A blockchain anomaly user detection method and system based on resistance perception
By using a resistance-based approach, the weights of edges in the graph are redefined using effective resistance and combined with multi-hop attention aggregation, which solves the problem of insufficient global structure perception in blockchain abnormal user detection, and achieves efficient abnormal user identification and improved robustness.
Patent Information
- Application Number
- CN202610055667.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-01-16
- Publication Date
- 2026-03-20
- Estimated Expiration
- 2046-01-16
AI Technical Summary
Existing methods for detecting abnormal users in blockchain suffer from insufficient global structure awareness, inadequate feature propagation control, weak model robustness, and poor interpretability of results, making it difficult to effectively identify abnormal users in complex on-chain interaction networks.
We adopt a resistance-sensing-based approach to redefine the weights of edges in the graph by calculating effective resistance. Combined with a multi-hop attention aggregation mechanism, we achieve global topology modeling and adaptive propagation. We also introduce structural perturbation and node regularization strategies to improve the model's generalization ability and anti-interference performance.
It significantly improves the accuracy and robustness of abnormal user identification, can capture local interaction relationships and global structural dependencies, reduces the risk of feature oversmoothing and information degradation, and improves the stability and interpretability of the model.
Smart Images

Figure CN121524705B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application relates to the technical field of blockchain anomaly detection, in particular to a blockchain anomaly user detection method and system based on resistance perception. BACKGROUND
[0002] With the development of graph neural network (GNN) technology, the existing technology begins to regard an account as a graph node, and regards a transaction as a weighted or directed edge, learns a node representation through neighborhood aggregation, and typical methods include GCN, GraphSAGE, GAT and the like. Such a model has achieved certain performance improvement in the chain anomaly identification task compared with traditional methods. However, the blockchain transaction network has the characteristics of complex fund flow direction, explicit long-range association, frequent multi-level covert transfer structure and the like, and the existing GNN model usually depends on local neighborhood average aggregation and fixed level propagation, and has two types of core adaptability problems: firstly, legal batch collection behavior and multi-level complex transaction link can all be expressed as a highly close local neighborhood structure, and uniform weighted neighborhood propagation is difficult to accurately distinguish the two; secondly, a long-range fund chain often crosses more than three hops, and shallow propagation is difficult to capture global dependence, and blindly increasing the number of aggregation layers is easy to cause feature oversmoothing and information degradation. In addition, there are a large number of structural noise edges introduced by airdrop, robot account and batch transfer on the chain, and the traditional GNN is easy to amplify the noise by multiple times in the message passing process, thereby causing the abnormal identification boundary to deviate.
[0003] In view of the characteristics of high noise, weak link dependence and cross-level behavior association commonly existing in the blockchain transaction graph, researchers begin to introduce an effective resistance and other global connectivity measurement tools to re-measure the association strength between nodes. The effective resistance can reflect the overall accessibility of the fund transmission path, and performs excellently in tasks such as graph sparsification and community division. However, the existing methods directly use the resistance measurement through edge deletion or graph topology reconstruction, which is easy to damage the original semantic consistency of the transaction graph; at the same time, how to continuously, learnably and adaptively fuse the effective resistance and the feature aggregation process of the graph neural network still lacks effective solutions, which limits the direct application of resistance in the blockchain fraud detection scene.
[0004] Therefore, there is an urgent need for a unified modeling framework that can retain the original transaction semantic structure, re-label the strength of weak related links, and realize adaptive feature aggregation in multi-hop propagation. SUMMARY
[0005] In order to solve the problems of structural noise interference, long-range dependence modeling deficiency, high misjudgment rate caused by data imbalance and difficulty in multi-hop evolution feature extraction in the blockchain anomaly user detection, the application provides a blockchain anomaly user detection method and system based on resistance perception.
[0006] In a first aspect, the present application provides a blockchain abnormal user detection method based on resistance perception, which adopts the following technical solution:
[0007] An original transaction data set is obtained.
[0008] The obtained original transaction data set is preprocessed.
[0009] Based on the preprocessed data, node feature extraction, structure encoding and feature fusion are performed to obtain a node feature matrix.
[0010] The node feature matrix is enhanced based on an effective resistance-based feature enhancement mechanism.
[0011] The enhanced features are aggregated based on a multi-hop aggregation mechanism based on resistance perception to obtain node high-dimensional embedding features.
[0012] The node high-dimensional embedding features are classified and optimized, and a risk prediction result is output.
[0013] In a second aspect, a blockchain abnormal user detection system based on resistance perception is provided, which comprises:
[0014] A data acquisition module configured to obtain an original transaction data set.
[0015] A preprocessing module configured to preprocess the obtained original transaction data set.
[0016] A feature matrix module configured to perform node feature extraction, structure encoding and feature fusion based on preprocessed data to obtain a node feature matrix.
[0017] A feature enhancement module configured to enhance the node feature matrix based on an effective resistance-based feature enhancement mechanism.
[0018] An aggregation module configured to aggregate the enhanced features based on a multi-hop aggregation mechanism based on resistance perception to obtain node high-dimensional embedding features.
[0019] A prediction module configured to classify and optimize the node high-dimensional embedding features and output a risk prediction result.
[0020] In a third aspect, the present application provides a computer-readable storage medium, which stores a plurality of instructions, the instructions being adapted to be loaded and executed by a processor of a terminal device to perform the blockchain abnormal user detection method based on resistance perception.
[0021] In a fourth aspect, the present application provides a terminal device, comprising a processor and a computer readable storage medium, the processor is used to implement instructions; the computer readable storage medium is used to store a plurality of instructions, the instructions are suitable for being loaded and executed by the processor to implement the method for detecting abnormal users of a blockchain based on resistance perception.
[0022] In summary, the present application has the following beneficial technical effects:
[0023] The present application proposes a method for identifying abnormal users of a blockchain based on resistance enhancement and multi-hop attention aggregation, aiming at the technical bottlenecks of the existing method for detecting abnormal users of a blockchain, such as insufficient global structure perception, improper feature propagation control, weak model robustness, and poor result interpretability. The method realizes efficient modeling of the interaction network on a complex chain and accurate detection of abnormal users through global topology modeling guided by resistance, adaptive propagation of hop count, and multi-layer attention aggregation mechanism. Compared with traditional graph neural network models that only rely on local neighborhood statistics, the present application can simultaneously capture local interaction relationships and global structure dependencies, significantly improving the accuracy and robustness of abnormal user identification.
[0024] In terms of feature structure modeling, the resistance weighting mechanism proposed by the present application redefines the weight of edges in the graph by calculating the effective resistance between nodes, making the connectivity strength of transaction paths more consistent with the real fund flow relationship. This mechanism realizes continuous modeling of global structure at the network level, effectively suppressing isolated noise transactions and redundant edges that interfere with feature propagation. At the same time, combined with the resistance-guided hop count adaptive control strategy, the model can automatically determine the optimal propagation depth according to the decay trend of the average resistance weight, balancing the information transmission range and the risk of feature degradation, thereby effectively avoiding the problems of over-smoothing and feature dissipation in traditional graph neural networks. Further, through the multi-hop attention aggregation module, the model can adaptively fuse feature information at different propagation levels, focusing on strengthening the interaction signals on low-resistance and high-correlation paths, and ensuring accurate capture of latent abnormal user groups and multi-layer value chain transfer relationships.
[0025] In terms of model optimization and stability, the application introduces structure disturbance and node regularization strategy, which improves the generalization ability and anti-interference performance of the model by randomly discarding part of the edge connection (DropEdge) and applying feature noise in the training stage. The experimental verification based on real data shows that the method of the application is significantly better than the mainstream control model in key evaluation indicators. On the test set, the Micro-F1 value reaches 88.3%, the Macro-F1 value is 86.1%, the precision and recall are 87.9% and 84.7% respectively, which are higher than the models such as GAT, GraphSAGE and Cluster-GCN; at the same time, the single batch reasoning time is only 0.78 seconds, which is about 19% higher than the 0.96 seconds of Cluster-GCN. In addition, the robustness retention rate (RI) under high disturbance is still as high as 0.88, which is significantly higher than the average level of 0.79 of the traditional model. In summary, the application has realized a systematic breakthrough in structure modeling, propagation control and stability optimization, and has strong engineering deployment value and popularization potential. BRIEF DESCRIPTION OF DRAWINGS
[0026] Figure 1 is a schematic diagram of a blockchain abnormal user detection method based on resistance perception according to an embodiment of the application;
[0027] Figure 2 is a performance comparison schematic diagram of the blockchain abnormal user detection method according to an embodiment of the application;
[0028] Figure 3 is a method reasoning time consumption comparison schematic diagram according to an embodiment of the application;
[0029] Figure 4 is a precision schematic diagram of different methods under disturbance according to an embodiment of the application;
[0030] Figure 5 is a model framework diagram of the method of the application according to an embodiment of the application. DETAILED DESCRIPTION
[0031] The application will be further described in detail below with reference to the accompanying drawings.
[0032] Embodiment 1
[0033] Referring to Figure 1 , the blockchain abnormal user detection method based on resistance perception according to an embodiment of the application comprises:
[0034] (1) Data collection and transaction network construction module
[0035] 1) Data acquisition and preprocessing
[0036] In the blockchain abnormal user detection task, on-chain transaction data is the most basic information source that can reflect the true behavior pattern of the account. Through the blockchain node interface or third-party on-chain monitoring platform, the account's fund interaction process can be continuously collected, reflecting the dynamic structural characteristics such as transaction frequency, fund direction, and in-degree and out-degree changes. However, the on-chain transaction record often has problems such as heterogeneous data sources, non-uniform field formats, and a high proportion of noise transactions, and is accompanied by a large number of background transactions unrelated to anomaly detection (such as zero-amount transfer, internal system call, batch automated clearing, etc.), which will weaken the discriminability of the account behavior pattern. Therefore, a robust on-chain data collection and preprocessing process needs to be designed to extract the semantic structure that can stably represent the account interaction characteristics.
[0037] In the data collection stage, the application continuously acquires transaction records through the blockchain full node program or public data interface. The collected data includes transaction hash, sending account address, receiving account address, transaction amount, timestamp, transaction fee, and transaction type, etc. To ensure structural consistency, the system uses a standard block synchronization mechanism to update the on-chain state regularly, ensuring data integrity and time continuity.
[0038] For the collected raw transaction data, considering the problems of heterogeneous sources, non-uniform field definitions, and a large number of redundant transactions, the technical solution designs a data preprocessing process.
[0039] Let the original transaction data set be represented as:
[0040] ,
[0041] Wherein, T is the total number of transactions, C is the number of feature channels of the transaction, including the amount, timestamp, and Gas fee fields.
[0042] To reduce noise interference and improve feature quality, the system performs filtering operations on the original transaction data. The filtering function is defined as:
[0043] ,
[0044] Wherein, d represents a single transaction record, amount is the transaction amount, and type is the transaction type. This filtering operation is used to retain transactions with real value transfer and eliminate zero-amount, internal call, and non-monetary transactions, thereby improving the effectiveness and robustness of the data.
[0045] After completing the data cleaning, the system constructs a transaction network based on the transaction relationship between accounts. The adjacency matrix A is defined as follows: A
[0046] ,
[0047] Thus the edge set The node set in the network V represents the on-chain account entity, and each edge represents the fund flow relationship between accounts.
[0048] After data preprocessing and feature extraction, the standardized transaction network finally obtained can be represented as:
[0049] ,
[0050] Among them, is a data processing and network construction function; V is a node set; E is an edge set; Y is an account category label matrix.
[0051] The transaction network realizes the structural expression of the interaction relationship between on-chain accounts in technology, and can reserve the transaction topology and behavior pattern at the same time. Through the above method, the interference of redundant transactions on feature extraction can be effectively reduced, the stability and accuracy of the subsequent abnormal account identification model are improved, and high-quality modeling of the account behavior network is realized.
[0052] 2) Node feature extraction and structure coding
[0053] Transaction behavior feature extraction
[0054] The transaction sequence of each node ( v i ) at time step (t) can be represented as:
[0055] ,
[0056] Among them is the transaction timestamp, is the transaction amount, is the transaction frequency.
[0057] The system calculates the statistical features:
[0058] ,
[0059] An 8-dimensional transaction statistical vector is formed to describe the fund flow pattern of the account.
[0060] Structure topology feature extraction
[0061] In order to capture the position relationship and local connection mode of the account in the network, the following indexes are calculated by the present application:
[0062] In-degree and out-degree , reflecting the balance between the activity and the fund flow of the account; clustering coefficient , measuring the closeness between the node and its neighbors; PageRank value , representing the centrality and influence of the account in the overall transaction network. Form the structural feature vector:
[0063] ,
[0064] Position encoding and global structure embedding
[0065] To introduce global geometric information, the invention calculates the directed graph Laplacian matrix , and obtains its first s non-trivial eigenvector to form the matrix:
[0066] ,
[0067] where is the eigenvector of L , representing the relative position of the node in the global topology space. U will be input into the subsequent module as the node position encoding, which will help to capture the cross-regional value flow relationship.
[0068] 3) Feature fusion and normalization
[0069] After integrating the above features, the complete node feature matrix is constructed:
[0070] ,
[0071] where represents the feature splicing operation. In order to eliminate the scale difference of different dimensional features, the system performs zero-mean standardization and normalization processing on each dimension:
[0072] ,
[0073] where , are the mean and standard deviation of the first j dimensional feature, respectively. After normalization, the input matrix with uniform scale is obtained, ensuring the comparability of different features in model learning.
[0074] This module outputs the transaction network structure and the node feature matrix , which are input into the subsequent "resistance feature enhancement module". The invention reconstructs the dynamic interaction relationship between on-chain accounts at the graph structure level, and realizes the transformation from raw transaction records to high-dimensional structured expression at the feature level, providing a stable and discriminative representation basis for downstream abnormal account identification.
[0075] (2) Resistance-aware feature enhancement module
[0076] In the on-chain account interaction graph, the value flow relationship between nodes (addresses) is complex and highly heterogeneous. The conventional feature propagation method based on the adjacency matrix only considers the local one-hop or fixed multi-hop neighbors, which cannot capture the potential global structural dependencies between nodes. Especially in the on-chain abnormal behavior identification scenario, high-risk accounts often use multi-level transfer accounts, fictitious address chains, or asset reflux paths to conceal the true behavior characteristics, making it difficult for traditional graph models to describe the "long-range dependence" and "global coupling" features at the structural level.
[0077] To solve this problem, the present application proposes a feature enhancement mechanism based on effective resistance to measure the global connection strength between nodes, and accordingly to perform resistance-aware reweighting on the adjacency matrix, thereby strengthening important structural paths and suppressing noise relationships at the propagation level of the graph neural network.
[0078] 1) Theoretical motivation and problem modeling
[0079] In the electrical network theory, the effective resistance between nodes can be regarded as the "resistance" of information flow, reflecting the ease of information transmission between two nodes. When there are multiple short and reliable paths between nodes, their equivalent resistance is small, representing high communication efficiency between the two; on the contrary, if the connection path is sparse or there is a bottleneck, the resistance value is high, representing limited interaction between nodes. This property has a natural correspondence with the value flow strength between addresses in the on-chain account interaction network of the blockchain. Therefore, introducing effective resistance into the adjacency weight modeling of the graph neural network can achieve quantitative characterization of the global correlation of nodes.
[0080] Let the original transaction network be a weighted directed graph G ( V , E , W ), where V is the set of account nodes, E is the set of transaction edges, W ij represents the transaction strength from account i to account j . The out-degree of a node is defined as:
[0081] ,
[0082] The total volume of the graph is defined as . Further define the out-degree matrix and the transition probability matrix:
[0083] ,
[0084] where P ij denotes the transition probability from node i to node j . The stationary distribution vector can be obtained from the random walk theory, satisfying . Let , the Laplacian matrix of the directed graph is defined as:
[0085] ,
[0086] where I is the identity matrix. The Laplacian matrix comprehensively considers the in-out flow of nodes and the transition characteristics of random walk, and is an important tool for describing the directionality structure of the transaction graph.
[0087] 2) Effective resistance calculation and global connectivity
[0088] The effective resistance between nodes in the present application is defined as:
[0089] ,
[0090] where is the Moore-Penrose pseudo-inverse of the Laplacian matrix, and are the unit basis vectors of nodes u and v , respectively. This quantity reflects the "energy consumption" of information propagation between two nodes, and can naturally depict the diversity and accessibility of global paths in the graph.
[0091] In terms of physical interpretation, if each edge in the graph is regarded as a wire with resistance , then the smaller the effective resistance, the stronger the equivalent conduction ability between the two nodes; on the contrary, there is strong structural isolation. Since fraudulent accounts often interact closely through high-frequency fund transfers, their equivalent resistance is significantly lower than that of ordinary nodes, so this index can be directly used as a physical quantitative basis for the correlation strength of nodes.
[0092] In the calculation process, in order to reduce the computational complexity, the present application uses a random walk subgraph approximation method. That is, for each target node v , a limited-step random walk is performed to construct a subgraph containing its multi-hop neighborhood, calculate its subgraph Laplacian , and then obtain the approximate effective resistance by pseudo-inverse operation:
[0093] ,
[0094] where i ,j ) are the indices of nodes ( v , u ) in . This approximation method can greatly reduce the matrix inversion overhead while ensuring the global feature expression ability, and is suitable for large-scale blockchain transaction networks.
[0095] 3) Resistance-guided adjacency weight and affinity normalization
[0096] After obtaining the effective resistance between node pairs, the present application further constructs a resistance-guided affinity matrix to replace the original adjacency relationship, achieving the purpose of "strengthening important connections and weakening noise paths". The affinity function is defined as:
[0097] ,
[0098] where controls the decay rate, adjusts the nonlinearity of resistance influence. In order to maintain numerical stability, a small constant is set and the adjacency weight of each node is normalized:
[0099] ,
[0100] The normalized resistance-aware adjacency matrix is denoted as . This matrix reconstructs the connection weights of the transaction network at the topological level, so that in the subsequent information propagation process, the model can automatically focus on low-resistance and high-trust path structures.
[0101] From a geometric point of view, the resistance weight operation is equivalent to a nonlinear transformation of neighbor nodes based on path reachability in the feature space, compressing the influence range of distant and low-trust neighbors, and expanding the weights of local tight clusters, so that the feature propagation process of the node presents the characteristics of "resistance-oriented aggregation".
[0102] 4) Resistance-enhanced feature fusion mechanism
[0103] After obtaining the resistance-aware adjacency matrix, the present application generates the enhanced feature representation of the node through neighborhood weighted aggregation. For any node v , its enhanced feature is calculated as:
[0104] ,
[0105] where x v is the node's own feature, w v , u ) is the resistance weighted coefficient, and Concat represents the concatenation operation. This formula fuses the local attributes of the node with the weighted features of its low-resistance neighbors, achieving the unification of structure perception and semantic aggregation.
[0106] In system implementation, the module outputs the resistance weighted adjacency matrix and the enhanced feature matrix , which are used as the input of the subsequent resistance guided multi-hop aggregation module to provide the model with global structure priori. Through this mechanism, the system obtains the transition capability from local relationship modeling to global topology perception, laying a foundation for global reasoning for fraud account identification in complex blockchain networks.
[0107] (3) Resistance guided multi-hop aggregation module
[0108] In the user interaction network on the blockchain chain, the behavior pattern of abnormal users is usually not limited to the direct value transfer relationship, but forms a complex structure dependence spanning multiple hops in the network through multi-level transfer paths, circular reflux channels or implicit value transmission chains. Traditional graph neural network models that rely on one-hop or two-hop neighborhood propagation cannot capture this kind of long-range interaction information; while blindly increasing the number of propagation layers will cause feature over-smoothing, making the model lose the ability to distinguish different users. To solve the above contradiction, the present invention proposes a multi-hop aggregation mechanism based on resistance perception, which realizes the adaptive regulation of cross-hop feature propagation intensity through resistance weighted adjacency relationship, and combines attention weight for multi-scale fusion, thereby maintaining the ability to capture global dependence while avoiding invalid diffusion.
[0109] 1) Multi-hop propagation motivation and modeling idea
[0110] The blockchain user interaction relationship graph has the characteristics of "small world" and "local cluster", that is, a small number of highly active users and a large number of low-frequency users together form a heterogeneous connection structure. Abnormal users often cross multiple clusters to transfer value, forming hidden associations through a small number of transfers. If only one-hop neighborhood is considered, the model can only obtain local patterns; if the propagation depth is increased without control, a large amount of noise will be introduced. Based on this, the present invention proposes a resistance guided multi-hop propagation mechanism, which automatically controls the depth and intensity of information diffusion by virtue of the physical property that resistance affinity decays with the number of hops, realizing "global perception within a bounded range".
[0111] Let the adjacency matrix after the resistance feature enhancement module be , and the node feature matrix be .To model multi-hop propagation relationships, the present invention generates propagation features at different hop numbers through matrix power operation:
[0112] ,
[0113] wherein Representing the characteristics of the node itself, Indicates the process k The global response state of nodes after hop propagation. Matrix exponentiation essentially simulates the multi-layered diffusion process of messages in a graph structure, allowing each node to... k Within the jump, it senses information about high-confidence nodes with lower resistance in its neighborhood.
[0114] 2) Resistance attenuation law and adaptive jump number truncation
[0115] During propagation, as the number of hops increases, the resistivity between nodes decreases. The propagation exhibits an exponential decay trend. This means that information transmission between distant nodes is limited, and after a certain number of hops, the contribution of new information gradually approaches zero. Continued propagation not only introduces nodes with high resistance noise but may also cause over-smoothing of features, making all node representations converge. To address this, this invention proposes a resistance-guided hop count truncation criterion, which adaptively determines the optimal propagation depth by monitoring the decay of average resistance affinity with the number of hops. .
[0116] Definition of the first k The set of jump node pairs is:
[0117] ,
[0118] in Represents a node ( u , v The shortest path length between () nodes. For the node pairs in this set, calculate the average resistance weight:
[0119] ,
[0120] Set tolerance parameters Define the set of acceptable jumps:
[0121] ,
[0122] The optimal hop count cutoff depth is:
[0123] ,
[0124] This criterion can dynamically balance the "depth" and "effectiveness" of feature propagation: when the resistance average weight attenuation exceeds a threshold... At this point, the model stops spreading to prevent excessive propagation from amplifying noise.
[0125] 3) Skip Feature Sequence Modeling and Spatial Projection
[0126] After determining the range of effective hop numbers, the application stacks each hop feature by level to form a cross-scale feature sequence for capturing the state changes of the node under different propagation radii. For a node v , the multi-hop feature sequence thereof is defined as:
[0127] ,
[0128] wherein is a feature projection matrix for mapping different hop features to a unified semantic space . The feature sequence spatially depicts the multi-level aggregation state evolution of the node from local to global, providing a basic representation for subsequent attention aggregation.
[0129] In this way, the system can explicitly express the "response curve of the node under different resistance scales", that is, the node features are mainly affected by local isomorphism when in a low resistance neighborhood, and reflect global topological constraints when in a high resistance expansion area. Multi-scale modeling enables the model to have differentiated perception of transaction dependencies at different levels.
[0130] 4) Multi-hop attention aggregation mechanism
[0131] To select the most discriminative structural information from different hop features, the application designs a resistance-guided multi-hop attention mechanism to adaptively weight and fuse each hop feature. The calculation formula of the attention weight is:
[0132] ,
[0133] wherein is the v hop embedding vector of the node k , and is a learnable attention parameter vector, and LeakyReLU is a linear rectifier function with leakage, ensuring that the gradient is still retained in the negative interval.
[0134] The final node representation calculation is:
[0135] ,
[0136] Through attention weighting, the model can adaptively allocate the contribution weight of different hop layer features according to the node context. For example, for a highly aggregated fraud cluster, smaller hop features are often more discriminative; while for a multi-level fund transfer chain, remote hop features contain more potential fraud behavior patterns.
[0137] This mechanism not only improves the structural adaptability of the model, but also enhances the feature interpretability, facilitating subsequent visual explanation of the detection results in the security audit scenario.
[0138] 5) Residual connection and stable training strategy
[0139] To avoid feature decay or gradient vanishing in the multi-hop aggregation process, the present application introduces a residual connection mechanism in each layer of the aggregation operation, which linearly superimposes the output of the current layer and the input of the previous layer:
[0140] ,
[0141] wherein represents the l-th layer node representation, is a trainable weight matrix, is a nonlinear activation function. The residual structure makes the model maintain information flow when the number of layers is increased, avoiding excessive gradient decay in deep networks.
[0142] In system implementation, the output of this module includes: the node final embedding matrix , wherein each row characterizes the comprehensive structural state of the node v ; and the skip-layer attention matrix , which can be used as input for the subsequent fraud account classification module and visual interpretation. This module enables the entire system to have the ability to analyze transaction patterns at multiple scales, providing a solid structural support for the identification and tracking of complex blockchain fraud behaviors.
[0143] (4) User classification and model training module
[0144] This module is mainly responsible for classifying and optimizing the training of the node high-dimensional embedding features output by the resistance-guided multi-hop aggregation module, so as to realize the intelligent identification and risk warning of normal users and multi-type abnormal users in the blockchain environment. This module establishes a supervised learning mechanism, combines cross-entropy loss, regularization constraints and dynamic optimization strategies to ensure stable convergence and generalization performance of the model on large-scale sparse transaction networks. Its core processes include: classification mapping modeling, loss function design, parameter optimization training and system reasoning output.
[0145] 1) Classification mapping modeling
[0146] After the foregoing resistance perception and multi-hop aggregation processing, each node v has an embedding vector containing global structure and local behavior features. This feature vector comprehensively reflects the multi-level semantic information of the account, including its topological position in the transaction network, fund flow characteristics, and association strength with suspicious accounts. To convert these embedding vectors into distinguishable account type labels, the present application designs a multi-layer linear mapping and probability normalization module.
[0147] Define the classification mapping function:
[0148] ,
[0149] where, is the set of all node embeddings, is the classification weight matrix, is the bias vector, and C is the total number of classes. The Softmax function is used to map the output to a multi-class probability distribution:
[0150] ,
[0151] This module outputs the probability value of each node belonging to different categories (such as resource-consuming users, high-frequency intermediary users, regular transaction users, high- volatility transaction users, risk transmission correlation users, and high-frequency random interaction users), thereby providing a probability quantification basis for subsequent risk identification and security warning.
[0152] To enhance the non-linear expression capability of the features, the invention can optionally add one or more non-linear transformation layers before the classifier:
[0153] ,
[0154] where is the hidden layer weight matrix, is the non-linear activation function (such as ReLU or GELU). This design further improves the model's fitting ability for complex boundary distributions, enabling the classifier to distinguish similar transaction features under different abnormal behaviors.
[0155] 2) Loss function design and regularization constraint
[0156] To achieve effective training of the model in a semi-supervised scenario, the invention uses a cross-entropy loss function as the main optimization objective, and only supervises the learning of the set of labeled nodes . The loss function is defined as:
[0157] ,
[0158] where represents the true label distribution of node v , is the predicted probability value. This loss function measures the distribution difference between the model output and the true label, and optimizes the classifier and the previous layer parameters through gradient backpropagation.
[0159] To improve the generalization ability of the model and prevent overfitting, the invention introduces parameter regularization constraints. The overall optimization objective is defined as:
[0160] ,
[0161] where the entire set of trainable parameters of the model (including etc.), is a regularization coefficient used to limit the instability of the model caused by excessively large weights. The introduction of the regularization term can suppress the over-learning of noise features while maintaining the classification accuracy.
[0162] In addition, to enhance the robustness and anti-interference ability of the model, the present application further introduces the DropEdge strategy and the node perturbation regularization term. The DropEdge strategy weakens the strong dependence of the model on certain local structures by randomly discarding a portion of the edge connections in each training iteration, thereby improving the anti-sensitivity to network perturbations. The node perturbation regularization term enhances the stability of the model in the near neighbor state by applying a small perturbation to the node embedding in the feature space. Its expression form is:
[0163]
[0164] where is a Gaussian perturbation noise, represents the network mapping function. The final comprehensive loss is:
[0165]
[0166] 3) Parameter optimization and training mechanism
[0167] The model training adopts a phased joint optimization strategy. First, the resistance affinity parameters are pre-adjusted to ensure that the adjacent weight process can stably reflect the global structural relationship between nodes. Then, the Adam optimizer is used for end-to-end gradient update, with a learning rate of , and a learning rate decay strategy is enabled to prevent oscillation.
[0168] During the training process, the present application adopts a batch node sampling mechanism to reduce the memory burden of large-scale graph calculation. Specifically, in each iteration, a portion of the subgraphs are randomly selected for forward propagation and gradient update, allowing the model to gradually converge to the global optimum on local substructures. For the resistance pseudo-inverse calculation part, the system uses a sparse matrix block approximation method to avoid the computational explosion problem caused by directly solving the pseudo-inverse matrix of the full graph. This method calculates the approximate pseudo-inverse on each subgraph , and then weights and fuses the results in the full graph range, thereby balancing the computational complexity and accuracy.
[0169] 4) Model inference and abnormal user identification
[0170] After the model training is completed, the system performs forward propagation on the full graph nodes in the inference stage, outputting the class probability vector . According to the maximum likelihood principle:
[0171] ,
[0172] The predicted category of each user is obtained. For the anomaly detection task, the system focuses on the nodes with the category of "suspicious behavior" or "abnormal interaction", and further calculates the anomaly risk score:
[0173] ,
[0174] wherein is a set of fraud categories. The risk score reflects the confidence of the user being judged as an abnormal type, which can be used to generate a hierarchical alarm. The system divides the prediction results into low-risk, medium-risk and high-risk users, forming an automatic early warning report.
[0175] The application converts the high-dimensional embedding vector output by the graph neural network into an operable abnormal user risk prediction result through the module, forming a full-process closed loop from "structure modeling - resistance perception - multi-hop propagation - risk identification". The method can finally output account classification results, fraud risk scores and corresponding explanation reports, providing an efficient, intelligent and explainable solution for blockchain ecological environment safety and on-chain behavior compliance analysis.
[0176] 4. Experimental verification
[0177] To verify the performance advantage of the blockchain abnormal user identification method proposed by the system in the complex on-chain interaction network scenario, a large-scale blockchain user interaction graph experimental data set is constructed. The data is collected from the public XBlock platform, which collects real blockchain transaction records and account feature information. The data set consists of the following three types of structural features: ① transaction topology features: account-to-account transfer connection relationships and transaction frequency, reflecting the structure of the flow of funds between accounts; ② account behavior features: including transaction total, average in-degree, average out-degree, income-to-expense ratio, transaction interval time, balance change rate, etc. statistical features, used to represent the dynamic behavior pattern of the account; ③ graph structure features: by calculating the effective resistance between nodes and the inverse result of the graph Laplacian matrix, the global association between node pairs is described.
[0178] In this data set, there are a total of 1,402,220 nodes and 2,815,028 edges, with nodes representing on-chain user entities and edges representing value interaction behaviors. According to the public labeling and on-chain audit information, users are divided into six categories: ① resource consumption type users; ② high-frequency intermediary users; ③ regular transaction users; ④ high volatility transaction users; ⑤ risk transmission associated users; ⑥ high-frequency random interaction users. Among them, 816 labeled nodes are selected as supervised samples, and the remaining unlabeled nodes participate in semi-supervised propagation learning. The data set is divided into training set, validation set and test set in the ratio of 6:2:2 to ensure balanced distribution of each category.
[0179] To verify the advantages of the method of the application in robustness, classification accuracy and computational efficiency, the following four types of mainstream benchmark models are set for comparison: ① GCN: standard graph convolutional network based on local neighborhood feature propagation; ② GAT: neighborhood weighting model based on attention mechanism; ③ GraphSAGE: structure model based on sampleable aggregation; ④ Cluster-GCN: adopts graph partitioning strategy to improve the training efficiency of large-scale graphs.
[0180] All methods are evaluated under the same data partitioning and experimental environment. To test the robustness of the model under feature noise conditions, three levels of disturbance conditions are set: ① mild disturbance (10%): 10% Gaussian noise is randomly injected into the node features to simulate mild feature interference; ② moderate disturbance (20%): the noise injection ratio increases to 20% to simulate real on-chain partial feature missing and disguised transactions; ③ strong disturbance (30%): 30% noise is randomly injected into the node features and a small amount of edge connections are discarded to simulate extreme abnormality and severe feature pollution environment. This disturbance design can systematically evaluate the robustness and anti-interference performance of the model under different noise intensities.
[0181] The evaluation indicators include: ① precision (Prec) and recall (Rec): evaluate the fine-grained performance of classification; ② Micro-F1 value and Macro-F1 value: measure the overall and class-balanced performance; ③ inference time (Time): single batch data processing delay, reflecting the deployment efficiency of the system.
[0182] Table 1 Comparison of data of different methods under five indicators
[0183] Method name Prec Rec Micro-F1 Macro-F1 Time(s) GCN 79.2% 77.1% 78.1% 75.5% 1.24 GAT 80.5% 78.3% 79.4% 76.8% 1.32 GraphSAGE 82.4% 80.1% 81.2% 78.9% 1.10 Cluster-GCN 83.6% 81.8% 82.6% 80.8% 0.96 The method of the present invention 87.9% 84.7% 88.3% 86.1% 0.78
[0184] The experimental results are shown in Table 1, Figure 2 , Figure 3 , Figure 4 The method of the application achieves the best results in precision, recall and comprehensive F1 indicators, with an improvement of about 5.7% in Micro-F1 value compared to the existing optimal method Cluster-GCN. At the same time, in terms of computational efficiency, the single batch inference time is only 0.78 seconds, which is significantly better than the 1.24 seconds of GCN and the 1.32 seconds of GAT, showing excellent structure modeling and computational efficiency.
[0185] To further verify the robustness of the model, the performance changes under different feature disturbance intensities (10%, 20%, 30%) are evaluated. The results show that when the noise ratio is 10%, the performance of the method of the application decreases by less than 1.8%; under 20% disturbance, it decreases by about 3.1%; even in a strong noise environment of 30%, the Micro-F1 value of the model remains above 0.85, while the traditional model decreases by an average of 7%-12%. This shows that the method of the application has significant feature robustness and anti-interference ability. In addition, through the visualization analysis of the resistance adjacency matrix and the multi-hop attention weight distribution, the model can focus on the high-conduction path and low-resistance subgraph area, thereby accurately identifying suspicious fund circulation and multi-level transfer accounts. The results verify the superiority of the resistance enhancement mechanism and the multi-hop aggregation strategy in the application in terms of feature propagation effectiveness and interpretability.
[0186] In summary, the method of the application has significant advantages in classification accuracy, robustness, time efficiency, and interpretability. Compared with traditional local propagation-based graph neural networks, the method of the application introduces global resistance relationship modeling and an adaptive multi-hop aggregation strategy, achieving a balance between "depth" and "effectiveness" of feature diffusion, maintaining high recognition rate and stable output in large-scale heterogeneous chain interaction graphs, and fully demonstrating its practical application value and promotion potential in blockchain security monitoring, fraud identification, and user behavior profiling.
[0187] Embodiment 2
[0188] The embodiment provides a blockchain abnormal user detection system based on resistance perception.
[0189] A computer-readable storage medium, wherein a plurality of instructions are stored, the instructions being adapted to be loaded and executed by a processor of a terminal device to perform the blockchain abnormal user detection method based on resistance perception.
[0190] A terminal device, comprising a processor and a computer-readable storage medium, the processor being configured to implement instructions, and the computer-readable storage medium being configured to store a plurality of instructions, the instructions being adapted to be loaded and executed by the processor to perform the blockchain abnormal user detection method based on resistance perception.
[0191] The above are preferred embodiments of the application, which do not limit the protection scope of the application, therefore: any equivalent changes made on the basis of the structure, shape, principle of the application should be covered within the protection scope of the application.
Claims
1. A blockchain abnormal user detection method based on resistance sensing, characterized in that, include: Obtain the original transaction dataset; Perform data preprocessing on the acquired raw transaction dataset; Based on the preprocessed data, node feature extraction, structural encoding, and feature fusion are performed to obtain the node feature matrix. Feature enhancement of the node feature matrix is performed using a feature enhancement mechanism based on effective resistance; The enhanced features are aggregated using a resistance-sensing multi-hop aggregation mechanism to obtain high-dimensional embedding features of nodes; The high-dimensional embedding features of nodes are classified and optimized for training, and the risk prediction results are output. The feature enhancement mechanism based on effective resistance for node feature matrix enhancement also includes defining the effective resistance between nodes: ,in The Moore-Penrose pseudoinverse of the Laplace matrix. and They are nodes u and v The unit basis vectors; using the random walk subgraph approximation method, for each target node... v Perform a finite-step random walk to construct a subgraph containing its multi-hop neighborhood. Calculate the Laplace subgraph Then, the approximate effective resistance is obtained through pseudo-inverse operation: ,in( i , j ) are nodes ( v , u )exist The index in the matrix is used to reduce the matrix inversion overhead while ensuring global feature representation. After obtaining the effective resistance between node pairs, a resistance-guided affinity matrix is constructed to replace the original adjacency relationship, where the affinity function is defined as follows: ,in Control the decay rate, To adjust the degree of nonlinearity of the resistance effect and maintain numerical stability, a small constant is set. And the adjacency weight of each node is normalized: The normalized resistance-sensing adjacency matrix is denoted as ; After obtaining the resistance-aware adjacency matrix, an enhanced feature representation of the nodes is generated through neighborhood weighted aggregation. For any node... v The enhanced features are calculated as follows: ,in x v For the characteristics of the node itself, w ( v , u ) represents the resistance weighting coefficient, and Concat indicates the splicing operation.
2. The blockchain abnormal user detection method based on resistance sensing according to claim 1, characterized in that, The data preprocessing of the acquired raw transaction dataset includes assuming the raw transaction dataset is represented as: ,in, T The total number of transactions. C To determine the number of feature channels for a transaction, and to reduce noise interference and improve feature quality, a filtering operation is performed on the original transaction data. The filtering function is defined as follows: , in, d This represents a single transaction record, where amount is the transaction amount and type is the transaction type. After data cleaning, a transaction network is constructed based on transaction relationships, and an adjacency matrix is defined. A for: , This yields the edge set. The set of nodes in a network V Each edge represents an on-chain account entity, and each edge represents the fund flow relationship between accounts. After data preprocessing and feature extraction, the final standardized transaction network is represented as follows: in, Functions for data processing and network construction; V A set of nodes; E Let it be the set of edges; Y This is a matrix of account category labels.
3. The blockchain abnormal user detection method based on resistance sensing according to claim 2, characterized in that, The process of extracting node features, encoding structures, and fusing features based on preprocessed data to obtain a node feature matrix includes first extracting transaction behavior features, and then assigning each node ( v i The transaction sequence at time step (t) is represented as: ,in For transaction timestamps, For the transaction amount, The number of transactions; then, statistical characteristics are calculated: , This generates an 8-dimensional transaction statistical vector; then, structural topological features are extracted to capture the positional relationships and local connectivity patterns of accounts within the network, by calculating the in-degree of the indicator. , out-degree Clustering coefficient and PageRank value This forms the structural feature vector: Next, positional encoding and global structure embedding are performed. To incorporate global geometric information, the directed graph Laplacian matrix is calculated. And obtain the matrix composed of its first s non-trivial eigenvectors: ,in for L The eigenvectors represent the relative positions of nodes in the global topological space. U The node position is encoded as input; finally, feature fusion and normalization are performed to construct a complete node feature matrix by combining the features: ,in This indicates a feature splicing operation.
4. The blockchain abnormal user detection method based on resistance sensing according to claim 3, characterized in that, The feature enhancement mechanism based on effective resistance for node feature matrix enhancement includes incorporating effective resistance into the adjacency weight model of graph neural networks to quantify the global correlation of nodes. The original transaction network is assumed to be a weighted directed graph. G =( V , E , W ),in V For a set of account nodes, E For the set of transaction edges, W ij Indicates from account i to account j The transaction strength is defined by the out-degree of a node as: The total volume of the graph is defined as Define the degree matrix And the transition probability matrix: ,in P ij Indicates from node i To the node j The transition probability, obtained from random walk theory, is the stationary distribution vector. ,satisfy ,remember The Laplace matrix of a directed graph is defined as: in I It is an identity matrix.
5. The blockchain abnormal user detection method based on resistance sensing according to claim 4, characterized in that, The enhanced features are aggregated using a resistance-sensing multi-hop aggregation mechanism to obtain high-dimensional embedded features of nodes. This includes using a resistance-guided multi-hop propagation mechanism to control the depth and intensity of information diffusion, achieving global perception within a bounded range. First, let the adjacency matrix after processing by the resistance feature enhancement module be... The node feature matrix is To model multi-hop propagation relationships, propagation features with different numbers of hops are generated through matrix exponentiation: ,in Representing the characteristics of the node itself, Indicates the process k The global response state of node features after jump propagation; During propagation, as the number of hops increases, the resistivity between nodes decreases. Exhibiting an exponential decay trend, the optimal propagation depth is adaptively determined by using a resistance-guided hop count cutoff criterion and monitoring the change in average resistance affinity as the hop count decreases. , where the definition of the first k The set of jump node pairs is: ,in Represents a node ( u , v Find the shortest path length between the nodes in the set, and calculate the average resistance weight for each pair of nodes in the set. Let tolerance parameter be set. Define the set of acceptable jumps: The optimal hop count cutoff depth is: .
6. The blockchain abnormal user detection method based on resistance sensing according to claim 5, characterized in that, The process involves aggregating the enhanced features using a resistance-sensing-based multi-hop aggregation mechanism to obtain high-dimensional embedding features for the nodes. It also includes stacking the hop features hierarchically after determining the effective hop count range to form a cross-scale feature sequence, used to capture the state changes of nodes under different propagation radii. v The multi-hop feature sequence is defined as follows: ,in This is the feature projection matrix, used to map different jump features to a unified semantic space. Then, to select the most discriminative structural information from different hop features, a resistance-guided multi-hop attention mechanism is used to adaptively weight and fuse the hop features, with attention weights... The calculation formula is: ,in For nodes v The k Jump embedding vector, Given a learnable attention parameter vector, LeakyReLU is a linear rectified function with leakage, and the final node representation is calculated as follows: Finally, to avoid feature decay or gradient vanishing during multi-hop aggregation, a residual connection mechanism is introduced in each aggregation operation to linearly superimpose the output of the current layer with the input of the previous layer. ,in This represents the node representation at level l. For trainable weight matrix, It is a non-linear activation function.
7. The blockchain abnormal user detection method based on resistance sensing according to claim 6, characterized in that, The process involves classifying and optimizing the high-dimensional embedded features of nodes, and outputting risk prediction results, including classification mapping modeling. After the aforementioned resistance sensing and multi-hop aggregation processing, each node... v Embedded vectors containing both global structural and local behavioral features First, using multi-level linear mapping and probability normalization, we define a classification mapping function: ,in, A set embedded for all nodes. This is the classification weight matrix. Here, C is the bias vector, and C is the total number of classes. The Softmax function is used to map the output to a multi-class probability distribution. Then, to enhance the nonlinear expressive power of features, a nonlinear transformation layer is added before the classifier: ,in The hidden layer weight matrix is... The activation function is non-linear; next, a loss function and regularization constraints are constructed. To achieve effective training of the model in a semi-supervised scenario, the cross-entropy loss function is used as the main optimization objective for the labeled node set. For supervised learning, the loss function is defined as: ,in Represents a node v The true label distribution This is the predicted probability value.
8. The blockchain abnormal user detection method based on resistance sensing according to claim 7, characterized in that, The process of classifying and optimizing the high-dimensional embedded features of nodes and outputting risk prediction results also includes introducing parameter regularization constraints and defining the overall optimization objective as: ,in This represents the complete set of trainable parameters of the model. The regularization coefficient is then introduced, followed by the DropEdge strategy and node perturbation regularization term, expressed as: ,in This is Gaussian perturbation noise. The network mapping function represents the final comprehensive loss as follows: Finally, a parameter optimization and training mechanism is implemented, employing a phased joint optimization strategy. First, the resistivity affinity parameter is optimized. After pre-tuning, the Adam optimizer is used for end-to-end gradient updates. After model training is complete, forward propagation is performed on all nodes in the graph during the inference phase to output the class probability vector for each user. According to the principle of maximum probability: The predicted category for each user is obtained, and an anomaly risk score is further calculated for the anomaly detection task. ,in This is a collection of fraud categories.
9. A blockchain abnormal user detection system based on resistance sensing, executing the blockchain abnormal user detection method based on resistance sensing as described in claim 1, characterized in that, include: The data acquisition module is configured to acquire the raw transaction dataset; The preprocessing module is configured to preprocess the acquired raw transaction dataset. The feature matrix module is configured to perform node feature extraction, structural encoding, and feature fusion based on the preprocessed data to obtain a node feature matrix. The feature enhancement module is configured to enhance the node feature matrix using a feature enhancement mechanism based on effective resistance. The aggregation module is configured to aggregate the enhanced features using a resistance-aware multi-hop aggregation mechanism to obtain high-dimensional embedding features of the nodes. The prediction module is configured to classify and optimize the high-dimensional embedded features of nodes and output risk prediction results.
Citation Information
Patent Citations
Method for discovering and repairing abnormal node of block chain and storage medium
CN114465873A
Abnormal user detection method based on graph structure learning
CN114626890A