Financial data flow anomaly detection method and system based on block chain

By using a blockchain-based method for detecting anomalies in financial data flows, this method analyzes the connections and topology of blockchain nodes, builds a model, and monitors abnormal transactions in real time. This solves the problems of insufficient data security and real-time performance in traditional systems, achieving efficient anomaly detection and rapid response, and improving the security of financial transactions and system stability.

CN121765585APending Publication Date: 2026-03-31CHINA CONSTR BANK CO LTD GUANGDONG BRANCH
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-24
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

Traditional financial data management systems are inadequate in terms of data security, real-time performance, and reliability, making it difficult to meet the demands of a rapidly evolving market. In particular, they are unable to effectively identify and respond to abnormal behavior when facing complex financial markets and high-frequency trading.

Method used

A blockchain-based financial data flow anomaly detection method is adopted. By analyzing the connection and topology of blockchain nodes, a topology model is constructed. Combined with historical anomaly transaction detection and consensus correction, an anomaly transaction detection model is built. Anomaly transactions are monitored and rolled back in real time, improving detection accuracy and response speed.

Benefits of technology

It improves the accuracy and security of financial data anomaly detection, enhances real-time performance and credibility, improves financial institutions' data management and anomaly detection capabilities in complex markets, reduces potential losses, and ensures the security and compliance of transactions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121765585A_ABST
    Figure CN121765585A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a financial data flow anomaly detection method and system based on a block chain. The method comprises the following steps: constructing a block chain topological structure model based on block chain link data; marking the block chain topological structure model based on the block chain financial data to determine a block chain node marking model; correcting the abnormal financial transaction detection data based on a block chain node marking model to determine abnormal financial transaction correction data, and constructing an abnormal financial transaction detection model; performing real-time abnormal financial transaction detection on the block chain financial data to determine real-time abnormal financial transaction data and real-time normal financial transaction data; transaction transaction rollback strategy analysis is carried out on the real-time financial transaction data according to the block chain node marking model to determine an abnormal transaction rollback strategy, and the abnormal transaction rollback strategy is uploaded to the financial block chain service platform so as to execute an abnormal transaction rollback task, so that decentralized data storage, processing and anomaly detection are realized, and the data processing efficiency is improved. And the accuracy of financial data anomaly detection is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of blockchain technology, and in particular to a method and system for detecting anomalies in financial data flows based on blockchain. Background Technology

[0002] With the continuous expansion of global financial markets and the acceleration of digitalization, financial institutions and market participants face increasingly complex financial risks and data management challenges. Traditional financial data management and anomaly detection methods can no longer meet the demands of a rapidly evolving market, particularly in terms of data security, real-time performance, and reliability.

[0003] Currently, traditional financial data management relies on centralized data storage and processing systems, which are often targets for attackers, making data security difficult to guarantee. Furthermore, traditional systems suffer from inefficiency and poor real-time performance when processing large-scale data, making it difficult to promptly detect and respond to potential anomalies. With the increasing complexity of financial markets and the growing frequency of transactions, financial institutions have an increasingly urgent need for real-time data analysis and anomaly detection. Traditional data processing methods often fail to meet the requirements for immediacy and accuracy. Summary of the Invention

[0004] This invention provides a blockchain-based method and system for detecting anomalies in financial data streams, enabling decentralized data storage, processing, and anomaly detection, thereby improving the accuracy of financial data anomaly detection.

[0005] In a first aspect, embodiments of the present invention provide a blockchain-based method for detecting anomalies in financial data flows, comprising: Obtain blockchain link data, analyze blockchain connection nodes based on the blockchain link data, determine the blockchain node connection network, and analyze the blockchain topology structure based on the blockchain node connection network to determine the blockchain topology structure model. Acquire blockchain financial data, perform historical abnormal financial transaction detection on the blockchain financial data, determine abnormal financial transaction detection data, and mark abnormal financial nodes in the blockchain topology model based on the abnormal financial transaction detection data to determine the blockchain node marking model. The abnormal financial transaction detection data is corrected by abnormal node consensus according to the blockchain node marking model to determine the abnormal financial transaction correction data, and an abnormal financial transaction detection model is constructed based on the abnormal financial transaction correction data. The abnormal financial transaction detection model is used to detect abnormal financial transactions in the blockchain financial data in real time, identify real-time abnormal financial transaction data and real-time normal financial transaction data, and upload the real-time normal financial transaction data to the financial blockchain service platform for the execution of real-time transaction tasks. The real-time abnormal financial transaction data is analyzed for transaction rollback strategies based on the blockchain node marking model. The abnormal transaction rollback strategies are then determined and uploaded to the financial blockchain service platform for execution of abnormal transaction rollback tasks.

[0006] Secondly, embodiments of the present invention also provide a blockchain-based financial data flow anomaly detection system, the system comprising: The blockchain topology analysis module is used to acquire blockchain link data, analyze blockchain connection nodes based on the blockchain link data, determine the blockchain node connection network, and perform blockchain topology analysis based on the blockchain node connection network to determine the blockchain topology model. An abnormal financial node marking module is used to acquire blockchain financial data, perform historical abnormal financial transaction detection on the blockchain financial data, determine abnormal financial transaction detection data, and mark abnormal financial nodes in the blockchain topology model based on the abnormal financial transaction detection data to determine the blockchain node marking model. An abnormal node consensus correction module is used to perform abnormal node consensus correction on the abnormal financial transaction detection data according to the blockchain node marking model, determine the abnormal financial transaction correction data, and construct an abnormal financial transaction detection model based on the abnormal financial transaction correction data. The real-time abnormal financial transaction detection module is used to perform real-time abnormal financial transaction detection on the blockchain financial data through the abnormal financial transaction detection model, determine the real-time abnormal financial transaction data and the real-time normal financial transaction data, and upload the real-time normal financial transaction data to the financial blockchain service platform for the execution of real-time transaction tasks. The rollback strategy analysis module is used to perform transaction rollback strategy analysis on the real-time abnormal financial transaction data according to the blockchain node marking model, determine the abnormal transaction rollback strategy, and upload the abnormal transaction rollback strategy to the financial blockchain service platform for execution of the abnormal transaction rollback task.

[0007] Thirdly, embodiments of the present invention also provide an electronic device, the electronic device comprising: One or more processors; Memory, used to store one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the blockchain-based financial data flow anomaly detection method provided in any embodiment of the present invention.

[0008] Fourthly, embodiments of the present invention provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the blockchain-based financial data flow anomaly detection method as provided in any embodiment of the present invention.

[0009] Fifthly, embodiments of the present invention provide a computer program product, including a computer program that, when executed by a processor, implements the blockchain-based financial data flow anomaly detection method provided in any embodiment of the present invention.

[0010] The technical solution of this invention, by analyzing the connection and topology of blockchain nodes, can establish an accurate blockchain topology model. This helps financial institutions understand the overall structure of the blockchain network they participate in and the relationships between nodes. This model can be used to identify potential single points of failure, network partitions, or the existence of abnormal nodes. Using historical blockchain financial data for abnormal transaction detection can help identify existing anomalies or violations. By combining the abnormal transaction detection results with the blockchain topology model, specific nodes associated with abnormal transactions can be marked. This facilitates further investigation and preventative measures. Consensus correction of abnormal transaction data through a blockchain node marking model can improve the accuracy and reliability of anomaly detection. Constructing a detection model based on abnormal transaction correction data helps to monitor and identify new abnormal financial transaction patterns in real time, thereby improving the system's anti-fraud capabilities and response speed. Monitoring real-time blockchain financial data using the abnormal financial transaction detection model allows for real-time identification and response to abnormal transactions. Simultaneously, uploading real-time normal financial transaction data to the financial blockchain service platform helps ensure the smooth operation of normal transactions, enhancing the overall system's stability and reliability. By analyzing abnormal transaction rollback strategies for real-time financial transaction data, effective countermeasures can be taken quickly when abnormal transactions occur. This strategic analysis and execution can minimize potential losses and ensure the security and compliance of financial transactions. In summary, these steps work together to improve financial institutions' data management, anomaly detection, and response capabilities in complex financial markets and high-frequency trading environments. The application of blockchain technology not only enhances data security and real-time performance but also improves the efficiency and credibility of the overall system, helping the financial industry better meet the challenges and demands of modernization.

[0011] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description

[0012] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0013] Figure 1 This is a flowchart of a blockchain-based financial data flow anomaly detection method provided in Embodiment 1 of the present invention; Figure 2 This is a flowchart of a blockchain-based financial data flow anomaly detection method provided in Embodiment 2 of the present invention; Figure 3 This is a flowchart of a blockchain-based financial data flow anomaly detection method provided in Embodiment 3 of the present invention; Figure 4 This is a schematic diagram of the structure of a blockchain-based financial data flow anomaly detection system provided in Embodiment 4 of the present invention; Figure 5 This is a schematic diagram of the structure of an electronic device that implements the blockchain-based financial data flow anomaly detection method according to embodiments of the present invention. Detailed Implementation

[0014] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0015] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0016] Example 1 Figure 1 This invention provides a flowchart of a blockchain-based financial data stream anomaly detection method according to Embodiment 1. This embodiment is applicable to situations where blockchain is used to detect anomalies in financial data streams. The method can be executed by a blockchain-based financial data stream anomaly detection system, which can be implemented in hardware and / or software and can be configured in an electronic device. Figure 1 As shown, the method includes: S110. Obtain blockchain link data, analyze blockchain connection nodes based on blockchain link data, determine the blockchain node connection network, and analyze the blockchain topology structure based on the blockchain node connection network to determine the blockchain topology structure model.

[0017] In this embodiment, the blockchain link data is raw data obtained from the blockchain network layer, reflecting the communication relationships between nodes. The blockchain link data is not the transaction content itself, but rather the propagation path information of transactions or blocks (e.g., a transaction is transmitted from node A to node B and then to node C) and the P2P connection relationships between nodes (e.g., direct connections between IP addresses). The blockchain node connection network is the result of formally expressing the blockchain link data using a graph theory model. In this network, a node represents a network entity (e.g., an IP address or a node ID), and an edge represents the observed connection or communication relationship between two nodes. The blockchain node connection network is a computationally usable graph structure. The blockchain topology model is a high-level knowledge representation derived from complex network analysis based on the node connection network. The blockchain topology model is not only a graph but also includes qualitative conclusions and quantitative characteristics of the network structure, such as identified core nodes (high-influence), auxiliary nodes, and whether the network is centralized or distributed. The blockchain topology model is the structural foundation for all subsequent analyses (e.g., anomaly marking, rollback strategies).

[0018] Specifically, blockchain link data is obtained from the financial blockchain network. This data includes transaction transmission paths and connections between nodes. Based on this data, blockchain node connection analysis is performed, and network analysis techniques (graph theory analysis and network traffic analysis) are used to construct the blockchain node connection network of the financial blockchain network. Complex network analysis methods (such as degree centrality and betweenness centrality) are employed to analyze the blockchain node connection network, identifying key and core nodes, thereby revealing the topological characteristics of the blockchain. These topological characteristics are then used to construct a blockchain topology model. For example, graph databases such as Neo4j or Python's NetworkX library are used for node analysis and topology visualization to better understand and optimize the blockchain network structure.

[0019] S120. Obtain blockchain financial data, perform historical abnormal financial transaction detection on the blockchain financial data, determine abnormal financial transaction detection data, and mark abnormal financial nodes in the blockchain topology model based on the abnormal financial transaction detection data to determine the blockchain node marking model.

[0020] In this embodiment, blockchain financial data refers to transaction content data at the application layer of a financial blockchain network, including transaction hashes, sending / receiving addresses, transaction amounts, timestamps, and smart contract call inputs. Abnormal financial transaction detection data is a list of all suspicious transactions detected in both ordinary and smart contract transactions. The blockchain node labeling model is the result of mapping the abnormal financial transaction detection data onto a blockchain topology model. The blockchain node labeling model is a topology model with risk labels. Through the blockchain node labeling model, not only can the importance of nodes (core / auxiliary) be determined, but also which nodes are associated with historical abnormal transaction behaviors (such as being labeled "fraudulent" or "suspected money laundering").

[0021] Specifically, blockchain financial data is obtained from the financial blockchain network. After acquiring anomaly detection data through historical anomaly transaction detection, this data needs to be combined with the established blockchain topology model. Based on the anomaly detection data, machine learning algorithms (such as cluster analysis or classifiers) can be used to label the blockchain topology model, identifying potential anomalous financial nodes. For example, algorithms such as Support Vector Machine (SVM) or Random Forest can be used to label possible anomalous nodes based on the propagation path and frequency of anomalous transactions. These node labels can aid in further analysis and correction of anomalous transactions.

[0022] S130. Based on the blockchain node marking model, perform abnormal node consensus correction on the abnormal financial transaction detection data, determine the abnormal financial transaction correction data, and construct an abnormal financial transaction detection model based on the abnormal financial transaction correction data.

[0023] In this embodiment, the abnormal financial transaction correction data is a more accurate and reliable historical abnormal dataset obtained by removing misjudged abnormal transaction node data from the abnormal financial transaction detection data. The abnormal financial transaction detection model is a machine learning model (such as SVM, random forest, neural network model) that can automatically determine whether a transaction is abnormal, constructed using supervised or unsupervised learning algorithms and the abnormal financial transaction correction data as key training input. This is the core engine of the system's real-time detection.

[0024] Specifically, consensus correction is performed on abnormal financial transaction detection data based on a blockchain node marking model. This includes using algorithms to verify and correct potentially false positives or false negatives for anomalous nodes. For example, by combining blockchain consensus mechanisms (such as proof-of-work or proof-of-stake), additional verification is performed on nodes marked as anomalous to ensure that only truly anomalous nodes are included in subsequent processing. This correction can be automated on the blockchain via smart contracts, guaranteeing data consistency and reliability.

[0025] For example, an anomaly detection model can be built based on corrected abnormal financial transaction data. This can be done using supervised or unsupervised learning methods, training the model with known abnormal and normal transaction data. For instance, machine learning algorithms such as support vector machines (SVMs) or neural networks can be used, combined with empirical data, to train the model to identify and predict possible future abnormal transaction patterns.

[0026] As an optional implementation of this disclosure, the abnormal financial transaction detection data is corrected based on the blockchain node tagging model to determine the abnormal financial transaction correction data. Specifically, this includes: extracting abnormal transaction node features from the abnormal financial transaction detection data to determine abnormal financial transaction node data; extracting abnormal financial transaction node link features from the blockchain node tagging model based on the abnormal financial transaction node data to determine abnormal financial transaction node link data; acquiring blockchain network protocol data and extracting consensus mechanism features from the blockchain network protocol data to determine blockchain consensus mechanism data; verifying misjudged abnormal nodes in the abnormal financial transaction node link data based on the blockchain consensus mechanism data to determine misjudged abnormal transaction node data; and correcting the abnormal financial transaction detection data based on the misjudged abnormal transaction node data to determine the abnormal financial transaction correction data.

[0027] In this embodiment, the abnormal financial transaction node data is a set of features extracted and structured from the initially detected abnormal financial transaction detection data. These features are used to describe the behavioral patterns of a node (or address) considered "abnormal". For example, the abnormal financial transaction node data may include, but is not limited to, transaction behavior features, time pattern features, network association features, and counterparty features. Transaction behavior features refer to the node's total transaction amount, transaction frequency, average transaction amount, and transaction amount variance during abnormal time periods. Time pattern features refer to the distribution of transaction time intervals and activity period preferences (e.g., whether it is only active at night). Network association features refer to the node's degree centrality, betweenness centrality, and the number and proportion of other abnormal nodes directly associated with it, based on a topology model. Counterparty features refer to the types of nodes the node primarily transacts with (e.g., core nodes, new addresses, and already tagged addresses). Abnormal financial transaction node link data tracks the complete propagation path of abnormal transactions in the blockchain node tagging model. It focuses on how abnormal behavior spreads and associates through connections between multiple nodes.

[0028] In this embodiment, blockchain network protocol data is parameter and state data extracted from the underlying client software, network protocol, or on-chain metadata of the target blockchain (i.e., a financial blockchain) to describe and quantify its consensus mechanism and network operation rules. Blockchain network protocol data is a quantitative representation of the blockchain's rule specification. It is not the transaction content itself, but rather the underlying logic that determines how transactions are packaged, confirmed, and how the network maintains consistency. For example, blockchain network protocol data may include, but is not limited to, consensus-related parameters, network state data, and protocol rule data. Consensus-related parameters include: for PoW (Proof-of-Work), current verification difficulty, average block time, and estimated computing power distribution; for PoS (Proof-of-Stake), the validator set list and its staking weight, epoch / slot length, and slashing condition parameters. Network state data refers to the dynamic changes in the total number of nodes, statistical information on block propagation delay, and the size of the unconfirmed transaction pool (Mempool). Protocol rule data refers to block size limits and rules for the gas fee mechanism (such as the calculation methods for base fees and priority fees).

[0029] In this embodiment, the blockchain consensus mechanism data consists of rule features extracted from the blockchain protocol used to determine the legality of transactions and blocks. For example, in Proof-of-Work (PoW), this includes computing difficulty and block time; in Proof-of-Stake (PoS), it includes staked amount and validator rounds. This data is used to verify the rationality of a node's behavior at the protocol level. False positives (or misidentified abnormal transaction node data) are nodes or transactions incorrectly marked as abnormal by the initial model after verifying the abnormal transaction node link data using the blockchain consensus mechanism data.

[0030] Specifically, in the detection of abnormal financial transactions, the first step is to extract the characteristics of abnormal transaction nodes from the raw transaction data initially detected as abnormal (i.e., abnormal financial transaction detection data). These characteristics may include abnormally high or low transaction amounts, abnormal transaction frequencies, etc. For example, data mining algorithms such as Isolation Forest or cluster analysis can be used to identify nodes that do not conform to the majority of transaction behaviors. It is also possible to analyze whether the transaction amounts match historical patterns or whether there are abnormally frequent transaction behaviors.

[0031] Specifically, based on the data of abnormal financial transaction nodes, further analysis is conducted on their correlation within the blockchain network, i.e., abnormal financial transaction node link feature extraction. This can be achieved by analyzing the relationship between transaction inputs and outputs, or intermediate nodes along the transaction path. For example, graph theory algorithms can be used to analyze the input-output relationships in transactions to identify abnormal transaction paths or involved intermediate nodes.

[0032] Specifically, blockchain network protocol data is obtained through financial blockchain networks, and consensus mechanism characteristics are extracted from them. The consensus mechanism of a blockchain system directly affects the verification and confirmation process of transactions, and different consensus mechanisms have different characteristics and security guarantees. For example, the Proof-of-Work (PoW) mechanism and Ethereum's Proof-of-Stake (PoS) mechanism identify and understand the possibility of abnormal nodes by analyzing characteristics such as block generation time and difficulty adjustment rules.

[0033] Specifically, based on the blockchain consensus mechanism data, it is verified whether the extracted abnormal financial transaction node link data has been misjudged. This can be achieved by comparing the behavior of abnormal nodes with expected patterns (such as transaction frequency and amount). For example, if the transaction behavior of abnormal nodes is within the normal range of the consensus mechanism, it may be a misjudgment and requires further adjustment and confirmation.

[0034] Specifically, the abnormal financial transaction detection data is corrected based on the data from falsely flagged abnormal transaction nodes. This means correcting transactions previously marked as abnormal to ensure accurate anomaly detection results. For example, adjusting the parameters of the detection algorithm or re-evaluating the characteristics of the transaction data can reduce the false positive rate and improve the accuracy of detection.

[0035] It should be noted that, as an optional implementation of this disclosure, feature extraction from abnormal financial transaction detection data can identify the specific transaction nodes causing the anomalies. These features include abnormal transaction amounts, abnormal frequencies, and abnormal participant identities, which helps to quickly locate the problem. Based on the abnormal transaction node data, its link characteristics within the blockchain network are further extracted. These features may include information such as the transaction transmission path and the blockchain nodes involved, which helps to understand the propagation path and scope of impact of abnormal transactions. Consensus mechanism features are extracted from the blockchain network protocol data. Different blockchains use different consensus algorithms, such as Proof of Work or Proof of Stake; these features help to understand how the blockchain operates and its security. Based on the blockchain consensus mechanism data, falsely identified abnormal nodes in the abnormal transaction node link data are verified. This step ensures that only truly abnormal nodes are included in the subsequent processing stage, reducing false alarms and misprocessing. Based on the falsely identified abnormal transaction node data, the original abnormal financial transaction detection data is corrected. This includes correcting incorrectly marked abnormal transactions, ensuring the accuracy and effectiveness of subsequent analysis and processing. Based on the corrected abnormal financial transaction data, an abnormal transaction detection model is constructed. This model can be used to monitor and detect new abnormal transaction patterns in real time, improving the system's ability to respond to potential risks and threats.

[0036] S140. The abnormal financial transaction detection model is used to detect abnormal financial transactions in the blockchain financial data in real time, identify abnormal financial transaction data and normal financial transaction data in real time, and upload the normal financial transaction data in real time to the financial blockchain service platform in order to execute real-time transaction tasks.

[0037] In this embodiment, real-time abnormal financial transaction data and real-time normal financial transaction data are the classification results output by the model in real time when the abnormal financial transaction detection model is applied to the real-time inflow of blockchain transaction streams. The system divides the transaction stream into two parts: transactions judged as abnormal by the model and transactions judged as normal. The financial blockchain service platform is an integrated, business-oriented software platform or infrastructure. The financial blockchain service platform is built on one or more blockchain networks. The financial blockchain service platform is used to provide programmable, supervised, and highly available financial products and services for financial institutions, enterprises, or users. For example, the financial blockchain service platform is a client or upstream system of this detection system. The real-time normal financial transaction data and abnormal transaction rollback strategies generated by the system need to be uploaded to the platform for execution. Real-time transaction tasks are financial business operations submitted through the financial blockchain service platform that need to be immediately confirmed and recorded by the blockchain network. For example, a real-time transaction task can be a payment initiated by a user, a token exchange, or an on-chain registration of a loan application. Once a real-time transaction task is judged as normal by the system, it should be pushed to the blockchain network for packaging and confirmation without human intervention, achieving low-latency processing and process automation.

[0038] Specifically, an established anomaly detection model is used to analyze and detect real-time blockchain financial data. By monitoring new transactions and events, potential abnormal transaction patterns are identified in a timely manner, while also generating real-time normal transaction data. This data can be uploaded to the financial blockchain service platform via API interfaces or data streaming to execute real-time transaction tasks. For example, data stream processing frameworks such as Apache Kafka or AWS Kinesis are used, combined with real-time inference from machine learning models, to efficiently process and respond to various transaction events.

[0039] S150. Analyze the transaction rollback strategy of real-time abnormal financial transaction data according to the blockchain node marking model, determine the abnormal transaction rollback strategy, and upload the abnormal transaction rollback strategy to the financial blockchain service platform so as to execute the abnormal transaction rollback task.

[0040] In this embodiment, the abnormal transaction rollback strategy is a remedial measure plan formulated based on the analysis of abnormal transactions detected in real time using a blockchain node marking model. For example, if the abnormal transaction involves a marked core node, the strategy might be to immediately suspend the node's service and conduct manual review; if it involves a peripheral node, the strategy might be to automatically reject the transaction and issue an alert. This strategy needs to consider the immutability of the blockchain and may be implemented through off-chain arbitration or smart contract suspension. The abnormal transaction rollback task is a series of remedial, reversal, or isolation operations initiated and executed by the financial blockchain service platform after detecting an abnormal transaction that has been executed (or is about to be executed).

[0041] Specifically, based on the analysis of the blockchain node labeling model, transaction rollback strategy analysis is performed on real-time financial transaction data. This includes determining when and how to roll back abnormal transactions to minimize potential negative impacts. For example, this could involve executing automated rollback strategies through smart contract programming or issuing transaction reversal instructions through a blockchain monitoring platform. Such strategies need to take into account the irreversible nature of the blockchain to ensure operational security and efficiency.

[0042] The technical solution of this invention, by analyzing the connection and topology of blockchain nodes, can establish an accurate blockchain topology model. This helps financial institutions understand the overall structure of the blockchain network they participate in and the relationships between nodes. This model can be used to identify potential single points of failure, network partitions, or the existence of abnormal nodes. Using historical blockchain financial data for abnormal transaction detection can help identify existing anomalies or violations. By combining the abnormal transaction detection results with the blockchain topology model, specific nodes associated with abnormal transactions can be marked. This facilitates further investigation and preventative measures. Consensus correction of abnormal transaction data through a blockchain node marking model can improve the accuracy and reliability of anomaly detection. Constructing a detection model based on abnormal transaction correction data helps to monitor and identify new abnormal financial transaction patterns in real time, thereby improving the system's anti-fraud capabilities and response speed. Monitoring real-time blockchain financial data using the abnormal financial transaction detection model allows for real-time identification and response to abnormal transactions. Simultaneously, uploading real-time normal financial transaction data to the financial blockchain service platform helps ensure the smooth operation of normal transactions, enhancing the overall system's stability and reliability. By analyzing abnormal transaction rollback strategies for real-time financial transaction data, effective countermeasures can be taken quickly when abnormal transactions occur. This strategic analysis and execution can minimize potential losses and ensure the security and compliance of financial transactions. In summary, these steps work together to enhance financial institutions' data management, anomaly detection, and response capabilities in complex financial markets and high-frequency trading environments. The application of blockchain technology not only enhances data security and real-time performance but also improves the efficiency and credibility of the overall system, helping the financial industry better meet the challenges and demands of modernization.

[0043] Example 2 Figure 2 This is a flowchart of a blockchain-based financial data flow anomaly detection method provided in Embodiment 2 of the present invention. Based on the above embodiments, this embodiment describes in detail the process of analyzing blockchain connection nodes based on blockchain linked data to determine the blockchain node connection network. Explanations of terms that are the same as or corresponding to those in the above embodiments are not repeated here. Figure 2 As shown, the method includes: S210. Obtain blockchain link data and extract node connection features from the blockchain link data to determine the blockchain node connection data.

[0044] In this embodiment of the disclosure, the blockchain node connection data is the result of formally representing the blockchain link data using a graph theory model. In this network, a node represents a network entity (such as an IP address or a node ID), and an edge represents an observed connection or communication relationship between two nodes. It is a graph structure that can be used for computation.

[0045] Specifically, acquiring blockchain link data from financial blockchains involves using public APIs or specialized data providers. For example, Ethereum nodes can obtain block and transaction data through APIs provided by Infura or Alchemy. The acquired data can include block height, transaction hashes, sender and receiver addresses, etc. Then, node connectivity characteristics need to be extracted. These characteristics can include the number of connections a node has (degree centrality), i.e., its connectivity metric in the network; the distance between a node and other nodes (density), and its proximity within the network; and the bridging role a node plays in the network (betweenness centrality), influencing communication traffic between other nodes. Network analysis tools such as NetworkX or Graph-tool can be used to construct a graphical representation from the blockchain link data and calculate the aforementioned characteristics for each node. For example, a Python script can be written to process Ethereum transaction data using the NetworkX library to calculate the degree centrality and betweenness centrality of each node.

[0046] S220. Based on the blockchain node connection data, divide the blockchain nodes and determine the core node connection data and auxiliary node connection data.

[0047] In this embodiment, the core node connection data and the auxiliary node connection data are functional classification results of the nodes in the topology. Core nodes are nodes with extensive connections in the network, located on critical paths, and with significant influence. Auxiliary nodes are nodes with fewer connections and located at the network edge. The connection data of both constitute a complete network view.

[0048] Specifically, blockchain nodes are divided into core nodes and auxiliary nodes based on their connectivity characteristics. Core nodes typically have high centrality and importance, while auxiliary nodes play a more peripheral role in the network. Clustering algorithms such as k-means clustering or thresholds based on centrality metrics can be used for node classification. For example, based on the degree centrality and betweenness centrality of nodes, thresholds can be set to classify nodes with higher centrality as core nodes and other nodes as auxiliary nodes.

[0049] As an optional implementation of this disclosure, dividing blockchain nodes based on blockchain node connection data to determine core node connection data and auxiliary node connection data may specifically include: statistically analyzing the number of blockchain node connections to determine high-frequency and low-frequency blockchain node data; dividing the high-frequency blockchain node data into core nodes to determine core node connection data, wherein the core node connection data includes central node connection data and secondary central node connection data; and dividing the low-frequency blockchain node data into auxiliary nodes based on the core node connection data to determine auxiliary node connection data.

[0050] In this embodiment, the number of blockchain node connections refers to the total frequency of direct financial transactions between a blockchain node (typically identified by its address or network endpoint) and other nodes within a statistical period, acting as a transaction sender or receiver. High-frequency connection blockchain node data and low-frequency connection blockchain node data are two subsets of nodes obtained by setting thresholds or proportionally dividing them based on the number of node connections. High-frequency connection blockchain node data consists of nodes ranking high in connection counts (e.g., top 20%) or exceeding a certain absolute threshold, along with their connection details. They represent the active core of the network. Low-frequency connection blockchain node data consists of nodes ranking low in connection counts or below a certain threshold, along with their connection details. They represent the long tail of the network, comprising the majority of nodes but with limited individual influence. Core blockchain nodes are further selected from high-frequency connection nodes; these nodes are not only active but also occupy key positions in the network topology and possess global influence. For example, the identification criteria for core blockchain nodes consider not only the number of connections (degrees) but also the quality of their connections and their structural importance. In this embodiment, the system can identify closely connected sub-networks that form hubs by constructing a high-frequency connection node network and calculating its density. The nodes in these sub-networks are candidate core nodes.

[0051] In this embodiment, the central node connection data and secondary central node connection data can be the result of hierarchical subdivision within the core nodes. Central node connection data describes the data of the single node with the highest number of connections (degrees) in the entire high-frequency network. It is a single hub in the network, typically representing hot wallet addresses of leading exchanges or critical infrastructure. Secondary central node connection data describes the set of nodes with high connection degrees among the remaining core nodes after removing the central node. They are the secondary hub group of the network, forming the core backbone layer of the network together with the central node. Blockchain auxiliary nodes are nodes that play specific functional roles in the network, categorized among low-frequency connection nodes based on their connection mode (one-way / two-way, number of connections) with the core nodes.

[0052] Specifically, this involves analyzing the connections between nodes in the blockchain, specifically the frequency of transactions or other interactions between nodes. This can be achieved by analyzing transaction data within the blockchain, such as a particular transaction record. It can be done by calculating the number of connections for each node, i.e., the number of transactions that node has with other nodes, which can be accomplished by counting the frequency with which each address appears as a sender or receiver. Based on the transaction frequency between nodes, they are categorized into high-frequency and low-frequency connection nodes. High-frequency connection nodes typically represent nodes that interact more frequently in the blockchain, while low-frequency connection nodes reflect nodes with fewer interactions.

[0053] Specifically, frequently connected blockchain nodes need to be classified as core nodes to further analyze their importance and centrality within the entire network. Centrality metrics such as degree centrality, betweenness centrality, or closeness centrality can be used to assess the importance of each node. Appropriate thresholds should be set to determine which nodes should be considered core nodes. For example, the top few dozen nodes can be marked as core nodes based on degree centrality ranking. Highly centralized nodes should be identified and recorded as core nodes. These nodes typically exhibit high transaction activity, influence, or other important network characteristics within the blockchain network.

[0054] Specifically, low-frequency connection nodes not classified as core nodes are designated as auxiliary nodes. These nodes interact less in the network but still play a role in the overall structure. Using the obtained core node data as a reference, the connection status and interaction patterns between core nodes are understood. Based on the relationship and connection properties between low-frequency connection nodes and core nodes, they are classified as auxiliary nodes. This can be done based on network analysis results and threshold settings. Core nodes and auxiliary nodes are integrated to construct a complete blockchain network structure model for further analysis and application. Using the Python programming language and network analysis libraries, combined with the centrality measurement and connection status of core nodes, nodes not classified as core nodes are marked as auxiliary nodes, thus completing the comprehensive classification and division of blockchain nodes.

[0055] It should be noted that, as an optional implementation of this disclosure, the frequency of connections can be used to determine which nodes interact frequently. Nodes with high-frequency connections are typically core nodes in the network, involved in more transaction verification, block generation, or other important functions. The stable operation of these nodes is crucial to the security and efficiency of the entire blockchain network. Nodes with low-frequency connections play a smaller role in the network but may be auxiliary or less active nodes. Identifying low-frequency connection nodes helps to understand the overall activity and node distribution in the network. Based on the data of nodes with high-frequency connections, core nodes are further identified. These nodes typically have high degree centrality and betweenness centrality, meaning they occupy key positions in the network and can quickly disseminate information, supporting the stability and security of the system. Identifying core nodes helps improve the overall efficiency and reliability of the blockchain system. Based on the identification of core nodes, nodes with low-frequency connections are classified as auxiliary nodes. These nodes do not directly participate in the execution of core functions but play a supporting and supplementary role in the network, such as storing data and providing additional computing resources. The identification of auxiliary nodes allows for better management and optimization of the resource utilization and network structure of the entire blockchain system.

[0056] As an optional implementation of this disclosure, dividing the high-frequency connected blockchain node data into core blockchain nodes and determining the core node connection data may specifically include: spatially connecting the high-frequency connected blockchain node data to determine the high-frequency connected blockchain node network; calculating the node density of the high-frequency connected blockchain node network to determine the high-frequency node network density data; dividing the high-frequency connected blockchain node network into a high-density network based on the high-frequency node network density data to determine the high-density node network; selecting the node with the highest number of connections in the high-density node network based on the high-frequency connected blockchain node data to determine the central node connection data; removing central node connection data from the high-frequency connected blockchain node data based on the central node connection data to determine the secondary central node connection data; and merging the central node connection data and the secondary central node connection data to determine the core node connection data.

[0057] In this embodiment, the high-frequency connected blockchain node network maps and reconstructs high-frequency connected blockchain node data (such as a list of nodes and transaction pairs) into a graph data structure in graph theory. In this graph, each high-frequency node becomes a vertex, and each transaction or connection between nodes forms an edge. This is a crucial step from tabular data to a network model. It enables analysis using graph algorithms. This network contains only high-frequency nodes, aiming to analyze connection patterns and community structure within active node groups, ignoring interference from low-frequency nodes. The high-frequency node network density data is a quantitative result obtained by calculating the graph density index of the high-frequency connected blockchain node network. The most commonly used index is average degree or graph density. Average degree = sum of connections of all nodes in the network / total number of nodes. Average degree reflects the average number of connections per node. Graph density = actual number of edges / theoretically maximum number of edges. Graph density measures the tightness of network connections.

[0058] In this embodiment, the high-density node network is a subgraph selected from the high-frequency connected blockchain node network by setting a threshold based on high-frequency node network density data. This subgraph contains the nodes with the densest connections, located in the core area of ​​the network, and the connections between them. For example, nodes with a degree higher than the network average degree by a certain percentage can be selected, and only these nodes and their edges are retained to form the high-density node network. The central node connection data is obtained by identifying and extracting the single node with the highest number of connections (i.e., the maximum degree) in the high-density node network, along with the connection information between this node and all other nodes in the network. The secondary central node connection data is the connection data of the remaining nodes after removing the central node and all its connected edges in the high-density node network. These nodes themselves also have high connection density and are important backbone nodes second only to the single central node.

[0059] Specifically, the data of frequently connected blockchain nodes is transformed into a network format for subsequent network analysis and computation. Based on this data, connections between nodes are established. This can be done by representing each node as a node in the network and establishing edges based on their transaction or communication frequency. A graph data structure from graph theory is used to represent the blockchain node network, where nodes represent blockchain addresses and edges represent connections between nodes. A complete network of frequently connected blockchain nodes is constructed based on these connections. This requires considering both direct connections and potential indirect connections between nodes, such as those through shared transaction participants or frequently transacting pairs. For example, the NetworkX library in Python can be used to create and analyze blockchain node networks, using blockchain data APIs to retrieve transaction records and establish connections between nodes.

[0060] Specifically, the density of each node in a high-frequency connected blockchain node network is calculated to assess its interconnectivity within the network. The degree of each node, i.e., the number of nodes directly connected to that node, can be calculated. This can be achieved by counting the number of neighboring nodes for each node. The average, median, or other metrics of degree are used to evaluate the overall network density. High density generally indicates tighter connections between nodes. Recording the degree of each node and the overall network density data provides a basis for subsequent network partitioning and analysis. For example, a Python script can be written using the NetworkX library to calculate the degree of each node in a high-frequency connected blockchain node network and calculate the network's average degree as an indicator of density.

[0061] Specifically, based on the calculated high-frequency node network density data, the high-frequency connected blockchain node network is divided into high-density node networks and other node networks. An appropriate density threshold is set to classify nodes into high-density and non-high-density nodes; this can be determined based on the distribution of node degree in the network or prior knowledge. Based on the node density value, they are categorized into high-density and low-density nodes. High-density nodes typically have more connections and interactions and play a more important role in the blockchain network. A sub-network containing high-density nodes is established, which will be used for subsequent selection and analysis of central and secondary central nodes. For example, Python can be used for data analysis and conditional judgment, marking nodes as high-density nodes according to the pre-set density threshold and generating a subgraph of high-density nodes for further analysis.

[0062] Specifically, the node with the highest number of connections is selected from the high-density node network as the central node to reflect its core position in the blockchain network. The number of connections between each high-density node and other nodes is counted. This can be done by calculating the degree (i.e., the number of connections) of the nodes. The node with the highest number of connections is selected as the central node. This usually means that the node has the highest interaction frequency in the high-density network and is a key node in the network. The selected central node and its connections with other nodes are recorded as a basis for subsequent steps. For example, a Python script can be written to use the NetworkX library to calculate the degree of each node in the high-density node network and select the node with the highest number of connections as the central node based on the maximum degree.

[0063] Specifically, based on the selected central node connection data, data related to the central node is removed from the high-frequency connection blockchain node data to obtain secondary central node connection data. Data directly related to the central node is removed from the high-frequency connection blockchain node data. This can be achieved by filtering and screening the dataset.

[0064] Specifically, two datasets containing central node connection data and secondary central node connection data are integrated to create a comprehensive core node connection dataset. The node identifiers and connection information in the datasets are ensured to be consistent and clear for subsequent network analysis and applications. A final dataset containing all core nodes and their connections is generated for further analysis and application of the blockchain network structure. For example, data structure operations and data merging techniques in the Python programming language can be used to merge the two datasets according to node identifiers to generate the final core node connection dataset.

[0065] It should be noted that, as an optional implementation of this disclosure, a high-frequency connected blockchain node network can be established by spatially connecting the frequently connected blockchain nodes. This means that the concept of physical or logical distance can be used to determine which nodes have relatively close communication relationships. This spatial connection can help identify physically close nodes, thereby better understanding the interaction patterns and network topology between nodes. Node density calculation aims to quantify the connection density of each node in the high-frequency connected blockchain node network, that is, the number or connectivity of its surrounding nodes. High-density nodes usually play an important role in the network, are key nodes for information propagation, or have high degree centrality. Through node density calculation, important nodes in the network can be identified, providing a basis for subsequent network partitioning. Based on the density data of the high-frequency node network, a high-density network partition is performed. The purpose is to divide the network into a high-density node network and other parts, so as to more accurately analyze and manage the key nodes in the blockchain network. High-density network partitioning helps to concentrate efforts and resources on the most important nodes, improving the reliability and efficiency of the system. In the high-density node network, the node with the highest number of connections is selected as the central node. These nodes are the most active or critical nodes in the entire network, and their high connectivity signifies their vital role in information transmission and system operation. Selecting these central nodes helps optimize network management and resource allocation. Based on the selected central nodes, connection data for these central nodes is removed from the high-frequency connection blockchain node data. This step ensures that the influence of central nodes is kept within an appropriate range in subsequent analysis, allowing for a more accurate analysis of secondary central nodes and their roles in the network. The connection data for central nodes and secondary central nodes are then merged to form a complete core node connection dataset. These core nodes play a crucial role in the entire blockchain network, and their connectivity and functionality are essential to the network's security, efficiency, and scalability. Merging the data helps to comprehensively assess the overall influence and role of the core nodes.

[0066] As an optional implementation of this disclosure, dividing low-frequency connection blockchain node data into auxiliary nodes based on core node connection data and determining auxiliary node connection data may specifically include: associating connection relationships between secondary central node connection data and low-frequency connection blockchain node data to determine unidirectional and bidirectional connection low-frequency blockchain node data; performing multi-bidirectional connection node statistics on bidirectional connection low-frequency blockchain node data to determine multi-node bidirectional connection node data; selecting relay connection nodes for bidirectional connection low-frequency blockchain node data based on multi-node bidirectional connection node data to determine relay node connection data; performing minimum connection node statistics on unidirectional connection low-frequency blockchain node data to determine minimum unidirectional connection node data; selecting dedicated unidirectional connection nodes for unidirectional connection low-frequency blockchain node data based on minimum unidirectional connection node data to determine dedicated service node connection data; and merging relay node connection data and dedicated service node connection data to determine auxiliary node connection data.

[0067] In this embodiment, unidirectional low-frequency blockchain node data refers to the set of nodes and their transaction data among low-frequency connected nodes that have only a unidirectional fund flow relationship with other nodes (especially secondary central nodes). Unidirectional means that the flow of funds is singular. For example, node A only transfers funds to node B but never receives funds from node B; or node A only receives funds from a certain contract but never sends a transaction to that contract. This pattern is common in addresses that only receive funds but do not make payments (such as certain donation addresses or fund collection addresses), or lightweight clients that only trigger but do not receive contract callbacks. Bidirectional low-frequency blockchain node data refers to the set of nodes and their transaction data among low-frequency connected nodes that have a bidirectional fund flow relationship (i.e., two-way transactions) with at least one other node. Bidirectional means that there is interaction and feedback between nodes, rather than a single operation. Multi-node bidirectional connected node data is a subset of nodes further filtered from the bidirectional connected low-frequency blockchain node data that have established bidirectional connections with multiple (usually ≥2) different nodes.

[0068] In this embodiment, relay node connection data refers to nodes formally identified as relay nodes based on multi-node bidirectional connection node data, along with their complete connection information. A node is selected as a relay node because it possesses the characteristic of multi-node bidirectional connections. This indicates high reliability and stability, enabling it to reliably transmit information and value among multiple non-adjacent or weakly connected node groups. Minimum unidirectional connection node data involves statistically analyzing low-frequency unidirectional connection blockchain node data to identify the subset of nodes with the fewest connections (e.g., only one unidirectional connection). The minimum determination method is typically based on a low threshold or the distribution of the degree of all unidirectional connection nodes (e.g., in the lowest 5%). These nodes are the most singularly connected and simplest-behavior entities in the network, with highly specialized functions. Dedicated service node connection data refers to nodes formally identified as dedicated service nodes based on minimum unidirectional connection node data, along with their connection information. Due to their extremely small number of connections and unidirectional nature, these nodes are considered to undertake very specific and singular tasks. For example, an address that only receives oracle data pushes from a specific contract, or an address used only for receiving one-time airdrops.

[0069] Specifically, the connections between secondary central nodes and low-frequency blockchain nodes are analyzed to establish relationships. This can be achieved using network analysis tools such as GraphX ​​or NetworkX, which can help identify unidirectional and bidirectional connections between nodes. For example, GraphX ​​can be used to analyze the connections between secondary central nodes and low-frequency blockchain nodes to determine which nodes have unidirectional or bidirectional connections.

[0070] Specifically, the analysis involves identifying low-frequency bidirectional connection blockchain node data to pinpoint nodes that simultaneously establish bidirectional connections with multiple nodes. This analysis can be achieved using data mining techniques, such as frequent itemset mining. The Apriori algorithm or FP-growth algorithm can be used to discover frequent bidirectional connection patterns, thereby obtaining multi-node bidirectional connection node data.

[0071] Specifically, using this multi-node bidirectional connection data, a graph network is constructed, where nodes represent blockchain nodes and edges represent bidirectional connections. Each edge carries a weight reflecting the strength of the connection or other relevant metrics. Based on the constructed graph network, network analysis tools such as NetworkX or similar tools are used to calculate the centrality metrics of each node, such as betweenness centrality or degree centrality. The degree centrality of each node is calculated, which is the number of connections it has. A high degree centrality may indicate that a node has significant influence or connectivity within the network. The betweenness centrality of each node measures its importance in the connected network. Nodes with high betweenness centrality are typically located in key positions within the network, serving as bridges connecting different subgroups or modules. The clustering coefficient of each node is calculated, measuring the tightness of connections between its neighbors. Nodes with high clustering coefficients may represent local communities or clusters. The multi-node bidirectional connection data shows which nodes have established bidirectional connections with multiple other nodes, indicating that these nodes have high stability and reliability and can effectively transmit information. Selecting nodes that have established bidirectional connections between multiple nodes as relay nodes helps optimize the communication traffic and efficiency of the entire blockchain network. These nodes can handle more information transmission tasks, reducing network congestion and latency. Finally, based on the above evaluation and selection process, relay nodes are determined, and relay node connection data is generated. This data describes the bidirectional connection relationships between each relay node and other nodes, supporting data transmission and communication within the blockchain network.

[0072] Specifically, for low-frequency blockchain node data with unidirectional connections, a statistical analysis of the fewest connected nodes is performed. This can be achieved using graph theory algorithms such as Dijkstra's algorithm, which finds the shortest paths between nodes. By identifying the nodes with the fewest connected paths, statistical results for the fewest unidirectional connected nodes can be obtained.

[0073] Specifically, a directed graph is constructed using unidirectional connection data, where nodes represent blockchain nodes and directed edges represent unidirectional connections. Based on the constructed directed graph, graph theory algorithms such as Dijkstra's algorithm are used to compute the shortest path or other relevant path metrics for each node. These metrics help evaluate the node's position and importance in the connected network. When selecting dedicated service nodes, data on nodes with the fewest unidirectional connections is specifically considered. This data shows which nodes have fewer unidirectional connections relative to other nodes, indicating that these nodes have a lower risk of network congestion or higher stability. Each node is evaluated by combining path metrics and the data on nodes with the fewest unidirectional connections. Nodes with appropriate path metrics and that satisfy the criteria for the fewest unidirectional connections are selected as dedicated service nodes. For example, if node B has a shorter average path length in the network and shows fewer connections in the data on nodes with the fewest unidirectional connections, then node B is a dedicated service node. Finally, the identified nodes are designated as dedicated service nodes, and dedicated service node connection data is generated. This data describes the unidirectional connection relationships between each dedicated service node and its connected nodes, and can be used to provide specific blockchain services or optimize the execution of specific tasks.

[0074] Specifically, relay node connection data and dedicated service node connection data are merged to obtain auxiliary node connection data. This can be accomplished through data integration and ETL (Extract, Transform, Load) processes, ensuring the merging and integrity of different types of node data. For example, ETL tools or custom scripts can be used to integrate the two types of node data into a unified dataset for further analysis and application.

[0075] It should be noted that, as an optional implementation of this disclosure, by associating secondary central node connection data and low-frequency connection blockchain node data, one-way and two-way connection low-frequency blockchain node data can be obtained respectively. This data helps to understand the communication patterns and network structure between low-frequency nodes, providing foundational data for subsequent steps. Multi-node statistics on the two-way connection low-frequency blockchain node data can determine which nodes have simultaneously established two-way connections with multiple other nodes. These nodes play an important intermediary role in the network, facilitating information transmission and data flow, and have a significant impact on the overall network stability and efficiency. Based on the multi-node two-way connection data, low-frequency blockchain nodes are selected as relay nodes. Relay nodes typically assume an intermediate role in data transmission, helping to connect different blockchain sub-networks or node groups, thereby improving network reliability and reachability. Minimum connection node statistics on the one-way connection low-frequency blockchain node data can identify nodes in the network that require only the fewest connections to achieve one-way communication. These nodes are suitable for use as dedicated service nodes, providing specific services or functions. Based on the minimum one-way connection node data, low-frequency blockchain nodes are selected as dedicated service nodes. Dedicated service nodes are typically optimized for specific functions or application scenarios, providing customized services to network users and improving overall service quality and user experience. Data from relay nodes and dedicated service nodes is merged to form auxiliary node connection datasets. These auxiliary nodes do not directly participate in core data exchange or decision-making processes, but play a supporting and supplementary role in the network, enhancing the overall network stability and flexibility.

[0076] S230. Based on the connection data of auxiliary nodes and the connection data of core nodes, establish blockchain network connections and determine the blockchain node connection network.

[0077] Specifically, the connection data between core nodes and auxiliary nodes is integrated to construct a complete blockchain node connection network. This connection data can be transaction flows, information transmissions, or other interactions between nodes. Graph theory algorithms such as shortest path algorithms or connectivity algorithms can be used to analyze the connections between nodes. For example, Dijkstra's algorithm can be used to calculate the shortest path and analyze the propagation path of information between core nodes and auxiliary nodes.

[0078] S240. Analyze the blockchain topology based on the blockchain node connection network to determine the blockchain topology model.

[0079] For example, topology analysis can be performed on a constructed blockchain node connection network to reveal important features and relationship patterns within the blockchain network. This includes analyzing metrics such as network diameter, community structure, and node concentration. Complex network analysis tools and algorithms can be used, such as community detection algorithms (e.g., the Louvain algorithm), node importance assessment (e.g., the PageRank algorithm), and network diameter calculation. For instance, the NetworkX library can be used to implement complex network analysis based on Python, thereby obtaining the topology model and related metrics of the blockchain network.

[0080] S250. Obtain blockchain financial data, perform historical abnormal financial transaction detection on the blockchain financial data, determine abnormal financial transaction detection data, and mark abnormal financial nodes in the blockchain topology model based on the abnormal financial transaction detection data to determine the blockchain node marking model.

[0081] S260. Based on the blockchain node marking model, perform abnormal node consensus correction on the abnormal financial transaction detection data, determine the abnormal financial transaction correction data, and construct an abnormal financial transaction detection model based on the abnormal financial transaction correction data.

[0082] S270. The abnormal financial transaction detection model is used to detect abnormal financial transactions in the blockchain financial data in real time, identify abnormal financial transaction data and normal financial transaction data in real time, and upload the normal financial transaction data in real time to the financial blockchain service platform in order to execute real-time transaction tasks.

[0083] S280. Analyze the transaction rollback strategy of real-time abnormal financial transaction data according to the blockchain node marking model, determine the abnormal transaction rollback strategy, and upload the abnormal transaction rollback strategy to the financial blockchain service platform so as to execute the abnormal transaction rollback task.

[0084] The technical solution of this invention involves acquiring blockchain link data, including connection information between nodes. Through node connection feature extraction, key features between each node can be analyzed and extracted, such as node degree, connection density, and connection pattern. These features are crucial for subsequent node partitioning and network analysis, helping to identify core and auxiliary nodes in the network. Based on the extracted feature data, blockchain nodes are partitioned. Nodes are typically divided into core nodes and auxiliary nodes. Core nodes have higher connectivity and importance, usually playing key roles in the network, such as transaction verification and block generation. Auxiliary nodes may have lower connectivity or weaker functionality, but they still play a supporting and supplementary role in the network. The partitioned core and auxiliary nodes are connected to form a complete blockchain node connection network. The establishment of this network structure is fundamental to understanding and analyzing the entire blockchain system architecture, helping to identify key connections and information transmission paths within the network. Based on the established blockchain node connection network, topology analysis is performed. This includes studying the overall network structure, the relationships between nodes, and the paths and characteristics of information flow. By establishing a blockchain topology model, a deeper understanding of the blockchain system's operating mechanism and the interactions between nodes can be achieved. This model helps predict system performance under different conditions, identify potential network bottlenecks or security vulnerabilities, and provide data support for system optimization.

[0085] Example 3 Figure 3 This is a flowchart of a blockchain-based financial data stream anomaly detection method provided in Embodiment 3 of the present invention. Based on the above embodiments, this embodiment describes in detail the process of detecting historical abnormal financial transactions in blockchain financial data and determining the abnormal financial transaction detection data. Explanations of terms that are the same as or corresponding to those in the above embodiments are not repeated here. Figure 3 As shown, the method includes: S310. Obtain blockchain link data, analyze blockchain connection nodes based on blockchain link data, determine the blockchain node connection network, and analyze the blockchain topology structure based on the blockchain node connection network to determine the blockchain topology structure model.

[0086] S320. Obtain blockchain financial data and extract historical financial transaction data from the blockchain financial data to determine the historical financial transaction data.

[0087] In this embodiment of the disclosure, historical financial transaction data is a collection of all confirmed transaction records extracted from blockchain financial data within a past period (e.g., the system-defined retention period of more than 3 days). Historical financial transaction data serves as the benchmark dataset for historical anomaly detection and analysis.

[0088] Specifically, it is necessary to acquire blockchain financial data from financial blockchain networks. This includes collecting transaction data from these networks, such as specific transaction records. Data acquisition can be achieved using a blockchain explorer's API or by connecting to a blockchain node. For example, for the Ethereum blockchain, historical transaction data can be queried using the Ethereum node's JSON-RPC interface. An RPC request can be sent using the Ethereum node's web3.js or WebSocket connection to retrieve transaction data from the blockchain. The returned transaction data is then parsed, including information such as transaction hash, sender address, receiver address, and transaction amount. This transaction data is then stored in a local database or data warehouse for subsequent data analysis and processing. Finally, transaction data stored for more than three days is extracted from the transaction data (blockchain financial data) to obtain historical financial transaction data.

[0089] S330. Classify historical financial transaction data by transaction node to determine transaction execution node data and smart contract execution node data.

[0090] In this embodiment, transaction execution node transaction data is a subset of historical financial transaction data that involves only simple transfers of native or standard tokens without triggering complex smart contract logic. On blockchains such as Ethereum, this is typically determined by the transaction's input field. If the input field is empty, 0x, or only contains a simple transfer function signature (such as an ERC-20 transfer), it is categorized here. Smart contract execution node transaction data is a subset of historical financial transaction data that calls smart contract functions and executes predetermined complex logic. Identification can be achieved by the transaction's receiving address being a contract address, and the input field containing selectors and parameter encodings for the contract function, indicating that a specific contract operation has been triggered.

[0091] Specifically, the acquired historical financial transaction data is categorized to distinguish between ordinary transactions and smart contract transactions. Ordinary transactions involve simple fund transfers, while smart contract transactions involve more complex logic execution. The transaction type field of each transaction (such as Ethereum's input field) can be analyzed to determine whether a smart contract is involved. For smart contract transactions, the contract address is further analyzed to determine the specific smart contract type (such as token transactions, DeFi protocol transactions, etc.). Ordinary transactions and smart contract transactions are stored in different datasets or database tables for subsequent anomaly detection and analysis.

[0092] S340. Perform transaction execution anomaly detection on the transaction data of the transaction execution node to identify abnormal transaction data of the transaction execution node.

[0093] In this embodiment, abnormal transaction data of the transaction execution node refers to a set of ordinary transfer transactions that are identified as suspicious or abnormal after applying anomaly detection rules or models to the transaction data of the transaction execution node. The detection method for abnormal transaction data of the transaction execution node is mainly based on statistical thresholds and pattern matching. Specifically, for abnormal amounts: a single transaction amount is significantly higher or lower than the historical average level; for abnormal frequencies: a surge in the number of transactions in a short period of time (high-frequency scalping); for abnormal associations: transactions with known blacklisted addresses, phishing addresses, or coin mixing service addresses; for behavioral intersections: short-term high-frequency and large-amount transactions occur simultaneously. The output format of abnormal transaction data of the transaction execution node can be a list containing details of all ordinary transfer transactions marked as abnormal.

[0094] Specifically, anomaly detection is performed on ordinary transaction data to identify potentially abnormal transaction behaviors, such as unusual transaction amounts, frequencies, or transactions with blacklisted addresses. Statistical methods or machine learning algorithms are used to detect outliers in transaction amounts. Time-series patterns of transactions are analyzed to detect abnormal transaction frequencies. Address tags or blacklists are used to filter out addresses involved in known malicious activities.

[0095] As an optional implementation of this disclosure, detecting transaction execution anomalies in transaction execution node data and determining abnormal transaction data at the transaction execution node may specifically include: extracting transaction amount features and transaction time features from the transaction execution node data to determine the transaction amount data and transaction time data of the transaction node; calculating the transaction frequency from the transaction time data to determine the transaction frequency data; statistically analyzing the high-frequency transaction frequency of accounts from the transaction frequency data to determine high-frequency trading account data; extracting short-term high-frequency trading features from the high-frequency trading account data to determine short-term high-frequency trading data; statistically analyzing the large transaction amount from the transaction amount data to determine the large transaction amount data; and performing an intersection calculation on the short-term high-frequency trading data and the large transaction amount data to determine the abnormal transaction data at the transaction execution node.

[0096] In this embodiment of the disclosure, the transaction amount data of the transaction node is a structured set of features related to the transaction value extracted from the transaction data of the transaction execution node. The transaction amount data of the transaction node may include raw data and derived features. The raw data includes the specific monetary value of each transaction. Derived features typically include aggregated statistics for each transaction address (account), generating metrics such as total transaction amount, average transaction amount, standard deviation of transaction amount, maximum / minimum single transaction amount, and histogram of amount distribution. The transaction amount data of the transaction node can be used to establish a behavioral baseline for each account in the amount dimension, in order to identify outliers that significantly deviate from this baseline.

[0097] In this embodiment of the disclosure, the transaction node transaction time data is a structured set of features extracted from the transaction execution node transaction data regarding the timing of transaction occurrences. The transaction node transaction time data may include raw data and derived features. The raw data includes the precise timestamp of each transaction. Derived features include absolute time periods (e.g., UTC hours) that can be converted into the occurrence of transactions, time intervals between consecutive transactions, and the distribution density of transactions in the time series. The transaction node transaction time data can be used to establish the activity pattern of each account in the time dimension to identify abnormal time clusters or irregularities.

[0098] In this embodiment, transaction frequency data is a quantitative indicator calculated based on transaction time data of transaction nodes, measuring the transaction activity of an account within a specific time window. Transaction frequency data is typically expressed as the number of transactions per unit of time, such as 100 transactions initiated in the past 24 hours (frequency of 100 transactions / day), or 50 transactions initiated in the past hour (frequency of 50 transactions / hour). Transaction frequency data is calculated by counting the number of transactions for each address using a sliding time window. Transaction frequency data can be used to transform time data into a core risk control indicator that directly measures activity levels. Abnormally high frequencies are typical signals of money laundering, fraudulent transactions, or cyberattacks.

[0099] In this embodiment, high-frequency trading account data is a list of accounts with trading frequencies significantly higher than normal levels, filtered by setting thresholds or statistical analysis (such as Z-score, percentiles), along with their detailed frequency information. The identification method for high-frequency trading account data can be to mark accounts with frequencies ranking in the top 1% or those exceeding the overall mean by three standard deviations as high-frequency. Short-term high-frequency trading data is the specific behavioral characteristics of trading sequences occurring within a very short time (such as minutes or even seconds) after in-depth analysis of high-frequency trading account data. Short-term high-frequency trading data can describe the micro-behavior of a high-frequency account during a burst period, such as account A initiating 20 consecutive transactions to 20 different addresses within 30 seconds from 02:15:00 to 02:15:30.

[0100] In this embodiment of the disclosure, the large transaction amount data is a set of transaction records with abnormally large transaction amounts selected based on the transaction amount data of transaction nodes by setting a threshold (such as a fixed amount or a multiple of the historical average). The method for identifying large transaction amount data can be to filter out all transactions with an amount greater than 1000 ETH, or transactions with an amount exceeding 100 times the historical average transaction amount of the account.

[0101] Specifically, transaction amount and transaction time features are extracted from transaction data. Transaction amount features may include the specific amount of each transaction, the distribution of transaction amounts (such as mean and standard deviation), and the frequency of transaction amounts. For example, the average transaction amount of a transaction node within a specific time period can be calculated, or abnormally high or low transaction amounts can be identified. For transaction time features, information such as the specific time point of the transaction and the distribution of transaction time intervals can be extracted. These features can help in further analyzing the transaction behavior patterns and regularities of transaction nodes.

[0102] Specifically, it's necessary to calculate the transaction frequency of transaction nodes, that is, the number of transactions that occur within a specific time period. For example, one can calculate the total number of transactions per hour, day, or week, or calculate the distribution of transactions within a specific time period. This data can help identify whether there are abnormally high-frequency transaction behaviors, or compare changes in transaction activity across different time periods.

[0103] Specifically, statistical analysis of high-frequency trading frequency is conducted for different accounts. High-frequency trading account data can reveal which accounts have abnormally high trading frequency within a specific time period, potentially involving abnormal trading behavior. For example, accounts that frequently trade within a short period can be identified, allowing for subsequent abnormal trading detection and analysis.

[0104] Specifically, it's necessary to extract specific characteristics of short-term high-frequency trading from high-frequency trading accounts. These characteristics include the number of trades within a short period, the concentration of trading amounts, and changes in trading objects. For example, accounts that trade frequently within minutes or whose trading amounts fluctuate significantly within a short time can be identified. These characteristics can help further analyze and identify potential abnormal trading behaviors.

[0105] Specifically, it's necessary to analyze the large transaction amounts within transaction nodes. Large transaction amount data can help identify high-volume fund flows involved in transactions and potentially risky trading behaviors. For example, thresholds can be set to identify transactions exceeding a certain amount, or the distribution of large transactions over time can be analyzed.

[0106] Specifically, by intersecting short-term, high-frequency trading data with large-amount trading data, potential abnormal trading behaviors within trading nodes can be identified. For example, analysis can reveal transactions that are both frequent and involve large sums of money within a short period, indicating a higher risk profile. This data can provide a basis for further abnormal transaction detection and risk control.

[0107] It should be noted that, as an optional implementation of this disclosure, by extracting the transaction amount and transaction time characteristics of the transaction execution node, the amount and timing of each transaction can be analyzed. This data is crucial for subsequent analysis and anomaly detection, revealing the amount patterns and time distribution characteristics of different transactions. Transaction frequency, i.e., the number of transactions per unit time, is calculated based on the transaction time data of the transaction node. High transaction frequency may indicate abnormal activity, such as malicious trading or the application of high-frequency trading algorithms. This analysis helps identify abnormal trading activity patterns. Statistics on high-frequency trading accounts can identify accounts that frequently conduct large-volume transactions. These accounts may be involved in illegal activities such as market manipulation and money laundering; monitoring and analyzing these accounts helps protect the fairness and normal operation of the market. Based on the high-frequency trading account data, high-frequency trading characteristics over a short period can be further extracted. These characteristics can help detect abnormal patterns of frequent trading within a short period, potentially revealing market manipulation or the use of fast trading algorithms. Statistics on large transaction amounts from the transaction node's transaction amount data can identify abnormally large transactions. Large transactions may involve risks such as money laundering and illegal transactions; monitoring and analyzing these transactions helps prevent financial crimes. By intersecting short-term high-frequency trading data with large-value transaction data, abnormal transactions exhibiting both high-frequency and large-value characteristics can be identified. These transactions often carry higher risks and require priority review and processing.

[0108] S350. Perform smart contract execution anomaly detection on the transaction data of the smart contract execution node to identify abnormal transaction data of the smart contract execution node.

[0109] In this embodiment, abnormal transaction data of smart contract execution nodes refers to a set of contract call transactions identified as suspicious or abnormal after applying specialized analysis methods to the transaction data of smart contract execution nodes. The detection method for abnormal transaction data of smart contract execution nodes focuses more on behavioral sequences and pattern deviations. Specifically, for caller anomalies: an address suddenly calls the contract at an extremely high frequency (possibly a flash loan attack or spam transaction attack); for preference deviations: the address's behavior significantly deviates from its historical preference range (e.g., an address that has long only engaged in stablecoin exchanges suddenly starts making a large number of NFT contract calls); for time interval anomalies: the call intervals are extremely short and do not conform to the norm (characteristics of bot attacks); for logic vulnerability exploitation: the transaction input data conforms to the attack patterns of known vulnerabilities (e.g., reentrancy, integer overflow). The output format of abnormal transaction data of smart contract execution nodes can be a list containing details of all smart contract call transactions marked as abnormal.

[0110] Specifically, anomaly detection is performed on smart contract transaction data to identify potential anomalies or vulnerabilities in contract execution logic. Execution logs or event logs of smart contracts are analyzed to detect unexpected contract state changes. Static analysis or dynamic execution simulation is used to detect logical vulnerabilities in smart contracts. Known smart contract vulnerability patterns are detected and identified, and the identified abnormal transaction data is integrated to obtain abnormal transaction data for smart contract execution nodes.

[0111] As an optional implementation of this disclosure, detecting smart contract execution anomalies in smart contract execution node transaction data and determining abnormal transaction data may specifically include: extracting caller address features from the smart contract execution node transaction data to determine caller contract address data; performing caller address statistics on the caller contract address data to determine high-frequency caller address data; dividing the high-frequency caller address data into caller preference regions to determine caller preference region data; extracting non-preference call addresses from the caller contract address data based on the caller preference region data to determine non-preference call address data; calculating the call time interval from the non-preference call address data based on the smart contract execution node transaction data to determine call time interval data, and performing low-interval call time statistics on the call time interval data to determine low call time interval data; associating the low call time interval data with the non-preference call address data to determine abnormal call address data, and selecting abnormal transaction data from the smart contract execution node transaction data based on the abnormal call address data to determine abnormal transaction data of the smart contract execution node.

[0112] In this embodiment, the caller contract address data is a list of all external account addresses that initiate smart contract calls and their related characteristics, extracted from the transaction data of the smart contract execution node. The extraction object is the "from" field in each smart contract transaction, i.e., the initiator of the transaction (EOA - external owner account address). High-frequency caller address data is a set of addresses whose call frequency is significantly higher than the average level, selected by statistically analyzing the total number of times each address calls the smart contract within a specific time period. High-frequency caller address data can be identified by statistically analyzing addresses that have called the contract more than 1000 times in the past 24 hours and listing them as high-frequency callers. Caller preference region data is the definition and description of different behavioral pattern groups (i.e., preference regions) derived from behavioral pattern clustering analysis of high-frequency caller address data. Clustering dimensions can include time preference, contract type preference, and functional preference. Time preference may mean that some addresses are only active during specific time periods (e.g., UTC working hours). Contract type preference may mean that some addresses only interact with specific types of contracts (e.g., only participate in DeFi lending or only trade NFTs). Function preferences could mean that certain addresses only call specific contract functions (e.g., only perform swap, never perform addLiquidity).

[0113] In this embodiment, the unpreference call address data is a list of smart contract caller addresses that do not conform to any defined caller preference region behavior patterns. Identification can be achieved by matching the behavioral characteristics of all caller addresses with each preference region, marking unclassifiable addresses as unpreferenced. Call interval data is calculated by determining the time difference (Δt) sequence between consecutive smart contract transactions initiated by addresses in the unpreference call address data. This can be done by sorting the historical transactions of these addresses by timestamp and then calculating the time difference between each transaction and the previous transaction. Low call interval data is transaction sequence data with extremely short time intervals (e.g., less than 1 second or less than a block time) filtered from the call interval data. Identification can be achieved by setting an extremely low time threshold and filtering out all intervals with Δt less than that threshold. Abnormal call address data is a final high-risk address list derived by combining the unpreference call address data (abnormal behavior patterns) and the low call interval data (abnormal timing behavior). The judgment logic is as follows: an address must simultaneously meet two conditions: its behavior deviates from the mainstream pattern (it is an unpreferenced address) and it exhibits machine-driven, rapid attack characteristics (it has a low call interval).

[0114] Specifically, the caller's address features are extracted from the transaction data of the smart contract execution node to obtain the caller's contract address data. In blockchain smart contracts, each transaction contains caller address information. By parsing transaction records, the caller's address can be extracted. For example, transaction records in the Ethereum blockchain contain a caller address field, and the caller's contract address data can be extracted by accessing and parsing transaction information through nodes.

[0115] Specifically, caller address statistics are performed on the caller contract address data to obtain high-frequency caller address data. Statistical analysis of the caller address frequency of smart contracts can reveal which addresses frequently execute transactions. For example, data analysis tools can be used to aggregate and count the extracted contract address data to determine which addresses are high-frequency callers.

[0116] Specifically, caller preference regions are segmented based on high-frequency caller address data to obtain caller preference region data. Smart contract callers may have preferences for specific time periods, specific geographical regions, or specific contracts. For example, by analyzing the transaction patterns of high-frequency callers through timestamp and geographic information data, they can be divided into different preference region groups to identify their activity patterns and preferences.

[0117] Specifically, non-preferred call addresses are extracted from caller contract address data based on caller preference region data to obtain non-preferred call address data. Addresses that do not conform to high-frequency call patterns are identified; these addresses may contain unusual or infrequent transaction patterns. For example, addresses outside the preference region are marked as non-preferred call addresses for further analysis of their transaction behavior.

[0118] Specifically, the call interval is calculated based on the transaction data of the smart contract execution nodes for the non-preferred call address data to obtain call interval data. Low-interval call time statistics are then performed on this call interval data to obtain low-interval call time data. Analyzing the transaction intervals of non-preferred call addresses can reveal abnormally frequent transaction patterns. For example, the time difference between two transactions from a non-preferred address can be calculated, and the distribution of these time intervals can be analyzed to identify abnormal behavior related to low-interval call times.

[0119] Specifically, by associating non-preferred call address data with low call interval data, abnormal call address data is obtained. Then, based on this abnormal call address data, abnormal transaction data is selected from the smart contract execution node's transaction data to obtain abnormal transaction data for the smart contract execution node. Identifying and analyzing non-preferred call addresses with low call intervals can reveal abnormal transaction patterns. For example, non-preferred addresses with high transaction frequency and extremely short time intervals are marked as abnormal call addresses, and the transaction data from these addresses is selected as abnormal transaction data for the smart contract execution node to further analyze potential risks and security issues.

[0120] It should be noted that, as an optional implementation of this disclosure, caller address features are extracted from the transaction data of smart contract execution nodes. These addresses identify which accounts or contracts conducted transactions during smart contract execution. This step is to identify the callers of the smart contract and their behavioral patterns. The frequency of caller addresses is statistically analyzed to identify high-frequency caller addresses. High-frequency caller addresses reflect accounts or contracts that frequently conduct smart contract transactions, and these addresses are significantly different from normal contract execution behavior. Based on the high-frequency caller address data, caller preference regions are segmented. This helps to understand which regions or areas on the blockchain have frequent smart contract transaction activity, potentially identifying active groups of contract executors. Based on the caller preference region data, call addresses that do not belong to preference regions are extracted. These non-preference call addresses represent abnormal or unusual activity patterns, worthy of further analysis and monitoring. The time interval data of non-preference call addresses during smart contract execution is calculated. This interval data can reveal abnormal transaction frequency patterns, such as abnormally high or low frequency call behavior. Based on low call interval data and other abnormal patterns, abnormal call addresses and corresponding transaction data are identified. These abnormal call addresses are related to unauthorized access to smart contracts, malicious operations, or exploitation of vulnerabilities, and require further review and processing.

[0121] S360 merges abnormal transaction data from transaction execution nodes and abnormal transaction data from smart contract execution nodes to determine abnormal financial transaction detection data, and marks abnormal financial nodes in the blockchain topology model based on the abnormal financial transaction detection data to determine the blockchain node marking model.

[0122] Specifically, abnormal transaction data from transaction execution nodes and smart contract execution nodes are merged to obtain a comprehensive dataset for detecting abnormal financial transactions. Ordinary abnormal transaction data and smart contract abnormal data are combined into the same data structure. Each abnormal transaction is ensured to have sufficient contextual information, such as transaction hash, anomaly type, and related addresses. The merged data can be exported as JSON, CSV, or stored in a relational database as needed. The abnormal transaction detection data needs to be correlated with the blockchain network topology to identify nodes or entities that may exhibit abnormal behavior. The correlation between transaction nodes or smart contracts involved in the abnormal transaction data is analyzed. Nodes related to abnormal transactions are marked on the blockchain topology model, such as involved addresses, smart contracts, or exchanges.

[0123] S370. Based on the blockchain node marking model, abnormal financial transaction detection data is corrected by abnormal node consensus to determine abnormal financial transaction correction data, and an abnormal financial transaction detection model is constructed based on the abnormal financial transaction correction data.

[0124] S380. The abnormal financial transaction detection model is used to detect abnormal financial transactions in blockchain financial data in real time, identify abnormal financial transaction data and normal financial transaction data in real time, and upload the normal financial transaction data in real time to the financial blockchain service platform in order to execute real-time transaction tasks.

[0125] S390. Analyze the transaction rollback strategy of real-time abnormal financial transaction data according to the blockchain node marking model, determine the abnormal transaction rollback strategy, and upload the abnormal transaction rollback strategy to the financial blockchain service platform so as to execute the abnormal transaction rollback task.

[0126] The technical solution of this invention, by extracting historical transaction records from blockchain financial data, can establish a detailed historical transaction database. This is crucial for understanding and analyzing past transaction behaviors and patterns in the blockchain network. Historical transaction data can be used for subsequent statistical analysis, model training, and anomaly detection. Classifying historical financial transaction data according to transaction nodes distinguishes between nodes executing transactions and nodes executing smart contracts. This classification helps blockchain analysts and systems identify different types of transaction behaviors and participants. Anomaly detection on transaction data from transaction execution nodes can quickly identify abnormal transaction behaviors, such as abnormal amounts and frequent transactions. This helps to detect potential fraud, errors, or malicious behavior early and take necessary countermeasures. Anomaly detection on transaction data from smart contract execution nodes can discover abnormal behaviors related to smart contract execution, such as unexpected smart contract calls and abnormal logic execution. This detection helps protect the security and reliability of smart contracts. Merging the detected abnormal transaction data from transaction execution nodes and smart contract execution nodes forms a comprehensive abnormal financial transaction detection dataset. Such a dataset provides a comprehensive perspective, helping to understand the distribution and characteristics of different types of abnormal transactions in the blockchain system. Based on abnormal financial transaction detection data, anomalous nodes in the blockchain topology model are marked. These markings help identify and analyze key nodes affecting the security and stability of the entire blockchain system, thereby enabling targeted adjustments and reinforcement measures.

[0127] The following are embodiments of the blockchain-based financial data flow anomaly detection system provided by the present invention. This system and the blockchain-based financial data flow anomaly detection methods described in the above embodiments belong to the same inventive concept. For details not described in detail in the embodiments of the blockchain-based financial data flow anomaly detection system, please refer to the embodiments of the blockchain-based financial data flow anomaly detection methods described above.

[0128] Example 4 Figure 4 This is a schematic diagram of the structure of a blockchain-based financial data flow anomaly detection system provided in Embodiment 4 of the present invention. Figure 4 As shown, the system includes: a blockchain topology analysis module 410, an abnormal financial node marking module 420, an abnormal node consensus correction module 430, a real-time abnormal financial transaction detection module 440, and a rollback strategy analysis module 450.

[0129] The blockchain topology analysis module 410 is used to acquire blockchain link data, analyze blockchain connection nodes based on the blockchain link data, determine the blockchain node connection network, and perform blockchain topology analysis based on the blockchain node connection network to determine the blockchain topology model. The abnormal financial node marking module 420 is used to acquire blockchain financial data, perform historical abnormal financial transaction detection on the blockchain financial data, determine abnormal financial transaction detection data, and mark abnormal financial nodes in the blockchain topology model based on the abnormal financial transaction detection data to determine the blockchain node marking model. The abnormal node consensus correction module 430 is used to correct abnormal nodes in the abnormal financial transaction detection data based on the blockchain node marking model. The consensus correction module identifies abnormal financial transaction correction data and constructs an abnormal financial transaction detection model based on this data. The real-time abnormal financial transaction detection module 440 uses this model to detect real-time abnormal financial transactions in the blockchain financial data, identifying both real-time abnormal and normal financial transaction data, and uploading the real-time normal financial transaction data to the financial blockchain service platform for real-time transaction execution. The rollback strategy analysis module 450 analyzes the real-time abnormal financial transaction data based on the blockchain node marking model, determines the abnormal transaction rollback strategy, and uploads the abnormal transaction rollback strategy to the financial blockchain service platform for execution.

[0130] The technical solution of this invention, by analyzing the connection and topology of blockchain nodes, can establish an accurate blockchain topology model. This helps financial institutions understand the overall structure of the blockchain network they participate in and the relationships between nodes. This model can be used to identify potential single points of failure, network partitions, or the existence of abnormal nodes. Using historical blockchain financial data for abnormal transaction detection can help identify existing anomalies or violations. By combining the abnormal transaction detection results with the blockchain topology model, specific nodes associated with abnormal transactions can be marked. This facilitates further investigation and preventative measures. Consensus correction of abnormal transaction data through a blockchain node marking model can improve the accuracy and reliability of anomaly detection. Constructing a detection model based on abnormal transaction correction data helps to monitor and identify new abnormal financial transaction patterns in real time, thereby improving the system's anti-fraud capabilities and response speed. Monitoring real-time blockchain financial data using the abnormal financial transaction detection model allows for real-time identification and response to abnormal transactions. Simultaneously, uploading real-time normal financial transaction data to the financial blockchain service platform helps ensure the smooth operation of normal transactions, enhancing the overall system's stability and reliability. By analyzing abnormal transaction rollback strategies for real-time financial transaction data, effective countermeasures can be taken quickly when abnormal transactions occur. This strategic analysis and execution can minimize potential losses and ensure the security and compliance of financial transactions. In summary, these steps work together to enhance financial institutions' data management, anomaly detection, and response capabilities in complex financial markets and high-frequency trading environments. The application of blockchain technology not only enhances data security and real-time performance but also improves the efficiency and credibility of the overall system, helping the financial industry better meet the challenges and demands of modernization.

[0131] Based on the above technical solution, the blockchain topology analysis module 410 may include: The blockchain node connection data determination submodule is used to extract node connection features from blockchain link data and determine the blockchain node connection data. The node connection data determination submodule is used to divide blockchain nodes based on blockchain node connection data and determine the core node connection data and auxiliary node connection data. The blockchain node connection network determination submodule is used to determine the blockchain node connection network based on the connection data of auxiliary nodes and the connection data of core nodes.

[0132] Based on the above technical solution, the node connection data determination submodule may include: The blockchain node data determination unit is used to count the number of blockchain node connections and determine the high-frequency and low-frequency blockchain node data. The core node connection data determination unit is used to divide the high-frequency connection blockchain node data into blockchain core nodes and determine the core node connection data. The core node connection data includes central node connection data and secondary central node connection data. The auxiliary node connection data determination unit is used to divide low-frequency connection blockchain node data into blockchain auxiliary nodes based on the core node connection data, and determine the auxiliary node connection data.

[0133] Based on the above technical solution, the core node connection data determination unit is specifically used for: spatial node connection of high-frequency connection blockchain node data to determine the high-frequency connection blockchain node network; node density calculation of the high-frequency connection blockchain node network to determine the high-frequency node network density data; high-density network division of the high-frequency connection blockchain node network based on the high-frequency node network density data to determine the high-density node network; selection of the node with the highest number of connections in the high-density node network based on the high-frequency connection blockchain node data to determine the central node connection data; elimination of central node connection data from the high-frequency connection blockchain node data based on the central node connection data to determine the secondary central node connection data; and merging the central node connection data and the secondary central node connection data to determine the core node connection data.

[0134] Based on the above technical solution, the auxiliary node connection data determination unit is specifically used for: associating the connection relationships between the secondary center node connection data and the low-frequency connection blockchain node data to determine the unidirectional and bidirectional connection low-frequency blockchain node data; performing multi-bidirectional connection node statistics on the bidirectional connection low-frequency blockchain node data to determine multi-node bidirectional connection node data; selecting relay connection nodes for the bidirectional connection low-frequency blockchain node data based on the multi-node bidirectional connection node data to determine relay node connection data; performing minimum connection node statistics on the unidirectional connection low-frequency blockchain node data to determine the minimum unidirectional connection node data; selecting dedicated unidirectional connection nodes for the unidirectional connection low-frequency blockchain node data based on the minimum unidirectional connection node data to determine dedicated service node connection data; and merging the relay node connection data and dedicated service node connection data to determine the auxiliary node connection data.

[0135] Based on the above technical solution, the abnormal financial node marking module 420 may include: The historical financial transaction data identification submodule is used to extract historical financial transaction data from blockchain financial data and identify historical financial transaction data. The execution node transaction data determination submodule is used to classify historical financial transaction data by transaction node and determine the transaction execution node transaction data and the smart contract execution node transaction data. The abnormal transaction data determination submodule for transaction execution nodes is used to detect abnormal transaction execution data of transaction execution nodes and determine abnormal transaction data of transaction execution nodes. The submodule for determining abnormal transaction data of smart contract execution nodes is used to detect abnormalities in the transaction data of smart contract execution nodes and determine the abnormal transaction data of smart contract execution nodes. The abnormal financial transaction detection data determination submodule is used to merge abnormal transaction data from transaction execution nodes and abnormal transaction data from smart contract execution nodes to determine abnormal financial transaction detection data.

[0136] Based on the above technical solution, the submodule for determining abnormal transaction data at the transaction execution node is specifically used for: extracting transaction amount and transaction time features from the transaction data at the transaction execution node to determine the transaction amount and transaction time data at the transaction node; calculating the transaction frequency from the transaction time data at the transaction node to determine the transaction frequency data; statistically analyzing the high-frequency trading frequency of accounts from the transaction frequency data to determine the high-frequency trading account data; extracting short-term high-frequency trading features from the high-frequency trading account data to determine the short-term high-frequency trading data; statistically analyzing the large transaction amounts from the transaction amount data at the transaction node to determine the large transaction amount data; and performing an intersection calculation between the short-term high-frequency trading data and the large transaction amount data to determine the abnormal transaction data at the transaction execution node.

[0137] Based on the above technical solution, the submodule for determining abnormal transaction data of smart contract execution nodes is specifically used for: extracting caller address features from the transaction data of smart contract execution nodes to determine caller contract address data; performing caller address statistics on the caller contract address data to determine high-frequency caller address data; dividing the caller preference region based on the high-frequency caller address data to determine caller preference region data; extracting non-preferred call addresses from the caller contract address data based on the caller preference region data to determine non-preferred call address data; calculating the call time interval from the non-preferred call address data based on the transaction data of smart contract execution nodes to determine the call time interval data, and performing low-interval call time statistics on the call time interval data to determine low call time interval data; associating the non-preferred call address data with the low call time interval data to determine abnormal call address data, and selecting abnormal transaction data from the transaction data of smart contract execution nodes based on the abnormal call address data to determine abnormal transaction data of smart contract execution nodes.

[0138] Based on the above technical solution, the abnormal node consensus correction module 430 is specifically used for: extracting abnormal transaction node features from abnormal financial transaction detection data to determine abnormal financial transaction node data; extracting abnormal financial transaction node link features from the blockchain node marking model based on the abnormal financial transaction node data to determine abnormal financial transaction node link data; acquiring blockchain network protocol data and extracting consensus mechanism features from the blockchain network protocol data to determine blockchain consensus mechanism data; verifying misjudged abnormal nodes in the abnormal financial transaction node link data based on the blockchain consensus mechanism data to determine misjudged abnormal transaction node data; and correcting abnormal transaction data from the abnormal financial transaction detection data based on the misjudged abnormal transaction node data to determine corrected abnormal financial transaction data.

[0139] The blockchain-based financial data flow anomaly detection system provided in this embodiment of the invention can execute the blockchain-based financial data flow anomaly detection method provided in any embodiment of the invention, and has the corresponding functional modules and beneficial effects for executing the blockchain-based financial data flow anomaly detection method.

[0140] It is worth noting that in the above embodiments of blockchain-based financial data flow anomaly detection, the various units and modules included are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be achieved; in addition, the specific names of each functional unit are only for easy differentiation and are not used to limit the scope of protection of this invention.

[0141] Example 5 Figure 5 A schematic diagram of an electronic device 10, which can be used to implement embodiments of the present invention, is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.

[0142] like Figure 5As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded from storage unit 18 into the RAM 13. The RAM 13 can also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0143] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0144] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, central processing unit (CPU), graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, digital signal processors (DSPs), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as blockchain-based financial data stream anomaly detection methods.

[0145] In some embodiments, the blockchain-based financial data flow anomaly detection method can be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the blockchain-based financial data flow anomaly detection method described above can be performed. Alternatively, in other embodiments, processor 11 can be configured to perform the blockchain-based financial data flow anomaly detection method by any other suitable means (e.g., by means of firmware).

[0146] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0147] Computer programs used to implement the methods of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs can be executed entirely on a machine, partially on a machine, as a standalone software package partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0148] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0149] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0150] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or middleware components (e.g., application servers), or frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.

[0151] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.

[0152] This invention also provides a computer program product, including a computer program that, when executed by a processor, implements the blockchain-based financial data flow anomaly detection method as provided in any embodiment of this application.

[0153] In implementing the computer program product, computer program code for performing the operations of this invention can be written in one or more programming languages ​​or a combination thereof. Programming languages ​​include object-oriented programming languages ​​such as Java, Smalltalk, and C++, as well as conventional procedural programming languages ​​such as C or similar languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider). This program product belongs to the same inventive concept as the blockchain-based financial data flow anomaly detection method disclosed in the embodiments of this application, and therefore will not be described further here.

[0154] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.

[0155] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.

Claims

1. A blockchain-based method for detecting anomalies in financial data flows, characterized in that, include: Obtain blockchain link data, analyze blockchain connection nodes based on the blockchain link data, determine the blockchain node connection network, and analyze the blockchain topology structure based on the blockchain node connection network to determine the blockchain topology structure model. Acquire blockchain financial data, perform historical abnormal financial transaction detection on the blockchain financial data, determine abnormal financial transaction detection data, and mark abnormal financial nodes in the blockchain topology model based on the abnormal financial transaction detection data to determine the blockchain node marking model. The abnormal financial transaction detection data is corrected by abnormal node consensus according to the blockchain node marking model to determine the abnormal financial transaction correction data, and an abnormal financial transaction detection model is constructed based on the abnormal financial transaction correction data. The abnormal financial transaction detection model is used to detect abnormal financial transactions in the blockchain financial data in real time, identify real-time abnormal financial transaction data and real-time normal financial transaction data, and upload the real-time normal financial transaction data to the financial blockchain service platform for the execution of real-time transaction tasks. The real-time abnormal financial transaction data is analyzed for transaction rollback strategies based on the blockchain node marking model. The abnormal transaction rollback strategies are then determined and uploaded to the financial blockchain service platform for execution of abnormal transaction rollback tasks.

2. The method according to claim 1, characterized in that, The step of analyzing blockchain connection nodes based on the blockchain link data to determine the blockchain node connection network includes: Node connection features are extracted from the blockchain link data to determine the blockchain node connection data; Based on the blockchain node connection data, the blockchain nodes are divided to determine the core node connection data and the auxiliary node connection data. The blockchain network connection is determined by establishing blockchain node connection based on the auxiliary node connection data and the core node connection data.

3. The method according to claim 2, characterized in that, The process of dividing the blockchain nodes based on the blockchain node connection data, and determining the core node connection data and auxiliary node connection data, includes: The number of blockchain node connections is counted to determine the high-frequency and low-frequency blockchain node connection data. The high-frequency connection blockchain node data is divided into blockchain core nodes to determine core node connection data, wherein the core node connection data includes central node connection data and secondary central node connection data. Based on the core node connection data, the low-frequency connection blockchain node data is divided into blockchain auxiliary nodes to determine the auxiliary node connection data.

4. The method according to claim 3, characterized in that, The step of dividing the high-frequency connected blockchain node data into core blockchain nodes and determining the core node connection data includes: Spatial node connections are made to the high-frequency connected blockchain node data to determine the high-frequency connected blockchain node network; Perform node density calculation on the high-frequency connected blockchain node network to determine the high-frequency node network density data; Based on the high-frequency node network density data, the high-frequency connected blockchain node network is divided into high-density network segments to determine the high-density node network. Based on the high-frequency connection blockchain node data, the node with the highest number of connections in the high-density node network is selected to determine the central node connection data. Based on the central node connection data, the high-frequency connection blockchain node data is processed by removing the central node connection data to determine the secondary central node connection data. The connection data of the central node and the connection data of the secondary central node are merged to determine the connection data of the core node.

5. The method according to claim 3, characterized in that, The step of dividing the low-frequency connection blockchain node data into blockchain auxiliary nodes based on the core node connection data and determining the auxiliary node connection data includes: The connection relationship between the secondary central node connection data and the low-frequency connection blockchain node data is associated to determine the one-way connection low-frequency blockchain node data and the two-way connection low-frequency blockchain node data. Perform multi-bidirectional connection node statistics on the bidirectional connection low-frequency blockchain node data to determine the multi-node bidirectional connection node data; Based on the multi-node bidirectional connection node data, a relay connection node is selected for the bidirectional connection low-frequency blockchain node data to determine the relay node connection data. The minimum number of connected nodes is statistically analyzed for the low-frequency blockchain node data with unidirectional connections to determine the data with the fewest unidirectional connected nodes. Based on the minimum unidirectional connection node data, a dedicated node unidirectional connection node is selected for the unidirectional connection low-frequency blockchain node data to determine the dedicated service node connection data. The connection data of the relay node and the connection data of the dedicated service node are merged to determine the connection data of the auxiliary node.

6. The method according to claim 1, characterized in that, The step of performing historical abnormal financial transaction detection on the blockchain financial data to determine abnormal financial transaction detection data includes: Historical financial transaction data is extracted from the blockchain financial data to determine the historical financial transaction data; The historical financial transaction data is classified into transaction nodes to determine transaction execution node transaction data and smart contract execution node transaction data; Perform transaction execution anomaly detection on the transaction data of the transaction execution node to identify abnormal transaction data of the transaction execution node; The smart contract execution node transaction data is subjected to smart contract execution anomaly detection to identify abnormal smart contract execution node transaction data; Abnormal transaction data from the transaction execution node and abnormal transaction data from the smart contract execution node are merged to determine abnormal financial transaction detection data.

7. The method according to claim 6, characterized in that, The step of detecting transaction execution anomalies in the transaction data of the transaction execution node and identifying abnormal transaction data of the transaction execution node includes: The transaction execution node's transaction data is subjected to transaction amount feature extraction and transaction time feature extraction to determine the transaction node's transaction amount data and transaction node's transaction time data; The transaction frequency data is determined by calculating the transaction time data of the transaction nodes. The transaction frequency data is used to perform high-frequency transaction frequency statistics for accounts to determine high-frequency transaction account data; Short-term high-frequency trading features are extracted based on the high-frequency trading account data to determine short-term high-frequency trading data; The transaction amount data of the transaction nodes is used to statistically analyze large transaction amounts to determine the large transaction amount data; The intersection of the short-term high-frequency transaction data and the large-amount transaction data is calculated to determine the abnormal transaction data of the transaction execution node.

8. The method according to claim 6, characterized in that, The step of detecting smart contract execution anomalies in the transaction data of the smart contract execution node to determine abnormal transaction data includes: The caller address features are extracted from the transaction data of the smart contract execution node to determine the caller contract address data; Perform caller address statistics on the caller contract address data to determine high-frequency caller address data; Based on the high-frequency caller address data, caller preference regions are divided to determine caller preference region data; Based on the caller preference region data, the caller contract address data is extracted to determine the non-preference call address data; The call interval is calculated based on the transaction data of the smart contract execution node to determine the call interval data, and the low interval call time is statistically analyzed based on the call interval data to determine the low call interval data. Based on the low call interval data, the non-preferred call address data is associated with the call to determine abnormal call address data. Based on the abnormal call address data, abnormal transaction data is selected from the transaction data of the smart contract execution node to determine the abnormal transaction data of the smart contract execution node.

9. The method according to claim 1, characterized in that, The step of performing abnormal node consensus correction on the abnormal financial transaction detection data according to the blockchain node marking model to determine the abnormal financial transaction correction data includes: The abnormal financial transaction detection data is subjected to abnormal transaction node feature extraction to determine the abnormal financial transaction node data; Based on the abnormal financial transaction node data, the abnormal financial transaction node link features are extracted from the blockchain node marking model to determine the abnormal financial transaction node link data. Obtain blockchain network protocol data, and extract consensus mechanism features from the blockchain network protocol data to determine blockchain consensus mechanism data; Based on the blockchain consensus mechanism data, the abnormal financial transaction node link data is used to verify the misjudged abnormal nodes and determine the misjudged abnormal transaction node data. Based on the misjudged abnormal transaction node data, the abnormal financial transaction detection data is corrected to determine the abnormal financial transaction correction data.

10. A blockchain-based financial data flow anomaly detection system, characterized in that, The system is used to execute the blockchain-based financial data stream anomaly detection method as described in claim 1, the system comprising: The blockchain topology analysis module is used to acquire blockchain link data, analyze blockchain connection nodes based on the blockchain link data, determine the blockchain node connection network, and perform blockchain topology analysis based on the blockchain node connection network to determine the blockchain topology model. An abnormal financial node marking module is used to acquire blockchain financial data, perform historical abnormal financial transaction detection on the blockchain financial data, determine abnormal financial transaction detection data, and mark abnormal financial nodes in the blockchain topology model based on the abnormal financial transaction detection data to determine the blockchain node marking model. An abnormal node consensus correction module is used to perform abnormal node consensus correction on the abnormal financial transaction detection data according to the blockchain node marking model, determine the abnormal financial transaction correction data, and construct an abnormal financial transaction detection model based on the abnormal financial transaction correction data. The real-time abnormal financial transaction detection module is used to perform real-time abnormal financial transaction detection on the blockchain financial data through the abnormal financial transaction detection model, determine the real-time abnormal financial transaction data and the real-time normal financial transaction data, and upload the real-time normal financial transaction data to the financial blockchain service platform for the execution of real-time transaction tasks. The rollback strategy analysis module is used to perform transaction rollback strategy analysis on the real-time abnormal financial transaction data according to the blockchain node marking model, determine the abnormal transaction rollback strategy, and upload the abnormal transaction rollback strategy to the financial blockchain service platform for execution of the abnormal transaction rollback task.