Block chain data processing method, device and equipment
By simulating blockchain transactions on a private test chain, a high-quality dataset of transaction behavior is generated, which solves the problem of insufficient labeled data in existing technologies and enables accurate identification of illegal financial activities in blockchain coin mixing services.
Patent Information
- Application Number
- CN202610142979.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-01-30
- Publication Date
- 2026-05-12
AI Technical Summary
Existing technologies struggle to obtain high-quality labeled data, resulting in insufficient performance of risk identification models for illegal financial activities in blockchain coin mixing services. Especially given the anonymity of coin mixing services, existing data labeling methods suffer from high error rates, small data scales, and data that is detached from the real environment, making it impossible to effectively identify complex risk patterns.
Construct a private test chain identical to the target public chain, generate transaction strategies based on preset risks, execute transaction processing on the private test chain, obtain transaction behavior data containing upstream and downstream resource link information, and perform data expansion processing through extension rules to generate a transaction behavior dataset targeting preset risks in the blockchain.
It achieves 100% accurate labeling of resource access address associations in a controlled environment, provides noise-free training data, meets the model's need for large-scale samples, and improves the performance of risk identification models such as those for illegal financial activities.
Smart Images

Figure CN122023002A_ABST
Abstract
Description
Technical Field
[0001] This document relates to the field of computer technology, and in particular to a method, apparatus and device for processing blockchain data. Background Technology
[0002] Blockchain technology, with its immutable and decentralized characteristics, has been widely used in financial transactions. However, its anonymity has also facilitated many illegal activities. Coin mixing services, as a key technology for enhancing the privacy of blockchain transactions, sever the link between the source and destination of resources by aggregating resources from multiple users and redistributing them with new addresses. Machine learning-based risk identification models (such as fraud risk, privacy data leakage risk, and illegal financial activity risk) have shown great potential in identifying complex resource network patterns; however, the performance of these models is highly dependent on high-quality training data. The anonymity of coin mixing services makes obtaining large-scale transaction data with precise labels extremely difficult, which has become a key bottleneck restricting the development of risk identification technology in coin mixing services. Therefore, it is necessary to build a technical solution that can accurately display coin mixing transaction scenarios and provide reliable labeled data to improve the performance of risk identification models for illegal financial activities in blockchain coin mixing services. Summary of the Invention
[0003] The purpose of the embodiments in this specification is to construct a technical solution that can accurately display coin mixing transaction scenarios and provide reliable label data, so as to improve the performance of risk identification models such as illegal financial activities in blockchain coin mixing services.
[0004] To achieve the above technical solution, the embodiments in this specification are implemented as follows: This specification provides an embodiment of a blockchain data processing method, the method comprising: constructing a private test chain identical to the target public chain based on information from the target public chain; generating a transaction strategy targeting the preset risk based on risk behaviors corresponding to preset risks in the target public chain; executing preset transaction processing on the private test chain based on the transaction strategy, and acquiring transaction behavior data containing upstream and downstream resource link information generated by executing the preset transaction processing on the private test chain; and performing data expansion processing on the acquired transaction behavior data containing upstream and downstream resource link information through preset expansion rules to obtain a transaction behavior dataset targeting the preset risk in the blockchain.
[0005] This specification provides an embodiment of a blockchain data processing device, comprising: a private chain creation module for constructing a private test chain identical to the target public chain based on information from the target public chain; a transaction strategy generation module for generating a transaction strategy targeting a preset risk based on risk behaviors corresponding to a preset risk in the target public chain; a transaction execution module for executing preset transaction processing on the private test chain based on the transaction strategy, and acquiring transaction behavior data containing upstream and downstream resource link information generated by executing the preset transaction processing on the private test chain; and a data acquisition module for performing data expansion processing on the acquired transaction behavior data containing upstream and downstream resource link information using preset expansion rules to obtain a transaction behavior dataset targeting a preset risk in the blockchain.
[0006] This specification provides an embodiment of a blockchain data processing device, comprising: a processor; and a memory arranged to store computer-executable instructions, wherein the executable instructions, when executed, cause the processor to: construct a private test chain identical to the target public chain based on information from the target public chain; generate a transaction strategy targeting the preset risk based on risk behaviors corresponding to preset risks in the target public chain; execute preset transaction processing on the private test chain based on the transaction strategy, and acquire transaction behavior data containing upstream and downstream resource link information generated by executing the preset transaction processing on the private test chain; and perform data expansion processing on the acquired transaction behavior data containing upstream and downstream resource link information through preset expansion rules to obtain a transaction behavior dataset targeting the preset risk in the blockchain.
[0007] This specification also provides a storage medium for storing computer-executable instructions. When executed by a processor, these instructions implement the following process: constructing a private test chain identical to the target public chain based on information from the target public chain; generating a transaction strategy targeting the preset risk based on risk behaviors corresponding to preset risks in the target public chain; executing preset transaction processing on the private test chain based on the transaction strategy, and acquiring transaction behavior data containing upstream and downstream resource link information generated by executing the preset transaction processing on the private test chain; and performing data expansion processing on the acquired transaction behavior data containing upstream and downstream resource link information using preset expansion rules to obtain a transaction behavior dataset targeting preset risks in the blockchain.
[0008] This specification also provides a computer program product, including a computer program that, when executed by a processor, implements the following process: constructing a private test chain identical to the target public chain based on information from the target public chain; generating a trading strategy for the preset risk based on risk behaviors corresponding to preset risks in the target public chain; executing preset transaction processing on the private test chain based on the trading strategy, and acquiring transaction behavior data containing upstream and downstream resource link information generated by executing the preset transaction processing on the private test chain; and performing data expansion processing on the acquired transaction behavior data containing upstream and downstream resource link information through preset expansion rules to obtain a transaction behavior dataset for the preset risk in the blockchain. Attached Figure Description
[0009] To more clearly illustrate the technical solutions in the embodiments or prior art of this specification, the drawings used in the description of the embodiments or prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. Figure 1 This is a schematic diagram of the structure of a blockchain data processing system described in this specification; Figure 2 This is a schematic diagram illustrating a blockchain data processing procedure as described in this specification. Figure 3 This is a schematic diagram illustrating another blockchain data processing procedure described in this specification; Figure 4 This is a schematic diagram illustrating yet another blockchain data processing procedure described in this specification; Figure 5 This is a schematic diagram illustrating yet another blockchain data processing procedure described in this specification; Figure 6 This is a schematic diagram illustrating yet another blockchain data processing procedure described in this specification; Figure 7 This is a schematic diagram illustrating yet another blockchain data processing procedure described in this specification; Figure 8 This is a schematic diagram illustrating yet another blockchain data processing procedure described in this specification; Figure 9 This is a schematic diagram illustrating yet another blockchain data processing procedure described in this specification; Figure 10 This is a schematic diagram illustrating yet another blockchain data processing procedure described in this specification; Figure 11 This is a schematic diagram of a blockchain data processing device as described in this specification; Figure 12 This is a schematic diagram of a blockchain data processing device described in this specification. Detailed Implementation
[0010] This specification provides a method, apparatus, and device for processing blockchain data.
[0011] To enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this specification, and not all embodiments. Based on the embodiments in this specification, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of this specification.
[0012] This specification provides a mechanism for synthesizing coin mixing transaction behavior for blockchain resource flow penetration analysis. Blockchain technology, with its immutable and decentralized characteristics, is widely used in financial transactions, but its anonymity also facilitates many illegal activities. Coin mixing services (technologies or services designed to enhance transaction privacy and sever resource links by aggregating resources from multiple users and then extracting them at a new address, making it difficult for outsiders to trace the relationship between the original source address and the final destination address of a specific resource) are key technologies for enhancing blockchain transaction privacy. By aggregating resources from multiple users and redistributing them at a new address, they sever the link between the source and destination of resources. Coin mixing services based on zero-knowledge proofs, such as Tornado Cash, have become important tools for illegal activities.
[0013] As the use of crypto assets in illicit transactions continues to rise, regulators are placing higher demands on blockchain-based illicit financial activities (which can be defined by a series of regulations, laws, and procedures to prevent users from laundering their illicit gains through the financial system; these regulations require financial institutions and other regulated entities to take measures to identify, monitor, and prevent such suspicious financial activities), particularly regarding resource flow penetration analysis of coin mixing transactions. Illegal financial activity risk identification models based on machine learning such as graph neural networks have shown great potential in identifying complex resource network patterns; however, the performance of these models is highly dependent on high-quality training data. However, the anonymity of coin mixing services makes obtaining large-scale transaction data with precise labels extremely difficult, which has become a key bottleneck restricting the development of technologies for identifying illegal financial activities through coin mixing services.
[0014] The current difficulty in addressing the untraceability of coin mixing transactions stems from the underlying design of coin mixing services (such as TornadoCash) based on zero-knowledge proofs. These services use smart contracts to completely decouple resource deposit and withdrawal addresses. Users can withdraw resources through a new address after depositing them, without disclosing the relationship between the two addresses. This design means that blockchain transaction records only reflect the "inflow" and "outflow" of resources into the mixing pool, failing to directly link specific resource deposit and withdrawal address pairs. Current methods of matching transaction resource data (such as transaction amount) and timestamps become completely ineffective against the anonymity barrier built by zero-knowledge proofs, leading to a fundamental dilemma of "broken resource deposit and withdrawal address associations" in resource tracking. Therefore, developing a technical solution that accurately displays coin mixing transaction scenarios and provides reliable labeling data is an urgent need to improve the performance of risk identification models for illegal financial activities in blockchain coin mixing services.
[0015] Typically, labeling can be based on on-chain rule matching. This method uses a series of heuristic rules to mine and label potential resource access address pairs for coin mixing transactions from publicly available blockchain transaction data. However, these rules are easily affected by the frequency and quantity of user transactions. Moreover, this method relies on preset rules to infer the association between resource access address pairs, such as by approximate resource quantities, overlapping time windows, and consistent Relayers. However, its limitation lies in the "probabilistic" nature of the rules. On the one hand, attackers can easily circumvent these rules by operating across time periods (such as at intervals of specified durations, such as 72 hours or more), rendering the rules ineffective. On the other hand, rule matching is essentially a guess based on correlation, making it impossible to distinguish between "coincidental matching" and "real association," resulting in a high labeling error rate that directly misleads the model training direction.
[0016] Alternatively, case extraction can be based on security reports. This method uses publicly available reports from security or law enforcement agencies as the data source to extract confirmed cryptocurrency mixing risk information, including the addresses involved, transaction paths, and resource flows. This verified information is then compiled into a labeled dataset. However, this method suffers from dual bottlenecks in terms of scale and timeliness. In terms of scale, cases in publicly available reports are only confirmed individual cases, and a single report typically involves no more than a hundred addresses, which cannot support high-sample-size model training. In terms of timeliness, reports mostly disclose outdated historical events, making it difficult to cover new cryptocurrency mixing strategies currently employed by attackers. Furthermore, the non-public nature of core reports results in extremely poor data reusability, making it impossible to form a standardized dataset.
[0017] Alternatively, neural network-based data generation can address the issue of insufficient data volume. Some technologies extend existing small-scale real-world datasets using neural network models. However, this approach suffers from problems such as "feature bias" and "behavioral distortion." On one hand, if the initial small-scale data contains feature biases (e.g., excessive concentration on a certain monetary pattern), the generated data will amplify this bias, causing the dataset's feature distribution to become disconnected from the real-world blockchain environment. On the other hand, the model can only learn simple patterns from known data and cannot generate complex strategies designed by attackers for adversarial tracking. The adversarial nature and diversity of the generated data are far lower than in real-world scenarios.
[0018] In summary, current implementations lack high-quality labeled data: Current blockchain risk identification models heavily rely on training data, but due to the anonymization design of coin mixing services, the true relationship between resource storage addresses and resource withdrawal addresses is completely hidden. Probabilistic inferences can only be made through heuristics and rule matching (such as matching resource quantity or time window overlap), resulting in high labeling error rates and dense noise, severely impacting model training performance. The scale of reliable data is extremely small: Typical data labeling relies on manual analysis or single-script simulation, which not only takes a long time to generate effective data but is also limited by human and equipment resources. The resulting reliable dataset typically consists of no more than a few hundred records, far from meeting the training requirements of neural network models, making it difficult for models to learn complex risk pattern features. The generated data is detached from the real on-chain environment: Current simulation data is mostly based on simplified... The generation of off-chain rules or isolated historical case fragments fails to reproduce the underlying protocol logic (such as Gas pricing mechanisms, block confirmation rules, smart contract interaction constraints, etc.) and ecosystem interaction scenarios of real blockchain networks. For example, simulated transactions often neglect the correlation between coin mixing operations and real DApp calls or simplify the timing logic of transaction confirmation, resulting in significant deviations between the behavioral characteristics of the generated data and the real on-chain environment. This makes it impossible for the model to learn risk behavior patterns that fit the actual scenario. Furthermore, the current datasets focus primarily on basic characteristics such as the quantity and time of a single transaction, neglecting the upstream and downstream resource flow paths of risky behaviors. This includes the aggregation path before resources flow into the mixer, the decentralized chain after flow out, and key behavioral data or fingerprints such as interaction preferences with specific DApps (such as cross-chain bridges, decentralized exchanges, etc.), preventing the model from capturing the complete risk chain. This specification provides an achievable technical solution in its embodiments to construct a technical solution that can accurately simulate real coin mixing transaction scenarios and provide reliable labeled data, thereby improving the risk identification performance of illegal financial activities in blockchain coin mixing services. Specific processing details can be found in the following embodiments.
[0019] The blockchain data processing methods provided in one or more embodiments of this specification are applicable to the implementation environment of blockchain data processing. (Refer to...) Figure 1 The implementation environment includes at least: Data processing device 100 and a private test chain 200 replicated from the target public chain, wherein: The data processing device 100 can be a terminal device or a server, etc. The terminal device can be a mobile phone, personal computer, tablet computer, e-book reader, wearable device, device for information interaction based on AR (Augmented Reality) or VR (Virtual Reality), and laptop computer, etc. The server can be one or more servers, a server cluster composed of several servers, or a cloud server of a cloud computing platform, etc.
[0020] The private testchain 200 includes multiple blockchain nodes, which can be terminal devices or servers. Each blockchain node has a blockchain client installed to execute blockchain programs to perform the full functions of the blockchain system, including transaction processing, data storage, blockchain network protocols, block generation and verification, etc. Moreover, the private testchain 200 can be highly consistent with the environment of the target public chain and is completely controllable.
[0021] In addition, it may include a database 300, which may be located in or outside the data processing device 100. The database 300 may store relevant data, rules, algorithms and so on in the risk identification process.
[0022] In this implementation environment, the data processing device 100 constructs a private test chain 200 identical to the target public chain based on the information of the target public chain; it generates a transaction strategy for the preset risks based on the risk behaviors corresponding to the preset risks in the target public chain; based on the transaction strategy, it executes the preset transaction processing on the private test chain 200 and obtains transaction behavior data containing upstream and downstream resource link information generated by executing the preset transaction processing on the private test chain 200; based on the obtained transaction behavior data containing upstream and downstream resource link information, it performs data expansion processing on the obtained transaction behavior data containing upstream and downstream resource link information through preset expansion rules to obtain a transaction behavior dataset for the preset risks in the blockchain.
[0023] like Figure 2As shown in the embodiments of this specification, a method for processing blockchain data is provided. The execution subject of this method can be a terminal device or a server, etc. The terminal device can be a mobile terminal device such as a mobile phone or tablet computer, a computer device such as a laptop or desktop computer, or an IoT device (specifically, a smartwatch, in-vehicle device, etc.). The server can be a single server or a server cluster composed of multiple servers. The server can be a backend server in fields such as finance or online shopping, or a backend server of an application. This embodiment uses a server as the execution subject for detailed description. For the case where the execution subject is a terminal device, please refer to the following server case processing, which will not be repeated here. The method may specifically include the following steps: In step S202, a private test chain identical to the target public chain is constructed based on the information of the target public chain.
[0024] The target public blockchain can be a distributed ledger system that ensures information security and immutability by chaining data together in the form of blocks. Each block in the target public blockchain contains a set of transaction data, a timestamp, and the hash value of the previous block, forming a continuous chain. The decentralized nature of the blockchain system allows data to be stored on multiple blockchain nodes. The failure or malicious behavior of any single blockchain node cannot affect the integrity of the entire blockchain network. This makes the blockchain system have broad application potential in multiple fields such as finance, supply chain management, and identity verification, because it can provide transparent, secure, and traceable transaction records. Target public blockchains can include various types, such as the Ethereum mainnet. A private test chain can be a blockchain system used for testing. The private test chain can be highly consistent with the environment of the target public blockchain and can be a fully controllable simulation space.
[0025] In practice, to test the risks of illegal financial transactions such as coin mixing in a blockchain system, the blockchain system to be tested (i.e., the target public chain) can be determined in advance. Relevant information about the target public chain can be obtained, such as information on deployed smart contracts, historical transaction data, the number of blockchain nodes, and relevant information for each blockchain node (such as the amount of remaining resources in the account (specifically, the account balance)). In addition, the format and status of the transaction data generated by the target public chain, as well as information on the data interaction logic, can be determined. An empty blockchain can be created. Then, based on the number of blockchain nodes in the target public blockchain and the relevant information of each blockchain node, the same number of blockchain nodes can be created in the empty blockchain. Each blockchain node can be set with the same attribute information as the corresponding blockchain node in the target public blockchain (including the amount of remaining resources in the account (such as the account balance), historical transaction data, etc.). In addition, smart contracts identical to those already deployed in the target public blockchain can be deployed in this blockchain. Furthermore, the same transaction data format, status, and data interaction logic as the target public blockchain can be set in the private test chain to ensure that the environment of the created blockchain is completely consistent with the real target public blockchain in terms of protocol rules and contract logic. Finally, the blockchain created in the above way can be used as a private test chain identical to the target public blockchain.
[0026] In step S204, a trading strategy is generated based on the risk behaviors corresponding to the preset risks in the target public chain.
[0027] The preset risks can include various types, such as fraud risk, illegal financial activity risk, and privacy data leakage risk, which can be set according to the actual situation. Risk behaviors can vary depending on the preset risks. For example, for the risk of illegal financial activity, risk behaviors can include one or more of the following: splitting a resource into multiple parts for savings or withdrawal, withdrawing resources at different time intervals, or selecting a specified transaction confirmation mode. For the risk of fraud, risk behaviors can include one or more of the following: impersonating a specified identity, clicking a specified link, or transferring resources, which can be set according to the actual situation. The transaction strategy can be the strategy used during the execution of a specified transaction process, and the transaction strategy can be constructed based on the risk behaviors.
[0028] In implementation, the preset risks in the target public blockchain can be analyzed to determine the risk behaviors corresponding to these preset risks. Then, corresponding trading strategies can be constructed based on the determined risk behaviors. For example, for the risk behavior of splitting a resource into multiple parts for savings or withdrawal in illegal financial activities, a corresponding resource splitting strategy can be constructed. For the risk behavior of withdrawing resources at different time intervals in illegal financial activities, a corresponding time-series strategy can be constructed. The constructed resource splitting strategy and / or time-series strategy can be used as the aforementioned trading strategy. It should be noted that the above are only two optional trading strategies for the risk of illegal financial activities. In practical applications, multiple different trading strategies can be included, specifically set according to different preset risks and the different risk behaviors corresponding to those preset risks. This specification does not limit this aspect.
[0029] In step S206, based on the above transaction strategy, a preset transaction process is executed on the private test chain, and transaction behavior data containing upstream and downstream resource link information generated by the preset transaction process executed on the private test chain is obtained.
[0030] In implementation, simulated test accounts can be pre-set, and a certain amount of test tokens (such as ETH) can be distributed to each account. These distributed test tokens can serve as initial resources for subsequent coin mixing transaction simulations. Then, specified transactions can be triggered, and pre-defined transaction processing can be executed on a private test chain, adhering to the aforementioned transaction strategies during the transaction processing. Complete upstream and downstream resource link information can be crawled using blockchain crawlers. This includes information such as resource origin, resource destination, and the smart contracts used. The upstream and downstream resource link information will contain behavioral fingerprint data, which refers to the unique patterns and characteristics exhibited by a specific entity (such as a user or a group of hackers) when performing a series of operations on the blockchain. This includes not only the characteristics of individual transactions but also complex correlation patterns between transactions, such as time, resource quantity, order, and target address selection. In addition, other relevant data can be collected, such as the amount of resources saved, the total amount of resources withdrawn, and the difference between saved and withdrawn resources, which can be set according to actual conditions. Transaction behavior data can be constructed based on the information obtained above.
[0031] In step S208, based on the acquired transaction behavior data containing upstream and downstream resource link information, the acquired transaction behavior data containing upstream and downstream resource link information is subjected to data expansion processing through preset expansion rules to obtain a transaction behavior dataset targeting preset risks in the blockchain.
[0032] The preset extension rules can include a variety of rules, such as extension rules based on network models like generative adversarial networks, or extension rules based on preset data augmentation strategies (such as rotation, scaling, cropping, flipping, etc.). The specific rules can be set according to the actual situation.
[0033] In practice, after obtaining transaction behavior data containing upstream and downstream resource link information through the above methods, the amount of transaction behavior data obtained is relatively small. When this data is subsequently used for application areas such as model training, it often fails to meet the requirements due to insufficient data volume. Therefore, the transaction behavior data can be expanded. Specifically, expansion rules can be pre-set according to the actual situation. Based on the obtained transaction behavior data containing upstream and downstream resource link information, the above-set expansion rules can be used to expand the transaction behavior data. For example, for each transaction behavior data, operations such as rotation, scaling, cropping, and flipping can be performed to obtain new transaction behavior data. Through the above methods, one or more different new transaction behavior data can be generated for each transaction behavior data. A transaction behavior dataset targeting preset risks in the blockchain can be constructed based on the transaction behavior data and the new transaction behavior data. Alternatively, adversarial networks can be used to generate adversarial data corresponding to each transaction behavior data. A transaction behavior dataset targeting preset risks in the blockchain can be constructed based on the transaction behavior data and the corresponding adversarial data. Other different methods can also be used to expand the transaction behavior data, which can be set according to the actual situation. This specification does not limit these methods in the embodiments.
[0034] After obtaining the transaction behavior dataset targeting the preset risks in the blockchain, the model can be trained on the identification model for the preset risks in the blockchain based on the data in the dataset. Alternatively, the model can be fine-tuned on a specified large model applied to the blockchain. The specific settings can be configured according to the actual situation.
[0035] This specification provides a method for processing blockchain data. Based on information from a target public chain, a private test chain identical to the target public chain is constructed. Then, a transaction strategy targeting a preset risk can be generated based on the risk behaviors corresponding to preset risks in the target public chain. Subsequently, based on the transaction strategy, preset transaction processing can be executed on the private test chain, and transaction behavior data containing upstream and downstream resource link information generated by executing preset transaction processing on the private test chain can be obtained. Finally, based on the obtained transaction behavior data containing upstream and downstream resource link information, data expansion processing can be performed on the obtained transaction behavior data containing upstream and downstream resource link information through preset expansion rules to obtain a transaction behavior dataset targeting preset risks in the blockchain. Through controlled environment simulation and programmatic operation, 100% accurate labeling of resource access address associations is achieved, providing a noise-free training foundation for the risk identification model. In addition, in terms of data scale and efficiency, a containerized parallel scheduling architecture is adopted to meet the model's need for large-scale samples, thereby accurately displaying coin mixing transaction scenarios, providing reliable labeled data, and improving the performance of risk identification models such as illegal financial activities in blockchain coin mixing services.
[0036] In practical applications, the specific processing method of step S202 can vary. The following provides another optional processing method, which may specifically include the processing of steps S2022 and S2024. Based on this, in the above... Figure 2 Based on this, the specific steps included in this method can be as follows: Figure 3 As shown.
[0037] In step S2022, a fork chain is created on the target public chain, and the information of the target public chain at a preset block height is replicated. The replicated information includes one or more of the following: deployed smart contracts, the amount of remaining resources in the account, and historical transaction data.
[0038] In implementation, to achieve the synthesis of coin mixing transaction data, a coin mixing transaction data synthesis system can be constructed that combines controlled environment simulation, programmatic transaction execution, and large-scale parallel scheduling. This system can include an environment initialization module, a transaction strategy generation module, an automated transaction execution module, a context behavior synthesis module, an extension module, and an output module. Among these, the environment initialization module is the foundation of the entire system, responsible for creating a simulation space that is highly consistent with and fully controllable to the real blockchain (i.e., the target public chain) environment. Specifically, a fork chain is created on the target public chain, and forking tools (such as Ganache or Hardhat) are used to replicate the complete state of the target public chain (such as the Ethereum mainnet) at a specified block height to obtain the replicated information.
[0039] In step S2024, based on the replicated information, the created forked chain is configured to obtain an initial private test chain that is identical to and controllable with the target public chain. Test resources are distributed to each preset simulated account in the initial private test chain, and the network parameters of the initial private test chain are configured to match the corresponding network with the actual network, thus obtaining a private test chain identical to the target public chain.
[0040] In implementation, the replicated information can be used to configure the created forked chain, ensuring it is identical to the target public chain (i.e., both operate in the same environment). This results in a forked chain on the target public chain, including all deployed smart contracts (such as Tornado Cash contracts), remaining resources in the account, and historical transaction data. This process ensures the simulated environment (the forked chain) is completely consistent with the real blockchain network (the target public chain) in terms of protocol rules and contract logic. Furthermore, the forked chain is fully controllable and can serve as the initial private test chain. In this replicated initial private test chain, test tokens (such as ETH) are distributed in batches to preset simulated accounts as initial test resources for subsequent coin mixing simulations. Simultaneously, the network parameters of the initial private test chain (such as Gas price mechanism and block generation speed) are configured to match the actual network (the network corresponding to the target public chain) to guarantee the authenticity of transactions. Furthermore, wallet applications and Tornado Cash applications can be used to connect to the Remote Procedure Call (RPC) interface of the initial test chain obtained through the Forking tool. Through the above process, a private test chain identical to the target public chain can be obtained.
[0041] In practical applications, the specific processing method of step S204 can vary. The following provides another optional processing method, which may specifically include the processing of steps S2042 and S2044. Based on this, in the above... Figure 2 Based on this, the specific steps included in this method can be as follows: Figure 4 As shown.
[0042] In step S2042, based on the risk behaviors corresponding to the preset risks in the target public chain, the transaction processing rules required for the preset transaction processing to be executed are determined. The transaction processing rules include one or more of the following: resource splitting rules, resource extraction timing rules, relay selection rules, and gas price selection rules. The resource splitting rules are used to split the resources to be stored into multiple resources that meet the fixed resource quantity in the mixing pool. The resource extraction timing rules are used to extract resources according to the preset timing rules. The gas price selection rules are used to select the gas price according to the network conditions.
[0043] In implementation, the transaction strategy generation module can generate transaction strategies or patterns that conform to the real attacker's strategy and meet the preset risk in the target public chain, based on the risk behaviors corresponding to the preset risks. Specifically, the transaction processing rules required for the preset transaction processing to be executed can be determined according to the characteristics or features that the real attacker may possess. These rules can include one or more of the following: resource-related transaction processing rules (i.e., resource splitting rules), time-related transaction processing rules (i.e., resource extraction time-series rules), relay selection rules, and gas price selection rules. For resource splitting rules, combinatorial optimization algorithms such as the knapsack algorithm can be used to split the resources to be stored (e.g., test resources) into multiple resource combinations that conform to a fixed amount in the mixing pool (e.g., 0.1 ETH, 1 ETH, 10 ETH, 100 ETH, etc.). For example, 5.3 ETH can be split into 5 combinations of 1 ETH and 3 combinations of 0.1 ETH to simulate the resource splitting operation performed by real users to avoid resource tracking. Resource splitting rules can be generated based on the above processing mechanism. Regarding resource extraction timing rules, a combination of stochastic process models and adversarial behavior analysis can be used to generate uncertain transaction time intervals. For example, randomly generating resource extraction times within 1 to 72 hours after saving resources, or simulating a burst trading pattern of "intensive operations + long periods of silence" to reproduce attackers' strategies for circumventing time feature analysis. Resource extraction timing rules can be generated based on this processing mechanism. Regarding relay selection rules, the relay selection strategies of real users in coin mixing transactions can be simulated to generate relay interaction characteristics that closely resemble those on the blockchain. Specifically, this could include randomly selecting known active relay URLs, or simulating two modes: "fixed relay preference" (using the same relay in multiple transactions for the same account) and "dynamic relay switching" (randomly changing relays for different transactions to circumvent correlation analysis). Relay selection rules can be generated based on this processing mechanism. Regarding the Gas price selection rules, the dynamic adjustment mechanism of Gas prices in a real blockchain environment can be reproduced to simulate the behavior of attackers selecting Gas prices based on network congestion, ensuring that the generated transactions are consistent with the transactions on the real blockchain in terms of Gas price characteristics. Gas price selection rules can be generated based on the above processing mechanism.
[0044] In step S2044, a trading strategy for preset risks is generated based on the determined trading processing rules.
[0045] In practice, the established trading rules can be used directly as trading strategies, or the established trading rules can be integrated to generate trading strategies for preset risks, or a specified algorithm can be pre-set to calculate the established trading rules, and the calculation results can be used as trading strategies for preset risks, etc. The specific settings can be set according to the actual situation.
[0046] In practical applications, transaction processing rules include Gas price selection rules. The specific processing method of step S2044 can vary. The following provides another optional processing method, which may include the processing of steps S20442 and S20444. Based on this, in the above... Figure 4 Based on this, the specific steps included in this method can be as follows: Figure 5 As shown.
[0047] In step S20442, based on the risk behavior corresponding to the preset risk in the target public chain, the transaction confirmation mode corresponding to the preset transaction processing to be executed is determined through the preset Gas price fluctuation model. The transaction confirmation mode includes fast confirmation mode and delayed confirmation mode.
[0048] The Gas price fluctuation model can be constructed using a specified algorithm, a specified network (such as a neural network (specifically, a convolutional neural network, a recurrent neural network, etc.), or a preset large model, and the specific model can be set according to the actual situation.
[0049] In implementation, data on risk behaviors corresponding to preset risks in the target public blockchain can be input into the Gas price fluctuation model. The Gas price fluctuation model determines the transaction confirmation mode corresponding to the preset transaction processing to be executed. For example, based on the Gas price fluctuation model, transaction confirmation modes such as "high Gas price fast confirmation" or "low Gas price delayed confirmation" can be randomly or strategically selected when the transaction is generated.
[0050] In step S20444, a trading strategy for a preset risk is generated based on the transaction confirmation mode and the preset data recording rules. The data recording rules are used to record one or more of the following: gas price information, gas usage, and transaction confirmation time.
[0051] In implementation, data recording rules can be pre-set to record relevant data such as gas price, gas usage, and transaction confirmation time, ensuring that the generated transactions are consistent with the transactions on the real blockchain in terms of fee characteristics. Based on the transaction confirmation mode and the pre-set data recording rules, transaction strategies targeting preset risks can be generated.
[0052] In practical applications, the following processing can also be performed in advance to lay the foundation for the specific processing of subsequent step S206. For details, please refer to the processing of step S210 below. Based on this, in the above... Figure 2 Based on this, the specific steps included in this method can be as follows: Figure 6 As shown.
[0053] In step S210, the resource access address pair that has undergone coin mixing transaction is obtained from the preset coin theft event security report.
[0054] In implementation, the context behavior synthesis module can be used to generate behavioral fingerprint data containing the complete resource chain through large-scale expansion driven by real cases. This overcomes the limitation of existing datasets that only focus on core coin mixing transactions. Specifically, security reports of coin theft incidents published by security agencies (such as Chainalysis) can be used as the data source to filter and extract resource access address pairs that have undergone coin mixing transactions.
[0055] Based on the processing of step S210 above, the specific processing method of step S206 above can be varied. The following provides another optional processing method, which may include the processing of steps S2062 and S2064.
[0056] In step S2062, based on the above transaction strategy, a preset transaction process is executed on the private test chain, and based on the resource access address pair, a blockchain crawler is called to crawl the upstream and downstream resource link information generated by the preset transaction process executed on the private test chain. The upstream and downstream resource link information includes one or more of the following: resource source, information of associated interactive smart contracts, resource destination, transaction frequency, and resource dismantling method.
[0057] In practice, based on the above resource access address pairs, blockchain crawling tools (such as BlockchainSpider) can be called to crawl complete upstream and downstream resource link information. The upstream and downstream resource link information includes one or more of the following: resource source, information of associated interactive smart contracts, resource destination, transaction frequency, and resource dismantling methods.
[0058] In step S2064, the aforementioned transaction behavior data is determined based on upstream and downstream resource link information.
[0059] In practice, in addition to upstream and downstream resource link information, other relevant information can also be obtained. The above transaction behavior data can be determined based on upstream and downstream resource link information and other relevant information. The specific settings can be made according to the actual situation.
[0060] In practical applications, the specific processing method of step S2064 can vary. The following provides another optional processing method, which may specifically include the processing of steps S20642 and S20644. Based on this, in the above... Figure 6 Based on this, the specific steps included in this method can be as follows: Figure 7 As shown.
[0061] In step S20642, a resource flow graph is constructed based on upstream and downstream resource link information. The resource flow graph includes nodes and edges. Nodes are constructed from resource extraction addresses, resource storage addresses, or smart contracts. Edges indicate that there is a transaction between two nodes. Edges also include attribute information, which includes one or more of the following: resource quantity, timestamp, and transaction type.
[0062] In step S20644, the transaction behavior data is determined based on the resource flow graph.
[0063] In practical applications, the specific processing method of step S208 can vary. The following provides another optional processing method, which may specifically include the processing of steps S20802 to S20806. Based on this, in the above... Figure 2 Based on this, the specific steps included in this method can be as follows: Figure 8 As shown.
[0064] In step S20802, the transaction behavior data is described with text to obtain the description text corresponding to the transaction behavior data.
[0065] In implementation, such as Figure 9 As shown, if the transaction behavior data is a resource flow graph, it can be converted into machine-understandable natural language text using the OpenGraph tool. Specifically, it can be converted into structured text description information containing node attributes and edge attributes, forming an input format that can be processed by a large language model, thereby obtaining the description text corresponding to the transaction behavior data.
[0066] In step S20804, corresponding prompts are generated based on the descriptive text corresponding to the transaction behavior data. The prompts and the descriptive text corresponding to the transaction behavior data are input into the large language model. The prompts guide the large language model to perform data expansion processing on the transaction behavior data to obtain expanded transaction behavior data.
[0067] In implementation, such as Figure 9As shown, a corresponding prompt message is generated based on the descriptive text corresponding to the transaction behavior data. The prompt message and the descriptive text corresponding to the transaction behavior data are input into the large language model. The prompt message guides the large language model to perform data expansion processing on the transaction behavior data to generate text data of diverse resource flows with similar behavioral structures.
[0068] In step S20806, a transaction behavior dataset targeting preset risks in the blockchain is constructed based on transaction behavior data and extended transaction behavior data.
[0069] In implementation, such as Figure 9 As shown, the text data generated by the large language model, after parsing, can be restored to a new resource flow graph and incorporated into the dataset as supplementary samples (i.e., constructing a transaction behavior dataset targeting preset risks in the blockchain based on transaction behavior data and extended transaction behavior data), thereby achieving large-scale expansion of real behavior fingerprint data (i.e., transaction behavior data). In this way, through the context behavior synthesis module, the system can generate massive amounts of transaction behavior data with complex upstream and downstream resource links based on a small number of real cases (i.e., transaction behavior data). This allows the synthesized coin mixing transaction graph to not only include core resource access behaviors but also encompass pre-aggregation and post-cleaning paths consistent with real risk scenarios, significantly improving the dataset's ecological relevance and feature richness.
[0070] In practical applications, the specific processing method of step S208 can vary. The following provides another optional processing method, which may specifically include the processing of steps S20808 to S20810. Based on this, in the above... Figure 2 Based on this, the specific steps included in this method can be as follows: Figure 10 As shown.
[0071] In step S20808, target transaction behavior data is obtained from the target public chain based on the transaction behavior data containing upstream and downstream resource link information.
[0072] In practice, blockchain crawlers can also be used to crawl target transaction behavior data generated during the transaction process from the target public chain, thereby enriching the transaction behavior data containing upstream and downstream resource link information obtained from the private test chain.
[0073] In step S20810, based on the acquired transaction behavior data containing upstream and downstream resource link information and target transaction behavior data, a transaction behavior dataset targeting preset risks in the blockchain is constructed.
[0074] In implementation, target transaction behavior data can be used to enrich and optimize the acquired transaction behavior data containing upstream and downstream resource link information, ultimately resulting in transaction behavior data with higher data richness, which can be used to construct a transaction behavior dataset targeting preset risks in the blockchain.
[0075] Furthermore, the automated transaction execution module simulates the complete interaction process of a real user in the coin mixing service through programmatic operations, ensuring the authenticity of the transaction behavior. Specifically, the automation tool Selenium can be used to control the browser and wallet application to simulate the user's actual operation path (including a series of operations such as wallet login, connecting to the coin mixing service webpage, entering the amount of resources to be saved, confirming the transaction, obtaining resource savings notes, and initiating resource withdrawal requests). During the operation, the constraints of the real transaction process are strictly followed, such as paying gas consumption fees as required by the coin mixing service, waiting for block confirmation, and handling transaction failure retries, ensuring that the generated transaction data is completely consistent with the data on the real blockchain in terms of format, status, and interaction logic.
[0076] This specification provides a method for processing blockchain data. Based on information from a target public chain, a private test chain identical to the target public chain is constructed. Then, a transaction strategy targeting a preset risk can be generated based on the risk behaviors corresponding to preset risks in the target public chain. Subsequently, based on the transaction strategy, preset transaction processing can be executed on the private test chain, and transaction behavior data containing upstream and downstream resource link information generated by executing preset transaction processing on the private test chain can be obtained. Finally, based on the obtained transaction behavior data containing upstream and downstream resource link information, data expansion processing can be performed on the obtained transaction behavior data containing upstream and downstream resource link information through preset expansion rules to obtain a transaction behavior dataset targeting preset risks in the blockchain. Through controlled environment simulation and programmatic operation, 100% accurate labeling of resource access address associations is achieved, providing a noise-free training foundation for the risk identification model. In addition, in terms of data scale and efficiency, a containerized parallel scheduling architecture is adopted to meet the model's need for large-scale samples, thereby accurately displaying coin mixing transaction scenarios, providing reliable labeled data, and improving the performance of risk identification models such as illegal financial activities in blockchain coin mixing services.
[0077] Moreover, in terms of behavioral pattern coverage, by combining optimization algorithms and resource extraction timing rules, known and unknown risk behavior patterns such as resource dismantling and cross-time period operations were reproduced. In addition, the full-link characteristics of resource aggregation and dispersion were supplemented, making the synthetic data closer to real risk scenarios and providing key support for improving the performance of blockchain risk identification models.
[0078] The following describes in detail a blockchain data processing method provided in this specification, using specific application scenarios. The preset risk can be the risk of illegal financial activities (which can be a series of regulations, laws, and procedures to prevent users from laundering their illegal gains through the financial system; these regulations require financial institutions and other regulated entities to take measures to identify, monitor, and prevent suspicious financial activities). Upstream and downstream resource link information can be upstream and downstream capital link information. The remaining resource quantity in the account can be the account balance. Transaction processing rules include deposit splitting rules, withdrawal timing rules, relay selection rules, and Gas price selection rules. Resource deposit and withdrawal address pairs can be deposit and withdrawal address pairs. Resource source can be the source of funds. Resource destination can be the destination of funds. Resource splitting method can be the amount splitting method. Resource flow graph can be the capital flow graph. Resource withdrawal address can be the withdrawal address. Resource savings address can be the deposit address. Resource quantity can be the amount. Test resource can be test tokens.
[0079] This specification provides a method for processing blockchain data. The execution subject of this method can be a terminal device or a server, such as a mobile terminal device like a mobile phone or tablet, a computer device like a laptop or desktop computer, or an IoT device (specifically, a smartwatch, in-vehicle device, etc.). The server can be a single server or a server cluster composed of multiple servers. The server can be a backend server in fields such as finance or online shopping, or a backend server for an application. This embodiment uses a server as the execution subject for detailed explanation. For the case where the execution subject is a terminal device, please refer to the following section on server-side processing, which will not be repeated here. The method specifically includes the following steps: In step A02, a fork chain is created on the target public chain, and the information of the target public chain at a preset block height is replicated. The replicated information includes one or more of the following: deployed smart contracts, account balances, and historical transaction data.
[0080] In step A04, based on the replicated information, the created fork chain is configured to obtain an initial private test chain that is identical to and controllable with the target public chain. Test tokens are distributed to each preset simulated account in the initial private test chain, and the network parameters of the initial private test chain are configured to match the actual network, thus obtaining a private test chain identical to the target public chain.
[0081] In step A06, based on the risk behaviors corresponding to the preset risks in the target public chain, the transaction processing rules required for the preset transaction processing to be executed are determined. The transaction processing rules include deposit splitting rules, withdrawal timing rules, relay selection rules, and gas price selection rules. The deposit splitting rules are used to split the deposit into fixed amounts that conform to the mixing pool. The withdrawal timing rules are used to make withdrawals according to the preset timing rules. The gas price selection rules are used to select the gas price according to the network conditions.
[0082] In step A08, a trading strategy is generated to address the risks of illegal financial activities based on the established transaction processing rules.
[0083] The transaction processing rules include Gas price selection rules, which can determine the transaction confirmation mode corresponding to the preset transaction processing to be executed based on the risk behavior corresponding to the preset risk in the target public chain and through the preset Gas price fluctuation model. The transaction confirmation mode includes fast confirmation mode and delayed confirmation mode. Based on the transaction confirmation mode and the preset data recording rules, a transaction strategy for the preset risk is generated. The data recording rules are used to record one or more of Gas price information, Gas usage, and transaction confirmation time.
[0084] In step A10, the deposit and withdrawal address pairs that have undergone coin mixing transactions are obtained from the preset coin theft event security report.
[0085] In step A12, based on the above transaction strategy, a preset transaction process is executed on the private test chain. Based on the deposit and withdrawal address pairs, a blockchain crawler is invoked to crawl the upstream and downstream capital chain information generated by the preset transaction process executed on the private test chain. The upstream and downstream capital chain information includes one or more of the following: source of funds, information of associated interactive smart contracts, destination of funds, transaction frequency, and amount breakdown method.
[0086] In step A14, a resource flow graph is constructed based on upstream and downstream resource link information. The resource flow graph includes nodes and edges. Nodes are constructed from withdrawal addresses, deposit addresses, or smart contracts. Edges indicate that there is a transaction between two nodes. Edges also include attribute information, which includes one or more of the following: amount, timestamp, and transaction type.
[0087] In step A16, the transaction behavior data is determined based on the resource flow diagram described above.
[0088] In step A18, the transaction behavior data is described with text to obtain the description text corresponding to the transaction behavior data.
[0089] In step A20, corresponding prompts are generated based on the descriptive text corresponding to the transaction behavior data. The prompts and the descriptive text corresponding to the transaction behavior data are input into the large language model. The prompts guide the large language model to perform data expansion processing on the transaction behavior data to obtain expanded transaction behavior data.
[0090] In step A21, a transaction behavior dataset targeting preset risks in the blockchain is constructed based on transaction behavior data and extended transaction behavior data.
[0091] This specification provides a method for processing blockchain data. Based on information from a target public chain, a private test chain identical to the target public chain is constructed. Then, a transaction strategy targeting a preset risk can be generated based on the risk behaviors corresponding to preset risks in the target public chain. Subsequently, based on the transaction strategy, preset transaction processing can be executed on the private test chain, and transaction behavior data containing upstream and downstream resource link information generated by executing preset transaction processing on the private test chain can be obtained. Finally, based on the obtained transaction behavior data containing upstream and downstream resource link information, data expansion processing can be performed on the obtained transaction behavior data containing upstream and downstream resource link information through preset expansion rules to obtain a transaction behavior dataset targeting preset risks in the blockchain. Through controlled environment simulation and programmatic operation, 100% accurate labeling of resource access address associations is achieved, providing a noise-free training foundation for the risk identification model. In addition, in terms of data scale and efficiency, a containerized parallel scheduling architecture is adopted to meet the model's need for large-scale samples, thereby accurately displaying coin mixing transaction scenarios, providing reliable labeled data, and improving the performance of risk identification models such as illegal financial activities in blockchain coin mixing services.
[0092] Moreover, in terms of behavioral pattern coverage, by combining optimization algorithms and resource extraction timing rules, known and unknown risk behavior patterns such as resource dismantling and cross-time period operations were reproduced. In addition, the full-link characteristics of resource aggregation and dispersion were supplemented, making the synthetic data closer to real risk scenarios and providing key support for improving the performance of blockchain risk identification models.
[0093] The above describes the blockchain data processing method provided in the embodiments of this specification. Based on the same idea, the embodiments of this specification also provide a blockchain data processing device, such as... Figure 11 As shown.
[0094] The blockchain data processing device includes: a private chain creation module 1101, a transaction strategy generation module 1102, a transaction execution module 1103, and a data acquisition module 1104, wherein: The private chain creation module 1101 constructs a private test chain identical to the target public chain based on the information of the target public chain. The transaction strategy generation module 1102 generates a transaction strategy for the preset risk based on the risk behavior corresponding to the preset risk in the target public chain; The transaction execution module 1103, based on the transaction strategy, executes a preset transaction process on the private test chain and obtains transaction behavior data containing upstream and downstream resource link information generated by the preset transaction process executed on the private test chain. The data acquisition module 1104, based on the acquired transaction behavior data containing upstream and downstream resource link information, performs data expansion processing on the acquired transaction behavior data containing upstream and downstream resource link information through preset expansion rules to obtain a transaction behavior dataset targeting preset risks in the blockchain.
[0095] In this embodiment of the specification, the private blockchain creation module 1101 includes: The information replication unit creates a fork chain on the target public chain and replicates the information of the target public chain at a preset block height. The replicated information includes one or more of the following: deployed smart contracts, the amount of remaining resources in the account, and historical transaction data. The private chain creation unit configures the created forked chain based on the replicated information to obtain an initial private test chain that is identical and controllable to the target public chain. It also distributes test resources to each preset simulated account in the initial private test chain and configures the network parameters of the initial private test chain to match the corresponding network with the actual network, thereby obtaining a private test chain identical to the target public chain.
[0096] In this embodiment of the specification, the trading strategy generation module 1102 includes: The processing rule determination unit determines the transaction processing rules required for the preset transaction processing to be executed based on the risk behavior corresponding to the preset risk in the target public chain. The transaction processing rules include one or more of the following: resource splitting rules, resource extraction timing rules, relay selection rules, and gas price selection rules. The resource splitting rules are used to split the resources to be stored into multiple resources that meet the fixed resource quantity in the mixing pool. The resource extraction timing rules are used to extract resources according to the preset timing rules. The gas price selection rules are used to select the gas price according to the network conditions. The trading strategy generation unit generates a trading strategy for the preset risk based on the determined trading processing rules.
[0097] In this embodiment of the specification, the transaction processing rules include Gas price selection rules. The transaction strategy generation unit determines the transaction confirmation mode corresponding to the preset transaction processing to be executed based on the risk behavior corresponding to the preset risk in the target public chain and through a preset Gas price fluctuation model. The transaction confirmation mode includes a fast confirmation mode and a delayed confirmation mode. Based on the transaction confirmation mode and preset data recording rules, a transaction strategy is generated for the preset risk. The data recording rules are used to record one or more of Gas price information, Gas usage, and transaction confirmation time.
[0098] In the embodiments described in this specification, the device further includes: The address pair acquisition module retrieves resource access address pairs that have undergone coin mixing transactions from a preset coin theft event security report; The transaction execution module 1103 includes: The resource link information acquisition unit executes a preset transaction process on the private test chain based on the transaction strategy, and calls a blockchain crawler to crawl the upstream and downstream resource link information generated by the preset transaction process executed on the private test chain based on the resource access address pair. The upstream and downstream resource link information includes one or more of the following: resource source, information of associated interactive smart contracts, resource destination, transaction frequency and resource dismantling method. The data determination unit determines the transaction behavior data based on the upstream and downstream resource link information.
[0099] In this embodiment of the specification, the data determination unit constructs a resource flow graph based on the upstream and downstream resource link information. The resource flow graph includes nodes and edges. The nodes are constructed from resource extraction addresses, resource storage addresses, or smart contracts. The edges represent transactions between two nodes. The edges also include attribute information, which includes one or more of resource quantity, timestamp, and transaction type. The transaction behavior data is determined based on the resource flow graph.
[0100] In this embodiment of the specification, the data acquisition module 1104 includes: The text description unit performs a text description on the transaction behavior data to obtain the description text corresponding to the transaction behavior data; The data expansion unit generates corresponding prompt information based on the descriptive text corresponding to the transaction behavior data, inputs the prompt information and the descriptive text corresponding to the transaction behavior data into the large language model, and guides the large language model to perform data expansion processing on the transaction behavior data through the prompt information to obtain expanded transaction behavior data. The dataset construction unit constructs a transaction behavior dataset targeting preset risks in the blockchain based on the transaction behavior data and the extended transaction behavior data.
[0101] In this embodiment of the specification, the data acquisition module 1104 includes: The target data acquisition unit acquires target transaction behavior data from the target public chain based on the acquired transaction behavior data containing upstream and downstream resource link information; The dataset construction unit constructs a transaction behavior dataset targeting preset risks in the blockchain, based on the acquired transaction behavior data containing upstream and downstream resource link information and the target transaction behavior data.
[0102] For ease of description, the above devices are described by dividing them into various modules or units based on their functions. Of course, when implementing one or more embodiments of this specification, the functions of each module or unit can be implemented in one or more software and / or hardware components, or a module that performs the same function can be implemented by a combination of multiple sub-modules or sub-units, etc. The device embodiments described above are merely illustrative; the division of each module and unit is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or modules can be combined or integrated into another system, or some features can be ignored or not executed, etc.
[0103] This specification provides a blockchain data processing device. Based on information from a target public blockchain, a private test chain identical to the target public blockchain is constructed. Then, a transaction strategy targeting a preset risk can be generated based on the risk behaviors corresponding to preset risks in the target public blockchain. Subsequently, based on the transaction strategy, preset transaction processing can be executed on the private test chain, and transaction behavior data containing upstream and downstream resource link information generated by executing preset transaction processing on the private test chain can be obtained. Finally, based on the obtained transaction behavior data containing upstream and downstream resource link information, data expansion processing can be performed on the obtained transaction behavior data containing upstream and downstream resource link information through preset expansion rules to obtain a transaction behavior dataset targeting preset risks in the blockchain. Through controlled environment simulation and programmatic operation, 100% accurate labeling of resource access address associations is achieved, providing a noise-free training foundation for the risk identification model. In addition, in terms of data scale and efficiency, a containerized parallel scheduling architecture is adopted to meet the model's need for large-scale samples, thereby accurately displaying coin mixing transaction scenarios, providing reliable labeled data, and improving the performance of risk identification models such as illegal financial activities in blockchain coin mixing services.
[0104] Moreover, in terms of behavioral pattern coverage, by combining optimization algorithms and resource extraction timing rules, known and unknown risk behavior patterns such as resource dismantling and cross-time period operations were reproduced. In addition, the full-link characteristics of resource aggregation and dispersion were supplemented, making the synthetic data closer to real risk scenarios and providing key support for improving the performance of blockchain risk identification models.
[0105] The above are examples of blockchain data processing devices provided in the embodiments of this specification. Based on the same idea, embodiments of this specification also provide a blockchain data processing device, such as... Figure 12 As shown.
[0106] The blockchain data processing device can provide terminal equipment or servers, etc., as described in the above embodiments.
[0107] Blockchain data processing devices can vary significantly in configuration and performance, and may include a communication interface 1202, a user interface 1204, a processor 1206, and a data storage 1208. These components are interconnected and communicate with each other via a system bus, network, or other connection mechanism 1210. The communication interface 1202 enables the blockchain data processing device 1200 to communicate with other devices, access networks, and transmission networks via analog or digital modulation. For example, the communication interface 1202 may include a chipset and antenna for wireless communication with a radio access network or access point. Furthermore, the communication interface 1202 can be a wired interface such as Ethernet, Token Ring, or a USB port, or a wireless interface such as Wi-Fi, Bluetooth, Global Positioning System (GPS), or a wide-area wireless interface (e.g., WiMAX or LTE). Of course, the communication interface 1202 may also support other forms of physical layer interfaces and standard or proprietary communication protocols. The communication interface 1202 may also include multiple physical communication interfaces, such as Wi-Fi, Bluetooth, and wide-area wireless interfaces.
[0108] User interface 1204 includes receiving user input and providing output to the user. Therefore, user interface 1204 may include input components such as a keypad, keyboard, touch-sensitive or presence-sensitive panel, computer mouse, trackball, joystick, microphone, still camera, and video camera, and output components such as a display screen (which may be combined with a touch-sensitive panel), CRT, LCD, LED, display using DLP technology, printer, and other similar devices known or developed in the future. User interface 1204 may also generate auditory output via speakers, speaker jacks, audio output ports, audio output devices, headphones, and other similar devices known or developed in the future. In some embodiments, user interface 1204 may include software, circuitry, or other forms of logic capable of transmitting and receiving data from external user input / output devices. Additionally or alternatively, blockchain data processing device 1200 may support remote access from other devices via communication interface 1202 or another physical interface (not shown). User interface 1204 may be configured to receive user input, the position and movement of which may be indicated by indicators or cursors described herein. User interface 1204 can also be configured as a display device for rendering or displaying text fragments.
[0109] Processor 1206 may contain one or more general-purpose processors and / or special-purpose processors.
[0110] Data storage 1208 may include one or more volatile and / or non-volatile storage components and may be integrated wholly or partially with processor 1206. Data storage 1208 may include removable and non-removable components.
[0111] Processor 1206 is capable of executing program instructions 1218 (e.g., compiled or uncompiled program logic and / or machine code) stored in data storage 1208 to implement the various functions described herein. Data storage 1208 may contain a non-transitory computer-readable medium on which program instructions are stored, which, when executed by blockchain data processing device 1200, enable blockchain data processing device 1200 to perform any methods, processes, or functions disclosed in this specification and / or the accompanying drawings. Processor 1206 executing program instructions 1218 may result in processor 1206 using data 1212.
[0112] For example, program instructions 1218 may include an operating system 1222 (e.g., an operating system kernel, device drivers, and / or other modules) and one or more applications 1220 (e.g., a browser, social media application, or game application) installed on the blockchain data processing device 1200. Similarly, data 1212 may include operating system data 1216 and application data 1214. Operating system data 1216 is primarily accessible to the operating system 1222, while application data 1214 is primarily accessible to one or more applications 1220. Application data 1214 may reside in a file system that is visible or hidden from the user of the blockchain data processing device 1200.
[0113] Application 1220 can communicate with operating system 1212 through one or more application programming interfaces (APIs). These APIs help application 1220 read and / or write application data 1214, transmit or receive information via communication interface 1202, receive or display information on user interface 1204, etc.
[0114] In some terminology, application 1220 may be simply referred to as "app". Furthermore, application 1220 can be downloaded to the blockchain data processing device 1200 through one or more online app stores or app markets. However, the application can also be installed on the blockchain data processing device 1200 in other ways, such as through a web browser or a physical interface (e.g., a USB port) on the blockchain data processing device 1200.
[0115] Specifically, in this embodiment, the blockchain data processing device 1200 includes a data storage 1208 and one or more program instructions 1218, wherein one or more program instructions 1218 are stored in the data storage 1208, and one or more program instructions 1218 are configured to be executed by one or more processors. The one or more program instructions include computer-executable instructions for performing the following: Based on the information from the target public blockchain, construct a private test chain identical to the target public blockchain; A trading strategy is generated based on the risk behaviors corresponding to the preset risks in the target public chain; Based on the transaction strategy, a preset transaction process is executed on the private test chain, and transaction behavior data containing upstream and downstream resource link information generated by the preset transaction process executed on the private test chain is obtained. Based on the acquired transaction behavior data containing upstream and downstream resource link information, the acquired transaction behavior data containing upstream and downstream resource link information is expanded through preset expansion rules to obtain a transaction behavior dataset targeting preset risks in the blockchain.
[0116] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the embodiments for processing blockchain data are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments.
[0117] This specification provides a blockchain data processing device. Based on information from a target public blockchain, a private test chain identical to the target public blockchain is constructed. Then, a transaction strategy targeting a preset risk can be generated based on the risk behaviors corresponding to preset risks in the target public blockchain. Subsequently, based on the transaction strategy, preset transaction processing can be executed on the private test chain, and transaction behavior data containing upstream and downstream resource link information generated by executing preset transaction processing on the private test chain can be obtained. Finally, based on the obtained transaction behavior data containing upstream and downstream resource link information, data expansion processing can be performed on the obtained transaction behavior data containing upstream and downstream resource link information through preset expansion rules to obtain a transaction behavior dataset targeting preset risks in the blockchain. Through controlled environment simulation and programmatic operation, 100% accurate labeling of resource access address associations is achieved, providing a noise-free training foundation for the risk identification model. In addition, in terms of data scale and efficiency, a containerized parallel scheduling architecture is adopted to meet the model's need for large-scale samples, thereby accurately displaying coin mixing transaction scenarios, providing reliable labeled data, and improving the performance of risk identification models such as illegal financial activities in blockchain coin mixing services.
[0118] Furthermore, based on the above Figures 1 to 10 This specification also provides a storage medium for storing computer-executable instruction information in one or more embodiments. In one specific embodiment, the storage medium may be a USB flash drive, optical disc, hard disk, etc. When the computer-executable instruction information stored in the storage medium is executed by a processor, it can realize the following process: Based on the information from the target public blockchain, construct a private test chain identical to the target public blockchain; A trading strategy is generated based on the risk behaviors corresponding to the preset risks in the target public chain; Based on the transaction strategy, a preset transaction process is executed on the private test chain, and transaction behavior data containing upstream and downstream resource link information generated by the preset transaction process executed on the private test chain is obtained. Based on the acquired transaction behavior data containing upstream and downstream resource link information, the acquired transaction behavior data containing upstream and downstream resource link information is expanded through preset expansion rules to obtain a transaction behavior dataset targeting preset risks in the blockchain.
[0119] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the above-described storage medium embodiment is basically similar to the method embodiment, so the description is relatively simple; relevant parts can be referred to the description of the method embodiment.
[0120] This specification provides a storage medium that constructs a private test chain identical to the target public chain based on information from the target public chain. Then, a trading strategy targeting a preset risk can be generated based on the risk behaviors corresponding to preset risks in the target public chain. Subsequently, based on the trading strategy, preset transaction processing can be executed on the private test chain, and transaction behavior data containing upstream and downstream resource link information generated by executing the preset transaction processing on the private test chain can be obtained. Finally, based on the obtained transaction behavior data containing upstream and downstream resource link information, data expansion processing can be performed on the obtained transaction behavior data containing upstream and downstream resource link information through preset expansion rules to obtain a transaction behavior dataset targeting preset risks in the blockchain. Through controlled environment simulation and programmatic operation, 100% accurate labeling of resource access address relationships is achieved, providing a noise-free training foundation for the risk identification model. Furthermore, in terms of data scale and efficiency, a containerized parallel scheduling architecture is adopted to meet the model's need for large-scale samples, thereby accurately displaying coin mixing transaction scenarios, providing reliable labeled data, and improving the performance of risk identification models for illegal financial activities in blockchain coin mixing services.
[0121] Furthermore, based on the above Figures 1 to 10 This specification also provides one or more embodiments of a computer program product, including a computer program, which, when executed by a processor, can perform the following processes: Based on the information from the target public blockchain, construct a private test chain identical to the target public blockchain; A trading strategy is generated based on the risk behaviors corresponding to the preset risks in the target public chain; Based on the transaction strategy, a preset transaction process is executed on the private test chain, and transaction behavior data containing upstream and downstream resource link information generated by the preset transaction process executed on the private test chain is obtained. Based on the acquired transaction behavior data containing upstream and downstream resource link information, the acquired transaction behavior data containing upstream and downstream resource link information is expanded through preset expansion rules to obtain a transaction behavior dataset targeting preset risks in the blockchain.
[0122] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the above-described embodiment of a computer program product is relatively simple in description because it is fundamentally similar to the method embodiment; relevant parts can be referred to the description of the method embodiment.
[0123] This specification provides a computer program product that constructs a private test chain identical to the target public chain based on information from the target public chain. Then, it generates a trading strategy targeting a preset risk based on the risk behaviors corresponding to preset risks in the target public chain. Following this, it executes preset transaction processing on the private test chain based on the trading strategy, acquiring transaction behavior data containing upstream and downstream resource link information generated during the execution of the preset transaction processing on the private test chain. Finally, based on the acquired transaction behavior data containing upstream and downstream resource link information, it performs data expansion processing through preset expansion rules to obtain a transaction behavior dataset targeting preset risks in the blockchain. Through controlled environment simulation and programmatic operation, it achieves 100% accurate labeling of resource access address relationships, providing a noise-free training foundation for the risk identification model. Furthermore, in terms of data scale and efficiency, it adopts a containerized parallel scheduling architecture, meeting the model's need for large-scale samples, thereby accurately displaying coin mixing transaction scenarios, providing reliable labeled data, and improving the performance of risk identification models for illegal financial activities in blockchain coin mixing services.
[0124] The foregoing has described specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps described in the claims may be performed in a different order than those shown in the embodiments and still achieve the desired results. Furthermore, the processes depicted in the drawings do not necessarily require a specific or sequential order to achieve the desired results. In some embodiments, multitasking and parallel processing are possible or may be advantageous. Moreover, although one or more embodiments of this specification provide method steps as described in the embodiments or flowcharts, it is understood that the order of steps listed in the embodiments or flowcharts is merely one possible execution order among many steps and does not represent the only execution order. Therefore, when method steps are involved in the claims, adjustments to the order of those steps, or parallelism between steps, are also within the scope of protection of the claims.
[0125] In the 1990s, improvements to a technology could be clearly distinguished as either hardware improvements (e.g., improvements to the circuit structure of diodes, transistors, switches, etc.) or software improvements (improvements to the methodology). However, with technological advancements, many methodological improvements today can be considered direct improvements to the hardware circuit structure. Designers almost always obtain the corresponding hardware circuit structure by programming the improved methodology into the hardware circuit. Therefore, it cannot be said that a methodological improvement cannot be implemented using hardware physical modules. For example, a Programmable Logic Device (PLD) (such as a Field Programmable Gate Array (FPGA)) is such an integrated circuit whose logic function is determined by the user programming the device. Designers can program and "integrate" a digital system onto a PLD themselves, without needing chip manufacturers to design and manufacture dedicated integrated circuit chips. Furthermore, nowadays, instead of manually manufacturing integrated circuit chips, this programming is mostly implemented using "logic compiler" software. Similar to the software compiler used in program development, the original code before compilation must also be written in a specific programming language, called a Hardware Description Language (HDL). There are many HDLs, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, and RHDL (Ruby Hardware Description Language). Currently, the most commonly used are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should also understand that by simply performing some logic programming on the method flow using one of these hardware description languages and programming it into an integrated circuit, the hardware circuit implementing the logical method flow can be easily obtained.
[0126] The controller can be implemented in any suitable manner. For example, it can take the form of a microprocessor or processor and a computer-readable medium storing computer-readable program code (e.g., software or firmware) executable by the (micro)processor, logic gates, switches, application-specific integrated circuits (ASICs), programmable logic controllers, and embedded microcontrollers. Examples of controllers include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicon Labs C8051F320. A memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art will also recognize that, in addition to implementing the controller in purely computer-readable program code form, the same functionality can be achieved by logically programming the method steps to make the controller take the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, and embedded microcontrollers. Therefore, such a controller can be considered a hardware component, and the means included therein for implementing various functions can also be considered as structures within the hardware component. Alternatively, the means for implementing various functions can be considered as both software modules implementing the method and structures within the hardware component.
[0127] The systems, devices, modules, or units described in the above embodiments can be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, a computer can be, for example, a personal computer, laptop computer, cellular phone, camera phone, smartphone, personal digital assistant, media player, navigation device, email device, game console, tablet computer, wearable device, or any combination of these devices.
[0128] For ease of description, the above apparatus is described by dividing it into various functional units. Of course, when implementing one or more embodiments of this specification, the functions of each unit can be implemented in one or more software and / or hardware.
[0129] Those skilled in the art will understand that the embodiments of this specification can be provided as methods, systems, or computer program products. Therefore, one or more embodiments of this specification may take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, one or more embodiments of this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0130] The embodiments described herein are illustrated with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this specification. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable device to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable device, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0131] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0132] These computer program instructions may also be loaded onto a computer or other programmable device to cause a series of operational steps to be performed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable device for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0133] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0134] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.
[0135] Computer-readable media include both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.
[0136] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical or equivalent elements in the process, method, article, or apparatus that includes said element. Furthermore, "a," "an," and "the" are not specifically singular and may include plural forms. Ordinal numbers such as "first," "second," etc., do not necessarily indicate order; they are often used to distinguish objects. For example, "first server" and "second server" usually refer to two servers, described as "first server" and "second server" to differentiate them; however, sometimes these two servers may be the same server. Moreover, in this specification, unless explicitly stated otherwise, "receiving and sending data" does not necessarily mean direct receiving and sending; it can be indirect receiving and sending (i.e., receiving and sending indirectly through one or more entities). Similarly, in this specification, unless otherwise stated, the relationships between structures can be direct or indirect.
[0137] Furthermore, the specific terms used in this specification to describe embodiments, such as "an embodiment," "one embodiment," or "some embodiments," refer to a particular feature, structure, or characteristic related to at least one embodiment of this specification. Therefore, it should be emphasized and noted that "an embodiment," "one embodiment," or "an alternative embodiment" mentioned twice or more in different locations in this specification do not necessarily refer to the same embodiment. Moreover, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of those different embodiments or examples, without contradiction.
[0138] Those skilled in the art will understand that the embodiments of this specification can be provided as methods, systems, or computer program products. Therefore, one or more embodiments of this specification may take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, one or more embodiments of this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0139] One or more embodiments of this specification can be described in the general context of computer-executable instructions, such as program modules, that are executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform a specific task or implement a specific abstract data type. One or more embodiments of this specification can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.
[0140] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to interchangeably. Each embodiment focuses on describing the differences from other embodiments. In particular, the system embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments.
[0141] The above description is merely an embodiment of this specification and is not intended to limit this document. Various modifications and variations can be made to this specification by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this specification should be included within the scope of the claims in this document.
Claims
1. A method for processing blockchain data, the method comprising: Based on the information from the target public blockchain, construct a private test chain identical to the target public blockchain; A trading strategy is generated based on the risk behaviors corresponding to the preset risks in the target public chain; Based on the transaction strategy, a preset transaction process is executed on the private test chain, and transaction behavior data containing upstream and downstream resource link information generated by the preset transaction process executed on the private test chain is obtained. Based on the acquired transaction behavior data containing upstream and downstream resource link information, the acquired transaction behavior data containing upstream and downstream resource link information is expanded through preset expansion rules to obtain a transaction behavior dataset targeting preset risks in the blockchain.
2. The method according to claim 1, wherein constructing a private test chain identical to the target public chain based on the information of the target public chain includes: Create a forked chain on the target public chain and replicate the information of the target public chain at a preset block height. The replicated information includes one or more of the following: deployed smart contracts, the amount of remaining resources in the account, and historical transaction data. Based on the replicated information, the created forked chain is configured to obtain an initial private test chain that is identical to and controllable with the target public chain. Test resources are distributed to each preset simulated account in the initial private test chain, and the network parameters of the initial private test chain are configured to match the corresponding network with the actual network, thus obtaining a private test chain identical to the target public chain.
3. The method according to claim 1, wherein generating a trading strategy for the preset risk based on the risk behavior corresponding to the preset risk in the target public chain includes: Based on the risk behaviors corresponding to the preset risks in the target public chain, the transaction processing rules required for the preset transaction processing to be executed are determined. The transaction processing rules include one or more of the following: resource splitting rules, resource extraction timing rules, relay selection rules, and gas price selection rules. The resource splitting rules are used to split the resources to be stored into multiple resources that meet the fixed resource quantity in the mixing pool. The resource extraction timing rules are used to extract resources according to the preset timing rules. The gas price selection rules are used to select the gas price according to the network conditions. Based on the established transaction processing rules, a transaction strategy is generated to address the preset risks.
4. The method according to claim 3, wherein the transaction processing rules include Gas price selection rules, and the step of generating a trading strategy for the preset risk based on the determined transaction processing rules includes: Based on the risk behaviors corresponding to the preset risks in the target public chain, the transaction confirmation mode corresponding to the preset transaction processing to be executed is determined through the preset Gas price fluctuation model. The transaction confirmation mode includes fast confirmation mode and delayed confirmation mode. Based on the transaction confirmation mode and the preset data recording rules, a transaction strategy is generated for the preset risk. The data recording rules are used to record one or more of the following: gas price information, gas usage, and transaction confirmation time.
5. The method according to claim 1, further comprising: Obtain resource access address pairs that have undergone coin mixing transactions from the pre-defined coin theft security report; The step of executing a preset transaction process on the private test chain based on the transaction strategy, and obtaining transaction behavior data containing upstream and downstream resource link information generated by the preset transaction process on the private test chain, includes: Based on the transaction strategy, a preset transaction process is executed on the private test chain, and based on the resource access address pair, a blockchain crawler is invoked to crawl the upstream and downstream resource link information generated by the preset transaction process executed on the private test chain. The upstream and downstream resource link information includes one or more of the following: resource source, information of associated interactive smart contracts, resource destination, transaction frequency, and resource dismantling method. The transaction behavior data is determined based on the upstream and downstream resource link information.
6. The method according to claim 5, wherein determining the transaction behavior data based on the upstream and downstream resource link information includes: Based on the upstream and downstream resource link information, a resource flow graph is constructed. The resource flow graph includes nodes and edges. The nodes are constructed by resource extraction addresses, resource storage addresses, or smart contracts. The edges indicate that there is a transaction between two nodes. The edges also include attribute information, which includes one or more of the following: resource quantity, timestamp, and transaction type. The transaction behavior data is determined based on the resource flow graph.
7. The method according to claim 1 or 6, wherein the step of performing data expansion processing on the acquired transaction behavior data containing upstream and downstream resource link information through preset expansion rules to obtain a transaction behavior dataset targeting preset risks in the blockchain includes: The transaction behavior data is described with text to obtain the description text corresponding to the transaction behavior data; Based on the descriptive text corresponding to the transaction behavior data, corresponding prompt information is generated. The prompt information and the descriptive text corresponding to the transaction behavior data are input into the large language model. The prompt information guides the large language model to perform data expansion processing on the transaction behavior data to obtain expanded transaction behavior data. Based on the transaction behavior data and the extended transaction behavior data, a transaction behavior dataset targeting preset risks in the blockchain is constructed.
8. The method according to claim 1 or 6, wherein the transaction behavior data containing upstream and downstream resource link information is expanded using preset expansion rules to obtain a transaction behavior dataset targeting preset risks in the blockchain, comprising: Based on the acquired transaction behavior data containing upstream and downstream resource link information, target transaction behavior data is obtained from the target public chain; Based on the acquired transaction behavior data containing upstream and downstream resource link information and the target transaction behavior data, a transaction behavior dataset targeting preset risks in the blockchain is constructed.
9. A blockchain data processing apparatus, the apparatus comprising: The private chain creation module constructs a private test chain identical to the target public chain based on the information of the target public chain. The transaction strategy generation module generates a transaction strategy for the preset risk based on the risk behaviors corresponding to the preset risk in the target public chain. The transaction execution module, based on the transaction strategy, executes a preset transaction process on the private test chain and obtains transaction behavior data containing upstream and downstream resource link information generated by the execution of the preset transaction process on the private test chain. The data acquisition module, based on the acquired transaction behavior data containing upstream and downstream resource link information, performs data expansion processing on the acquired transaction behavior data containing upstream and downstream resource link information through preset expansion rules, to obtain a transaction behavior dataset targeting preset risks in the blockchain.
10. A blockchain data processing device, the blockchain data processing device comprising: processor; as well as A memory configured to store computer-executable instructions, which, when executed, cause the processor to: Based on the information from the target public blockchain, construct a private test chain identical to the target public blockchain; A trading strategy is generated based on the risk behaviors corresponding to the preset risks in the target public chain; Based on the transaction strategy, a preset transaction process is executed on the private test chain, and transaction behavior data containing upstream and downstream resource link information generated by the preset transaction process executed on the private test chain is obtained. Based on the acquired transaction behavior data containing upstream and downstream resource link information, the acquired transaction behavior data containing upstream and downstream resource link information is expanded through preset expansion rules to obtain a transaction behavior dataset targeting preset risks in the blockchain.