A privacy-preserving decentralized graph learning-based cryptocurrency fraud detection method and system

CN122694445APending Publication Date: 2026-09-04DONGHUA UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610761007.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-05-29
Publication Date
2026-09-04

AI Technical Summary

Technical Problem

[0009]本发明旨在解决现有中心化建模隐私泄露、联邦图学习中间信息泄密、模型聚合单点故障、通信时延高、模型时效性滞后的技术问题,在全程不泄露用户原始交易数据与中间计算信息的前提下,实现海量分布式节点的高效协同建模与高精度加密货币欺诈检测

Benefits of technology

[0044]Through the above-mentioned complete technical solution, this invention realizes an integrated privacy and security risk control system that includes source data protection, end-to-end encrypted computation, efficient model aggregation, and high-precision intelligent detection. It effectively solves various defects in existing technologies and adapts to scenarios of collaborative modeling with massive distributed nodes under the premise of zero original data and zero intermediate plaintext leakage, significantly improving the accuracy, efficiency, and privacy and security level of cryptocurrency fraud detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure FT_1
    Figure FT_1
  • Figure FT_2
    Figure FT_2
  • Figure FT_3
    Figure FT_3
Patent Text Reader

Abstract

The application provides a privacy protection decentralized graph learning cryptocurrency fraud detection method, comprising the following steps: first, constructing a decentralized transaction subgraph based on local transaction records; second, designing a homomorphic encryption and secure aggregation mechanism, constructing a privacy protection forward and backward propagation process, and completing node representation learning without leaking gradient and feature information; then, designing an adaptive node division strategy according to node computing power, realizing decentralized multi-layer model parallel aggregation; finally, training a fraud detection model using the learned node features to realize cryptocurrency transaction fraud identification. This method does not need to collect original transaction data centrally, can effectively defend against de-anonymization, attribute inference and graph reconstruction attacks, solves the problems of privacy leakage in traditional centralized modeling, information leakage in federated graph learning, single point failure and long communication delay in model aggregation, realizes privacy protection while ensuring fraud detection performance, and meets the deployment requirements of large-scale distributed nodes.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a privacy-preserving decentralized graph learning-based cryptocurrency fraud detection method and system, belonging to the fields of blockchain technology, cryptocurrency risk control, privacy-preserving federated learning, and graph neural network intelligent detection technology. Background Technology

[0002] With the rapid iteration of blockchain technology, cryptocurrencies have gained widespread application due to their decentralized, anonymized, and cross-border circulation characteristics. However, they have also become a significant vehicle for fraudulent activities such as money laundering, illicit fund transfers, and dark web transactions. Cryptocurrency transactions abandon the traditional centralized financial regulatory model; transaction data exists in a dynamic topological network of "user address-transaction behavior-user address," exhibiting complex, transnational, and covert characteristics that pose significant challenges to financial risk control and compliance supervision.

[0003] Current mainstream cryptocurrency fraud detection methods can be categorized into four types: traditional statistical modeling methods, machine learning tabular modeling methods, centralized graph neural network detection methods, and federated graph learning distributed detection methods. Each method has inherent technical limitations and cannot be adapted to large-scale, high-privacy cryptocurrency regulatory scenarios. Specific limitations are as follows:

[0004] 1. Traditional modeling methods have poor adaptability. Traditional tabular data models such as logistic regression and boosting trees can only process structured transaction data and cannot capture fraud features such as "multiple inflows and single outflows for money laundering" and "cross-chain time-series transfers" in cryptocurrency transactions. The fraud detection accuracy is extremely low and it is difficult to meet the risk control needs of complex transaction scenarios.

[0005] 2. Centralized graph learning modeling poses high privacy risks. Existing graph neural network detection solutions rely on regulatory agencies to centrally collect raw transaction data from all users across the network, requiring the aggregation of sensitive information such as all user addresses, transaction amounts, and transaction times. On the one hand, cryptocurrency anonymization mechanisms make the collection of raw, compliant data extremely difficult; on the other hand, centralized data storage and modeling are highly susceptible to large-scale user privacy leaks, making them vulnerable to deanonymization attacks by attackers to uncover users' true identities and transaction behaviors.

[0006] 3. Federated graph learning suffers from intermediate information leakage vulnerabilities. To address privacy issues in centralized modeling, existing federated graph learning employs a distributed collaborative training model, where users retain their original data locally and only collaboratively complete model training. However, during the forward propagation representation extraction and backward gradient update processes, frequent interaction is required to exchange intermediate information such as node features, model gradients, and attention parameters. Attackers can use attribute inference attacks and graph structure reconstruction attacks to infer users' original transaction records based on the leaked intermediate information, resulting in significant weaknesses in privacy and security protection.

[0007] 4. Performance bottlenecks exist in model aggregation mechanisms. Traditional federated learning uses a centralized model aggregation method, which suffers from serious single points of failure and communication bottlenecks; asynchronous aggregation methods are prone to delays in the timeliness of local models, resulting in significant deviations in the global model after aggregation; fixed-layer federated learning architectures cannot adapt to the massive, heterogeneous, and dynamically changing node computing power and communication resources of cryptocurrency networks, leading to high model aggregation latency, slow convergence speed, and a significant decrease in detection performance under large-scale node deployment.

[0008] In summary, existing technologies cannot simultaneously meet the four core requirements of protecting the privacy of raw data, ensuring secure interaction of intermediate information, efficiently aggregating large-scale nodes, and detecting fraud with high precision. They suffer from technical pain points such as the inability to balance privacy and security with detection performance and poor adaptability to large-scale deployment. There is an urgent need to design a privacy and security fraud detection solution that is suitable for decentralized cryptocurrency scenarios. Summary of the Invention

[0009] This invention aims to solve the technical problems of privacy leakage in existing centralized modeling, leakage of intermediate information in federated graph learning, single point of failure in model aggregation, high communication latency, and lagging model timeliness. Under the premise of not leaking users' original transaction data and intermediate computing information throughout the process, it achieves efficient collaborative modeling of massive distributed nodes and high-precision cryptocurrency fraud detection.

[0010] To address the aforementioned technical problems, the first aspect of the present invention discloses a privacy-preserving decentralized graph learning-based cryptocurrency fraud detection method, characterized by comprising: Collect raw cryptocurrency transaction data from the entire network to construct a global transaction topology map, in which each cryptocurrency user corresponds to an independent central node. ; Each cryptocurrency user node constructs a decentralized transaction subgraph containing only itself and its single-hop neighbor nodes, relying solely on the raw transaction data stored locally. We construct an AM homomorphic addition and multiplication operation mechanism, an SA secure aggregation mechanism, and a HESA homomorphic encryption and secure aggregation composite mechanism to adapt to different distributed computing scenarios based on decentralized transaction subgraphs and achieve full-scenario encrypted secure operation. Construct a privacy-preserving federated graph learning forward-backward propagation process to complete the extraction of node feature representations and reverse update of model gradients in a encrypted state for decentralized transaction subgraphs; Based on the real-time computing and communication capabilities of participating nodes, an adaptive node partitioning strategy is adopted to construct a decentralized multi-layer model aggregation framework, which performs local model aggregation in a layered and parallel manner to obtain a global node feature representation module. Regulatory agencies train a cryptocurrency transaction fraud detection model based on the node features output by the global node feature representation module to identify transaction fraud.

[0011] Preferably, the unique user address of the cryptocurrency is used as the network node, and the transaction behavior is represented as a network edge with timestamps and transaction amount weights. Multiple transaction edges between the same node are merged to simplify the network topology and construct the global transaction topology graph. ,in, For a set of nodes, For a set of edges, equipped with a node type mapping function ,node With nodes The feature vector of the edge is represented as This includes statistical indicators such as transaction frequency and average transaction amount; In the decentralized transaction subgraph, each node only retains its own data and that of its single-hop neighbors locally. The original features and transaction information of the neighbors are not visible to the outside world. Each local node generates its own dimension based on its transaction records. Node features .

[0012] Preferably, the SA secure aggregation mechanism satisfies the formula:

[0013] in: For the first Local model data for each node It is a pseudo-random number generator. For nodes With nodes Shared keys between them; Each node encrypts and exchanges masked data, which is then aggregated locally to obtain a global model, achieving secure aggregation without plaintext leakage.

[0014] Preferably, the AM homomorphic multiplication mechanism is used for encrypted dot product aggregation operations between local vectors and neighboring vectors.

[0015] Preferably, the HESA homomorphic encryption and secure aggregation composite mechanism is used for composite ciphertext operations of scalars and multi-neighbor vectors, satisfying the formula:

[0016]

[0017] in: For local scalars, For the first neighbor vectors, This is a homomorphic multiplication operation. This is a homomorphic addition operation. This represents the ciphertext after homomorphic encryption.

[0018] Preferably, during the model forward propagation phase, the node feature extraction is completed, specifically including the following steps: Each node calculates initial features using a multilayer perceptron. :

[0019] in, For nodes The original transaction characteristics include basic information such as transaction frequency and transaction amount. The initial high-dimensional node features after MLP mapping; The self-attention module maps the feature matrix and constructs the feature association relationship between nodes and their neighbors:

[0020]

[0021]

[0022] in, , , These are learnable parameters for the self-attention mechanism. For nodes The initial feature set of all corresponding neighbor nodes, , , These are the local query matrix, the neighborhood key matrix, and the neighborhood value matrix, respectively. Calculate the importance weight of neighbors:

[0023] in, For local decryption operators, The dimension of the feature matrix is... For the first The feature association attention weights of each neighboring node The query vector is obtained by linearly transforming the query matrix into the feature representation of the target node. The key vector is obtained by mapping the features of the j-th neighbor node through the key matrix; Calculate the edge attention score:

[0024] in, For learnable parameters, This is the set of neighborhood transaction edges corresponding to the local node. Topological association attention score; Multi-head attention aggregation and node representation output:

[0025]

[0026]

[0027]

[0028] in, To normalize the overall attention weights, This is a single-head attention aggregation feature. This is the result of multi-head feature fusion. For the final privacy protection node characteristics, Let be the set of neighboring nodes of node i. The number of attention heads in a multi-head attention mechanism; The final output is a privacy-preserving node feature representation. .

[0029] Preferably, during the model backpropagation training phase, the model gradient is updated backward, specifically including the following steps: Define the formula for updating the parameters of the fraud detection model:

[0030] in, For model parameters, For training rounds, For learning rate, The loss function; Based on the AM homomorphic addition-multiplication mechanism, the SA secure aggregation mechanism, and the HESA homomorphic encryption and secure aggregation composite mechanism, gradients are securely solved respectively:

[0031]

[0032]

[0033]

[0034] in, for , representing the number of neighboring nodes of node i; The entire interaction is encrypted, without revealing the gradient and feature plaintext.

[0035] Preferably, an adaptive node partitioning strategy is used to construct a decentralized two-layer model aggregation framework, which performs local model aggregation in a layered and parallel manner to obtain a global node feature representation module, including: Calculate the model update time for each participating node. Model upload time ; An optimization model is established with the objective of minimizing the total aggregation latency of the model:

[0036] in, The number of head nodes, For model update time, The time taken to upload the model For the first Small clusters The number of nodes included. To define the number of aggregation layers in a decentralized multi-layered model aggregation framework. The total number of nodes participating in the aggregation; The optimal number of head nodes is determined based on the optimization model described above.

[0037] in, For mathematical expectation; Before selection A high-performance node is used as the head node, and the remaining nodes are divided into multiple sub-clusters by corresponding head nodes. Each head node completes the model aggregation within its sub-cluster. Each head node uses a decentralized communication method to complete the second-layer model aggregation and obtain the global node feature representation.

[0038] Preferably, the construction of the decentralized multi-layer model aggregation framework specifically includes the following steps: Initial cluster partitioning: based on the optimal number of head nodes obtained from the solution. The set of all participating nodes Divide equally into Basic sub-clusters The formula for satisfying the cluster node number balance constraint is:

[0039] The node with the shortest model update time and the lowest communication latency within each sub-cluster is selected as the cluster head node. Responsible for the cluster model aggregation task at this level; Sub-cluster recursive layering: for each basic sub-cluster The recursive hierarchical partitioning strategy is executed, and the recursion terminates when the number of sub-cluster nodes is reached. , For recursive levels; Define the hierarchy depth Adaptive calculation formula:

[0040] By adaptively partitioning the hierarchy, a multi-level nested decentralized parallel aggregation architecture is constructed to adapt to the computing power and communication differences of massive heterogeneous nodes. Hierarchical parallel model aggregation: Each level's head node independently performs local model parameter aggregation within the cluster. The aggregation formula for a single-level cluster is:

[0041] in, These are the model parameters trained locally on ordinary nodes. These are the parameters of the hierarchical model after aggregation from a single cluster; Iterates and aggregates layer by layer from the bottom to the top, ultimately outputting the global aggregation model parameters. ; Global model multicast distribution: The top-level head node cluster adopts a multicast concurrent push mechanism to distribute global node feature modules and global model parameters. The model is distributed synchronously to all participating nodes, and the model distribution latency meets the following requirements:

[0042] in, This represents the total time consumed in multi-layer polymerization. Multicast distribution takes time; By adopting a multi-layer parallel aggregation + global multicast distribution architecture, the single point of failure problem of centralized aggregation is completely eliminated, the lag problem of lagging nodes in distributed training is effectively alleviated, and the overall model aggregation latency is significantly reduced.

[0043] The second aspect of the technical solution of this invention discloses a privacy-preserving decentralized graph learning-based cryptocurrency fraud detection system, characterized in that it includes: The subgraph construction module is used to collect cryptocurrency transaction data and build a global transaction graph and local decentralized transaction subgraphs for each node. The privacy representation learning module integrates three privacy-preserving computational units: AM, SA, and HESA. It performs self-attention forward propagation of the Transformer model and extracts node features from the ciphertext. The privacy backpropagation module is used to solve various gradients of the model in an encrypted state and complete local parameter iterative updates. The multi-layer model aggregation module is used to adaptively partition node clusters, build a decentralized two-layer / multi-layer aggregation framework, and aggregate in parallel to obtain the global node feature module; The fraud detection and defense module is used to train a fraud detection model to defend against three types of privacy attacks and identify transaction fraud.

[0044] Through the above-mentioned complete technical solution, this invention realizes an integrated privacy and security risk control system that includes source data protection, end-to-end encrypted computation, efficient model aggregation, and high-precision intelligent detection. It effectively solves various defects in existing technologies and adapts to scenarios of collaborative modeling with massive distributed nodes under the premise of zero original data and zero intermediate plaintext leakage, significantly improving the accuracy, efficiency, and privacy and security level of cryptocurrency fraud detection. Attached Figure Description

[0045] Figure 1 The diagram shows a flowchart of a privacy-preserving decentralized graph learning cryptocurrency fraud detection method disclosed in one embodiment of the present invention. Figure 2 The diagram shown is a schematic diagram of the cryptocurrency transaction graph construction process according to an embodiment of the present invention, wherein (a) illustrates cryptocurrency transaction data, (b) illustrates the transaction network, and (c) illustrates the transaction graph; Figure 3 The diagram shows a process for constructing a decentralized subgraph based on distributed transaction data according to an embodiment of the present invention, wherein (a) illustrates a transaction graph and (b) illustrates a decentralized transaction graph. Figure 4 The diagram shown is a schematic diagram of the DECRAFT framework node feature representation learning and model training architecture according to an embodiment of the present invention. Figure 5 The diagram shows a decentralized two-layer model aggregation framework based on adaptive node partitioning, according to an embodiment of the present invention. Figure 6 The diagram shows a decentralized multi-layer model aggregation framework based on adaptive node partitioning, as described in an embodiment of the present invention. Figure 7 The diagram shows the principle structure of the privacy-preserving decentralized graph learning cryptocurrency fraud detection system of this invention. Detailed Implementation

[0046] The present invention will be further illustrated below with reference to specific embodiments. It should be understood that these embodiments are for illustrative purposes only and are not intended to limit the scope of the invention. Furthermore, it should be understood that after reading the teachings of this invention, those skilled in the art can make various alterations or modifications to the invention, and these equivalent forms also fall within the scope defined by the appended claims.

[0047] The following specific examples illustrate the implementation of the present invention. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. The present invention can also be implemented or applied through other different specific embodiments, and various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present invention. It should be noted that, unless otherwise specified, the following embodiments and features described therein can be combined with each other.

[0048] It should be noted that the illustrations provided in the following embodiments are only schematic representations of the basic concept of the present invention. Therefore, the drawings only show the components related to the present invention and are not drawn according to the actual number, shape and size of the components in the actual implementation. In the actual implementation, the shape, quantity and proportion of each component can be arbitrarily changed, and the layout of the components may also be more complex.

[0049] Figure 1 This is a schematic diagram of a transaction scenario for a privacy-preserving decentralized graph learning cryptocurrency fraud detection system according to the present invention. Figure 1 As shown, in one embodiment of the present invention, the designed DECRAFT privacy-preserving graph learning algorithm is distributed across all user nodes and the regulatory server. Each cryptocurrency user node retains original transaction data using local storage capabilities and possesses the ability to construct local transaction subgraphs and calculate privacy features. User nodes can securely upload local privacy features and exchange encrypted neighborhood information through encrypted interaction channels. After the regulatory server aggregates the compliant privacy feature data across the entire network, it learns an approximately optimal fraud detection strategy adapted to the distributed transaction scenario through decentralized graph learning training. Since cryptocurrency trading networks are dynamic, open, and distributed networks, user nodes exhibit characteristics such as random online / offline activity, real-time changes in transaction behavior, and dynamic fluctuations in node computing power. The designed privacy-preserving graph learning and model aggregation algorithm must be executed within a defined training time window. An excessively large time window cannot meet the real-time requirements of cryptocurrency real-time fraud risk control, while a time window that is too small cannot guarantee sufficient learning of graph model features and stable model convergence. This figure fully illustrates the entire process from original transaction data and transaction network construction to standardized transaction graph construction, providing basic scenario support for subsequent decentralized privacy modeling and fraud detection algorithm operation.

[0050] Figure 2 The schematic diagram of the entire process of standardizing cryptocurrency transaction graphs is the basic modeling step for fraud feature mining in this invention. It is divided into three core implementation stages: collection of original transaction records, construction of the initial transaction network, and aggregation of standardized transaction graphs. Based on graph structure data, it accurately depicts the topological fraud features of cryptocurrency user fund flows.

[0051] First, raw cryptocurrency transaction records from across the entire network are collected. This raw data includes core fields such as the user addresses of both parties, transaction amount, transaction timestamp, and transaction frequency. Based on this collected data, an initial transaction network is constructed. The network topology follows the core association logic of "user address - transaction behavior - user address," defining the basic unit of the initial transaction network as follows: each node uniquely corresponds to a cryptocurrency user, and the set of nodes is denoted as […]. A directed edge between nodes corresponds to a single transaction, and the set of edges is denoted as . Each original transaction edge carries basic attributes such as transaction amount and timestamp.

[0052] Secondly, to address the redundancy issue of multiple scattered transactions between a single user node, transaction edge aggregation optimization is performed. This merges multiple original transaction edges between the same group of bidirectional transaction nodes into a single aggregated transaction edge, and a statistical feature vector is configured for the aggregated edge. The feature vector includes multi-dimensional statistical indicators such as transaction frequency, average transaction amount, and transaction time distribution, ultimately completing the construction of a standardized transaction graph. The overall formal definition of the transaction graph is as follows: At the same time, configure the node type mapping function. ,in This is a set of node types used to distinguish the node attributes of legitimate users from those of fraudulent users.

[0053] This modeling approach can accurately capture complex fraud topology features that traditional machine learning models cannot identify, including "multiple inflows and one outflows" money laundering fund aggregation patterns and cross-chain short-term high-frequency transfer association patterns, providing standardized and structured data support for subsequent graph neural network feature learning.

[0054] like Figure 3 As shown, this invention provides a method for constructing a decentralized subgraph based on distributed transaction data, including the following steps: Figure 3 This diagram illustrates the process of constructing a decentralized subgraph based on distributed transaction data. It represents the core pre-design of this invention, adapting to the decentralized nature of blockchain and ensuring the privacy of original data. Since cryptocurrency users generally employ anonymity and privacy protection mechanisms, original transaction data is stored only on the user's local device and cannot be centrally collected by regulatory agencies. Traditional global transaction graph modeling schemes are completely ineffective; therefore, this invention adopts a distributed local subgraph modeling paradigm.

[0055] In practice, each cryptocurrency user corresponds to an independent central node. Each central node A dedicated decentralized local subgraph is constructed using only locally stored raw transaction data. The subgraph construction rule is as follows: a local node is at the core, and only its one-hop direct transaction neighbor nodes are associated, forming a local topology structure of "central node + neighboring nodes," strictly avoiding cross-node raw data collection. Each local node generates its own dimension based on its transaction records. Node features At the same time, it retains the statistical characteristics of the aggregated transaction edges between nodes, hides the original characteristic information of all neighboring nodes, and ensures that the original transaction data does not leave the local machine at all.

[0056] Based on this decentralized subgraph architecture, this invention systematically avoids three types of core privacy and security threats. The corresponding attack principles and protection logic are as follows: First, deanonymization attacks: This invention does not perform global transaction data aggregation operations, so attackers cannot deduce the user's real identity through address clustering and entity mapping. Second, attribute reasoning attacks: Subsequent model training uses encrypted operations throughout, without plaintext gradients or feature interactions, so attackers cannot optimize and deduce the original transaction information through virtual input. Third, graph structure reconstruction attacks: The subgraph only retains local topology and has no global graph structure data, so attackers cannot achieve complete transaction graph topology reconstruction.

[0057] Meanwhile, this invention introduces a secure aggregation (SA) mechanism to achieve low-cost privacy protection, and the single-node local data encryption formula is as follows:

[0058] in, For the first Local model data for each node, It is a pseudo-random number generator. For nodes With nodes The shared key is used by each node to encrypt local data using this formula before exchanging data, thus avoiding the risk of plaintext data leakage at the source.

[0059] like Figure 4 As shown, the DECRAFT framework node feature representation learning and model training architecture method of this invention includes the following steps: S1: Design three exclusive privacy-preserving computation methods to adapt to different distributed computing scenarios and achieve encrypted secure computation in all scenarios; S2: In the forward propagation stage of the model, the privacy features of cryptocurrency nodes are extracted and fused, with no plaintext feature interaction throughout the process, accurately mining fraud-related features of nodes; S3: During the model backpropagation training phase, to address the security risk that gradient parameters are vulnerable to attackers inferring the original data, differentiated encryption protection is implemented for different types of gradient parameters.

[0060] This invention proposes a privacy-preserving graph learning training method that addresses privacy leak vulnerabilities in traditional federated graph learning models across multiple scenarios, including vector interaction, feature aggregation, and gradient transmission. It designs three differentiated encryption mechanisms (AM, SA, and HESA) to cover the entire graph learning computation process. By completing node feature mapping, attention weight calculation, neighborhood feature fusion, and gradient iterative updates in encrypted form, the method ensures that original transaction data, intermediate features, and gradient parameters remain locally and are never exposed in plaintext. Compared to traditional federated graph learning methods that only offer single privacy protection, this invention constructs a comprehensive, differentiated privacy and security protection system. It can completely resist deanonymization attacks, attribute inference attacks, and graph structure reconstruction attacks without sacrificing cryptocurrency fraud detection accuracy. It is adaptable to large-scale training scenarios with massive distributed nodes in blockchain, effectively solving the technical challenge of balancing privacy and security with detection performance in decentralized graph learning modeling.

[0061] Further, step S1 includes: S11: Construct an AM homomorphic addition and multiplication mechanism to adapt to local and neighborhood vector encrypted dot product scenarios. To address the fundamental computational scenario of dot product aggregation between local and neighboring vectors in decentralized graph learning, an AM encryption mechanism based on homomorphic addition and multiplication is established. Relying on the core homomorphic encryption operator, this mechanism enables vector dot product aggregation computation in ciphertext. This mechanism can complete basic feature interaction computations without exposing the plaintext information of local and neighboring node vectors, eliminating the privacy leakage risk caused by plaintext vector interactions at the source, and is suitable for node basic feature association modeling scenarios.

[0062] S12: Construct an SA secure aggregation mechanism to adapt to distributed neighbor feature batch aggregation scenarios. For computational scenarios involving batch aggregation of distributed features from multiple neighboring nodes, a secure aggregation mechanism (SA) is established. This mechanism relies on pseudo-random number masking encryption to uniformly and securely aggregate distributed feature data from multiple nodes. By using shared keys between nodes and a pseudo-random number generation algorithm, a dynamic mask is added to local data to hide the plaintext information of single-point node features. This effectively avoids security risks such as single-point feature leakage and malicious inference of local data, making it suitable for feature aggregation scenarios involving large-scale distributed nodes in blockchain.

[0063] S13: Construct a composite mechanism of HESA homomorphic encryption and secure aggregation to adapt to scalar-vector composite operation scenarios. For high-order composite multiplication aggregation scenarios involving local scalars and multi-neighbor vectors, this paper integrates homomorphic encryption and secure aggregation techniques to construct a HESA composite privacy-preserving computation mechanism. This mechanism enables secure ciphertext computation of complex multidimensional features. The core calculation formula is as follows:

[0064]

[0065] in, For local node scalar parameters, For the first The feature vectors of the neighboring nodes Represents homomorphic multiplication. Represents homomorphic addition. It is a pseudo-random number generator. For nodes With nodes Shared key, This represents the ciphertext after homomorphic encryption.

[0066] This composite mechanism integrates the dual advantages of AM homomorphic operations and SA secure aggregation, enabling precise ciphertext computation in complex scenarios. It overcomes the limitations of single encryption mechanisms in handling high-order feature operations, meeting the privacy and security requirements of high-order aggregation of multi-dimensional features during model training. Three privacy protection mechanisms are layered to adapt to simple, batch, and complex computation scenarios, achieving comprehensive privacy protection across all scenarios, including graph learning forward and backward propagation.

[0067] Further, step S2 includes: S21: High-dimensional mapping of local initial features at each node. Each distributed node relies on a multilayer perceptron (MLP) to perform high-dimensional mapping on the original cryptocurrency transaction features stored locally, generating standardized, high-dimensional initial features for the node. This completes the preprocessing and dimensionality upgrade of the original features. The calculation formula is as follows:

[0068] in, For nodes The original transaction characteristics include basic information such as transaction frequency and transaction amount. This represents the initial high-dimensional node features after MLP mapping. This step is performed entirely locally on the node, without any external interaction of raw data, thus ensuring the privacy and security of basic data.

[0069] S22: Transformer self-attention Q / K / V feature space mapping, based on the node's local initial features and the initial feature set of neighboring nodes, learns parameters through the self-attention mechanism to complete the spatial mapping of the query, key, and value three-dimensional feature matrix, and constructs the feature association relationship between the node and its neighbors. The calculation formula is as follows:

[0070]

[0071]

[0072] in, , , These are learnable parameters for the self-attention mechanism. For nodes The initial feature set of all corresponding neighbor nodes, , , These are the local query matrix, the neighborhood key matrix, and the neighborhood value matrix, respectively. The neighborhood feature matrix is ​​distributed across all neighboring nodes, without centralized plaintext aggregation.

[0073] S23: Dual-layer encrypted differential calculation of attention weights. The method disclosed in this invention constructs a dual attention weight calculation mechanism, calculating weights from two dimensions: node feature association and transaction topology association. The entire process relies on encryption to prevent plaintext leakage. The specific calculation method is as follows: First, the feature association attention weights are calculated using the AM homomorphic multiplication mechanism in encrypted form to avoid plaintext leakage of node features. The calculation formula is as follows:

[0074] in, For local decryption operators, The dimension of the feature matrix is... For the first The feature association attention weights of each neighboring node The query vector is obtained by linearly transforming the query matrix into the feature representation of the target node. The key vector is obtained by mapping the features of the j-th neighbor node through the key matrix.

[0075] Second, the topological association attention score, which combines the topological features of transaction edges between nodes and strengthens the transaction association weight through an activation function, is calculated as follows:

[0076] in, For learnable parameters, This is the set of neighborhood transaction edges corresponding to the local node. The topological association attention score is used. The dual-weight design can simultaneously mine fraudulent association information in both the feature dimension and the topological dimension, improving feature learning accuracy.

[0077] S24: Multi-head attention feature fusion to generate privacy node representation By fusing dual attention weights and aggregating neighborhood features through a multi-head attention mechanism, the final privacy-preserving node features are generated through feature concatenation, MLP mapping, residual connections, and layer normalization. The core calculation formula is as follows:

[0078]

[0079]

[0080]

[0081] in, To normalize the overall attention weights, This is a single-head attention aggregation feature. This is the result of multi-head feature fusion. For the final privacy protection node characteristics, Let be the set of neighboring nodes of node i. This refers to the number of attention heads in the multi-head attention mechanism. The generated node features are only encrypted and uploaded to regulatory agencies; no original transaction data or plaintext intermediate features are leaked throughout the process.

[0082] Further, step S3 includes: S31: Safe update of neighbor feature gradients based on the SA mechanism. During the model backpropagation phase, to address the risk of leakage of neighbor node feature gradients, the SA safe aggregation mechanism is used to complete the gradient aggregation calculation. The gradient calculation formula is as follows:

[0083] in, for , where represents the number of neighboring nodes of node i.

[0084] This step uses SA masking encryption aggregation to hide the plaintext gradient information of all neighboring nodes, preventing attackers from inferring the original characteristics of neighboring nodes through gradient data, eliminating attribute inference attacks, and ensuring the privacy and security of the neighborhood gradient update process.

[0085] S32: Attention weight gradient secure update based on AM mechanism. Addressing the privacy risks of the attention weight gradient interaction process, it utilizes the AM homomorphic multiplication mechanism to complete ciphertext operations, iterating the weight gradient without plaintext leakage. The gradient calculation formula is as follows:

[0086] This step encrypts the local gradient information before performing homomorphic operations with the neighborhood features, without revealing the neighbor node features and the local gradient plaintext throughout the process. This ensures accurate updates of the attention weight gradients, balancing model iteration accuracy with privacy and security.

[0087] S33: Query Vector Gradient-Safe Update Based on HESA Mechanism For scenarios involving complex local query vector gradient calculations, a combined mechanism of HESA homomorphic encryption and secure aggregation is used to complete high-order ciphertext gradient calculations, avoiding the risk of information leakage of query vectors and neighbor key vectors. The gradient calculation formula is as follows:

[0088] This step is adapted to complex gradient composite operation scenarios, solves the problem that a single encryption mechanism cannot achieve secure computation of high-order gradients, and completely blocks attack paths such as gradient inference and parameter theft.

[0089] like Figure 5 As shown, this invention also provides a decentralized two-layer model aggregation framework based on adaptive node partitioning, which is the core architecture of this invention to solve the problems of single point of failure, communication bottlenecks, and heterogeneous node lag in traditional federated learning centralized aggregation. This framework constructs a hierarchical aggregation structure through an adaptive node partitioning strategy, aiming to minimize model aggregation latency and achieve efficient fusion of massive distributed node models.

[0090] In practice, each participating node first uploads its local device status parameters to the regulatory agency. ,in, The time required to update the node model The time taken to upload the node model. The regulatory body adaptively selects the optimal number of head nodes based on ascending order, according to node computing power and communication performance. And solve for the following optimization objective:

[0091] in, The number of head nodes, For model update time, The time taken to upload the model For the first Small clusters The number of nodes included. The number of aggregation layers for a decentralized multi-layer model aggregation framework The total number of nodes; Furthermore, by solving for the optimal number of head nodes:

[0092] in, This represents the total number of participating nodes. The formula is used to dynamically balance aggregation latency and communication cost to obtain the optimal set of head nodes for the current layer, and to complete the cluster partitioning based on the node status.

[0093] After filtering, select the previous one. A high-performance node serves as the head node, and the remaining ordinary nodes are evenly distributed among the head node clusters to form independent aggregation units. The two-layer aggregation process is as follows: In the first layer, the head nodes within each cluster aggregate the local model parameters of their subordinate ordinary nodes; in the second layer, all head nodes complete the global model fusion in a decentralized peer-to-peer manner, and finally, the global model is synchronized to all participating nodes through multicast technology.

[0094] This two-layer architecture can completely eliminate the single point of failure risk of centralized aggregation, significantly reduce the global aggregation latency through cluster parallel computing, and dynamically adapt to the characteristics of heterogeneous node computing power and dynamic online / offline scenarios, thus alleviating the model timeliness deviation problem caused by lagging nodes.

[0095] like Figure 6 As shown, this invention also provides a decentralized multi-layer model aggregation framework based on adaptive node partitioning, which is a hierarchical extension and optimization of the two-layer aggregation architecture. It addresses the problems of insufficient aggregation parallelism and high communication loss under ultra-large node scale by achieving multi-level parallel aggregation through recursive cluster splitting, thereby further improving model training efficiency.

[0096] In practice, based on the two-level cluster partitioning, an adaptive node partitioning strategy is recursively executed for each first-level cluster, continuously splitting it into smaller-granularity sub-clusters, and building a tree-like multi-layered aggregation architecture layer by layer. The partitioning terminates when the current cluster has the optimal number of head nodes. No further splitting is needed. Architectural hierarchy. It adapts and dynamically adjusts with the size of the nodes. The larger the number of nodes, the more hierarchical levels there are, and the growth of the levels has convergence, without the problem of infinite splitting.

[0097] The multi-layer aggregation implementation process is as follows: the bottom sub-clusters prioritize completing local model aggregation, which is then aggregated layer by layer upwards, and finally the top-level head node completes the global model fusion. Compared to the two-layer architecture, the multi-layer architecture significantly improves the aggregation parallelism in large-scale node scenarios. Experiments have verified that, at a scale of 10,000 nodes, the multi-layer architecture reduces communication loss by an average of 42.3% and latency by 21.4% compared to the two-layer architecture, perfectly adapting to the large-scale modeling needs of cryptocurrency's massive distributed nodes.

[0098] like Figure 6 As shown, this invention further provides an Adaptive Node Partitioning-based Decentralized Multi-layer Model Aggregation Framework (ANP-DMMA), which is based on an adaptive node partitioning strategy. Figure 5This invention presents a hierarchical expansion and optimization scheme based on a decentralized two-layer model aggregation framework. Addressing the problems of increased head node communication pressure, limited aggregation parallelism, and rapid increase in communication latency in two-layer aggregation architectures under ultra-large-scale node environments, this invention achieves efficient model fusion of large-scale distributed nodes through recursive node partitioning and a tree-like hierarchical aggregation mechanism.

[0099] In practice, the initial node partitioning is first completed according to the two-layer aggregation framework to obtain several first-level clusters:

[0100] in, This indicates the number of head nodes in the first level. Indicates the first A primary cluster.

[0101] Subsequently, the adaptive node partitioning strategy is recursively executed for each primary cluster. In the... During layer aggregation, for the current cluster Re-establish the model aggregation latency optimization objective:

[0102] in, Indicates the first Number of layer head nodes Indicates the first The time required to update the layer head node model Indicates the time taken to upload the model. Indicates the first The layer corresponds to the number of nodes in the cluster.

[0103] Based on the above optimization objective, the optimal number of head nodes in the current layer can be further calculated:

[0104] in, This indicates the number of nodes participating in the aggregation at the current layer; This represents the mathematical expectation of the upload time for a node.

[0105] After calculating the optimal head node, the current cluster is divided into multiple sub-clusters with smaller granularity:

[0106] Then, a new head node is elected within each sub-cluster to continue the aggregation.

[0107] The termination condition for recursive partitioning is:

[0108] The current cluster requires only one head node to complete aggregation, indicating that further partitioning cannot further reduce aggregation latency; therefore, recursive splitting is stopped. Since each partition adaptively calculates the optimal number of head nodes based on the current node size, the aggregation level can dynamically adjust with network size. When the node size increases, the system automatically increases the aggregation level; when the node size decreases, the aggregation level automatically decreases, thus ensuring convergence in level growth and preventing infinite recursive partitioning.

[0109] After recursive partitioning, a tree-like multi-layered model aggregation structure is finally formed:

[0110] in, Represents a set of aggregate nodes. This represents the set of aggregation relationships between nodes.

[0111] During the model training phase, each leaf layer sub-cluster first completes local model aggregation, and then the aggregation results are passed up layer by layer according to the tree structure:

[0112] in, Indicates the first Layer aggregation model parameters, This indicates a model aggregation operation, in which the top-level head node ultimately completes the global model fusion, resulting in global node feature representations and the final fraud detection model.

[0113] Compared to a two-layer aggregation architecture, the multi-layer aggregation framework proposed in this invention significantly improves aggregation parallelism in ultra-large-scale node environments, effectively reducing head node communication load and cross-cluster transmission overhead. Experimental results show that in a 10,000-node scenario, the multi-layer aggregation architecture reduces communication loss by an average of 42.3% and aggregation latency by 21.4% compared to the two-layer aggregation architecture, meeting the efficient collaborative modeling requirements of massive distributed nodes in cryptocurrency networks.

[0114] like Figure 7As shown, this invention also provides a privacy-preserving decentralized graph learning cryptocurrency fraud detection system, comprising: a distributed transaction privacy graph construction module, a privacy-preserving feature learning and training module, and an adaptive hierarchical model aggregation module. The distributed transaction privacy graph construction module is used to construct a decentralized local subgraph and a standardized transaction topology graph based on distributed cryptocurrency transaction data, achieving privacy isolation of the original transaction data and transaction topology modeling. The privacy-preserving feature learning and training module is used to construct a privacy-preserving graph learning framework based on a differentiated privacy encryption operation mechanism and complete node encrypted feature learning and gradient iterative updates. The adaptive hierarchical model aggregation module is used to adaptively partition the cluster based on the real-time computing power and communication status of nodes, and obtain the optimal fraud detection model in a decentralized scenario through two-layer and multi-layer recursive aggregation iterations.

[0115] It should be noted that, in order to highlight the innovative aspects of this invention, this embodiment does not include modules that are not closely related to solving the technical problems proposed by this invention, but this does not mean that there are no other modules in this embodiment.

[0116] Furthermore, those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working process of the system described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here. In the embodiments provided by this invention, it should be understood that the disclosed system and method can be implemented in other ways. For example, the division of modules is merely a logical functional division, and in actual implementation, there may be other division methods; for example, multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed.

[0117] The modules described as separate components may or may not be physically separate. Similarly, the components shown as modules may or may not be physical modules; they may be located in one place or distributed across multiple network modules. Some or all of the units can be selected to achieve the purpose of this embodiment, depending on actual needs.

[0118] Furthermore, the functional modules in the various embodiments of the present invention can be integrated into one processing module, or each module can exist physically separately, or two or more modules can be integrated into one module. The integrated modules described above can be implemented in hardware or as software functional units.

[0119] If the integrated module is implemented as a software functional module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0120] As described above, the present invention provides a method for achieving efficient collaborative modeling and high-precision cryptocurrency fraud detection across a massive number of distributed nodes without disclosing the user's original transaction data or intermediate computational information throughout the entire process. Therefore, the present invention effectively overcomes the various shortcomings of the prior art and has high industrial application value.

[0121] The above embodiments are merely illustrative of the principles and effects of the present invention and are not intended to limit the invention. Any person skilled in the art can modify or alter the above embodiments without departing from the spirit and scope of the present invention. Therefore, all equivalent modifications or alterations made by those skilled in the art without departing from the spirit and technical concept disclosed in the present invention should still be covered by the claims of the present invention.

Claims

1. A privacy-preserving decentralized graph learning-based cryptocurrency fraud detection method, characterized in that, include: Collect raw cryptocurrency transaction data from the entire network to construct a global transaction topology map, in which each cryptocurrency user corresponds to an independent central node. ; Each cryptocurrency user node constructs a decentralized transaction subgraph containing only itself and its single-hop neighbor nodes, relying solely on the raw transaction data stored locally. We construct an AM homomorphic addition and multiplication operation mechanism, an SA secure aggregation mechanism, and a HESA homomorphic encryption and secure aggregation composite mechanism to adapt to different distributed computing scenarios based on decentralized transaction subgraphs and achieve full-scenario encrypted secure operation. Construct a privacy-preserving federated graph learning forward-backward propagation process to complete the extraction of node feature representations and reverse update of model gradients in a encrypted state for decentralized transaction subgraphs; Based on the real-time computing and communication capabilities of participating nodes, an adaptive node partitioning strategy is adopted to construct a decentralized multi-layer model aggregation framework, which performs local model aggregation in a layered and parallel manner to obtain a global node feature representation module. Regulatory agencies train a cryptocurrency transaction fraud detection model based on the node features output by the global node feature representation module to identify transaction fraud.

2. The cryptocurrency fraud detection method based on privacy-preserving decentralized graph learning according to claim 1, characterized in that, Using unique user addresses of cryptocurrencies as network nodes, and transaction behaviors as network edges with timestamps and transaction amount weights, multiple transaction edges between the same node are merged to simplify the network topology, thus constructing the global transaction topology graph. ,in, For a set of nodes, For a set of edges, equipped with a node type mapping function ,node With nodes The feature vector of the edge is represented as This includes statistical indicators such as transaction frequency and average transaction amount; In the decentralized transaction subgraph, each node only retains its own data and that of its single-hop neighbors locally. The original characteristics and transaction information of the neighbors are not visible to the outside world. Each local node generates its own dimension based on its transaction records. Node features .

3. The cryptocurrency fraud detection method based on privacy-preserving decentralized graph learning according to claim 2, characterized in that, The SA secure aggregation mechanism satisfies the following formula: in: For the first Local model data for each node It is a pseudo-random number generator. For nodes With nodes Shared keys between them; Each node encrypts and exchanges masked data, which is then aggregated locally to obtain a global model, achieving secure aggregation without plaintext leakage.

4. The cryptocurrency fraud detection method based on privacy-preserving decentralized graph learning according to claim 3, characterized in that, The AM homomorphic multiplication mechanism is used for encrypted dot product aggregation operations between local vectors and neighboring vectors.

5. The cryptocurrency fraud detection method based on privacy-preserving decentralized graph learning according to claim 3, characterized in that, The HESA homomorphic encryption and secure aggregation composite mechanism is used for composite ciphertext operations of scalar and multi-neighbor vectors, satisfying the formula: in: For local scalars, For the first neighbor vectors, This is a homomorphic multiplication operation. This is a homomorphic addition operation. This represents the ciphertext after homomorphic encryption.

6. The cryptocurrency fraud detection method based on privacy-preserving decentralized graph learning according to claim 1, characterized in that, During the model forward propagation phase, the node feature representation extraction is completed, specifically including the following steps: Each node calculates initial features using a multilayer perceptron. : in, For nodes The original transaction characteristics include basic information such as transaction frequency and transaction amount. The initial high-dimensional node features after MLP mapping; The self-attention module maps the feature matrix and constructs the feature association relationship between nodes and their neighbors: in, , , These are learnable parameters for the self-attention mechanism. For nodes The initial feature set of all corresponding neighbor nodes, , , These are the local query matrix, the neighborhood key matrix, and the neighborhood value matrix, respectively. Calculate the importance weight of neighbors: in, For local decryption operators, The dimension of the feature matrix, For the first The feature association attention weights of each neighboring node The query vector is obtained by linearly transforming the query matrix into the feature representation of the target node. The key vector is obtained by mapping the features of the j-th neighbor node through the key matrix; Calculate the edge attention score: in, For learnable parameters, This is the set of neighborhood transaction edges corresponding to the local node. Topological association attention score; Multi-head attention aggregation and node representation output: in, To normalize the overall attention weights, This is a single-head attention aggregation feature. This is the result of multi-head feature fusion. For the final privacy protection node characteristics, Let i be the set of neighboring nodes. The number of attention heads in a multi-head attention mechanism; The final output is a privacy-preserving node feature representation. .

7. The cryptocurrency fraud detection method based on privacy-preserving decentralized graph learning according to claim 5, characterized in that, During the model backpropagation training phase, the model gradient is updated backward, specifically including the following steps: Define the formula for updating the parameters of the fraud detection model: in, For model parameters, For training rounds, For learning rate, The loss function; Based on the AM homomorphic addition-multiplication mechanism, the SA secure aggregation mechanism, and the HESA homomorphic encryption and secure aggregation composite mechanism, gradients are securely solved respectively: in, for , representing the number of neighboring nodes of node i; The entire interaction is encrypted, without revealing the gradient and feature plaintext.

8. The cryptocurrency fraud detection method based on privacy-preserving decentralized graph learning according to claim 1, characterized in that, A decentralized two-layer model aggregation framework is constructed using an adaptive node partitioning strategy. Local model aggregation is performed in a layered and parallel manner to obtain a global node feature representation module, including: Calculate the model update time for each participating node. Model upload time ; An optimization model is established with the objective of minimizing the total aggregation latency of the model: in, The number of head nodes, For model update time, The time taken to upload the model For the first Small clusters The number of nodes included. To define the number of aggregation layers in a decentralized multi-layered model aggregation framework. The total number of nodes participating in the aggregation; The optimal number of head nodes is determined based on the optimization model described above. in, For mathematical expectation; Before selection A high-performance node is used as the head node, and the remaining nodes are divided into multiple sub-clusters by corresponding head nodes. Each head node completes the model aggregation within its sub-cluster. Each head node uses a decentralized communication method to complete the second-layer model aggregation and obtain the global node feature representation.

9. The cryptocurrency fraud detection method based on privacy-preserving decentralized graph learning according to claim 8, characterized in that, The construction of the decentralized multi-layer model aggregation framework specifically includes: Initial cluster partitioning: based on the optimal number of head nodes obtained from the solution. The set of all participating nodes Divide equally into Basic sub-clusters The formula for satisfying the cluster node number balance constraint is: The node with the shortest model update time and the lowest communication latency within each sub-cluster is selected as the cluster head node. Responsible for the cluster model aggregation task at this level; Sub-cluster recursive layering: for each basic sub-cluster The recursive hierarchical partitioning strategy is executed, and the recursion terminates when the number of sub-cluster nodes is reached. , For recursive levels; Define the hierarchy depth Adaptive calculation formula: By adaptively dividing the hierarchy, a multi-level nested decentralized parallel aggregation architecture is constructed to adapt to the computing power and communication differences of massive heterogeneous nodes; Hierarchical parallel model aggregation: Each level's head node independently performs local model parameter aggregation within the cluster. The aggregation formula for a single-level cluster is: in, These are the model parameters trained locally on ordinary nodes. These are the parameters of the hierarchical model after aggregation from a single cluster; Iterates and aggregates layer by layer from the bottom to the top, ultimately outputting the global aggregation model parameters. ; Global model multicast distribution: The top-level head node cluster adopts a multicast concurrent push mechanism to distribute global node feature modules and global model parameters. The model is distributed synchronously to all participating nodes, and the model distribution latency meets the following requirements: in, This represents the total time consumed in multi-layer polymerization. Multicast distribution takes time.

10. A privacy-preserving decentralized graph learning-based cryptocurrency fraud detection system, characterized in that, include: The subgraph construction module is used to collect cryptocurrency transaction data and build a global transaction graph and local decentralized transaction subgraphs for each node. The privacy representation learning module integrates three privacy-preserving computational units: AM, SA, and HESA. It performs self-attention forward propagation of the Transformer model and extracts node features from the ciphertext. The privacy backpropagation module is used to solve various gradients of the model in an encrypted state and complete local parameter iterative updates. The multi-layer model aggregation module is used to adaptively partition node clusters, build a decentralized two-layer / multi-layer aggregation framework, and aggregate in parallel to obtain the global node feature module; The fraud detection and defense module is used to train a fraud detection model to defend against three types of privacy attacks and identify transaction fraud.