Open Access
ARTICLE
AMLHunter: An On-Chain Risky Address Identification Method Based on Temporally Consistent Transaction Semantic Constraints and Generative Augmentation
School of Cyber Science and Engineering, Southeast University, Nanjing, China
* Corresponding Authors: Sanfeng Zhang. Email: ; Shouwei Li. Email:
Computers, Materials & Continua 2026, 89(2), 83 https://doi.org/10.32604/cmc.2026.088083
Received 28 June 2026; Accepted 19 August 2026; Issue published 15 September 2026
Abstract
On-chain risky address identification is an important task in blockchain security analysis and digital asset risk management. In practical on-chain risk control, however, risky addresses are usually far fewer than benign ones. Fund flows also follow complex propagation paths and strict temporal orders, which makes it difficult for existing methods to handle class imbalance, structural semantic modeling, and information leakage under temporal split settings at the same time. To address these challenges, this paper proposes AMLHunter, an on-chain risky address identification method based on temporally consistent transaction semantic constraints and generative graph augmentation. AMLHunter first constructs a heterogeneous transaction graph from UpbitHack security incidents. In this graph, address nodes, transaction nodes, address-transaction-address paths, and projected inter-address fund flow edges are used to represent transaction event semantics and fund propagation structures. It then uses a teacher model and a conditional diffusion model to generate synthetic risky nodes in the risky address feature space, so as to alleviate the shortage of risky samples in the training set. To connect the generated nodes to the original transaction graph in a way that is consistent with real on-chain behavior, AMLHunter further designs a structural completion mechanism constrained by temporal consistency and transaction semantics. This mechanism is combined with generated-node quality gating and generated-edge quality filtering to reduce the influence of low-quality synthetic samples and low-confidence connections on the augmented graph. Experimental results on the UpbitHack-50k temporal split dataset show that AMLHunter achieves an area under the precision-recall curve (PR-AUC) of 0.523, a Precision@100 (P@100) of 0.850, and a risk-class Recall of 0.543. Compared with representative detection baselines from several categories and graph augmentation baselines, AMLHunter provides better or more stable performance on metrics related to risky candidate ranking.Keywords
Cite This Article
Copyright © 2026 The Author(s). Published by Tech Science Press.This work is licensed under a Creative Commons Attribution 4.0 International License , which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.


Submit a Paper
Propose a Special lssue
View Full Text
Download PDF
Downloads
Citation Tools