Zheng Che

dblp:335/1970 · DBLP profile ↗
← Back
5ranked-venue papers
1as first author
5since 2021 · last 2025
0009-0001-8575-7488ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 1 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Across-Platform Detection of Malicious Cryptocurrency Accounts via Interaction Feature Learning
abstract
With the rapid evolution of Web3.0, cryptocurrency has become a cornerstone of decentralized finance. While these digital assets enable efficient and borderless financial transactions, their pseudonymous nature has also attracted malicious activities such as money laundering, fraud, and other financial crimes. Effective detection of malicious accounts is crucial to maintaining the security and integrity of the Web 3.0 ecosystem. Existing malicious account detection methods rely on large amounts of labeled data and suffer from low generalization. Label-efficient and generalizable malicious account detection remains a challenging task. In this paper, we propose ShadowEyes, a framework for detecting malicious accounts by leveraging interaction feature learning with only a small labeled dataset. Specifically, We first propose a generalized account representation named TxGraph, which captures the universal interaction features of Ethereum and Bitcoin. Then we carefully design an account representation augmentation method tailored to simulate the evolution of malicious accounts to generate positive pairs. We conduct extensive experiments using public datasets to evaluate the performance of ShadowEyes. The results demonstrate that it outperforms state-of-the-art (SOTA) methods in four typical scenarios. Specifically, in the scenario of acrossplatform malicious account detection, ShadowEyes maintains an F1 score of around 90%, which is 10% higher than the SOTA method. In the zero-shot learning scenario, it can achieve an F1 score of 79.56% for detecting gambling accounts, surpassing the SOTA method by 10.44%.
Zheng Che, Meng Shen 0001, Zhehui Tan, Hanbiao Du, Wei Wang 0012, Ting Chen 0002, Qinglin Zhao, Yong Xie 0003, Liehuang Zhu
IEEE Trans. Inf. Forensics Secur.1
2025 Fine-Grained and Class-Incremental Malicious Account Detection in Ethereum via Dynamic Graph Learning
abstract
Ethereum serves as the cornerstone for value transfer in Web 3.0, providing a decentralized and efficient trust mechanism for global connectivity. However, the anonymity of Ethereum undermines market regulatory capabilities, leading to frequent malicious behaviors such as Ponzi Scheme, Money Laundering, and Phishing. Therefore, in the face of the diverse and continuously emerging malicious behaviors, implementing fine-grained detection is crucial for maintaining the prosperous development of the blockchain ecosystem. In this paper, we propose FiMAD, a fine-grained and class-incremental malicious account detection framework based on dynamic graph learning. Specifically, we first propose a general graph structure calledDynamic Account Relation Graph (DARG), which dynamically models Ethereum accounts from a continuous-time perspective. Then, we design a cascade graph feature extraction method to capture deep temporal evolution patterns and neighbor interaction features in DARG. Next, we construct a pre-training universal encoder to transform account features into high-dimensional embeddings, followed by fine-tuning the model classifier with a few labeled samples, enabling accurate fine-grained detection and rapid updates for incremental classes. We conduct extensive experiments using real Ethereum data. The results demonstrate that FiMAD outperforms state-of-the-art (SOTA) methods in fine-grained detection across five typical scenarios: class-incremental, full data, new malicious accounts, imbalanced data, and binary classification. In the class-incremental scenario, FiMAD improves the Macro-F1 by up to 26.4% compared to SOTA methods.
Hanbiao Du, Meng Shen 0001, Yang Liu 0171, Zheng Che, Jinhe Wu, Wei Wang 0012, Liehuang Zhu
IEEE Trans. Inf. Forensics Secur.4
2024 Breaking the Anonymity of Ethereum Mixing Services Using Graph Feature Learning
abstract
With the property of helping users further enhance the anonymity of transactions, mixing services in blockchain have gained wide popularity in recent years. However, the strong untraceability offered by mixing services has led to the abuse of them by criminals for money laundering and committing fraud. These illegal actions pose significant threats to the blockchain ecosystem and financial order. In this paper, we focus on the problem of correlating the addresses of mixing transactions in Tornado Cash, a widely-used mixing service on Ethereum. We propose a graph neural network framework named MixBroker, which aims to break the anonymity of Tornado Cash by correlate mixing addresses from the perspective of node-pair link prediction. Specifically, we construct a Mixing Interaction Graph (MIG) using raw Ethereum mixing transaction data that can be used for subsequent analysis. To better represent the properties of mixing account nodes, we extract features from account nodes in the MIG from multiple perspectives. Furthermore, we design a GNN-based link prediction mechanism to serve as the backbone of MixBroker. This mechanism captures the interconnected nature of nodes within the MIG and calculates the probability of correlation between account nodes through node embeddings. In addition, to solve the problem of lacking ground-truth, we collect a large number of real mixing transactions of Ethereum in Tornado Cash and construct a ground-truth dataset by combining the principles of Ethereum Name Service (ENS). We conduct extensive experiments on the datasets, and the results demonstrate that MixBroker has a superior performance over other state-of-the-art methods on the address correlation problem in Ethereum mixing transactions.
Hanbiao Du, Zheng Che, Meng Shen 0001, Liehuang Zhu, Jiankun Hu
IEEE Trans. Inf. Forensics Secur.2
2023 Robust clustering of Ethereum transactions using time leakage from fixed nodes
abstract
Ethereum has received increasing attention as the first blockchain platform to support smart contracts. Data mining has become an important tool for analyzing Ethereum transactions. However, existing methods have the disadvantage of covering partial transactions and being vulnerable to privacy-enhancing techniques. In this paper, we propose a scheme for transaction correlation with the node as an entity, which can cover all transactions while being resistant to privacy-enhancing techniques. Utilizing timestamps relayed from N fixed nodes to describe the network properties of transactions, we cluster transactions that enter the network from the same source node. Experimental results show that our method can determine with 97% precision whether two transactions enter the network from the same source node.
Congcong Yu, Chen Yang 0011, Zheng Che, Liehuang Zhu
Blockchain Res. Appl.3
2022 Traffic Correlation for Deanonymizing Cryptocurrency Wallet Through Tor
Meng Shen 0001, Zheng Che, Congcong Yu, Liehuang Zhu
BlockSys3