EWDPS: A Novel Framework for Early Warning and Detection on Ethereum Phishing Scams

Chang Xu,Rongrong Li,Liehuang Zhu,Xiaodong Shen,Kashif Sharif
DOI: https://doi.org/10.1109/jiot.2024.3409742
IF: 10.6
2024-01-01
IEEE Internet of Things Journal
Abstract:Ethereum is the second-largest blockchain platform, and the financial value of its cryptocurrency has constantly increased. Unfortunately, regulatory challenges have resulted in a surge of scams, particularly phishing, which now accounts for over 50% of fraudulent funds. Therefore, phishing scam issues have become a top priority, thus calling for dynamic early warning and accurate identification to achieve effective market regulation. However, the existing works focusing on phishing address detection do not consider early warnings for phishing scams. Furthermore, these methods depend on static graphs to extract node information and overlook the dynamic evolution process of the Ethereum network. In this article, we propose EWDPS, a novel framework to achieve dynamic early warning and effectively identify phishing scams on Ethereum. Specifically, we create a new network called the dynamic temporal transaction network (DTTN), which effectively models the dynamic temporal evolution of transactions. In DTTN, we propose the concepts of temporal evolution interaction network and account feature interaction network. Next, we design a novel feature extraction module to capture temporal sequential patterns effectively. This module takes full advantage of the dynamic interaction process of node-related transactions. Finally, we innovatively use the extracted account, network, and temporal features to enhance transaction representation in multiple dimensions. Extensive experiments show that our proposed scheme effectively achieves dynamic early warning and accurately identifies phishing scams. EWDPS achieves 92.20% accuracy, 95.90% precision, 96.77% recall, and 96.53% F1-score, and outperforms the state-of-the-art methods in phishing address identification.
What problem does this paper attempt to address?