Multi-Level Ethereum Malicious Account Detection through Transaction Behavioural Modelling and Adaptive Anomaly Reclassification
Abstract
The growth of the usage of decentralized applications on Ethereum has seen the rise of an increasing number of bad actors that are using it to commit fraud, phishing, money laundering and financial scams. Traditional detection methods are less effective to detect accounts with more complex and changing behaviours. The paper suggests a novel multi-level framework for detecting malicious Ethereum accounts based on supervised classification and adaptive anomalous account verification using a routing based on probabilities. To get the transaction behavior features, opcode features and time-interval features from the publicly available EtherShield data set, we use the entire data set to extract the entire features. The first is a Level-1 where an XGBoost machine learning model classifies Ethereum accounts into Fair, Likely Malicious and Malicious categories, and outputs calibrated probability scores for any account. Uncertainty about malicious accounts are escalated to level-2 where anomaly verification and behavioural re-assessment are carried out by using models such as Random Forest and Isolation Forest. The final classification is obtained by decision fusion process, which combines the results obtained from both levels. The Random Forest-based verification module is evaluated in the experiments and is found to be 95% accurate, 94% macro precision, 95% macro recall and 95% macro F1-score, which is significantly better than the Isolation Forest (baseline). Besides, stratified 5-Fold Cross Validation further demonstrates that the proposed framework is robust and generalizable with a mean accuracy of 94.96% ± 0.43, mean precision of 94.40% ± 0.42, mean recall of 94.84% ± 0.47 and mean F1-Score of 94.66% ± 0.42. The proposed framework proves to be an effective solution to minimize misclassification, enhance the reliability of detection and offer a scalable answer to safeguard Ethereum blockchain ecosystems from newly emerged malicious activities.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.