Cross-chain-bridge abnormal transaction detection method and device based on multi-agent cooperation

By using a multi-agent collaborative method to construct a cross-chain transaction information flow diagram and mine the account-role-authority relationship, combined with a rule engine to detect abnormal transactions, the accuracy problem of cross-chain bridge abnormal transaction detection is solved, and efficient cross-chain bridge abnormal transaction detection is achieved.

CN120634727APending Publication Date: 2025-09-12SUN YAT SEN UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510770770.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-10
Publication Date
2025-09-12

AI Technical Summary

Technical Problem

Existing technologies can only mine transaction information on a single chain, and it is difficult to restore the complete transaction process of the cross-chain bridge, resulting in the inability to meet the accuracy requirements of abnormal transaction detection on the cross-chain bridge.

Method used

A multi-agent collaboration-based method is adopted to construct a cross-chain transaction information flow diagram through data analysis agents, and a heterogeneous graph neural network is constructed using graph analysis agents to mine account-role-authority allocation relationships. Abnormal transaction detection is then performed in combination with anomaly detection agents and rule engines.

Benefits of technology

It achieves accurate cross-chain bridge abnormal transaction detection, solves the accuracy problem of cross-chain bridge abnormal transaction detection in existing technologies, is suitable for a variety of cross-chain scenarios, improves detection efficiency and accuracy, and reduces reliance on manual intervention.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120634727A_ABST
    Figure CN120634727A_ABST
Patent Text Reader

Abstract

The invention discloses a cross-chain bridge abnormal transaction detection method and device based on multi-agent collaboration, and the method comprises the steps: constructing a cross-chain transaction information flow graph based on a data analysis agent according to the transaction data, relay data and log data of a cross-chain transaction; and based on a graph analysis agent, according to the cross-chain transaction information flow graph, constructing a heterogeneous graph neural network used for mining a potential account-role-permission distribution relationship in the cross-chain transaction information flow graph. And based on the anomaly detection agent, according to the output of the heterogeneous graph neural network, combining a rule engine and a preset classifier to realize anomaly transaction detection. Through multi-agent cooperation, accurate cross-chain-bridge abnormal transaction detection is realized, and the technical problem that in the prior art, only transaction information on a single chain can be mined, a complete cross-chain-bridge transaction process is difficult to recover, and the accuracy requirement of cross-chain-bridge abnormal transaction detection cannot be met is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of blockchain technology, and in particular to a method and device for detecting abnormal transactions across a cross-chain bridge based on multi-agent collaboration. Background Art

[0002] With the development of blockchain technology, different blockchain platforms coexist within the blockchain ecosystem. This multi-chain ecosystem presents high demands for cross-chain communication, giving rise to cross-chain bridges, which specialize in providing cross-chain services. A cross-chain bridge is a specialized decentralized application consisting of smart contracts deployed on multiple chains. It coordinates cross-chain transactions by introducing off-chain relays, enabling the exchange of assets and data between different blockchain platforms. Cross-chain bridges involve both on-chain smart contracts and off-chain relay verification, as well as information exchange and security verification between the source and target chains. This design leads to numerous potential security vulnerabilities in the cross-chain bridge workflow, resulting in numerous incidents of asset theft or anomalous transfers. Existing technologies can only mine transaction information on a single chain. However, transactions on a cross-chain bridge involve three parties: the source chain, the off-chain relay, and the target chain. Transaction information on a single chain is insufficient to fully recover the complete transaction flow of the cross-chain bridge, making accurate detection of anomalous cross-chain transactions difficult. Summary of the Invention

[0003] The present invention provides a method and device for detecting abnormal transactions on a cross-chain bridge based on multi-agent collaboration, which is used to solve the technical problem that the existing technology can only mine transaction information on a single chain and is difficult to restore the complete transaction process of the cross-chain bridge, resulting in the inability to meet the accuracy requirements of abnormal transaction detection on the cross-chain bridge.

[0004] In view of this, the first aspect of the present invention provides a cross-chain bridge abnormal transaction detection method based on multi-agent collaboration, comprising:

[0005] Based on the data analysis agent, a cross-chain transaction information flow diagram is constructed according to the transaction data, relay data and log data of the cross-chain transaction;

[0006] Based on the cross-chain transaction information flow graph, a graph analysis agent is used to construct a heterogeneous graph neural network to mine the potential account-role-permission allocation relationship in the cross-chain transaction information flow graph. The output of the heterogeneous graph neural network includes account embedding vectors, account role sets, and role permission sets.

[0007] Based on the anomaly detection agent, according to the output of the heterogeneous graph neural network, combined with the rule engine and preset classifier, abnormal transaction detection is performed to obtain the cross-chain bridge abnormal transaction detection results.

[0008] Optionally, based on the data parsing agent, a cross-chain transaction information flow diagram is constructed according to the transaction data, relay data, and log data of the cross-chain transaction, including:

[0009] Based on the first model and the first executor in the data parsing agent, a cross-chain transaction information flow diagram is constructed according to the transaction data, relay data and log data of the cross-chain transaction.

[0010] Optionally, based on the first model and the first executor in the data parsing agent, a cross-chain transaction information flow graph is constructed according to the transaction data, relay data, and log data of the cross-chain transaction, including:

[0011] Based on the first model in the data analysis agent, locate the cross-chain bridge contract address;

[0012] Parse the cross-chain bridge contract application binary interface based on the first model in the data parsing agent;

[0013] Based on the first model in the data parsing agent, according to the cross-chain bridge contract application binary interface, the core APIs of different chains are called to obtain the transaction data, relay data and log data of cross-chain transactions;

[0014] Based on the first executor in the data parsing agent, the transaction data, relay data and log data of cross-chain transactions are parsed and converted into a unified data format to construct a cross-chain transaction information flow diagram.

[0015] Optionally, based on the graph analysis agent, a heterogeneous graph neural network is constructed according to the cross-chain transaction information flow graph to mine potential account-role-authority allocation relationships in the cross-chain transaction information flow graph, including:

[0016] Based on the second model and the second executor in the graph analysis agent, a heterogeneous graph neural network is constructed according to the metadata of the cross-chain transaction information flow graph to mine the potential account-role-authority allocation relationship in the cross-chain transaction information flow graph.

[0017] Optionally, based on the second model and the second executor in the graph analysis agent, a heterogeneous graph neural network is constructed according to the metadata of the cross-chain transaction information flow graph to mine potential account-role-authority allocation relationships in the cross-chain transaction information flow graph, including:

[0018] Based on the second model in the graph analysis agent, a heterogeneous graph neural network is constructed;

[0019] Based on the second executor in the graph analysis agent, the characteristics of the cross-chain transaction information flow graph are used as the input of the heterogeneous graph neural network to generate a high-dimensional account embedding vector. By calculating the similarity between the high-dimensional account embedding vector and the characteristics of the cross-chain core role, the account-role-authority allocation relationship is obtained. Among them, the cross-chain core roles are divided into six categories: ordinary users, managers, vaults, routers, executors, and other roles.

[0020] Optionally, based on the anomaly detection agent, abnormal transaction detection is performed according to the output of the heterogeneous graph neural network, combined with the rule engine and the preset classifier to obtain the cross-chain bridge abnormal transaction detection results, including:

[0021] A third model based on anomaly detection agents generates dynamic detection strategies;

[0022] The third executor based on the anomaly detection agent executes a dynamic detection strategy to detect anomalies in the transaction data of cross-chain transactions and obtains cross-chain transaction anomaly detection results. The cross-chain transaction anomaly detection results include whether there is an anomaly in the transaction and the type of anomaly.

[0023] Dynamic detection strategies include:

[0024] Taking high-dimensional account embedding vectors as input features, a pre-built classifier is used to output outliers.

[0025] Using the account role set and role permission set as input, a rule engine is used to classify abnormal transactions.

[0026] Optionally, the rule engine includes a correspondence between security modes and abnormal transaction categories, and the correspondence between security modes and abnormal transaction categories is:

[0027] The safety modes include a first safety mode, a second safety mode, a third safety mode, a fourth safety mode, a fifth safety mode, a sixth safety mode, and a seventh safety mode;

[0028] The first security mode corresponds to a fake deposit transaction. The first security mode is: the deposit address is equal to the vault address, the number of tokens deposited in the deposit event is equal to the increase in the vault account balance, and the token type deposited in the deposit event is equal to the token contract address to be deposited;

[0029] The second security mode corresponds to illegal permission transactions. The second security mode is: the function called by the user belongs to the permission of the user role, and the parameters passed by the user must meet the restrictions of the calling function;

[0030] The third security mode corresponds to the fake routing forwarding transaction. The third security mode is: the generation address of the deposit event is equal to the routing role or vault address;

[0031] The fourth security mode corresponds to an erroneous withdrawal transaction. The fourth security mode is: the account balance of the vault role decreases by an amount equal to the number of tokens to be withdrawn, and the type of token withdrawn in the withdrawal event is equal to the contract address of the token to be withdrawn;

[0032] The fifth security mode corresponds to permissionless withdrawal transactions. The fifth security mode is: the initiator of the withdrawal transaction is the executor role, and the function called by the withdrawal path belongs to the permission of the router role;

[0033] The sixth safety mode and abnormally large withdrawal transactions: The sixth safety mode is: the withdrawal token quantity is less than the threshold;

[0034] The seventh security mode corresponds to abnormal arbitrage transactions. The seventh security mode is: the transfer function cannot be called multiple times in a transaction and the target address must be the same user.

[0035] The second aspect of the present invention provides a cross-chain bridge abnormal transaction detection device based on multi-agent collaboration, comprising:

[0036] The data parsing agent module is used to build a cross-chain transaction information flow diagram based on the transaction data, relay data, and log data of the cross-chain transaction based on the data parsing agent;

[0037] The graph analysis agent module is used to build a heterogeneous graph neural network based on the graph analysis agent and the cross-chain transaction information flow graph to mine the potential account-role-permission allocation relationship in the cross-chain transaction information flow graph. The output of the heterogeneous graph neural network includes the account embedding vector, the account role set, and the role permission set;

[0038] The anomaly detection agent module is used to detect abnormal transactions based on the output of the heterogeneous graph neural network, combined with the rule engine and preset classifier, to obtain the cross-chain bridge abnormal transaction detection results.

[0039] Optionally, the data parsing agent module is specifically used to:

[0040] Based on the first model and the first executor in the data parsing agent, a cross-chain transaction information flow diagram is constructed according to the transaction data, relay data and log data of the cross-chain transaction.

[0041] Optionally, the data parsing agent module is specifically used to:

[0042] Based on the first model in the data analysis agent, locate the cross-chain bridge contract address;

[0043] Parse the cross-chain bridge contract application binary interface based on the first model in the data parsing agent;

[0044] Based on the first model in the data parsing agent, according to the cross-chain bridge contract application binary interface, the core APIs of different chains are called to obtain the transaction data, relay data and log data of cross-chain transactions;

[0045] Based on the first executor in the data parsing agent, the transaction data, relay data and log data of cross-chain transactions are parsed and converted into a unified data format to construct a cross-chain transaction information flow diagram.

[0046] From the above technical solutions, it can be seen that the cross-chain bridge abnormal transaction detection method based on multi-agent collaboration provided by the present invention has the following advantages:

[0047] The present invention provides a cross-chain bridge abnormal transaction detection method based on multi-agent collaboration. The method uses a data analysis agent to construct a cross-chain transaction information flow graph based on the transaction data, relay data, and log data of the cross-chain transaction. The method uses a graph analysis agent to construct a heterogeneous graph neural network based on the cross-chain transaction information flow graph to mine potential account-role-authority allocation relationships in the cross-chain transaction information flow graph. The method uses an anomaly detection agent to perform anomaly detection on the transaction data of cross-chain transactions based on the output of the heterogeneous graph neural network. The method obtains cross-chain bridge abnormal transaction detection results, achieving accurate cross-chain bridge abnormal transaction detection. This solves the technical problem that the existing technology can only mine transaction information on a single chain and is difficult to restore the complete transaction process of the cross-chain bridge, resulting in an inability to meet the accuracy requirements of cross-chain bridge abnormal transaction detection.

[0048] At the same time, the cross-chain bridge abnormal transaction detection method based on multi-agent collaboration provided by the present invention constructs a rule engine, and combines the rule engine and heterogeneous graph neural network to identify cross-chain bridge abnormal transactions. It is suitable for various cross-chain scenarios and has a wide range of applications.

[0049] Furthermore, the cross-chain bridge abnormal transaction detection method based on multi-agent collaboration provided by the present invention uses a heterogeneous graph neural network to perform role mining on the cross-chain transaction information flow graph, which can effectively obtain the account authority allocation relationship contained in the graph data, solving the technical problem that the existing technology lacks the ability to mine account authority allocation relationships in the cross-chain transaction information flow graph.

[0050] The cross-chain bridge abnormal transaction detection method based on multi-agent collaboration provided by the present invention fully calls on the capabilities of the large language model, and realizes data cleaning, data analysis, feature mining and anomaly identification through the collaboration of multiple agents. It solves the technical problem that the existing technology is highly dependent on manual intervention in cross-chain data governance, especially in the acquisition, cleaning and standardization of multi-chain data, which requires a lot of manpower to adapt, filter and unify the format of heterogeneous data sources, resulting in low efficiency and the risk of subjective errors. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying any creative work.

[0052] Figure 1This is a flow chart of a method for detecting abnormal transactions on a cross-chain bridge based on multi-agent collaboration, provided in an embodiment of the present invention;

[0053] Figure 2 This is a schematic diagram of the structure of the cross-chain transaction information flow diagram provided in an embodiment of the present invention;

[0054] Figure 3 This is a schematic diagram of the structure of a cross-chain bridge abnormal transaction detection device based on multi-agent collaboration provided in an embodiment of the present invention;

[0055] Figure 4 This is a structural diagram of a cross-chain bridge abnormal transaction detection device based on multi-agent collaboration provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0056] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.

[0057] For easier understanding, see Figure 1 The present invention provides an embodiment of a cross-chain bridge abnormal transaction detection method based on multi-agent collaboration, comprising:

[0058] Step 101: Based on the data parsing agent, a cross-chain transaction information flow diagram is constructed according to the transaction data, relay data and log data of the cross-chain transaction.

[0059] It should be noted that a cross-chain bridge is an intermediary for the exchange of assets and data between different blockchain platforms. It is composed of smart contracts deployed on different blockchain platforms and off-chain relays. Cross-chain transactions are divided into three phases: deposit / locking phase on the source chain, relay verification phase, and withdrawal / minting phase on the target chain.

[0060] Phase 1: Deposit / locking on the source chain. The user first initiates a transaction request to the routing contract, exchanging assets from the source chain for assets on the target chain. After receiving the cross-chain request, the routing contract calls the token contract to lock the user's assets, effectively depositing them into the cross-chain bridge. Finally, the token contract executes a deposit event, which can be captured by the off-chain relay.

[0061] Phase 2: Relay Verification. Off-chain relays fall into two categories: centralized third-party institutions, which rely on their own assets and credit to guarantee user security; and decentralized relay chains, which rely on validators on the relay chain to ensure the security of cross-chain transactions. Centralized institutions employ a traditional credit guarantee model, which lacks transparency and auditability and is beyond the scope of this research. During the relay verification process on the relay chain, the off-chain relay nodes of the relay chain capture and parse deposit events issued on the source chain, then send the parsed results to the signature contract, which is then called by the validator to generate a signature to verify the legitimacy and authenticity of the cross-chain transaction.

[0062] Phase 3: Withdrawal / minting on the target chain. The relay node initiates a transaction request to the routing contract on the target chain, sending the target chain's assets to the user's address. Upon receiving the request, the routing contract verifies the relay signature and user permissions. Once verified, it calls the token contract to release and execute the withdrawal event. Finally, the assets are sent to the user's address.

[0063] As you can see, the cross-chain bridge initiates transactions on both the source and target chains. These transactions are considered external transactions. Transactions on blockchains are categorized into two types: external transactions and internal transactions. External transactions are initiated by externally owned accounts (EOA). EOA accounts are controlled by private keys and are typically associated with individual user wallets. These transactions include operations such as transferring funds or invoking smart contracts. Internal transactions are not actual transactions. They occur when a user initiates an external transaction to a smart contract. The resulting inter-contract calls triggered by the smart contract during execution are internal transactions, which contain a wealth of data, including the function call parameters, function output values, and event logs. Therefore, when a transaction is initiated on a chain, in addition to the external transaction itself, several internal transactions may also exist.

[0064] A Large Language Model (LLM) is an AI system based on the Transformer architecture and trained on massive amounts of text. It can read, understand, and generate natural language, just like humans. By analyzing and understanding natural language, LLMs can handle a variety of tasks, from text generation to complex reasoning, enabling interaction with humans. Existing high-performance large models include GPT-4, DeepSeek-R1, and Claude 3.7 Sonnet.

[0065] An intelligent agent is a computing entity capable of environmental perception, autonomous decision-making, and action execution. For example, the control system in a self-driving car is an intelligent agent, analyzing road conditions in real time and deciding whether to accelerate or brake. An intelligent agent consists of two parts: a large language model and an actuator. The relationship between these two parts is similar to that of a "body" and a "brain." The large language model provides the agent with action strategies through semantic parsing and logical reasoning, while the actuator implements specific actions by invoking tools and executing code, translating the language model's ideas into actual actions. These two components form a closed "cognition-execution" loop.

[0066] In this embodiment of the present invention, the primary task of the data parsing agent is to understand user commands expressed in natural language and break them down into executable steps. This step-by-step process involves acquiring and cleaning multi-chain data, parsing the raw data, and finally structuring the data graph to construct a high-quality cross-chain transaction information flow diagram for subsequent analysis. Users simply issue commands to the data parsing agent, which then autonomously completes the task. The large language model within the data parsing agent, based on semantic understanding and contextual reasoning of user commands, transforms abstract requirements into executable technical operation chains. For example, when a user inputs "Monitor all cross-chain stablecoin transfers exceeding $100,000 between Ethereum and Binance Smart Chain," the model uses pre-trained cross-chain financial knowledge to identify key elements (source chain, target chain, asset type, threshold, etc.), then activates the Chain of Thought (CoT) reasoning mechanism. First, the large language model in the data parsing agent locates the relevant cross-chain bridge contract address. Second, the large language model in the data parsing agent parses the contract application binary interface (ABI) to capture transfer events. Third, the large language model in the data parsing agent calls the core application programming interface (API) of different chains to obtain external and internal transaction information. Fourth, based on the transaction information, the executor in the data parsing agent parses the transaction data, relay data, and log data of the cross-chain transactions into a unified data format, constructing a cross-chain transaction information flow graph. This process dynamically adjusts the reasoning path through a self-attention mechanism, ultimately outputting a structured task list to guide the data parsing agent's execution.

[0067] The executor in the data parsing agent, based on the task list generated by the large language model, autonomously calls the API interface adapted to different blockchain protocols to complete the data closed loop. It obtains transaction data on heterogeneous chains and parses and converts it into a unified data format, and finally constructs a cross-chain transaction information flow diagram. The structure of the cross-chain transaction information flow diagram here is as follows:

[0068] The structural diagram of the cross-chain transaction information flow diagram is as follows: Figure 2 As shown, cross-chain transactions consist of three parts: transactions on the source chain, relay verification, and transactions on the target chain. External transactions initiated by users on the source chain serve as the entry point. Internal transactions between cross-chain bridge smart contracts are derived from these external transactions. Some transactions trigger events (such as deposit events). Transaction data on the relay chain connects the transaction data on the source and target chains, resulting in a complete cross-chain transaction information flow diagram. The cross-chain transaction information flow diagram has three types of nodes: account / relay nodes, transaction nodes, and log nodes. Account / relay nodes represent the various account addresses involved in cross-chain transactions, including user accounts, contract accounts, and relay accounts. Transaction nodes contain rich information, including contract functions, function parameter values, and function output values. Log nodes represent event records generated during smart contract execution, containing information about specific events or state changes that occurred during the transaction. Every transaction is initiated by an account node and targeted at another account node. Contract functions invoked during a transaction may generate event records, so transaction nodes may also generate log nodes. Therefore, the data parsing agent's input is commands described in natural language, and its output is a cross-chain transaction information flow diagram. By relaying data, it connects the transaction data on the source and target chains, fully restoring the transaction call chain of the cross-chain bridge. This can be used to accurately identify abnormal cross-chain transactions.

[0069] Step 102: Based on the graph analysis agent, a heterogeneous graph neural network is constructed according to the cross-chain transaction information flow graph to mine potential account-role-authority allocation relationships in the cross-chain transaction information flow graph, wherein the output of the heterogeneous graph neural network includes an account embedding vector, an account role set, and a role permission set.

[0070] It should be noted that the main task of the graph analysis agent is to accept the cross-chain transaction information flow graph provided by the data analysis agent and build a heterogeneous graph neural network to mine the potential "account-role-authority" allocation relationship in the graph.

[0071] The cross-chain transaction information flow diagram obtained in step 101 contains numerous account nodes, each representing an external account or contract account, and each account belongs to a specific role. Transaction nodes contain contract function information, and the account initiating the transaction node has permission to call that function. Therefore, each function is a permission assigned to a specific role. For example, a regular user has permission to deposit funds but not to change the routing address. Role mining technology can generate a "role-permission matrix" from massive amounts of transaction data, assign permissions to roles, and then assign each account to a corresponding role. This "role-permission matrix" allows consistency checks between roles and permissions, quickly determining whether an account node has called a contract function that exceeds its permission range.

[0072] The large language model in the graph analysis agent automatically constructs a heterogeneous graph neural network for "account-role-authority" mining based on the metadata of the cross-chain transaction information flow graph (node ​​type, edge relationship, attribute dimension).

[0073] The executor in the graph analysis agent inputs the time-series data stream of the cross-chain transaction information flow graph into a heterogeneous graph neural network, and generates a high-dimensional account embedding vector (dimension = 256) through the graph attention aggregation layer. This vector represents the cross-chain behavior pattern of the account, including the topological characteristics of capital flow (transaction frequency, number of associated contracts), the diversity of asset interactions (token type, cross-chain path), and the sensitivity of permissions (contract call depth). At the same time, the executor simultaneously loads the cross-chain account role library defined by human experts. This library classifies accounts participating in the cross-chain ecosystem into the following six core roles: ordinary users, managers, vaults, routers, executors, and other roles. The definitions of the six core roles are as follows:

[0074] Normal Users: ordinary users who participate in cross-chain transactions.

[0075] Owners: Those who have the authority to change contract configurations and manage contract operations.

[0076] Treasures: A role that manages cross-chain bridge assets and can receive and transfer assets.

[0077] Routers: Responsible for cross-chain message delivery.

[0078] Executors: Roles responsible for executing cross-chain operations.

[0079] Other roles: Other participants who do not belong to the above roles, such as the governance and voting roles of the cross-chain bridge ecosystem.

[0080] Finally, the similarity between the high-dimensional account embedding vector and the core role features is calculated (excluding abnormal discrete values ​​in the embedding vector). Similar accounts and the permissions they invoke are assigned to corresponding roles. The output is the account role assignment result and the corresponding permission set of the role.

[0081] Therefore, the input to the graph analysis agent is the cross-chain transaction information flow graph, and the output is the account embedding vector, the account role set, and the role permission set (all three of which are input to the anomaly detection agent in step 103). Leveraging the power of large language models, this agent can deeply explore the characteristics of cross-chain transaction behavior, effectively improving the ability and efficiency of detecting abnormal transaction behavior.

[0082] Step 103: Based on the anomaly detection agent, abnormal transaction detection is performed according to the output of the heterogeneous graph neural network, combined with the rule engine and the preset classifier to obtain the cross-chain bridge abnormal transaction detection results.

[0083] It should be noted that the main task of the anomaly detection agent is to detect whether transactions contain anomalies based on the account embedding vectors, account role sets, and role permission sets provided by the graph analysis agent, combined with a rule engine developed by human experts and a pre-set classifier. The pre-set classifier is a multilayer perceptron (MLP) classifier.

[0084] The anomaly detection agent's large language model generates dynamic detection strategies based on account roles and permission sets. This dynamic detection strategy includes: 1. Using high-dimensional account embedding vectors as input features, a pre-configured classifier outputs outliers; 2. Using account role sets and role permission sets as input, a rule engine is used to classify abnormal transactions. Table 1 shows the rule engine, which maps security modes to abnormal transaction classifications. Security modes include the first, second, third, fourth, fifth, sixth, and seventh security modes.

[0085] The first security mode corresponds to a fake deposit transaction. The first security mode is: the deposit address is equal to the vault address and the number of tokens deposited in the deposit event is equal to the increase in the vault account balance, and the token type deposited in the deposit event is equal to the token contract address to be deposited.

[0086] The second security mode corresponds to illegal permission transactions. The second security mode is: the function called by the user belongs to the permission of the user role, and the parameters passed by the user should meet the restrictions of the called function.

[0087] The third security mode corresponds to the fake routing forwarding transaction. The third security mode is: the generation address of the deposit event is equal to the routing role or vault address.

[0088] The fourth security mode corresponds to an erroneous withdrawal transaction. The fourth security mode is: the account balance of the vault role decreases by a value equal to the number of tokens to be withdrawn, and the token type extracted in the withdrawal event is equal to the contract address of the token to be withdrawn.

[0089] The fifth security mode corresponds to the permissionless withdrawal transaction. The fifth security mode is: the initiator of the withdrawal transaction is the executor role, and the function called by the withdrawal path belongs to the permission of the routing role.

[0090] The sixth safety mode is related to abnormally large withdrawal transactions. The sixth safety mode is: the number of withdrawal tokens is less than the threshold.

[0091] The seventh security mode corresponds to abnormal arbitrage transactions. The seventh security mode is: the transfer function cannot be called multiple times in a transaction and the target address must be the same user.

[0092] Table 1 Correspondence between security modes and abnormal transaction classifications

[0093]

[0094] The executor of the anomaly detection agent is responsible for executing the aforementioned strategy. Outliers in the account embedding vector are marked as "abnormal transactions." Transactions that violate the rule engine are not only marked as "abnormal transactions," but also output the type of anomaly. Therefore, the input to the anomaly detection agent is the account embedding vector, the account role set, and the role permission set. The output is whether the transaction is an abnormal transaction and, if so, the type of anomaly it belongs to.

[0095] The multi-agent collaborative cross-chain bridge abnormal transaction detection method provided in the embodiments of the present invention uses a data parsing agent as the entry point. Users initiate requests through natural language instructions. The data parsing agent uses a large language model to parse the instructions and break them down into cross-chain data collection, cleaning, and structuring processes, constructing a unified cross-chain transaction information flow graph. The graph analysis agent is then called to mine the potential associations between account roles and permissions using a heterogeneous graph neural network based on the cross-chain transaction information flow graph, generating role embedding vectors and permission sets. Finally, the anomaly detection agent integrates a rule engine with a pre-set classifier to dynamically detect transaction anomalies, achieving an end-to-end autonomous risk control closed loop from semantic understanding to risk decision-making, and outputting abnormal transaction detection results. This approach leverages the efficiency and performance advantages of multi-agent collaboration to achieve rapid dynamic detection of cross-chain abnormal transactions.

[0096] The present invention provides a cross-chain bridge abnormal transaction detection method based on multi-agent collaboration. The method uses a data analysis agent to construct a cross-chain transaction information flow graph based on the transaction data, relay data, and log data of the cross-chain transaction. The method uses a graph analysis agent to construct a heterogeneous graph neural network based on the cross-chain transaction information flow graph to mine potential account-role-authority allocation relationships in the cross-chain transaction information flow graph. The method uses an anomaly detection agent to perform anomaly detection on the transaction data of cross-chain transactions based on the output of the heterogeneous graph neural network. The method obtains cross-chain bridge abnormal transaction detection results, achieving accurate cross-chain bridge abnormal transaction detection. This solves the technical problem that the existing technology can only mine transaction information on a single chain and is difficult to restore the complete transaction process of the cross-chain bridge, resulting in an inability to meet the accuracy requirements of cross-chain bridge abnormal transaction detection.

[0097] At the same time, the cross-chain bridge abnormal transaction detection method based on multi-agent collaboration provided by the present invention constructs a rule engine, and combines the rule engine and heterogeneous graph neural network to identify cross-chain bridge abnormal transactions. It is suitable for various cross-chain scenarios and has a wide range of applications.

[0098] Furthermore, the cross-chain bridge abnormal transaction detection method based on multi-agent collaboration provided by the present invention uses a heterogeneous graph neural network to perform role mining on the cross-chain transaction information flow graph, which can effectively obtain the user permission information contained in the graph data, solving the technical problem that the existing technology lacks the ability to mine account permission allocation relationships in the cross-chain transaction information flow graph.

[0099] The cross-chain bridge abnormal transaction detection method based on multi-agent collaboration provided by the present invention fully calls on the capabilities of the large language model, and realizes data cleaning, data analysis, feature mining and anomaly identification through the collaboration of multiple agents. It solves the technical problem that the existing technology is highly dependent on manual intervention in cross-chain data governance, especially in the acquisition, cleaning and standardization of multi-chain data, which requires a lot of manpower to adapt, filter and unify the format of heterogeneous data sources, resulting in low efficiency and the risk of subjective errors.

[0100] For easier understanding, see Figure 3 The present invention provides an embodiment of a cross-chain bridge abnormal transaction detection device based on multi-agent collaboration, comprising:

[0101] The data parsing agent module is used to build a cross-chain transaction information flow diagram based on the transaction data, relay data, and log data of the cross-chain transaction based on the data parsing agent;

[0102] The graph analysis agent module is used to build a heterogeneous graph neural network based on the graph analysis agent and the cross-chain transaction information flow graph to mine the potential account-role-permission allocation relationship in the cross-chain transaction information flow graph. The output of the heterogeneous graph neural network includes the account embedding vector, the account role set, and the role permission set;

[0103] The anomaly detection agent module is used to detect abnormal transactions based on the output of the heterogeneous graph neural network, combined with the rule engine and preset classifier, to obtain the cross-chain bridge abnormal transaction detection results.

[0104] In one embodiment, the data parsing agent module is specifically used to:

[0105] Based on the first model and the first executor in the data parsing agent, a cross-chain transaction information flow diagram is constructed according to the transaction data, relay data and log data of the cross-chain transaction.

[0106] In one embodiment, the data parsing agent module is specifically used to:

[0107] Based on the first model in the data analysis agent, locate the cross-chain bridge contract address;

[0108] Parse the cross-chain bridge contract application binary interface based on the first model in the data parsing agent;

[0109] Based on the first model in the data parsing agent, according to the cross-chain bridge contract application binary interface, the core APIs of different chains are called to obtain the transaction data, relay data and log data of cross-chain transactions;

[0110] Based on the first executor in the data parsing agent, the transaction data, relay data and log data of cross-chain transactions are parsed and converted into a unified data format to construct a cross-chain transaction information flow diagram.

[0111] In one embodiment, the graph analysis agent module is specifically configured to:

[0112] Based on the second model and the second executor in the graph analysis agent, a heterogeneous graph neural network is constructed according to the metadata of the cross-chain transaction information flow graph to mine the potential account-role-authority allocation relationship in the cross-chain transaction information flow graph.

[0113] In one embodiment, the graph analysis agent module is specifically configured to:

[0114] Based on the second model in the graph analysis agent, a heterogeneous graph neural network is constructed;

[0115] Based on the second executor in the graph analysis agent, the characteristics of the cross-chain transaction information flow graph are used as the input of the heterogeneous graph neural network to generate a high-dimensional account embedding vector. By calculating the similarity between the high-dimensional account embedding vector and the characteristics of the cross-chain core role, the account-role-authority allocation relationship is obtained. Among them, the cross-chain core roles are divided into six categories: ordinary users, managers, vaults, routers, executors, and other roles.

[0116] In one embodiment, the anomaly detection agent module is specifically configured to:

[0117] A third model based on anomaly detection agents generates dynamic detection strategies;

[0118] The third executor based on the anomaly detection agent executes a dynamic detection strategy to detect anomalies in the transaction data of cross-chain transactions and obtains cross-chain transaction anomaly detection results. The cross-chain transaction anomaly detection results include whether there is an anomaly in the transaction and the type of anomaly.

[0119] Dynamic detection strategies include:

[0120] Taking high-dimensional account embedding vectors as input features, a pre-built classifier is used to output outliers.

[0121] Using the account role set and role permission set as input, a rule engine is used to classify abnormal transactions.

[0122] In one embodiment, the rule engine includes a correspondence between security modes and abnormal transaction categories. The correspondence between security modes and abnormal transaction categories is:

[0123] The safety modes include a first safety mode, a second safety mode, a third safety mode, a fourth safety mode, a fifth safety mode, a sixth safety mode, and a seventh safety mode;

[0124] The first security mode corresponds to a fake deposit transaction. The first security mode is: the deposit address is equal to the vault address, the number of tokens deposited in the deposit event is equal to the increase in the vault account balance, and the token type deposited in the deposit event is equal to the token contract address to be deposited;

[0125] The second security mode corresponds to illegal permission transactions. The second security mode is: the function called by the user belongs to the permission of the user role, and the parameters passed by the user must meet the restrictions of the calling function;

[0126] The third security mode corresponds to the fake routing forwarding transaction. The third security mode is: the generation address of the deposit event is equal to the routing role or vault address;

[0127] The fourth security mode corresponds to an erroneous withdrawal transaction. The fourth security mode is: the account balance of the vault role decreases by an amount equal to the number of tokens to be withdrawn, and the type of token withdrawn in the withdrawal event is equal to the contract address of the token to be withdrawn;

[0128] The fifth security mode corresponds to permissionless withdrawal transactions. The fifth security mode is: the initiator of the withdrawal transaction is the executor role, and the function called by the withdrawal path belongs to the permission of the router role;

[0129] The sixth safety mode and abnormally large withdrawal transactions: The sixth safety mode is: the withdrawal token quantity is less than the threshold;

[0130] The seventh security mode corresponds to abnormal arbitrage transactions. The seventh security mode is: the transfer function cannot be called multiple times in a transaction and the target address must be the same user.

[0131] For easier understanding, see Figure 4 The present invention provides an embodiment of a cross-chain bridge abnormal transaction detection device based on multi-agent collaboration, the device including a processor and a memory:

[0132] The memory is used to store program codes and transmit the program codes to the processor;

[0133] The processor is used to execute any of the cross-chain bridge abnormal transaction detection methods based on multi-agent collaboration provided in the embodiments of the cross-chain bridge abnormal transaction detection method based on multi-agent collaboration according to the instructions in the program code.

[0134] The present invention also provides an embodiment of a computer-readable storage medium, which is used to store program code, and the program code is used to execute any of the embodiments of the cross-chain bridge abnormal transaction detection method based on multi-agent collaboration provided in the present invention.

[0135] As described above, the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit the same. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that the technical solutions described in the above embodiments can still be modified, or some of the technical features thereof can be replaced by equivalents. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A cross-chain bridge abnormal transaction detection method based on multi-agent collaboration, characterized by: include: Based on the data analysis agent, a cross-chain transaction information flow diagram is constructed according to the transaction data, relay data and log data of the cross-chain transaction; Based on the cross-chain transaction information flow graph, a graph analysis agent is used to construct a heterogeneous graph neural network to mine the potential account-role-permission allocation relationship in the cross-chain transaction information flow graph. The output of the heterogeneous graph neural network includes account embedding vectors, account role sets, and role permission sets. Based on the anomaly detection agent, according to the output of the heterogeneous graph neural network, combined with the rule engine and preset classifier, abnormal transaction detection is performed to obtain the cross-chain bridge abnormal transaction detection results.

2. The cross-chain bridge abnormal transaction detection method based on multi-agent collaboration according to claim 1 is characterized in that: Based on the data analysis agent, a cross-chain transaction information flow diagram is constructed based on the transaction data, relay data, and log data of the cross-chain transaction, including: Based on the first model and the first executor in the data parsing agent, a cross-chain transaction information flow diagram is constructed according to the transaction data, relay data and log data of the cross-chain transaction.

3. The cross-chain bridge abnormal transaction detection method based on multi-agent collaboration according to claim 2 is characterized in that: Based on the first model and the first executor in the data parsing agent, a cross-chain transaction information flow diagram is constructed according to the transaction data, relay data, and log data of the cross-chain transaction, including: Based on the first model in the data analysis agent, locate the cross-chain bridge contract address; Parse the cross-chain bridge contract application binary interface based on the first model in the data parsing agent; Based on the first model in the data parsing agent, according to the cross-chain bridge contract application binary interface, the core APIs of different chains are called to obtain the transaction data, relay data and log data of cross-chain transactions; Based on the first executor in the data parsing agent, the transaction data, relay data and log data of cross-chain transactions are parsed and converted into a unified data format to construct a cross-chain transaction information flow diagram.

4. The cross-chain bridge abnormal transaction detection method based on multi-agent collaboration according to claim 1 is characterized in that: Based on the cross-chain transaction information flow graph, a heterogeneous graph neural network is constructed to mine the potential account-role-authority allocation relationships in the cross-chain transaction information flow graph, including: Based on the second model and the second executor in the graph analysis agent, a heterogeneous graph neural network is constructed according to the metadata of the cross-chain transaction information flow graph to mine the potential account-role-authority allocation relationship in the cross-chain transaction information flow graph.

5. The cross-chain bridge abnormal transaction detection method based on multi-agent collaboration according to claim 4 is characterized in that: Based on the second model and the second executor in the graph analysis agent, a heterogeneous graph neural network is constructed according to the metadata of the cross-chain transaction information flow graph to mine the potential account-role-authority allocation relationship in the cross-chain transaction information flow graph, including: Based on the second model in the graph analysis agent, a heterogeneous graph neural network is constructed; Based on the second executor in the graph analysis agent, the characteristics of the cross-chain transaction information flow graph are used as the input of the heterogeneous graph neural network to generate a high-dimensional account embedding vector. By calculating the similarity between the high-dimensional account embedding vector and the characteristics of the cross-chain core role, the account-role-authority allocation relationship is obtained. Among them, the cross-chain core roles are divided into six categories: ordinary users, managers, vaults, routers, executors, and other roles.

6. The cross-chain bridge abnormal transaction detection method based on multi-agent collaboration according to claim 1 is characterized in that: Based on the anomaly detection agent, according to the output of the heterogeneous graph neural network, combined with the rule engine and the preset classifier, abnormal transaction detection is performed to obtain the cross-chain bridge abnormal transaction detection results, including: The third model generates dynamic detection strategies based on anomaly detection agents; The third executor based on the anomaly detection agent executes a dynamic detection strategy to detect anomalies in the transaction data of cross-chain transactions and obtains cross-chain transaction anomaly detection results. The cross-chain transaction anomaly detection results include whether there is an anomaly in the transaction and the type of anomaly. Dynamic detection strategies include: Taking high-dimensional account embedding vectors as input features, a pre-built classifier is used to output outliers. Using the account role set and role permission set as input, a rule engine is used to classify abnormal transactions.

7. The cross-chain bridge abnormal transaction detection method based on multi-agent collaboration according to claim 6 is characterized in that: The rule engine includes the corresponding relationship between security mode and abnormal transaction classification. The corresponding relationship between security mode and abnormal transaction classification is as follows: The safety modes include a first safety mode, a second safety mode, a third safety mode, a fourth safety mode, a fifth safety mode, a sixth safety mode, and a seventh safety mode; The first security mode corresponds to a fake deposit transaction. The first security mode is: the deposit address is equal to the vault address, the number of tokens deposited in the deposit event is equal to the increase in the vault account balance, and the token type deposited in the deposit event is equal to the token contract address to be deposited; The second security mode corresponds to illegal permission transactions. The second security mode is: the function called by the user belongs to the permission of the user role, and the parameters passed by the user must meet the restrictions of the calling function; The third security mode corresponds to the fake routing forwarding transaction. The third security mode is: the generation address of the deposit event is equal to the routing role or vault address; The fourth security mode corresponds to an erroneous withdrawal transaction. The fourth security mode is: the account balance of the vault role decreases by an amount equal to the number of tokens to be withdrawn, and the type of token withdrawn in the withdrawal event is equal to the contract address of the token to be withdrawn; The fifth security mode corresponds to permissionless withdrawal transactions. The fifth security mode is: the initiator of the withdrawal transaction is the executor role, and the function called by the withdrawal path belongs to the permission of the router role; The sixth safety mode and abnormally large withdrawal transactions: The sixth safety mode is: the withdrawal token quantity is less than the threshold; The seventh security mode corresponds to abnormal arbitrage transactions. The seventh security mode is: the transfer function cannot be called multiple times in a transaction and the target address must be the same user.

8. A cross-chain bridge abnormal transaction detection device based on multi-agent collaboration, characterized in that: include: The data parsing agent module is used to build a cross-chain transaction information flow diagram based on the transaction data, relay data, and log data of the cross-chain transaction based on the data parsing agent; The graph analysis agent module is used to build a heterogeneous graph neural network based on the graph analysis agent and the cross-chain transaction information flow graph to mine the potential account-role-permission allocation relationship in the cross-chain transaction information flow graph. The output of the heterogeneous graph neural network includes the account embedding vector, the account role set, and the role permission set; The anomaly detection agent module is used to detect abnormal transactions based on the output of the heterogeneous graph neural network, combined with the rule engine and preset classifier, to obtain the cross-chain bridge abnormal transaction detection results.

9. The cross-chain bridge abnormal transaction detection device based on multi-agent collaboration according to claim 8 is characterized in that: The data analysis agent module is specifically used to: Based on the first model and the first executor in the data parsing agent, a cross-chain transaction information flow diagram is constructed according to the transaction data, relay data and log data of the cross-chain transaction.

10. The cross-chain bridge abnormal transaction detection device based on multi-agent collaboration according to claim 9 is characterized in that: The data analysis agent module is specifically used to: Based on the first model in the data analysis agent, locate the cross-chain bridge contract address; Parse the cross-chain bridge contract application binary interface based on the first model in the data parsing agent; Based on the first model in the data parsing agent, according to the cross-chain bridge contract application binary interface, the core APIs of different chains are called to obtain the transaction data, relay data and log data of cross-chain transactions; Based on the first executor in the data parsing agent, the transaction data, relay data and log data of cross-chain transactions are parsed and converted into a unified data format to construct a cross-chain transaction information flow diagram.