Dan Lin 0007

dblp:181/2634-7 · DBLP profile ↗
← Back
21ranked-venue papers
6as first author
21since 2021 · last 2026
0000-0001-7067-2396ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 2 first-author · 6 since 2021Systems, architecture and hardware · 5 · 5 since 2021Software engineering, systems software and programming languages · 4 · 1 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 first-author · 4 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-author · 2 since 2021
YearPublicationVenuePosition
2026 PonziHunter: Hunting Ethereum Ponzi Contract via Static Analysis and Contrastive Learning on the Bytecode Level
abstract
In recent years, blockchain technology has developed rapidly and received widespread attention. However, its pseudonymous and decentralized nature has also attracted many criminal activities. Ponzi schemes, a kind of classic financial scam, also hide their true face in smart contracts, causing massive financial losses to blockchain users. Although several methods have been proposed to detect Ponzi contracts, there are still limitations in broad applicability, semantics understanding, and adversarial robustness. In this article, we propose PonziHunter, an intelligent framework for hunting Ponzi contracts on Ethereum. To tackle the problem of broad applicability, we train a detection model that does not require expert experience based on publicly available on-chain bytecode and off-chain contract labels. To tackle the problem of semantics understanding, we employ cross-function control flows and state variable dependencies to understand the logic of Ponzi contracts. Specifically, we decompile bytecodes into higher-order representations to analyze control flows and state variable dependencies and model the information as graph data. By combining the idea of code slicing, we identify the basic blocks related to Ponzi contract recognition. To tackle the problem of adversarial robustness, we model Ponzi contract recognition as a graph classification problem based on contrastive pre-training. We propose a data augmentation method for control flow graphs (CFGs), which preserves the basic blocks related to Ponzi contract recognition as much as possible during data perturbation. Experimental results show that PonziHunter outperforms state-of-the-art tools with average improvements of at least 4.77% on real-world ground-truth data and can newly discover 85 Ponzi contracts in the wild. More importantly, PonziHunter is robust against adversarial examples and can locate the critical basic blocks for smart Ponzi detection.
Jinze Chen, Jieli Liu, Jianlin Wu, Dan Lin 0007, Jiajing Wu, Zibin Zheng
ACM Trans. Softw. Eng. Methodol.4
2025 Safeguarding Blockchain Ecosystem: Understanding and Detecting Attack Transactions on Cross-chain Bridges
abstract
Cross-chain bridges are essential decentralized applications (DApps) to facilitate interoperability between different blockchain networks. Unlike regular DApps, the functionality of cross-chain bridges relies on the collaboration of information both on and off the chain, which exposes them to a wider risk of attacks. According to our statistics, attacks on cross-chain bridges have resulted in losses of nearly 4.3 billion since 2021. Therefore, it is particularly necessary to understand and detect attacks on cross-chain bridges. In this paper, we collect the largest number of cross-chain bridge attack incidents to date, including 49 attacks that occurred between June 2021 and September 2024, of which 22 were attacks on cross-chain bridge business logic. Our analysis reveal that attacks against cross-chain business logic cause significantly more damage than those that do not. These cross-chain attacks exhibit different patterns compared to normal transactions in terms of call structure, which effectively indicates potential attack behaviors. Given the significant losses in these cases and the scarcity of related research, this paper aims to detect attacks against cross-chain business logic, and propose the BridgeGuard tool. Specifically, BridgeGuard models cross-chain transactions from a graph perspective, and employs a two-stage detection framework comprising global and local graph mining to identify attack patterns in cross-chain transactions. We conduct multiple experiments on the datasets with 203 attack transactions and 40,000 normal cross-chain transactions. The results show that BridgeGuard's reported recall score is 36.32% higher than that of state-of-the-art tools and can detect unknown attack transactions.
Jiajing Wu, Kaixin Lin, Dan Lin 0007, Bozhao Zhang, Zhiying Wu, Jianzhong Su
WWW3
2025 RiskProp: Account Risk Rating on Ethereum via De-anonymous Score and Network Propagation
abstract
As one of the most popular blockchain platforms supporting smart contracts, Ethereum has caught the interest of both investors and criminals. Differently from traditional financial scenarios, executing Know Your Customer verification on Ethereum is rather difficult due to its pseudonymous nature. Fortunately, as the transaction records stored in the Ethereum blockchain are publicly accessible, we can understand the behavior of accounts or detect illicit activities via transaction mining. Existing risk control techniques have primarily been developed from the perspectives of de-anonymizing address clustering and illicit account classification. However, these techniques cannot ascertain the potential risks for all accounts and are limited by specific heuristic strategies or insufficient label information. These constraints motivate us to seek an effective rating method for quantifying the spread of risk in a transaction network. To the best of our knowledge, we are the first to address the problem of account risk rating on Ethereum by proposing a novel model calledRiskProp, which includes a de-anonymous score to measure transaction anonymity and a network propagation mechanism to formulate the relationships between accounts and transactions. Experimental results on a realistic Ethereum dataset demonstrate that proposedRiskPropnewly discovered 63% of the Top 150 high-risk accounts as suspicious. The superior performance of risk score-based account classification experiments further verifies the effectiveness of our rating method (85.63% accuracy).
Dan Lin 0007, Jiajing Wu, Qishuang Fu, Zibin Zheng, Ting Chen 0002
IEEE Trans. Dependable Secur. Comput.1
2025 Connector: Enhancing the Traceability of Decentralized Bridge Applications via Automatic Cross-Chain Transaction Association
abstract
Decentralized bridge applications are important software that connects various blockchains and facilitates cross-chain asset transfer in the decentralized finance (DeFi) ecosystem which currently operates in a multi-chain environment. Cross-chain transaction association identifies and matches unique transactions executed by bridge DApps, which is important research to enhance the traceability of cross-chain bridge DApps. However, existing methods rely entirely on unobservable internal ledgers or APIs, violating the open and decentralized properties of blockchain. In this paper, we analyze the challenges of this issue and then present CONNECTOR, an automated cross-chain transaction association analysis method based on bridge smart contracts. Specifically, CONNECTOR first identifies deposit transactions by extracting distinctive and generic features from the transaction traces of bridge contracts.With the accurate deposit transactions, CONNECTOR mines the execution logs of bridge contracts to achieve withdrawal transaction matching. We conduct real-world experiments on different types of bridges to demonstrate the effectiveness of CONNECTOR. The experiment demonstrates that CONNECTOR successfully identifies 100% deposit transactions, associates 95.95% withdrawal transactions, and surpasses methods for CeFi bridges. Based on the association results, we obtain interesting findings about cross-chain transaction behaviors in DeFi bridges and analyze the tracing abilities of CONNECTOR to assist the DeFi bridge apps.
Dan Lin 0007, Jiajing Wu, Yuxin Su 0001, Ziye Zheng, Yuhong Nan, Qinnan Zhang, Zibin Zheng
IEEE Trans. Inf. Forensics Secur.1
2025 Track and Trace: Automatically Uncovering Cross-Chain Transactions in the Multi-Blockchain Ecosystems
abstract
Cross-chain technology enables seamless asset transfer and message-passing within decentralized finance (DeFi) ecosystems, facilitating multi-chain coexistence in the current blockchain environment. However, this development also raises security concerns, as malicious actors exploit cross-chain asset flows to conceal the provenance and destination of assets, thereby facilitating illegal activities such as money laundering. Consequently, the need for cross-chain transaction traceability has become increasingly urgent. Prior research on transaction traceability has predominantly focused on single-chain and centralized finance (CeFi) cross-chain scenarios, overlooking DeFi-specific considerations. This paper proposesABCTracer, an automated, bi-directional cross-chain transaction tracing tool, specifically designed for DeFi ecosystems. By harnessing transaction event log mining and named entity recognition techniques,ABCTracerautomatically extracts explicit cross-chain cues. These cues are then combined with information retrieval techniques to encode implicit cues.ABCTracerfacilitates the autonomous learning of latent associated information and achieves bidirectional, generalized cross-chain transaction tracing. Our experiments on 12 mainstream cross-chain bridges demonstrate thatABCTracerattains 91.75% bi-directional traceability (F1 metrics) with self-adaptive capability. Furthermore, we applyABCTracerto real-world cross-chain attack transactions and money laundering traceability, thereby bolstering the traceability and blockchain ecological security of DeFi bridging applications.
Dan Lin 0007, Ziye Zheng, Jiajing Wu, Kaixin Lin, Zibin Zheng
IEEE Trans. Serv. Comput.1
2025 Who Is Pulling the Strings: Unveiling Smart Contract State Manipulation Attacks Through State-Aware Dataflow Analysis
Shuo Yang 0012, Jiachi Chen, Lei Xiao 0015, Jinyuan Hu, Dan Lin 0007, Jiajing Wu, Tao Zhang 0001, Zibin Zheng
IEEE Trans. Software Eng.5
2025 Malo in the Code Jungle: Explainable Fault Localization for Decentralized Applications
abstract
Decentralized applications (DApps) have long been sitting ducks for hackers due to their valuable cryptocurrency assets, exposing them to various security risks. When a DApp is attacked, promptly identifying faults is crucial to minimizing financial losses and ensuring effective fault repair. However, existing fault localization methods, which mostly rely on code coverage, often fall short for DApps, particularly when dealing with only one fault case. Furthermore, according to a prior survey, most developers expect fault localization tools to provide reasonable explanations.In this paper, we present Malo, a method for DApp-specific explainable fault localization. It identifies fault functions throughsuspicious token transfer-guided analysis, and then employs Large Language Models (LLMs) to generate explanations for these identified fault functions. Specifically, Malo examines function call traces and source codes of fault cases to acquireinternal knowledge, and also retrieves relevant project documents from the Web to obtainexternal knowledge. By integrating internal and external knowledge, Malo generates reasonable explanations for faults in DApps. Our evaluation on a dataset of 68 real-world DApp faults demonstrates that Malo can locate 62% of faults within the Top-5, 9% higher than the state-of-the-art method. The experiment results also demonstrate a remarkable alignment accuracy of 71% between the explanations generated by Malo and the ground truth. In addition, we conduct a user study, which confirms that explanations generated by Malo can aid developers in comprehending the root cause of faults. Our code and dataset are available online: https://github.com/SodalimeZero/Malo_Code.git.
Hui Zhang 0002, Jiajing Wu, Zhiying Wu, Dan Lin 0007, Jiachi Chen, Zibin Zheng
IEEE Trans. Software Eng.5
2024 XSema: A Novel Framework for Semantic Extraction of Cross-chain Transactions
abstract
As the number of blockchain platforms continues to grow, the independence of these networks poses challenges for transferring assets and information across chains. Cross-chain bridge technology has emerged to address this issue, establishing communication protocols to facilitate cross-chain interaction of assets and information, thereby enhancing user experience. However, the complexity of cross-chain transactions increases the difficulty of security regulation, rendering traditional single-chain detection methods inadequate for cross-chain scenarios. Therefore, understanding cross-chain transaction semantics is crucial, as it forms the foundation for cross-chain security detection tasks. Although there are existing methods for extracting transaction semantics specifically for single chains, these approaches often overlook the unique characteristics of cross-chain scenarios, limiting their applicability. This paper introduces XSema, a novel cross-chain semantic extraction framework grounded in asset transfer and message-passing, designed specifically for cross-chain contexts. Experimental results demonstrate that XSema effectively distinguishes between cross-chain and non-cross-chain transactions, surpassing existing methods by over 9% for the generality metric and over 10% for the generalization metric. Furthermore, we analyze the underlying asset transfer patterns and message-passing event logs associated with cross-chain transactions. We offer new insights into the coexistence of multiple blockchains and the cross-chain ecosystem.
Ziye Zheng, Jiajing Wu, Dan Lin 0007, Quanzhong Li 0001, Na Ruan
HPCC3
2024 Detecting Fake Deposit Attacks on Cross-chain Bridges from a Network Perspective
abstract
Cross-chain bridges are currently the most popular solution to support asset interoperability between heterogeneous blockchains. Over the past year, there have been more than ten serious attacks against cross-chain bridges, resulting in billions of dollars in losses. Among these attacks, fake deposits stand out as particularly destructive. Hackers can perpetrate such attacks by verifying the authenticity of proof associated with fake deposits on the target blockchain, subsequently pilfering the assets. However, existing tools have limitations in detecting this type of attack. To address this problem, this work proposes a tool to protect cross-chain bridges from fake deposit attacks by analyzing the network of transaction traces. Specifically, the framework first records the execution traces for each transaction, and then extracts the relevant contract interactions therein to extract statistical and structural features. Finally, real case labels are utilized to identify attacking and non-attacking transactions. We conducted experiments to validate the tool’s effectiveness and efficiency. In particular, for the detection of fake deposit transactions, our method achieved an average precision of 0.89, a recall value of 0.83, and the ability to identify 38.65 transactions per second.
Kaixin Lin, Dan Lin 0007, Ziye Zheng, Yixiang Tan, Jiajing Wu
ISCAS2
2024 DenseFlow: Spotting Cryptocurrency Money Laundering in Ethereum Transaction Graphs
abstract
In recent years, money laundering crimes on blockchain, especially on Ethereum, have become increasingly rampant, resulting in substantial losses. The unique features of money laundering on Ethereum, such as decentralization and pseudonymity, pose new challenges for Ethereum anti-money laundering. Specifically, the existence of dense and extensive laundering gangs and intricate multilayered laundering pathways makes it exceptionally challenging for regulators to identify suspicious accounts and trace money flows. To address this issue, we propose an innovative DenseFlow framework that effectively identifies and traces money laundering activities by finding dense subgraphs and applying the maximum flow idea. We conduct multiple experiments on four datasets from Ethereum to validate the effectiveness of our approach. The precision of our DenseFlow is 16.34% higher than the start-of-the-art comparison methods on average, highlighting its distinctive contribution to tackling money laundering issues on blockchain.
Dan Lin 0007, Jiajing Wu, Yunmei Yu, Qishuang Fu, Zibin Zheng, Changlin Yang
WWW1
2024 A General Framework for Account Risk Rating on Ethereum: Toward Safer Blockchain Technology
abstract
As the largest blockchain platform that supports smart contracts, Ethereum has attracted wide attention from both academia and industry in recent years. Along with the prosperous development of Ethereum, the high-risk illegal practices on it are becoming more and more rampant, seriously jeopardizing the system’s trading security and long-term development. Therefore, the detection and quantification of account risk are of great importance for both cryptocurrency investors and blockchain security researchers. In this article, we propose the first general framework for account risk rating on Ethereum, which includes a devisable suspiciousness metric to adapt to various illicit fraud detection and a network propagation mechanism to formulate the relations between accounts and transactions. By conducting extensive experiments on a real-world dataset from Ethereum, we show the universality of the account risk rating framework. Particularly, statistical analyses on different risk levels of accounts demonstrate that the risk rating framework has access to detect various illicit accounts. And the metric analysis of risk rating results put forward some insights. Moreover, visualization of a suspicious transaction chain reveals the process of illicit activities on Ethereum, enabling investors to obtain an understanding of the risky accounts and avoid significant financial losses.
Qishuang Fu, Dan Lin 0007, Jiajing Wu, Zibin Zheng
IEEE Trans. Comput. Soc. Syst.2
2024 Toward Understanding Asset Flows in Crypto Money Laundering Through the Lenses of Ethereum Heists
abstract
With the overall momentum of the blockchain industry, financial crimes related to blockchain crypto-assets are becoming increasingly prevalent. After committing a crime, the main goal of cybercriminals is to obfuscate the source of the illicit funds in order to convert them into cash and get away with it. Many studies have analyzed money laundering (ML) in the field of the traditional financial sector. However, in terms of the emerging blockchain crypto-asset ecosystem, there is currently only one public anti-money laundering (AML) dataset for Bitcoin– the Elliptic dataset, whose binary labels (licit vs. illicit transactions) cannot cover the ML behaviors in the evergrowing crypto-asset market. To fill this gap, in this paper, we propose a framework named XBlockFlow which identifies ML addresses starting from Ethereum heist incidents and obtains the first detailed Ethereum ML dataset named$\textit {EthereumHeist}$, and then conducts a comprehensive feature and evolution analysis on the$\textit {EthereumHeist}$dataset according to the three main phases of ML. We first search for the source cybercriminal accounts including exchange hackers, DeFi exploiters, and scammers. Then, employing the idea of taint analysis, we track the diverse downstream transactions and addresses layer by layer. At the end of tracking, we identify and categorize service providers, and go a step further to investigate advanced ML methods that do not exist in the Bitcoin scenario, e.g. token swap and counterfeit token creation. Based on the ML identification results, we obtain many interesting findings about crypto-asset money laundering, observing the escalating money laundering methods such as creating counterfeit tokens and masquerading as speculators.
Jiajing Wu, Dan Lin 0007, Qishuang Fu, Shuo Yang 0012, Ting Chen 0002, Zibin Zheng
IEEE Trans. Inf. Forensics Secur.2
2024 Who Stole My NFT? Investigating Web3 NFT Phishing Scams on Ethereum
abstract
With the popularity of Non-Fungible Tokens (NFTs), the high value of NFTs makes them a target for phishing scammers, which harms the security and reliability of the Web3 NFT ecosystem. Despite the significance of this issue, there is a lack of systematic research in the area of emerging NFT phishing scams. To address this gap, we are the first to conduct a case retrospective analysis and empirical measurement study of real-world historical NFT phishing scams on Ethereum. We collect and publicly release the first NFT phishing dataset which includes 1,625 NFT phishing accounts and transaction records as of August 2023. We further categorize the existing scams into four phishing patterns and investigate their distinguishable behaviors. Then, we reveal the modus operandi preferences and economic impacts to characterize NFT phishing scams. We find that NFT phishers stole 67,188 NFTs, with a total direct selling profit of${\$}$20.92 million. We also observe that scammers favor certain categories and collections of NFTs, coupled with signs of gang theft. Furthermore, we design a variety of account features for the classification task of NFT phishers based on empirical conclusions. Experimental results on real-world NFT transaction data demonstrate the effectiveness of these features in detecting NFT phishing accounts, and outperform traditional phishing detection methods with 41% average Precision and 44% average Recall.
Jieli Liu, Dan Lin 0007, Jiajing Wu, Baoying Huang, Quanzhong Li 0001, Zibin Zheng
IEEE Trans. Inf. Forensics Secur.3
2024 2DynEthNet: A Two-Dimensional Streaming Framework for Ethereum Phishing Scam Detection
abstract
In recent years, phishing scams have emerged as one of the most serious crimes on Ethereum. Existing phishing scam detection methods typically model public transaction records on the blockchain as a graph, and then identify phishing addresses through manual feature extraction or graph learning frameworks. Meanwhile, these methods model transactions within a period as a static network for analysis. Therefore, these methods lack the ability to capture fine-grained time dynamics, and on the other hand, they cannot handle the large-scale and continuously growing transaction data on the Ethereum blockchain, resulting in lower scalability and efficiency. In this paper, we propose a two-dimensional streaming framework 2DynEthNet for Ethereum phishing scam detection. First, we cast the transaction series into 6 slices according to block numbers, treating each as a separate task. In the first dimension, we treat transaction features as edge features instead of node features within one task, allowing each transaction to be streamed in 2DynEthNet, aiming to capture the evolutionary features of the Ethereum transaction network at a fine-grained level in continuous time. In the second dimension, we adopt the strategy of incremental information training between tasks, which utilizes meta-learning to quickly update the model parameters under new slices, thus effectively improving the scalability of the model. Finally, experimental results on large-scale real Ethereum phishing scam datasets show that our 2DynEthNet outperforms the state-of-the-art methods with 28.44% average Recall and achieves the most efficient training speed, proving the effectiveness of both temporal edge representation and meta-learning. In addition, we provide an Ethereum large-scale dynamic graph transaction dataset, ETGraph, which aligns with the data distribution in real transaction scenarios without sampling and filtering unlabeled accounts.
Wenjia Yu, Jiajing Wu, Dan Lin 0007, Zhiying Wu, Zibin Zheng
IEEE Trans. Inf. Forensics Secur.4
2024 Who is Who on Ethereum? Account Labeling Using Heterophilic Graph Convolutional Network
abstract
To combat cybercrimes and maintain financial security for the blockchain ecosystem, “know your customer” (KYC) is an essential and also challenging process due to the pseudonymity nature of blockchain technology. To unlock the potential of KYC on blockchain-based platforms like Ethereum, account labeling is a powerful means which can de-anonymize addresses by mining public transaction records. Existing studies on account labeling are mainly conducted via machine learning (ML) methods fed with hand-crafted features or graph neural networks based on the modeled transaction network. However, ML approaches based on hand-crafted features ignore the global interaction information between accounts, making it easy for criminals to evade detection. Moreover, the performance of traditional GCN methods when applied to Ethereum transaction network encounters limitations due to label sparsity, network heterophily, and large network size of the transaction network. In this article, we first analyze Ethereum accounts involved in typical businesses, in terms of both account and topological features. Then based on the analytical results, we propose a novel GCN method named know-your-customer graph convolutional network (KYC-GCN) which contains two key designs: 1) multihop aggregators and importance-based sampling are designed to tackle the dilemma between accuracy and efficiency. 2) GCN architecture is improved to explicitly capture local and more global information. Experimental results on a realistic Ethereum dataset show that the proposed KYC-GCN (90.2% accuracy, 86.2% Marco-F1) achieves state-of-the-art classification performance, and results on six benchmarks demonstrate that it yields great performance under homophily and heterophily.
Dan Lin 0007, Jiajing Wu, Tao Huang 0021, Kaixin Lin, Zibin Zheng
IEEE Trans. Syst. Man Cybern. Syst.1
2023 Money Laundering Detection on Ethereum: Applying Traditional Approaches to New Scene
abstract
With the continuous evolution of blockchain technology, cryptocurrency platforms such as Ethereum have emerged as centers for digital asset transactions and smart contracts deployment. However, this nascent financial ecosystem also introduces potential money laundering risks. The traditional financial industry has accumulated significant antimoney laundering (AML) experience and technical means for monitoring and detecting money laundering activities. Yet, the adaptability of these established AML algorithms in the context of blockchain remains unclear. This paper aims to investigate the practical adaptability of traditional AML algorithms on Ethereum data through empirical experiments. We gather eight real-world money laundering case datasets collected from Ethereum and conduct experiments using three traditional AML algorithms on these datasets. We evaluate the performance of these algorithms from various angles, including precision, recall, and the distribution of detected accounts' labels in comparison to the original datasets. It turns out algorithms demonstrate distinct performance in diverse money laundering cases, indicating that the adaptability of traditional AML algorithms on Ethereum data presents certain adaptability and limitations. Holoscope's accuracy demonstrates the value of dense subgraph properties in Ethereum money laundering detection, and further research can be conducted based on this model framework combined with the money laundering characteristics of Ethereum. Our study provides valuable insights for strengthening AML mechanisms on blockchain platforms and offers guidance for further research on detecting money laundering accounts in blockchain environments.
Yunmei Yu, Jiajing Wu, Dan Lin 0007, Qishuang Fu
ICPADS3
2023 Does Money Laundering on Ethereum Have Traditional Traits?
abstract
As the largest blockchain platform that supports smart contracts, Ethereum has developed with an incredible speed. Yet due to the anonymity of blockchain, the popularity of Ethereum has fostered the emergence of various illegal activities and money laundering by converting ill-gotten funds to cash. In the traditional money laundering scenario, researchers have uncovered the prevalent traits of money laundering. However, since money laundering on Ethereum is an emerging means, little is known about money laundering on Ethereum. To fill the gap, in this paper, we conduct an in-depth study on Ethereum money laundering networks through the lens of a representative security event on Upbit Exchange to explore whether money laundering on Ethereum has traditional traits. Specifically, we construct a money laundering network on Ethereum by crawling the transaction records of Upbit Hack. Then, we present five questions based on the traditional traits of money laundering networks. By leveraging network analysis, we characterize the money laundering network on Ethereum and answer these questions. In the end, we summarize the findings of money laundering networks on Ethereum, which lay the groundwork for money laundering detection on Ethereum.
Qishuang Fu, Dan Lin 0007, Yiyue Cao, Jiajing Wu
ISCAS2
2023 Ethereum Phishing Fraud Detection Based on Heterogeneous Transaction Subnets
abstract
As one of the most active blockchain platforms at present, Ethereum attracts a great deal of interest, including that of fraudsters. They exploit the anonymity of Ethereum accounts to perpetrate varieties of scams, the most common of which is phishing frauds. However, existing phishing detection work ignores the heterogeneity of Ethereum transaction edges. In fact, the activities on Ethereum include external transactions, internal transactions, and token transactions. Therefore, this paper proposes an Ethereum account phishing fraud detection method named HTSGCN. Based on heterogeneous transaction subnets, our method makes full use of the type and direction information contained in transactions. First, we collect Ethereum transaction data and construct a k-order heterogeneous subnet for each account. To aggregate the neighbor feature, we design a message propagation mechanism based on graph convolution network. Finally, we classify node representation vectors containing neighborhood and its own characteristics. Experimental results show that HTSGCN has a better effect on detecting phishing accounts than previous work which is based on homogeneous networks.
Baoying Huang, Jieli Liu, Jiajing Wu, Quanzhong Li 0001, Dan Lin 0007
ISCAS5
2022 Evolution of Ethereum Transaction Relationships: Toward Understanding Global Driving Factors From Microscopic Patterns
abstract
Much of the current research in Ethereum transaction records focuses on the statistical analysis and measurements of existing data; however, the evolution mechanism of Ethereum transactions is an important, yet seldom discussed issue. In this work, we first collect the transaction data of Ethereum and build network models from a microlevel view and then use a link-prediction-based framework to quantify the impact of network characteristics on Ethereum evolution. Next, we explore the graph structure properties and the driving factors of newly generated transaction relationships. Experimental results show that the local and microscopic structure of Ethereum networks is star-shaped, and the transaction frequency of addresses has a great impact on the evolution of Ethereum transaction relationships. First-layer nodes of microstructures dominate the network evolution. Moreover, the degree of addresses is an effective basis for predicting the direction of new transactions. Potential further studies on Ethereum transaction link prediction are discussed, for example, the label effect of center addresses.
Dan Lin 0007, Jialan Chen, Jiajing Wu, Zibin Zheng
IEEE Trans. Comput. Soc. Syst.1
2022 Who Are the Phishers? Phishing Scam Detection on Ethereum via Network Embedding
abstract
Recently, blockchain technology has become a topic in the spotlight but also a hotbed of various cybercrimes. Among them, phishing scams on blockchain have been found to make a notable amount of money, thus emerging as a serious threat to the trading security of the blockchain ecosystem. In order to create a favorable environment for investment, an effective method for detecting phishing scams is urgently needed in the blockchain ecosystem. To this end, this article proposes an approach to detect phishing scams on Ethereum by mining its transaction records. Specifically, we first crawl the labeled phishing addresses from two authorized websites and reconstruct the transaction network according to the collected transaction records. Then, by taking the transaction amount and timestamp into consideration, we propose a novel network embedding algorithm calledtrans2vecto extract the features of the addresses for subsequent phishing identification. Finally, we adopt the one-class support vector machine (SVM) to classify the nodes into normal and phishing ones. Experimental results demonstrate that the phishing detection method works effectively on Ethereum, and indicate the efficacy oftrans2vecover existing state-of-the-art algorithms on feature extraction for transaction networks. This work is thefirstinvestigation on phishing detection on Ethereum via network embedding and provides insights into how features of large-scale transaction networks can be embedded.
Jiajing Wu, Dan Lin 0007, Weili Chen, Chuan Chen 0001, Zibin Zheng
IEEE Trans. Syst. Man Cybern. Syst.3
2021 Deep Learning-Based Transaction Prediction in Ethereum
Zhuoming Gu, Dan Lin 0007, Jiatao Zheng, Jiajing Wu, Chaoxin Hu
BlockSys2