Blockchain dynamic risk identification method, system and device, and storage medium

CN122840943APending Publication Date: 2026-09-29SHANGHAI YUNXIANG CHAIN DIGITAL TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611137404.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-07-29
Publication Date
2026-09-29

AI Technical Summary

Technical Problem

然而,现有研究多聚焦于单一层次的安全分析,缺乏对跨层攻击传导机制的系统性探索

Benefits of technology

首先,在实体识别与关系构建层面,现有技术主要依赖地址聚类方法对同一控制主体的多个地址进行归并,但传统聚类方法在漏判率与误判率控制上存在明显瓶颈,且缺乏对地址实体细粒度属性的深入挖掘。近年来虽有研究尝试结合复杂网络理论进行实体聚合与识别,或通过双层交易网络挖掘地址间的隐藏关系,但这些方法仍以单一维度的交易关系为核心,未能对地址的类型属性、活跃度、关联频次、余额分布等多维细粒度特征进行系统性标注。本发明提出了基于地址标签库与启发式规则引擎相结合的细粒度属性识别方法,并进一步引入基于图注意力网络的实体对齐模型,将链上地址实体与链下实体关系数据进行跨源融合,构建包含地址层、账户层、机构层和行业层的四层级区块链实体关系图谱,实现了从单一交易关系到多源异构实体关系的跨越式突破。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122840943A_ABST
    Figure CN122840943A_ABST
Patent Text Reader

Abstract

The application discloses a kind of blockchain dynamic risk identification method, system, device and storage medium, belong to blockchain security technical field.The method includes: acquisition blockchain multi-source heterogeneous data and pre-processing;Address fine-grained attribute identification is carried out using address label library and heuristic rule engine;Directed weighted heterogeneous graph is constructed and off-chain entity relationship is fused, and multi-level entity relationship graph is generated;Community discovery is carried out using Louvain algorithm and risk label is labeled;Four-level risk identification model is constructed, and cross-level risk association reasoning is carried out through hierarchical graph attention network, to realize risk event accurate characterization and dynamic early warning;Incremental learning update is carried out using elastic weight consolidation method.The application realizes the accurate identification of blockchain diversification entity and multi-level relationship construction, supports cross-level risk association reasoning from address level to industry level, and continuously improves the identification ability through dynamic self-enhancement mechanism, applicable to blockchain security supervision and risk prevention and control scene.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of blockchain security technology, specifically relating to a method, system, device, and storage medium for dynamic risk identification in blockchain. Background Technology

[0002] The rapid development of blockchain technology and its widespread application in digital finance, supply chain management, and digital asset trading have brought significant advantages such as decentralization and immutability, but have also brought increasingly severe security risks and challenges. The anonymity of blockchain networks makes it difficult to effectively link addresses to real-world entities—a large number of illegal transactions, money laundering, pyramid schemes, phishing attacks, and other malicious activities are hidden within complex transaction networks, posing a serious threat to the security and stability of the blockchain ecosystem. How to accurately identify risky entities from massive and rapidly growing blockchain transaction data, construct a complete network of entity relationships, and promptly detect potential risks has become a core issue that urgently needs to be addressed in the field of blockchain security technology.

[0003] Currently, research on blockchain security risk identification has made some progress. In entity identification, existing technologies mainly use address clustering methods to merge multiple addresses of the same controlling entity. However, traditional clustering methods have significant bottlenecks in controlling false negative and false positive rates and lack in-depth mining of fine-grained attributes of address entities. In risk detection, deep learning methods such as graph neural networks have been introduced into blockchain transaction analysis. By modeling the dependencies between nodes through graph convolution operations, they can identify abnormal transactions and malicious accounts. Community detection algorithms such as the Leuven algorithm have also been used to identify potential manipulation groups and money laundering groups. However, existing research mostly focuses on single-level security analysis and lacks systematic exploration of cross-layer attack transmission mechanisms. Furthermore, current risk identification models are mostly static models, making it difficult to adapt to the continuous evolution of blockchain network transaction patterns and the emergence of new attack methods.

[0004] Therefore, existing blockchain risk identification technologies still suffer from the following key unresolved issues: First, they lack the ability to accurately identify and efficiently construct the diverse, large-scale entities and their complex relationships within the blockchain network, and there is a lack of effective means for cross-source alignment between on-chain addresses and off-chain entities; second, the risk identification level is singular, failing to achieve cross-level risk correlation reasoning and comprehensive judgment from the address level to the institution and industry level; third, the risk identification model lacks a dynamic self-enhancing mechanism, unable to continuously learn and self-optimize using newly identified risk events. To address these technical challenges, this invention proposes a blockchain dynamic risk identification method, system, device, and storage medium. Summary of the Invention

[0005] This invention addresses the shortcomings of existing technologies by providing a method, system, and storage medium for dynamic risk identification in blockchain.

[0006] To solve the above-mentioned technical problems, the present invention provides the following technical solution:

[0007] A method for dynamic risk identification in blockchain includes the following steps: Real-time collection and preprocessing of blockchain network data yields standardized multi-source heterogeneous data, including on-chain transaction data, smart contract bytecode data, block metadata, and off-chain related data. Based on the standardized multi-source heterogeneous data, a preset address tag library and heuristic rule engine are used to perform fine-grained attribute identification on address entities in the blockchain network. The identified fine-grained attributes are associated and stored with the corresponding address entities to form a set of entities with attribute labels. Using the address entities in the attribute-annotated entity set as graph nodes and the transaction interaction relationships between address entities as edges, an initial blockchain transaction relationship graph is constructed. The off-chain entity relationship data is acquired and merged with the initial blockchain transaction relationship graph to generate a multi-level blockchain entity relationship graph and perform multi-level community discovery. The nodes in the multi-level blockchain entity relationship graph are divided into several community clusters to obtain the community discovery results. Based on the results of the community discovery and the multi-level blockchain entity relationship graph, a multi-level risk identification model is constructed and risk events are identified. The risk identification results of the lower level are transmitted and aggregated to the upper level to obtain the results of cross-level risk association reasoning. The risk events are then accurately characterized to obtain accurate characterization results. Based on the accurate characterization results of the risk event and the preset dynamic early warning rule engine, a risk warning signal is generated. The risk event and the accurate characterization results are fed back to the multi-level risk identification model for incremental learning and updating. The warning thresholds of the address tag library and the dynamic early warning rule engine are updated based on the risk warning signal.

[0008] As one possible implementation, the heuristic rule engine includes address classification rules based on transaction frequency, address classification rules based on transaction amount distribution, address classification rules based on contract call patterns, and address classification rules based on time series behavior; the address tag library adopts a key-value pair storage structure, where the key is the address hash value and the value is a set of address type tags and attribute tags. The address tag library is constructed and updated through a combination of manual annotation and automatic annotation. The address classification rule based on transaction frequency divides addresses into active transaction addresses and passive receiving addresses according to the ratio of the number of transactions initiated to the number of transactions received within a preset time window. The address classification rule based on transaction amount distribution divides addresses into large-transaction addresses and small-transaction addresses according to the statistical characteristics of the mean, variance, quantiles and extreme values ​​of the transaction amount. The address classification rule based on contract call patterns identifies the contract interaction behavior pattern of an address by analyzing the function selection subsequence in the smart contract call sequence initiated by the address. The function selection subsequence includes the first 4 bytes of the Keccak-256 hash value of the smart contract function signature. The address classification rules based on time-series behavior identify automated and manual transaction behavior patterns of addresses by performing periodicity and burst detection on the transaction time interval sequence of the address.

[0009] As one possible implementation, the initial blockchain transaction graph adopts a directed weighted heterogeneous graph structure, where the edge weights are calculated based on a combination of transaction amount, transaction frequency, and time decay factor; the time decay factor uses an exponential decay function, ensuring that the weight of recent transactions is higher than that of historical transactions; the edge weights are expressed as follows: W(u,v,t)=α·A(u,v)+β·F(u,v,Δt)+γ·D(Δt) Where u and v represent the sender and receiver addresses of the transaction, respectively, and t represents the timestamp of the transaction; A(u,v) represents the cumulative transaction amount between addresses u and v within a preset historical time window, after logarithmic normalization; F(u,v,Δt) represents the transaction frequency between addresses u and v within the preset historical time window, where Δt represents the time difference between the current transaction time and the most recent historical transaction time, and F is obtained by time-weighting the historical transaction frequency using an exponential decay function; D(Δt) represents the time decay factor, calculated using the formula D(Δt)=exp(-λ·Δt), where λ is the preset time decay coefficient; α, β, and γ are preset weight coefficients, satisfying α+β+γ=1; the node attributes in the directed weighted heterogeneous graph include the fine-grained attributes of the address entities, and the edge attributes include transaction amount, transaction timestamp, transaction gas consumption, and transaction type identifier.

[0010] As one possible implementation, the step of acquiring off-chain entity relationship data and fusing it with the initial blockchain transaction relationship graph to generate a multi-level blockchain entity relationship graph includes the following steps: An entity alignment model is constructed based on a graph attention network. The entity alignment model calculates the similarity between the attribute feature vectors of on-chain address entities and the attribute feature vectors of off-chain entities, and performs joint optimization by combining graph structure context information. The entity alignment model includes an encoding layer, an attention layer, an alignment layer, and a verification layer. The encoding layer uses a graph convolutional network to encode the attributes and graph structure of the on-chain address entities, generating low-dimensional embedding vectors of the on-chain address entities. At the same time, a text encoder is used to encode the descriptive text of the off-chain entities, generating low-dimensional embedding vectors of the off-chain entities. The attention layer uses a multi-head attention mechanism to calculate the cross-modal attention weights between on-chain address entities and off-chain entities. The number of heads in the multi-head attention mechanism is a preset value. Each attention head independently calculates the semantic similarity between entities, and the outputs of multiple heads are concatenated or averaged. The alignment layer constructs candidate alignment relationships between on-chain address entities and off-chain entities based on the cross-modal attention weights and semantic similarity between entities, and filters candidate alignment relationships using a preset similarity threshold. The verification layer uses a blockchain consensus mechanism or a manual review mechanism to verify the selected candidate alignment relationships, and adds the verified alignment relationships to the multi-level blockchain entity relationship graph.

[0011] As one possible implementation, the multi-level community discovery is based on the Leuven algorithm with modularity optimization; The Leuven algorithm includes a first stage of node movement optimization and a second stage of community cohesion optimization. The first stage iteratively moves nodes to neighboring communities that maximize their modularity gain. The second phase consolidates the community formed in the first phase into supernodes and builds a new community network. The first and second phases are executed alternately until the modularity no longer increases. During the community discovery process, risk labels are applied to different communities based on the fine-grained attributes. These risk labels include high-risk trading communities, high-risk contract communities, and high-risk associated communities. All nodes within the same community are aggregated into a supernode. The sum of edge weights within a community is used as the self-loop weight of the supernode, and the sum of edge weights between communities is used as the edge weight between supernodes. A new community network is then constructed for the next iteration.

[0012] As one possible implementation, the construction of a multi-level risk identification model and the identification of risk events, the transmission and aggregation of risk identification results from lower levels to higher levels to obtain cross-level risk correlation reasoning results, and the accurate characterization of risk events to obtain accurate characterization results, includes the following steps: A multi-level risk identification model is constructed based on graph neural networks. The multi-level risk identification model includes an intra-level graph attention layer and an inter-level graph attention layer. The hierarchical graph attention layer is used for message passing and aggregation of risk features between nodes within the same level. It uses a graph attention mechanism to calculate the attention weights of neighboring nodes to the current node within the same level. The attention weights are calculated based on the node feature vector and the edge feature vector. The inter-level graph attention layer is used to transmit and aggregate risk features between nodes at different levels. Risk features at lower levels are transmitted to the parent node at the upper level through entity affiliation and holding relationships, and risk features at upper levels are fed back to the child nodes at the lower level through entity affiliation and holding relationships. The multi-level risk identification model employs residual connections and layer normalization techniques to avoid gradient vanishing and representation degradation problems in deep networks. By utilizing the intermediate layer output of the multi-level risk identification model, and through backpropagation and gradient significance analysis, the set of nodes and edges that contribute the most to risk judgment are located, forming an accurate characterization of risk events, which serves as the basis for tracking risk propagation paths.

[0013] As one possible implementation method, the accurate characterization of the risk event is obtained by judging and identifying the risk event based on the correlation reasoning results of the multi-level risk identification model; The identification process includes identifying the triggering entity of the risk event, tracing the propagation path of the risk event, assessing the scope of the risk event's impact, and determining the type of the risk event. The precise characterization results include risk event ID, triggering entity address, list of involved accounts, propagation path node sequence, impact scope level identifier, risk type label, risk level score, and timestamp; Based on the accurate characterization results and the preset dynamic early warning rule engine, it is determined whether the early warning triggering conditions are met. When the early warning triggering conditions are met, a risk early warning signal is generated, which includes the early warning level, early warning content, a list of affected entities, and suggested handling measures. The risk early warning signal is then distributed to each blockchain node and regulatory node through the P2P broadcast mechanism of the blockchain network.

[0014] A blockchain dynamic risk identification system includes: The data acquisition and preprocessing module collects blockchain network data in real time and preprocesses it to obtain standardized multi-source heterogeneous data. The blockchain network data includes on-chain transaction data, smart contract bytecode data, block metadata, and off-chain related data. The attribute recognition module, based on the standardized multi-source heterogeneous data, uses a preset address tag library and heuristic rule engine to perform fine-grained attribute recognition on address entities in the blockchain network, and associates and stores the recognized fine-grained attributes with the corresponding address entities to form an attribute-labeled entity set. The entity relationship graph construction module constructs an initial blockchain transaction relationship graph based on the address entities in the attribute-annotated entity set as graph nodes and the transaction interaction relationships between address entities as edges. The community discovery module acquires off-chain entity relationship data and merges it with the initial blockchain transaction relationship graph to generate a multi-level blockchain entity relationship graph and perform multi-level community discovery. The nodes in the multi-level blockchain entity relationship graph are divided into several community clusters to obtain the community discovery results. The risk event identification module, based on the results discovered by the community and the multi-level blockchain entity relationship graph, constructs a multi-level risk identification model and identifies risk events. It then transmits and aggregates the risk identification results of the lower level to the upper level to obtain the results of cross-level risk association reasoning and accurately characterizes the risk events to obtain accurate characterization results. The feedback update module generates a risk warning signal based on the accurate characterization result of the risk event and the preset dynamic warning rule engine, feeds back the risk event and accurate characterization result to the multi-level risk identification model for incremental learning and updating, and updates the warning threshold of the address tag library and the dynamic warning rule engine based on the risk warning signal.

[0015] A blockchain dynamic risk identification device includes: at least one memory; at least one processor; and a communication interface; when the processor executes program instructions stored in the memory, it jointly invokes the communication interface to perform all of the following steps: Real-time collection and preprocessing of blockchain network data yields standardized multi-source heterogeneous data, including on-chain transaction data, smart contract bytecode data, block metadata, and off-chain related data. Based on the standardized multi-source heterogeneous data, a preset address tag library and heuristic rule engine are used to perform fine-grained attribute identification on address entities in the blockchain network. The identified fine-grained attributes are associated and stored with the corresponding address entities to form a set of entities with attribute labels. Using the address entities in the attribute-annotated entity set as graph nodes and the transaction interaction relationships between address entities as edges, an initial blockchain transaction relationship graph is constructed. The off-chain entity relationship data is acquired and merged with the initial blockchain transaction relationship graph to generate a multi-level blockchain entity relationship graph and perform multi-level community discovery. The nodes in the multi-level blockchain entity relationship graph are divided into several community clusters to obtain the community discovery results. Based on the results of the community discovery and the multi-level blockchain entity relationship graph, a multi-level risk identification model is constructed and risk events are identified. The risk identification results of the lower level are transmitted and aggregated to the upper level to obtain the results of cross-level risk association reasoning. The risk events are then accurately characterized to obtain accurate characterization results. Based on the accurate characterization results of the risk event and the preset dynamic early warning rule engine, a risk warning signal is generated. The risk event and the accurate characterization results are fed back to the multi-level risk identification model for incremental learning and updating. The warning thresholds of the address tag library and the dynamic early warning rule engine are updated based on the risk warning signal.

[0016] A computer-readable storage medium having a computer program stored thereon, the computer program, when executed by a processor, implementing the method described in any of the following ways: Real-time collection and preprocessing of blockchain network data yields standardized multi-source heterogeneous data, including on-chain transaction data, smart contract bytecode data, block metadata, and off-chain related data. Based on the standardized multi-source heterogeneous data, a preset address tag library and heuristic rule engine are used to perform fine-grained attribute identification on address entities in the blockchain network. The identified fine-grained attributes are associated and stored with the corresponding address entities to form a set of entities with attribute labels. Using the address entities in the attribute-annotated entity set as graph nodes and the transaction interaction relationships between address entities as edges, an initial blockchain transaction relationship graph is constructed. The off-chain entity relationship data is acquired and merged with the initial blockchain transaction relationship graph to generate a multi-level blockchain entity relationship graph and perform multi-level community discovery. The nodes in the multi-level blockchain entity relationship graph are divided into several community clusters to obtain the community discovery results. Based on the results of the community discovery and the multi-level blockchain entity relationship graph, a multi-level risk identification model is constructed and risk events are identified. The risk identification results of the lower level are transmitted and aggregated to the upper level to obtain the results of cross-level risk association reasoning. The risk events are then accurately characterized to obtain accurate characterization results. Based on the accurate characterization results of the risk event and the preset dynamic early warning rule engine, a risk warning signal is generated. The risk event and the accurate characterization results are fed back to the multi-level risk identification model for incremental learning and updating. The warning thresholds of the address tag library and the dynamic early warning rule engine are updated based on the risk warning signal.

[0017] This invention, by adopting the above technical solutions, has significant technical effects: Firstly, at the level of entity identification and relationship construction, existing technologies mainly rely on address clustering methods to merge multiple addresses of the same controlling entity. However, traditional clustering methods have significant bottlenecks in controlling the false negative and false positive rates, and lack in-depth mining of the fine-grained attributes of address entities. Although some studies in recent years have attempted to combine complex network theory for entity aggregation and identification, or to mine hidden relationships between addresses through two-layer transaction networks, these methods still focus on single-dimensional transaction relationships and fail to systematically label multi-dimensional fine-grained features such as address type attributes, activity, association frequency, and balance distribution. This invention proposes a fine-grained attribute identification method based on an address tag library and a heuristic rule engine, and further introduces an entity alignment model based on graph attention networks to fuse on-chain address entity and off-chain entity relationship data across sources, constructing a four-layer blockchain entity relationship graph including address layer, account layer, institution layer, and industry layer, achieving a leapfrog breakthrough from single transaction relationships to multi-source heterogeneous entity relationships.

[0018] Secondly, at the risk identification architecture level, existing blockchain risk detection technologies mostly focus on single-level security analysis. For example, graph neural networks are used to model node dependencies in transaction graphs to identify abnormal accounts, or community discovery algorithms are used to identify potential risk groups. However, these methods lack a systematic exploration of cross-layer attack transmission mechanisms. Although existing research has also attempted two-layer GNN architectures or hierarchical graph Transformers, their hierarchical division is still limited to the transaction network itself, failing to incorporate multi-level entity relationships at the address, account, institution, and even industry levels into a unified risk reasoning framework. This invention constructs a risk identification model containing four levels and uses a hierarchical graph attention network architecture to achieve cross-level risk correlation reasoning. It can start from abnormal behavior at the address level and trace upwards to the systemic risk transmission at the account, institution, and even industry levels, realizing a qualitative leap in risk identification from single-point detection to full-link correlation reasoning.

[0019] Finally, regarding the continuous evolution capability of the model, most existing risk identification models are static models, trained on fixed datasets and then put into use, making it difficult to adapt to the continuous evolution of blockchain network transaction patterns and the emergence of new attack methods. Although graph continuous learning and federated continuous learning have emerged in recent years, these methods mainly address the catastrophic forgetting problem of models in sequential tasks and have not yet formed a closed-loop feedback with the labeled samples generated in real time in blockchain risk identification tasks. This invention introduces the elastic weight consolidation method into the field of blockchain risk identification, enabling the system to incrementally learn and update using newly identified risk events, while dynamically adjusting the threshold of the early warning rule engine, thus realizing a closed-loop mechanism in which the risk identification capability continuously self-reinforces as the network environment evolves. Attached Figure Description

[0020] Figure 1 This is a schematic flowchart of the method of the present invention; Figure 2 This is a diagram showing the composition of the system of the present invention. Detailed Implementation

[0021] To clearly illustrate the present invention and make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings, so that those skilled in the art can implement the invention based on the description. The technology of the present invention will be described in detail below with reference to the accompanying drawings and specific embodiments.

[0022] Example 1: A method for dynamic risk identification in blockchain, such as Figure 1 As shown, it includes the following steps: S100. Real-time collection and preprocessing of blockchain network data to obtain standardized multi-source heterogeneous data, including on-chain transaction data, smart contract bytecode data, block metadata, and off-chain related data. S200. Based on the standardized multi-source heterogeneous data, a preset address tag library and heuristic rule engine are used to perform fine-grained attribute identification on address entities in the blockchain network. The identified fine-grained attributes are associated and stored with the corresponding address entities to form an entity set with attribute annotations. S300. Based on the address entities in the attribute-annotated entity set as graph nodes, and the transaction interaction relationships between address entities as edges, construct an initial blockchain transaction relationship graph; S400: Obtain off-chain entity relationship data and merge it with the initial blockchain transaction relationship graph to generate a multi-level blockchain entity relationship graph and perform multi-level community discovery. Divide the nodes in the multi-level blockchain entity relationship graph into several community clusters to obtain the community discovery results. S500. Based on the results of the community discovery and the multi-level blockchain entity relationship graph, a multi-level risk identification model is constructed and risk events are identified. The risk identification results of the lower level are transmitted and aggregated to the upper level to obtain the results of cross-level risk association reasoning. The risk events are accurately characterized to obtain accurate characterization results. S600. Based on the accurate characterization results of the risk event and the preset dynamic early warning rule engine, a risk warning signal is generated. The risk event and the accurate characterization results are fed back to the multi-level risk identification model for incremental learning and updating. The warning thresholds of the address tag library and the dynamic early warning rule engine are updated based on the risk warning signal.

[0023] S100. Real-time collection and preprocessing of blockchain network data to obtain standardized multi-source heterogeneous data, including on-chain transaction data, smart contract bytecode data, block metadata, and off-chain related data. The on-chain transaction data in this embodiment of the invention includes transaction hash, sender address, receiver address, transaction amount, timestamp, and gas consumption. The smart contract bytecode data includes contract creation transactions, contract call traces, and contract state variable change logs. The block metadata includes block height, block hash, parent block hash, Merkle root hash, and timestamp. The collected on-chain transaction data, smart contract bytecode data, and block metadata are preprocessed by data cleaning, format normalization, and missing value imputation to obtain standardized multi-source heterogeneous data.

[0024] S200. Based on the standardized multi-source heterogeneous data, a preset address tag library and heuristic rule engine are used to perform fine-grained attribute identification on address entities in the blockchain network. The identified fine-grained attributes are associated and stored with the corresponding address entities to form an entity set with attribute annotations. In this embodiment of the invention, based on the standardized multi-source heterogeneous data, a preset address tag library and heuristic rule engine are used to perform fine-grained attribute identification on address entities in the blockchain network. The fine-grained attributes include address type attributes, address activity attributes, address association frequency attributes, and address balance distribution attributes. The address type attribute is determined through address tag library matching and transaction pattern analysis, used to distinguish between ordinary user addresses, exchange addresses, miner addresses, smart contract addresses, and black hole addresses. The address activity attribute is calculated based on the transaction frequency and transaction amount volatility of the address within a preset time window. The address association frequency attribute is obtained based on the statistical analysis of the number of transaction interactions between the address and other addresses. The address balance distribution attribute is obtained by extracting statistical features from the balance change sequence of the address within a preset time window. The identified fine-grained attributes are associated and stored with the corresponding address entities to form an attribute-labeled entity set. The heuristic rule engine includes address classification rules based on transaction frequency, address classification rules based on transaction amount distribution, address classification rules based on contract call patterns, and address classification rules based on time series behavior. The address tag library adopts a key-value pair storage structure, where the key is the address hash value and the value is a set of type tags and attribute tags for the address. The address tag library is constructed and updated through a combination of manual and automatic annotation. The address classification rule based on transaction frequency divides addresses into active transaction addresses and passive receiving addresses according to the ratio of the number of transactions initiated to the number of transactions received within a preset time window. The address classification rule based on transaction amount distribution divides addresses into large-transaction addresses and small-transaction addresses according to the statistical characteristics of the mean, variance, quantiles and extreme values ​​of the transaction amount. The address classification rule based on contract call patterns identifies the contract interaction behavior pattern of an address by analyzing the function selection subsequence in the smart contract call sequence initiated by the address. The function selection subsequence includes the first 4 bytes of the Keccak-256 hash value of the smart contract function signature. The address classification rules based on time-series behavior identify automated and manual transaction behavior patterns of addresses by performing periodicity and burst detection on the transaction time interval sequence of the address.

[0025] S300. Based on the address entities in the attribute-annotated entity set as graph nodes, and the transaction interaction relationships between address entities as edges, construct an initial blockchain transaction relationship graph; The transaction interaction relationships described in this embodiment of the invention include direct transaction relationships, indirect transaction relationships, and time-series transaction relationships. Direct transaction relationships are established based on direct transfers between the sender's address and the receiver's address in on-chain transaction records. Indirect transaction relationships are established based on transitive associations between address entities in multi-hop transaction paths. Time-series transaction relationships are established by creating directed edges with timestamps according to the chronological order of transaction occurrences. The initial blockchain transaction relationship graph adopts a directed weighted heterogeneous graph structure, where the edge weights are calculated based on transaction amount, transaction frequency, and a time decay factor. The time decay factor uses an exponential decay function, ensuring that recent transactions have a higher weight than historical transactions. The initial blockchain transaction graph adopts a directed weighted heterogeneous graph structure, where the edge weights are calculated based on transaction amount, transaction frequency, and time decay factor. The time decay factor uses an exponential decay function, ensuring that recent transactions have higher weights than historical transactions. The edge weights W(u,v,t) of the directed weighted heterogeneous graph are calculated according to the following formula: W(u,v,t)=α·A(u,v)+β·F(u,v,Δt)+γ·D(Δt) Where u and v represent the sender and receiver addresses of the transaction, respectively, and t represents the timestamp of the transaction; A(u,v) represents the cumulative transaction amount between addresses u and v within a preset historical time window, after logarithmic normalization; F(u,v,Δt) represents the transaction frequency between addresses u and v within the preset historical time window, where Δt represents the time difference between the current transaction time and the most recent historical transaction time, and F is obtained by time-weighting the historical transaction frequency using an exponential decay function; D(Δt) represents the time decay factor, calculated using the formula D(Δt)=exp(-λ·Δt), where λ is the preset time decay coefficient; α, β, and γ are preset weight coefficients, satisfying α+β+γ=1; the node attributes in the directed weighted heterogeneous graph include the fine-grained attributes of the address entities, and the edge attributes include transaction amount, transaction timestamp, transaction gas consumption, and transaction type identifier.

[0026] S400: Obtain off-chain entity relationship data and merge it with the initial blockchain transaction relationship graph to generate a multi-level blockchain entity relationship graph and perform multi-level community discovery. Divide the nodes in the multi-level blockchain entity relationship graph into several community clusters to obtain the community discovery results. In this embodiment of the invention, off-chain entity relationship data is acquired and fused with the initial blockchain transaction relationship graph to generate a multi-level blockchain entity relationship graph and perform multi-level community discovery. The off-chain entity relationship data includes institutional relationship data extracted from publicly disclosed information, entity relationship data extracted from regulatory filing information, and entity name alias mapping data extracted from publicly available internet data. An entity alignment model based on graph attention networks is adopted to perform cross-source alignment between on-chain address entities and off-chain entities. The entity alignment model calculates the similarity between the attribute feature vectors of on-chain address entities and the attribute feature vectors of off-chain entities, and performs joint optimization by combining graph structure context information to generate the fused multi-level blockchain entity relationship graph. The multi-level blockchain entity relationship graph includes four levels: address layer, account layer, institutional layer, and industry layer. Each level is connected across layers through entity affiliation and holding relationships. The step of acquiring off-chain entity relationship data and integrating it with the initial blockchain transaction relationship graph to generate a multi-level blockchain entity relationship graph includes the following steps: An entity alignment model is constructed based on a graph attention network. The entity alignment model calculates the similarity between the attribute feature vectors of on-chain address entities and the attribute feature vectors of off-chain entities, and performs joint optimization by combining graph structure context information. The entity alignment model includes an encoding layer, an attention layer, an alignment layer, and a verification layer. The encoding layer uses a graph convolutional network to encode the attributes and graph structure of the on-chain address entities, generating low-dimensional embedding vectors of the on-chain address entities. At the same time, a text encoder is used to encode the descriptive text of the off-chain entities, generating low-dimensional embedding vectors of the off-chain entities. The attention layer uses a multi-head attention mechanism to calculate the cross-modal attention weights between on-chain address entities and off-chain entities. The number of heads in the multi-head attention mechanism is a preset value. Each attention head independently calculates the semantic similarity between entities, and the outputs of multiple heads are concatenated or averaged. The alignment layer constructs candidate alignment relationships between on-chain address entities and off-chain entities based on the cross-modal attention weights and semantic similarity between entities, and filters candidate alignment relationships using a preset similarity threshold. The verification layer uses a blockchain consensus mechanism or a manual review mechanism to verify the selected candidate alignment relationships, and adds the verified alignment relationships to the multi-level blockchain entity relationship graph.

[0027] S500. Based on the results of the community discovery and the multi-level blockchain entity relationship graph, a multi-level risk identification model is constructed and risk events are identified. The risk identification results of the lower level are transmitted and aggregated to the upper level to obtain the results of cross-level risk association reasoning. The risk events are accurately characterized to obtain accurate characterization results. In this embodiment of the invention, the nodes in the multi-level blockchain entity relationship graph are divided into several community clusters to obtain the community discovery result. The Leuven algorithm includes a first stage of node movement optimization and a second stage of community cohesion optimization. In the first stage, nodes are iteratively moved to neighboring communities that maximize their modularity gain. In the second stage, the communities formed in the first stage are agglomerated into supernodes and a new community network is constructed. The two stages are executed alternately until the modularity no longer increases. During the community discovery process, different communities are labeled with risk tags based on the fine-grained attributes. The risk tags include high-risk transaction communities, high-risk contract communities, and high-risk associated communities. The multi-level community discovery is implemented based on the Leuven algorithm with modularity optimization. The Leuven algorithm includes a first stage of node movement optimization and a second stage of community cohesion optimization. The first stage iteratively moves nodes to neighboring communities that maximize their modularity gain. The second phase consolidates the community formed in the first phase into supernodes and builds a new community network. The first and second phases are executed alternately until the modularity no longer increases. During the community discovery process, risk labels are applied to different communities based on the fine-grained attributes. These risk labels include high-risk trading communities, high-risk contract communities, and high-risk associated communities. All nodes within the same community are aggregated into a supernode. The sum of edge weights within a community is used as the self-loop weight of the supernode, and the sum of edge weights between communities is used as the edge weight between supernodes. A new community network is then constructed for the next iteration.

[0028] The formula for calculating the modularity Q can be implemented as follows: Q=(1 / 2m)·Σ_{i,j}[A_{ij}-(k_i·k_j) / (2m)]·δ(c_i,c_j) Where m represents the total number of edges in the multi-level blockchain entity relationship graph, A_{ij} represents the weight of the edge between node i and node j, k_i represents the degree of node i, k_j represents the degree of node j, c_i represents the community to which node i belongs, c_j represents the community to which node j belongs, and δ(c_i,c_j) is an indicator function that takes a value of 1 when c_i=c_j, and a value of 0 otherwise; In the node movement optimization stage, the module degree gain ΔQ of node i moving to its neighbor community C can be calculated according to the following formula: ΔQ=[(Σ_in+k_i_in) / (2m)-((Σ_tot+k_i) / (2m))^2]-[Σ_in / (2m)-(Σ_tot / (2m))^2-(k_i / (2m))^2] Where Σ_in represents the sum of edge weights within community C, Σ_tot represents the sum of degrees of all nodes within community C, k_i_in represents the sum of edge weights between node i and nodes within community C, and k_i represents the degree of node i; the community cohesion optimization stage aggregates all nodes within the same community into a supernode, uses the sum of edge weights within the community as the self-loop weight of the supernode, and uses the sum of edge weights between communities as the edge weights between supernodes, constructing a new community network for the next iteration.

[0029] S600. Generate a risk warning signal based on the accurate characterization result of the risk event and the preset dynamic warning rule engine, feed the risk event and accurate characterization result back to the multi-level risk identification model for incremental learning and updating, and update the warning threshold of the address tag library and the dynamic warning rule engine based on the risk warning signal. The multi-level risk identification model in this embodiment of the invention includes an address-level risk identification sub-model, an account-level risk identification sub-model, an institution-level risk identification sub-model, and an industry-level risk identification sub-model. Each level of risk identification sub-model extracts a risk feature vector corresponding to its level. The risk feature vector includes transaction pattern features, capital flow features, temporal behavior features, and network topology features. A hierarchical risk propagation model based on graph neural networks is adopted to transmit and aggregate the risk identification results of lower levels to higher levels, realizing cross-level risk correlation reasoning. Based on the results of the cross-level risk correlation reasoning, risk events are accurately characterized. The accurate characterization includes identifying the triggering entity of the risk event, tracing the risk propagation path, assessing the scope of risk impact, and determining the risk type. According to the accurate characterization results of the risk event and a preset dynamic early warning rule engine, a risk early warning signal is generated. The early warning threshold of the dynamic early warning rule engine is dynamically adjusted according to the real-time status of the blockchain network and the statistical distribution of historical risk events. According to the accurate characterization results of the risk event, the preset dynamic early warning rule engine generates a risk early warning signal. The process of constructing a multi-level risk identification model and identifying risk events, then passing and aggregating the risk identification results from lower levels to higher levels to obtain cross-level risk correlation reasoning results, and finally accurately characterizing risk events to obtain accurate characterization results, includes the following steps: A multi-level risk identification model is constructed based on graph neural networks. The multi-level risk identification model includes an intra-level graph attention layer and an inter-level graph attention layer. The hierarchical graph attention layer is used for message passing and aggregation of risk features between nodes within the same level. It uses a graph attention mechanism to calculate the attention weights of neighboring nodes to the current node within the same level. The attention weights are calculated based on the node feature vector and the edge feature vector. The inter-level graph attention layer is used to transmit and aggregate risk features between nodes at different levels. Risk features at lower levels are transmitted to the parent node at the upper level through entity affiliation and holding relationships, and risk features at upper levels are fed back to the child nodes at the lower level through entity affiliation and holding relationships. The multi-level risk identification model employs residual connections and layer normalization techniques to avoid gradient vanishing and representation degradation problems in deep networks. By utilizing the intermediate layer output of the multi-level risk identification model, and through backpropagation and gradient significance analysis, the set of nodes and edges that contribute the most to risk judgment are located, forming an accurate characterization of risk events, which serves as the basis for tracking risk propagation paths.

[0030] Furthermore, the accurate characterization of the risk event is obtained by judging and identifying the risk event based on the results of the correlation reasoning of the multi-level risk identification model; The identification process includes identifying the triggering entity of the risk event, tracing the propagation path of the risk event, assessing the scope of the risk event's impact, and determining the type of the risk event. The precise characterization results include risk event ID, triggering entity address, list of involved accounts, propagation path node sequence, impact scope level identifier, risk type label, risk level score, and timestamp; Based on the accurate characterization results and the preset dynamic early warning rule engine, it is determined whether the early warning triggering conditions are met. When the early warning triggering conditions are met, a risk early warning signal is generated, which includes the early warning level, early warning content, a list of affected entities, and suggested handling measures. The risk early warning signal is then distributed to each blockchain node and regulatory node through the P2P broadcast mechanism of the blockchain network.

[0031] Furthermore, in this embodiment, the identified risk events and their precise characterization results are used as new labeled samples and fed back to the fine-grained attribute recognition model, the entity alignment model, and the multi-level risk recognition model for incremental learning and updating. The incremental learning and updating adopts an elastic weight consolidation method, which constrains the variation range of important parameters while updating the model parameters to avoid catastrophic forgetting. At the same time, the warning thresholds of the address tag library and the dynamic warning rule engine are updated based on the risk warning signal.

[0032] In summary, this invention employs a dual-track on-chain and off-chain data acquisition mechanism to ensure data comprehensiveness; fine-grained attribute identification utilizes address tag library matching and a heuristic rule engine to achieve multi-dimensional labeling of address entities; complex entity relationship graph construction uses a directed weighted heterogeneous graph structure, with a time decay factor to give higher weight to recent transactions; multi-source entity relationship fusion uses a graph attention network to achieve cross-source entity alignment; graph mining and community discovery employ the Leuven algorithm for multi-level community segmentation; dynamic self-reinforcing multi-level risk identification constructs a four-level risk identification model and uses a hierarchical graph attention network for cross-level inference; dynamic self-reinforcing and model updating employ an elastic weight consolidation method to achieve incremental learning, wherein the dynamic self-reinforcing and model updating module uses the elastic weight consolidation method for incremental learning updates, and the elastic weight consolidation method calculates the weight of model parameters in historical training tasks. To enhance the importance of parameters, additional regularization constraints are applied to changes in important parameters when updating model parameters. The parameter importance is estimated using the diagonal elements of the Fisher information matrix, which is calculated based on the squared gradient of the model on historical training data. The loss function for incremental learning updates can be calculated using the formula L_total=L_current+Σ_i(λ / 2)·F_i·(θ_i-θ_i^)², where L_current is the loss function for the current training task, λ is a preset regularization coefficient, F_i is the estimated value of the diagonal elements of the Fisher information matrix for the i-th parameter, θ_i is the current parameter value, and θ_i^ is the parameter value after the completion of the historical training task. The warning threshold update of the dynamic warning rule engine is based on the risk level score distribution of newly identified risk events, and the threshold of each warning level is dynamically adjusted using a quantile adaptive method.

[0033] Example 2: A blockchain-based dynamic risk identification system, such as Figure 2 As shown, it includes: The data acquisition and preprocessing module 100 acquires blockchain network data in real time and preprocesses it to obtain standardized multi-source heterogeneous data. The blockchain network data includes on-chain transaction data, smart contract bytecode data, block metadata, and off-chain related data. The attribute recognition module 200, based on the standardized multi-source heterogeneous data, uses a preset address tag library and heuristic rule engine to perform fine-grained attribute recognition on address entities in the blockchain network, and associates and stores the recognized fine-grained attributes with the corresponding address entities to form an entity set with attribute annotations. The entity relationship graph construction module 300 constructs an initial blockchain transaction relationship graph based on the address entities in the attribute-annotated entity set as graph nodes and the transaction interaction relationships between address entities as edges. The community discovery module 400 acquires off-chain entity relationship data and merges it with the initial blockchain transaction relationship graph to generate a multi-level blockchain entity relationship graph and perform multi-level community discovery. The nodes in the multi-level blockchain entity relationship graph are divided into several community clusters to obtain the community discovery results. The risk event identification module 500, based on the results discovered by the community and the multi-level blockchain entity relationship graph, constructs a multi-level risk identification model and identifies risk events. It transmits and aggregates the risk identification results of the lower level to the upper level to obtain the results of cross-level risk association reasoning, and accurately characterizes the risk events to obtain accurate characterization results. The feedback update module 600 generates a risk warning signal based on the accurate characterization result of the risk event and the preset dynamic warning rule engine, feeds back the risk event and accurate characterization result to the multi-level risk identification model for incremental learning and updating, and updates the warning threshold of the address tag library and the dynamic warning rule engine based on the risk warning signal.

[0034] The above description of the embodiments is provided to enable those skilled in the art to understand and apply the present invention. It will be apparent to those skilled in the art that various modifications can be made to the above embodiments, and the general principles described herein can be applied to other embodiments without inventive effort. Therefore, the present invention is not limited to the above embodiments, and any improvements and modifications made to the present invention by those skilled in the art based on the disclosure thereof should be within the scope of protection of the present invention.

Claims

1. A method for dynamic risk identification in blockchain, characterized in that, Includes the following steps: Real-time collection and preprocessing of blockchain network data yields standardized multi-source heterogeneous data, including on-chain transaction data, smart contract bytecode data, block metadata, and off-chain related data. Based on the standardized multi-source heterogeneous data, a preset address tag library and heuristic rule engine are used to perform fine-grained attribute identification on address entities in the blockchain network. The identified fine-grained attributes are associated and stored with the corresponding address entities to form a set of entities with attribute labels. Using the address entities in the attribute-annotated entity set as graph nodes and the transaction interaction relationships between address entities as edges, an initial blockchain transaction relationship graph is constructed. The off-chain entity relationship data is acquired and merged with the initial blockchain transaction relationship graph to generate a multi-level blockchain entity relationship graph and perform multi-level community discovery. The nodes in the multi-level blockchain entity relationship graph are divided into several community clusters to obtain the community discovery results. Based on the results of the community discovery and the multi-level blockchain entity relationship graph, a multi-level risk identification model is constructed and risk events are identified. The risk identification results of the lower level are transmitted and aggregated to the upper level to obtain the results of cross-level risk association reasoning. The risk events are then accurately characterized to obtain accurate characterization results. Based on the accurate characterization results of the risk event and the preset dynamic early warning rule engine, a risk warning signal is generated. The risk event and the accurate characterization results are fed back to the multi-level risk identification model for incremental learning and updating. The warning thresholds of the address tag library and the dynamic early warning rule engine are updated based on the risk warning signal.

2. The blockchain dynamic risk identification method according to claim 1, characterized in that, The heuristic rule engine includes address classification rules based on transaction frequency, address classification rules based on transaction amount distribution, address classification rules based on contract call patterns, and address classification rules based on time series behavior. The address tag library adopts a key-value pair storage structure, where the key is the address hash value and the value is a set of type tags and attribute tags for the address. The address tag library is constructed and updated through a combination of manual and automatic annotation. The address classification rule based on transaction frequency divides addresses into active transaction addresses and passive receiving addresses according to the ratio of the number of transactions initiated to the number of transactions received within a preset time window. The address classification rule based on transaction amount distribution divides addresses into large-transaction addresses and small-transaction addresses according to the statistical characteristics of the mean, variance, quantiles and extreme values ​​of the transaction amount. The address classification rule based on contract call patterns identifies the contract interaction behavior pattern of an address by analyzing the function selection subsequence in the smart contract call sequence initiated by the address. The function selection subsequence includes the first 4 bytes of the Keccak-256 hash value of the smart contract function signature. The address classification rules based on time-series behavior identify automated and manual transaction behavior patterns of addresses by performing periodicity and burst detection on the transaction time interval sequence of the address.

3. The blockchain dynamic risk identification method according to claim 1, characterized in that, The initial blockchain transaction graph adopts a directed weighted heterogeneous graph structure, where the edge weights are calculated based on transaction amount, transaction frequency, and a time decay factor. The time decay factor uses an exponential decay function, ensuring that recent transactions have higher weights than historical transactions. The edge weights are expressed as follows: W(u,v,t)=α·A(u,v)+β·F(u,v,Δt)+γ·D(Δt) Where u and v represent the sender and receiver addresses of the transaction, respectively, and t represents the timestamp of the transaction; A(u,v) represents the cumulative transaction amount between addresses u and v within a preset historical time window, after logarithmic normalization; F(u,v,Δt) represents the transaction frequency between addresses u and v within the preset historical time window, where Δt represents the time difference between the current transaction time and the most recent historical transaction time, and F is obtained by time-weighting the historical transaction frequency using an exponential decay function; D(Δt) represents the time decay factor, calculated using the formula D(Δt)=exp(-λ·Δt), where λ is the preset time decay coefficient; α, β, and γ are preset weight coefficients, satisfying α+β+γ=1; the node attributes in the directed weighted heterogeneous graph include the fine-grained attributes of the address entities, and the edge attributes include transaction amount, transaction timestamp, transaction gas consumption, and transaction type identifier.

4. The blockchain dynamic risk identification method according to claim 1, characterized in that, The process of acquiring off-chain entity relationship data and integrating it with the initial blockchain transaction relationship graph to generate a multi-level blockchain entity relationship graph includes the following steps: An entity alignment model is constructed based on a graph attention network. The entity alignment model calculates the similarity between the attribute feature vectors of on-chain address entities and the attribute feature vectors of off-chain entities, and performs joint optimization by combining graph structure context information. The entity alignment model includes an encoding layer, an attention layer, an alignment layer, and a verification layer. The encoding layer uses a graph convolutional network to encode the attributes and graph structure of the on-chain address entities, generating low-dimensional embedding vectors of the on-chain address entities. At the same time, a text encoder is used to encode the descriptive text of the off-chain entities, generating low-dimensional embedding vectors of the off-chain entities. The attention layer uses a multi-head attention mechanism to calculate the cross-modal attention weights between on-chain address entities and off-chain entities. The number of heads in the multi-head attention mechanism is a preset value. Each attention head independently calculates the semantic similarity between entities, and the outputs of multiple heads are concatenated or averaged. The alignment layer constructs candidate alignment relationships between on-chain address entities and off-chain entities based on the cross-modal attention weights and semantic similarity between entities, and filters candidate alignment relationships using a preset similarity threshold. The verification layer uses a blockchain consensus mechanism or a manual review mechanism to verify the selected candidate alignment relationships, and adds the verified alignment relationships to the multi-level blockchain entity relationship graph.

5. The blockchain dynamic risk identification method according to claim 1, characterized in that, The multi-level community discovery is implemented based on the Leuven algorithm with modularity optimization; The Leuven algorithm includes a first stage of node movement optimization and a second stage of community cohesion optimization. The first stage iteratively moves nodes to neighboring communities that maximize their modularity gain. The second phase consolidates the communities formed in the first phase into supernodes and builds a new community network. The first and second phases are executed alternately until the modularity no longer increases. During the community discovery process, risk labels are applied to different communities based on the fine-grained attributes. These risk labels include high-risk trading communities, high-risk contract communities, and high-risk associated communities. All nodes within the same community are aggregated into a supernode. The sum of edge weights within a community is used as the self-loop weight of the supernode, and the sum of edge weights between communities is used as the edge weight between supernodes. A new community network is then constructed for the next iteration.

6. The blockchain dynamic risk identification method according to claim 1, characterized in that, The process of constructing a multi-level risk identification model and identifying risk events, then passing and aggregating the risk identification results from lower levels to higher levels to obtain cross-level risk correlation reasoning results, and finally accurately characterizing risk events to obtain precise characterization results, includes the following steps: A multi-level risk identification model is constructed based on graph neural networks. The multi-level risk identification model includes an intra-level graph attention layer and an inter-level graph attention layer. The hierarchical graph attention layer is used for message passing and aggregation of risk features between nodes within the same level. It uses a graph attention mechanism to calculate the attention weights of neighboring nodes to the current node within the same level. The attention weights are calculated based on the node feature vector and the edge feature vector. The inter-level graph attention layer is used to transmit and aggregate risk features between nodes at different levels. Risk features at lower levels are transmitted to the parent node at the upper level through entity affiliation and holding relationships, and risk features at upper levels are fed back to the child nodes at the lower level through entity affiliation and holding relationships. The multi-level risk identification model employs residual connections and layer normalization techniques to avoid gradient vanishing and representation degradation problems in deep networks. By utilizing the intermediate layer output of the multi-level risk identification model, and through backpropagation and gradient significance analysis, the set of nodes and edges that contribute the most to risk judgment are located, forming an accurate characterization of risk events, which serves as the basis for tracking risk propagation paths.

7. The blockchain dynamic risk identification method according to claim 6, characterized in that, The accurate characterization of the risk event is obtained by judging and identifying the risk event based on the correlation reasoning results of the multi-level risk identification model; The identification process includes identifying the triggering entity of the risk event, tracing the propagation path of the risk event, assessing the scope of the risk event's impact, and determining the type of the risk event. The precise characterization results include risk event ID, triggering entity address, list of involved accounts, propagation path node sequence, impact scope level identifier, risk type label, risk level score, and timestamp; Based on the accurate characterization results and the preset dynamic early warning rule engine, it is determined whether the early warning triggering conditions are met. When the early warning triggering conditions are met, a risk early warning signal is generated, which includes the early warning level, early warning content, a list of affected entities, and suggested handling measures. The risk early warning signal is then distributed to each blockchain node and regulatory node through the P2P broadcast mechanism of the blockchain network.

8. A blockchain dynamic risk identification system, characterized in that, include: The data acquisition and preprocessing module collects blockchain network data in real time and preprocesses it to obtain standardized multi-source heterogeneous data. The blockchain network data includes on-chain transaction data, smart contract bytecode data, block metadata, and off-chain related data. The attribute recognition module, based on the standardized multi-source heterogeneous data, uses a preset address tag library and heuristic rule engine to perform fine-grained attribute recognition on address entities in the blockchain network, and associates and stores the recognized fine-grained attributes with the corresponding address entities to form an attribute-labeled entity set. The entity relationship graph construction module constructs an initial blockchain transaction relationship graph based on the address entities in the attribute-annotated entity set as graph nodes and the transaction interaction relationships between address entities as edges. The community discovery module acquires off-chain entity relationship data and merges it with the initial blockchain transaction relationship graph to generate a multi-level blockchain entity relationship graph and perform multi-level community discovery. The nodes in the multi-level blockchain entity relationship graph are divided into several community clusters to obtain the community discovery results. The risk event identification module, based on the results discovered by the community and the multi-level blockchain entity relationship graph, constructs a multi-level risk identification model and identifies risk events. It then transmits and aggregates the risk identification results of the lower level to the upper level to obtain the results of cross-level risk association reasoning and accurately characterizes the risk events to obtain accurate characterization results. The feedback update module generates a risk warning signal based on the accurate characterization result of the risk event and the preset dynamic warning rule engine, feeds back the risk event and accurate characterization result to the multi-level risk identification model for incremental learning and updating, and updates the warning threshold of the address tag library and the dynamic warning rule engine based on the risk warning signal.

9. A blockchain dynamic risk identification device, characterized in that, The apparatus includes: at least one memory; at least one processor; and a communication interface; wherein when the processor executes program instructions stored in the memory, it jointly invokes the communication interface to execute all the steps described in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the method as described in any one of claims 1 to 7.