Ethereum fraud detection method and system based on Hash correlation hypergraph modeling

Through hash-related hypergraph modeling and double sampling strategy, the difficult problem of identifying high-order dependency relationships in Ethereum fraud detection is solved, and efficient and robust account fraud detection is achieved.

CN120725699APending Publication Date: 2025-09-30ARTIFICIAL INTELLIGENCE INNOVATION RES INST OF ZHEJIANG UNIV OF TECH BINJIANG DISTRICT HANGZHOU
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511233419.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-01
Publication Date
2025-09-30

AI Technical Summary

Technical Problem

Existing Ethereum fraud detection methods are unable to effectively capture high-order dependencies between accounts, which limits the model's ability to identify complex fraudulent activities. At the same time, building a full graph faces the challenges of high training complexity and high storage overhead, affecting the accuracy and robustness of detection.

Method used

Hash-associated hypergraph modeling is adopted. A hypergraph is constructed through transaction hashing, and then combined with hyperedge random sampling and node sampling, it is converted into an isomorphic graph and input into the graph neural network for account classification. A double sampling strategy is used to compress the graph size and reduce computational complexity.

Benefits of technology

It effectively captures multi-party interaction patterns, improves the accuracy and robustness of fraud detection, reduces computational complexity and storage overhead, and improves detection performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120725699A_ABST
    Figure CN120725699A_ABST
Patent Text Reader

Abstract

The invention discloses an Ethereum fraud detection method and system based on Hash association hypergraph modeling, and belongs to the technical field of Ethereum fraud detection.The method comprises the steps that firstly, external transaction Hash of a target account is extracted, and related internal transactions are tracked; constructing a hypergraph by taking the transaction hash as a hyperedge and taking the participation address as a node; random sampling is carried out on hyperedges of a target account neighborhood through a double sampling strategy, and node sampling is carried out on the basis that nodes with tags are preferentially reserved in the hyperedges so as to compress the graph scale; converting the sampled hypergraph into a homograph based on incidence matrix calculation; and finally inputting the same composition and account features into a graph neural network classifier to realize account classification. According to the method, the complex transaction relationship is accurately expressed through hypergraph modeling, the calculation complexity is reduced by using double sampling, the method is compatible with a standard graph neural network algorithm, and the behavior pattern recognition capability is improved while a key transaction structure is reserved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of Ethereum fraud detection, and in particular relates to an Ethereum fraud detection method and system based on hash association hypergraph modeling. Background Art

[0002] The Ethereum platform, a blockchain-based platform, has formed a complex financial ecosystem. The resulting fraudulent activities, such as Ponzi schemes, pose a serious threat to the security of user assets. Existing fraud detection methods typically model inter-account transaction behavior as a graph structure, but such approaches suffer from fundamental flaws. First, they focus solely on binary transaction relationships between accounts and fail to fully capture the complex multi-party interaction patterns inherent in Ethereum. For example, during a smart contract invocation, a single transaction may involve the coordinated operations of multiple accounts. Traditional graph models simplify this into binary relationships, resulting in the loss of crucial interaction information. Second, standard graph neural networks primarily rely on information propagation between nodes and their immediate neighbors to learn node representations, making it difficult to effectively model high-order dependencies between accounts. In real-world fraud scenarios, complex fraudulent activities, such as Ponzi schemes, often involve multiple intermediary accounts, forming indirect transaction chains or specific fund flow patterns. These high-order dependencies are crucial features for identifying fraud. However, the inability of existing methods to capture these high-order relationships limits their ability to identify fraudulent patterns. Furthermore, the massive scale of the Ethereum network makes directly constructing the full graph challenging due to high training complexity and storage overhead, further limiting the practicality of detection systems. In summary, existing technologies have significant shortcomings in modeling multi-party interactions, capturing high-order dependencies, and dealing with computational complexity, which directly affect the accuracy and robustness of fraud detection. Summary of the Invention

[0003] To solve the above technical problems, the present invention proposes an Ethereum fraud detection method and system based on hash association hypergraph modeling to solve the problems existing in the above-mentioned prior art.

[0004] In a first aspect, to achieve the above-mentioned objectives, the present invention provides an Ethereum fraud detection method based on hash-related hypergraph modeling, comprising the following steps:

[0005] S1. Extract the external transaction information of the target account and collect the transaction hash;

[0006] S2. Track each transaction hash corresponding to the internal transactions related to the target account;

[0007] S3. Build a hypergraph with transaction hashes as hyperedges and participating addresses as nodes.

[0008] S4. Randomly sample hyperedges within the neighborhood of the target account, retaining no more than a preset number of hyperedges;

[0009] S5. Sample the nodes inside the retained hyperedge, giving priority to retaining the target nodes with identity labels;

[0010] S6, converting the sampled hypergraph into an isomorphic graph;

[0011] S7. Input the isomorphic graph and the initial account features into the graph neural network classifier for account classification.

[0012] Optionally, the processes of S1 and S2 include:

[0013] Obtain external and internal transaction information through the Ethereum data interface;

[0014] External transactions are direct transactions with the target account as the sender or receiver;

[0015] Internal transactions are value transfers or message calls triggered by smart contract execution.

[0016] Optionally, the process of constructing the hypergraph in S3 includes:

[0017] Define the account node set and the hyperedge set defined by the transaction hash;

[0018] Generate an association matrix to record the affiliation between nodes and hyperedges;

[0019] The initial feature matrix and identity label set of associated accounts.

[0020] Optionally, the process of S4 includes:

[0021] Determine the set of hyperedges associated with the target account;

[0022] When the number of hyperedges exceeds a preset threshold, hyperedges that do not exceed the threshold are randomly sampled;

[0023] Otherwise, all associated hyperedges are retained.

[0024] Optionally, the process of S5 includes:

[0025] Determine the node set for each retained hyperedge;

[0026] When the number of nodes exceeds the preset threshold:

[0027] Prioritize retaining the target account node;

[0028] Randomly sample from the remaining nodes until the total number does not exceed the threshold.

[0029] Optionally, the isomorphic graph conversion process in S6 includes:

[0030] Calculate the adjacency matrix based on the hypergraph incidence matrix;

[0031] The adjacency matrix is ​​generated in the following way:

[0032] Count the number of nodes jointly participating in the hyperedge;

[0033] Remove the diagonal elements representing the node's own associations.

[0034] In a second aspect, the present invention further provides an Ethereum fraud detection system based on hash-related hypergraph modeling, which is used to implement an Ethereum fraud detection method based on hash-related hypergraph modeling. The system includes:

[0035] Data acquisition and preprocessing module, used to extract external transaction information of the target account and collect transaction hashes to track internal transactions;

[0036] A hypergraph construction module, used to construct a hypergraph with transaction hashes as hyperedges and participating addresses as nodes;

[0037] A dual sampling module, which randomly samples hyperedges within the neighborhood of the target account and samples nodes inside the retained hyperedges;

[0038] Hyper-isomorphic graph conversion module, used to convert the sampled hypergraph into an isomorphic graph;

[0039] Model training module, used to train graph neural network classifiers based on isomorphic graphs and account initial features;

[0040] Behavior detection module, used to classify accounts using trained classifiers.

[0041] In a third aspect, the present invention further provides a computer terminal device, comprising:

[0042] one or more processors;

[0043] a memory, coupled to the processor, for storing one or more programs;

[0044] When the one or more programs are executed by the one or more processors, the one or more processors implement the steps of the Ethereum fraud detection method based on hash association hypergraph modeling in the above-mentioned first aspect.

[0045] In a fourth aspect, the present invention further provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the Ethereum fraud detection method based on hash-associated hypergraph modeling in the above-mentioned first aspect.

[0046] In a fifth aspect, the present invention further provides a computer program product, comprising a computer program, which, when executed by a processor, implements the steps of the Ethereum fraud detection method based on hash association hypergraph modeling in the above-mentioned first aspect.

[0047] Compared with the prior art, the present invention has the following advantages and technical effects:

[0048] The present invention provides an Ethereum fraud detection method and system based on hash-associated hypergraph modeling. The present invention constructs a hypergraph through transaction hashes, expresses multi-party transaction relationships with hyperedges, and fully captures high-order interaction patterns between accounts. It adopts a dual strategy of hyperedge random sampling and node refined sampling to significantly compress the graph size and reduce computational complexity. The hypergraph is converted into an isomorphic graph expressed by an adjacency matrix, which is compatible with standard graph neural network algorithms. Neighborhood information is aggregated based on the hyperisomorphic graph structure, and discriminative representation vectors are learned in combination with initial account features to improve the recognition ability of complex behavior patterns. While retaining key transaction structures, efficient and robust account classification is achieved. BRIEF DESCRIPTION OF THE DRAWINGS

[0049] The accompanying drawings, which constitute part of the present invention, are provided to provide a further understanding of the present invention. The exemplary embodiments of the present invention and their descriptions are provided to explain the present invention and do not constitute an undue limitation of the present invention. In the accompanying drawings:

[0050] Figure 1 This is a flowchart of Ethereum fraud detection for a target account according to an embodiment of the present invention;

[0051] Figure 2 is a flow chart of a double sampling process according to an embodiment of the present invention;

[0052] Figure 3 This is a framework diagram of the Ethereum fraud detection system according to an embodiment of the present invention. DETAILED DESCRIPTION

[0053] It should be noted that, in the absence of conflict, the embodiments and features of the embodiments of the present invention can be combined with each other. The present invention will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.

[0054] It should be noted that the steps shown in the flowcharts of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and that, although a logical order is shown in the flowcharts, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0055] Example 1

[0056] This embodiment provides an Ethereum fraud detection method based on hash-related hypergraph modeling, including:

[0057] S1. Extract the external transaction information of the target account and collect the transaction hash;

[0058] S2. Track each transaction hash corresponding to the internal transactions related to the target account;

[0059] S3. Build a hypergraph with transaction hashes as hyperedges and participating addresses as nodes.

[0060] S4. Randomly sample hyperedges within the neighborhood of the target account, retaining no more than a preset number of hyperedges;

[0061] S5. Sample the nodes inside the retained hyperedge, giving priority to retaining the target nodes with identity labels;

[0062] S6, converting the sampled hypergraph into an isomorphic graph;

[0063] S7. Input the isomorphic graph and the initial account features into the graph neural network classifier for account classification.

[0064] The specific process is as follows:

[0065] S1: For the target account, extract its external transaction information and collect the corresponding transaction hash;

[0066] S2: For each transaction hash, track and extract internal transactions related to the target account;

[0067] S3: Build a hypergraph with transaction hashes as hyperedges and participating addresses as nodes;

[0068] S4: For the target account being analyzed, from all the hyperedges existing in its neighborhood, a random sampling method is used to retain some hyperedges according to preset conditions;

[0069] S5: Further sample the nodes contained in the retained hyperedges to reduce the size of the hypergraph;

[0070] S6: Convert the sampled hypergraph into a hyperisomorphic graph;

[0071] S7: Input the hyperisomorphic graph and its corresponding initial account features into a downstream classifier to classify and identify fraudulent accounts such as Ponzi schemes.

[0072] As an implementation method in this embodiment, the processes of S1 and S2 include:

[0073] Obtain external and internal transaction information through the Ethereum data interface;

[0074] External transactions are direct transactions with the target account as the sender or receiver;

[0075] Internal transactions are value transfers or message calls triggered by smart contract execution.

[0076] Specifically, in steps S1 and S2, external transaction information and internal transaction information are obtained through the Ethereum data interface; external transactions refer to transactions directly with the target account as the sender or receiver, and internal transactions refer to value transfers or message calls related to the target account triggered by the execution of smart contracts.

[0077] As an implementation method in this embodiment, the process of constructing the hypergraph in S3 includes:

[0078] Define the account node set and the hyperedge set defined by the transaction hash;

[0079] Generate an association matrix to record the affiliation between nodes and hyperedges;

[0080] The initial feature matrix and identity label set of associated accounts.

[0081] Specifically, in step S3, the constructed Ethereum interaction hypergraph can be expressed as .in, Is a collection of account nodes; is a set of hyperedges, each hyperedge Defined by a unique transaction hash and connecting all account nodes involved in the transaction; is the incidence matrix of the hypergraph, if the account belongs to (i.e. is linked to) a hyperedge , then the corresponding element in the matrix , otherwise 0; is the initial feature matrix of the account, where It is an account of dimensional feature vector; It is a set of known identity labels of some accounts (for example, fraudulent accounts or normal accounts) used for model training and evaluation.

[0082] As an implementation method in this embodiment, the process of S4 includes:

[0083] Determine the set of hyperedges associated with the target account;

[0084] When the number of hyperedges exceeds a preset threshold, hyperedges that do not exceed the threshold are randomly sampled;

[0085] Otherwise, all associated hyperedges are retained.

[0086] Specifically including: S4: for each target account node, filter its associated hyperedges. Specifically, for a target node , first determine the set of all its associated hyperedges, and then use the preset upper limit threshold of the number of hyperedge samples Make a judgment. If the number of hyperedges associated with the node exceeds the threshold , then randomly sample from its hyperedge set If the threshold is not exceeded, all its associated hyperedges are retained. The process is formalized as follows:

[0087] ;

[0088] ;

[0089] in, Indicates that it contains nodes The set of all hyperedges of represents the set of hyperedges retained after filtering, Represents from the set Randomly draw without replacement elements.

[0090] As an implementation method in this embodiment, the process of S5 includes:

[0091] Determine the node set for each retained hyperedge;

[0092] When the number of nodes exceeds the preset threshold:

[0093] Prioritize retaining the target account node;

[0094] Randomly sample from the remaining nodes until the total number does not exceed the threshold.

[0095] Specifically including: S5: Based on the hyperedge filtering, in order to further simplify the scale of the graph, the nodes contained in each retained hyperedge are subsampled. Specifically, for the hyperedge set obtained in step S4 Each hyperedge in , first determine the node set it contains , and according to the preset upper limit threshold of the number of nodes Make a judgment. If the number of nodes contained in the hyperedge exceeds the threshold , then node sampling is performed within the hyperedge, and in order to ensure the integrity of the target information, the target nodes with labels are retained first. (if it is in the hyperedge), and randomly sample from the remaining nodes so that the total number of nodes retained is ; If the number of nodes contained in the hyperedge does not exceed the threshold , then all nodes within the hyperedge are retained. The process is formulated as follows:

[0096] ;

[0097] in, Represents a hyperedge The set of all nodes contained in represents the set of nodes that the hyperedge ultimately retains after refinement. Represents a hyperedge The number of nodes with known identity labels contained in . Through the two-step operation of hyperedge filtering and node refinement, we can effectively retain key structural information while significantly reducing the scale of the graph and the complexity of subsequent calculations. The specific graph scale statistics are shown in Table 1.

[0098] Table 1 Statistics of the size of hypergraphs and hyperisomorphic graphs

[0099]

[0100] As an implementation method of this embodiment, the isomorphic graph conversion process in S6 includes:

[0101] Calculate the adjacency matrix based on the hypergraph incidence matrix;

[0102] The adjacency matrix is ​​generated in the following way:

[0103] Count the number of nodes jointly participating in the hyperedge;

[0104] Remove the diagonal elements representing the node's own associations.

[0105] The specific steps of super-isomorphic graph conversion are:

[0106] S6: In order to utilize mature graph neural network algorithms, this step converts the sampled hypergraph structure into a standard isomorphic graph, namely the hyperisomorphic graph. The core of the conversion is to use the hypergraph’s association matrix To generate the adjacency matrix of the hyperisomorphic graph , and its calculation formula is:

[0107] ;

[0108] In this calculation, we first perform matrix multiplication Construct a node co-occurrence matrix, where the value of each element represents the number of hyperedges that two nodes participate in, thereby capturing the high-order correlation between nodes. Then, by subtracting the diagonal matrix of the co-occurrence matrix , effectively removing the self-loops in the graph. The final result is It is a symmetric adjacency matrix. The edges in the hyperisomorphic graph it represents indicate that two nodes have participated in at least one transaction event together, which can be directly used as the input of the downstream GNN model.

[0109] The specific steps for fraud detection are:

[0110] S7: This step is the final step of the entire detection process, responsible for converting the hyperisomorphic graph adjacency matrix generated in S6 And the corresponding account initial feature matrix The input is fed into an end-to-end graph neural network (GNN) classifier. The classifier consists of a GraphSAGE model and a multi-layer perceptron (MLP) classification head. During the processing, the GNN feature extractor first performs iterative message passing and aggregation on the structure of the hyperisomorphic graph, learning a representation vector for each node that captures its high-order neighborhood structure and feature information. The calculation formula is:

[0111] ;

[0112] Subsequently, this high information content representation vector It is fed into the MLP classification head, passes through the fully connected layer and the Softmax activation function, and finally outputs the probability of each account belonging to the fraud or normal category.

[0113] ;

[0114] in and are the weights and biases of the MLP. The Softmax function outputs the probability that an account belongs to each category (e.g., fraud, non-fraud). The training goal of the model is to minimize the cross entropy loss between the predicted label and the true label :

[0115] ;

[0116] in is the number of labeled accounts in the training set, is the total number of categories, It is an account The true label (if the account Belong to category 1 if yes, 0 otherwise). Is the model prediction account Belong to category To verify the effectiveness of our proposed method, we compared it with various baseline methods and conducted experiments on multiple graph neural network models (such as GCN and SAGE). The final detection results are shown in Table 2. The evaluation metrics include precision, recall, F1-score, and area under the receiver operating characteristic (ROC) curve (AUC).

[0117] Table 2 Statistics of fraud detection results under different detection models

[0118]

[0119] The table compares different graph representation learning methods. For example, "isomorphic graph" refers to the traditional method of directly modeling transactions as binary relationships; "hypergraph" refers to the use of a hypergraph neural network directly on a hypergraph for detection; and "the present invention's method (hyperisomorphic graph)" involves first converting a hypergraph into a hyperisomorphic graph and then using a standard graph neural network for detection. By comparing the performance differences of different base models on different graph structures, it can be found that the method proposed in this invention achieves optimal or near-optimal performance in all indicators. This fully demonstrates that hypergraph modeling can effectively capture high-order dependencies among multiple parties in a transaction, and converting it into a hyperisomorphic graph can better integrate with existing mature graph neural network models, thereby improving the accuracy and robustness of detection while retaining key fraud patterns.

[0120] Based on this, the embodiment of the present invention provides an Ethereum fraud detection method based on hash association hypergraph modeling. Compared with the existing technology, the beneficial effects of the present invention are as follows:

[0121] Compared to existing technologies, this paper proposes an Ethereum fraud detection method and system based on hypergraph modeling, dual sampling, and hyperisomorphic graph transformation. This paper offers the following key advantages: First, it leverages hypergraph structures to accurately capture the multi-party, high-order interaction patterns prevalent in Ethereum transactions, addressing the information loss caused by traditional graph models that simplify complex transactions into binary relationships. Second, it devises a dual sampling strategy (including hyperedge filtering and node refinement) to effectively address the challenges of high training complexity and storage overhead posed by the massive scale of the Ethereum network. Third, it proposes a hyperisomorphic graph transformation mechanism that cleverly transforms the high-order information contained in the hypergraph into the topological structure of a standard graph. This allows for efficient detection using the mature and powerful graph neural network (GNN) algorithm, improving the model's detection performance and applicability. Based on these advantages, the present invention designs an efficient Ethereum fraud detection system, which primarily comprises the following core modules.

[0122] The data acquisition and preprocessing module collects all relevant external and internal transaction data based on the target account and constructs the initial feature vector of each address node; the hypergraph construction module uses transaction hashes as hyperedges and participating addresses as nodes to construct an initial hypergraph that can reflect multi-party interactions; the double sampling module compresses the scale of the initial hypergraph according to the double sampling strategy to obtain a lightweight sampled hypergraph; the hyperisomorphic graph conversion module is responsible for converting the sampled lightweight hypergraph into a standard hyperisomorphic graph. The adjacency matrix it generates can explicitly express the high-order associations between nodes due to their joint participation in transactions; the model training module inputs the converted hyperisomorphic graph structure and node features into the graph neural network classifier, and by training on labeled data, learns and optimizes the model parameters, and finally obtains a fraud detection model with high generalization ability; the fraud detection module uses the trained model to classify the accounts to be detected and finally outputs its fraud detection results.

[0123] Example 2

[0124] Based on the same general inventive concept, the present invention also provides an Ethereum fraud detection system based on hash association hypergraph modeling. The following describes an Ethereum fraud detection system based on hash association hypergraph modeling provided by the present invention. The Ethereum fraud detection system based on hash association hypergraph modeling described below and the Ethereum fraud detection method based on hash association hypergraph modeling described above can be referenced to each other. Figure 3 As shown, the system includes:

[0125] The data acquisition and preprocessing module is responsible for collecting domain interaction data based on the target account, including external and internal transactions, and constructing initial feature vectors for all involved address nodes;

[0126] The hypergraph construction module constructs the preprocessed data into an initial interaction hypergraph that can reflect multi-party interactions, using transaction hashes as hyperedges and participating addresses as nodes, and generates its association matrix;

[0127] The dual sampling module addresses the computational complexity caused by the large size of the initial hypergraph by compressing the graph through a two-stage strategy of hyperedge filtering and node refinement, resulting in a lightweight hypergraph that retains key interaction structures.

[0128] The hyperisomorphic graph conversion module is responsible for converting the sampled lightweight hypergraph into a standard hyperisomorphic graph. By generating its adjacency matrix, the high-order associations in the hypergraph are explicitly expressed as edges in the graph to adapt to the standard graph neural network model.

[0129] The model training module inputs the hyperisomorphic graph structure, node features, and known labels into the composite model, and optimizes the parameters of the neural network and classification head in an end-to-end manner, ultimately learning and obtaining a fraud detection model with high generalization capabilities.

[0130] The fraud detection module adopts an inductive learning method, uses the trained detection model to learn and classify the hyperisomorphic graph constructed by the new account to be detected, and finally returns its fraud detection result.

[0131] It should be understood that the Ethereum fraud detection system based on hash association hypergraph modeling provided by the embodiment of the present invention has all the advantages of the Ethereum fraud detection method based on hash association hypergraph modeling provided by the above embodiment.

[0132] Example 3

[0133] In this embodiment, a computer terminal device is provided, including:

[0134] one or more processors;

[0135] a memory, coupled to the processor, for storing one or more programs;

[0136] When the one or more programs are executed by the one or more processors, the one or more processors implement the steps of the above-mentioned Ethereum fraud detection method based on hash association hypergraph modeling.

[0137] In this embodiment, a computer-readable storage medium is further provided, on which a computer program is stored. When the computer program is executed by a processor, the steps of the above-mentioned Ethereum fraud detection method based on hash association hypergraph modeling are implemented.

[0138] In this embodiment, an electronic device is also provided, including a memory and a processor, wherein a computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps of the above-mentioned Ethereum fraud detection method based on hash association hypergraph modeling.

[0139] In this embodiment, a computer program product is also provided, including a computer program, which, when executed by a processor, implements the steps of the above-mentioned Ethereum fraud detection method based on hash association hypergraph modeling.

[0140] The above program can be executed in a processor or stored in a memory (or computer-readable medium). Computer-readable media includes both permanent and non-permanent, removable and non-removable media, and can be implemented using any method or technology to store information. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape, disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible by a computing device.

[0141] These computer programs can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for executing on the computer or other programmable device to implement the process. Figure 1 a process or multiple processes and / or boxes Figure 1 The steps of the functions specified in a block or multiple blocks can be implemented by different modules corresponding to different steps.

[0142] This embodiment provides such a device or system. The system is called an Ethereum fraud detection system based on hash-related hypergraph modeling, and includes:

[0143] Data acquisition and preprocessing module, used to extract external transaction information of the target account and collect transaction hashes to track internal transactions;

[0144] A hypergraph construction module, used to construct a hypergraph with transaction hashes as hyperedges and participating addresses as nodes;

[0145] A dual sampling module, which randomly samples hyperedges within the neighborhood of the target account and samples nodes inside the retained hyperedges;

[0146] Hyper-isomorphic graph conversion module, used to convert the sampled hypergraph into an isomorphic graph;

[0147] Model training module, used to train graph neural network classifiers based on isomorphic graphs and account initial features;

[0148] Behavior detection module, used to classify accounts using trained classifiers.

[0149] As an implementation method of this embodiment, the data acquisition and preprocessing module includes:

[0150] External transaction acquisition unit, used to obtain direct transactions with the target account as the sender or receiver through the Ethereum interface;

[0151] Internal transaction tracking unit, used to trigger value transfer or message call through smart contract execution.

[0152] As an implementation method of this embodiment, the hypergraph construction module includes:

[0153] Node set generation unit, used to define the account node set;

[0154] A hyperedge set generation unit, used to define a hyperedge set by transaction hash;

[0155] The association matrix generation unit is used to record the affiliation between nodes and hyperedges.

[0156] As an implementation method of this embodiment, the dual sampling module includes:

[0157] A hyperedge sampling unit, configured to randomly sample hyperedges that do not exceed a preset threshold when the number of hyperedges associated with the target account exceeds the threshold;

[0158] The node sampling unit is used to prioritize the target account node and randomly sample from the remaining nodes when the number of nodes in the hyperedge exceeds a preset threshold.

[0159] As an implementation method of this embodiment, the hyperisomorphic graph conversion module includes:

[0160] The co-occurrence relationship calculation unit is used to calculate the number of nodes participating in the hyperedge together;

[0161] The adjacency matrix generation unit is used to remove the diagonal elements associated with the node itself to generate the adjacency matrix.

[0162] As an implementation method of this embodiment, the behavior detection module includes:

[0163] Graph neural network unit, used to aggregate neighborhood information and learn account representation vectors through a message passing mechanism;

[0164] The classification decision unit is used to output the account category probability through a multi-layer perceptron.

[0165] The system or device is used to implement the functions of the method in the above-mentioned embodiment. Each module in the system or device corresponds to each step in the method, which has been explained in the method and will not be repeated here.

[0166] Through the above implementation, the problem of Ethereum fraud detection based on hash association hypergraph modeling in the related art is solved, thereby ensuring that the problems existing in the existing technology are solved.

[0167] The above are merely preferred embodiments of the present invention, but the scope of protection of the present invention is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present invention should be included in the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be based on the scope of protection of the claims.

Claims

1. An Ethereum fraud detection method based on hash-related hypergraph modeling, characterized in that: The following steps are involved: S1. Extract the external transaction information of the target account and collect the transaction hash; S2. Track each transaction hash corresponding to the internal transactions related to the target account; S3. Build a hypergraph with transaction hashes as hyperedges and participating addresses as nodes. S4. Randomly sample hyperedges within the neighborhood of the target account, retaining no more than a preset number of hyperedges; S5. Sample the nodes inside the retained hyperedge, giving priority to retaining the target nodes with identity labels; S6, converting the sampled hypergraph into an isomorphic graph; S7. Input the isomorphic graph and the initial account features into the graph neural network classifier for account classification.

2. The method according to claim 1, characterized in that The S1 and S2 processes include: Obtain external and internal transaction information through the Ethereum data interface; External transactions are direct transactions with the target account as the sender or receiver; Internal transactions are value transfers or message calls triggered by smart contract execution.

3. The method according to claim 1, characterized in that The process of constructing the hypergraph in S3 includes: Define the account node set and the hyperedge set defined by the transaction hash; Generate an association matrix to record the affiliation between nodes and hyperedges; The initial feature matrix and identity label set of associated accounts.

4. The method according to claim 1, wherein The S4 process includes: Determine the set of hyperedges associated with the target account; When the number of hyperedges exceeds a preset threshold, hyperedges that do not exceed the threshold are randomly sampled; Otherwise, all associated hyperedges are retained.

5. The method according to claim 1, wherein The S5 process includes: Determine the node set for each retained hyperedge; When the number of nodes exceeds the preset threshold: Prioritize retaining the target account node; Randomly sample from the remaining nodes until the total number does not exceed the threshold.

6. The method according to claim 1, characterized in that The isomorphic graph conversion process of S6 includes: Calculate the adjacency matrix based on the hypergraph incidence matrix; The adjacency matrix is ​​generated in the following way: Count the number of nodes jointly participating in the hyperedge; Remove the diagonal elements representing the node's own associations.

7. An Ethereum fraud detection system based on hash-related hypergraph modeling, characterized in that: The system comprises: Data acquisition and preprocessing module, used to extract external transaction information of the target account and collect transaction hashes to track internal transactions; A hypergraph construction module, used to construct a hypergraph with transaction hashes as hyperedges and participating addresses as nodes; A dual sampling module, which randomly samples hyperedges within the neighborhood of the target account and samples nodes inside the retained hyperedges; Hyper-isomorphic graph conversion module, used to convert the sampled hypergraph into an isomorphic graph; Model training module, used to train graph neural network classifiers based on isomorphic graphs and account initial features; Behavior detection module, used to classify accounts using trained classifiers.

8. A computer terminal device, characterized in that: include: one or more processors; a memory, coupled to the processor, for storing one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the steps of the method according to any one of claims 1 to 6.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.

10. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.