture the hidden topological relationship between addresses. A multi-scale feature fusion module is deployed at the top semantic decision layer, and text descriptions, numerical statistics and graph structure features are integrated through a cross-granularity attention mechanism. A cross-modal aggregator is set at the top level of the pyramid, and the transmission weights of features at different levels are dynamically adjusted through a spatiotemporal gating mechanism to eliminate redundant feature interference.

7. The method for detecting illegal transactions in blockchain using high-order semantic subspace learning enhancement according to claim 1 is characterized in that: The specific analysis of step S5 is as follows: designing a phased feature screening architecture. In the first phase, a Transformer-based abnormal pattern capture module is used to identify high-frequency abnormal transaction fragments through a self-attention mechanism. In the second phase, an adaptive integrated decision engine is deployed to dynamically assign base classifier weights based on feature importance and optimize the voting mechanism through a reinforcement learning strategy. A dynamic routing layer is set up between feature screening and decision fusion. The shallow fast reasoning path or the deep refined analysis path is selected in real time according to the sample confidence. An online incremental learning mechanism is introduced to actively label boundary samples and trigger fine-tuning of base classifier parameters. The feature importance evaluation results are updated synchronously. A federated learning framework is used to realize multi-party data collaborative training. The transaction privacy is protected through a secure aggregation protocol to ensure model convergence consistency.