通过链上交易数据挖掘游戏用户行为模式,揭示潜在隐私风险。
Clustering and analysis of user behaviour in blockchain: A case study of Planet IX
- 构建用户行为分析流水线,整合交易与智能合约数据
- 用图神经网络提取行为图嵌入,聚类出多类用户行为模式
- 发现可被恶意利用的隐私泄露路径,警示安全风险
基于公开区块链的去中心化应用(dApps)虽具透明可信优势,但其交易数据可被追踪分析,带来隐私隐患。本文以区块链游戏 Planet IX 为例,提出用户行为分析流程:从链上收集包含智能合约的交易数据,提取原始交易信息与事件,重构用户游戏行为流,并扩展分析非同质化代币(NFT)在其中的使用方式。将行为流输入图神经网络(GNN)生成图嵌入,再由聚类算法划分用户行为群组。对比多种经典聚类方法,结果以图形式可视化并分析。研究发现可识别出具有代表性的用户行为模式,这些信息可能被恶意方利用,进而提出针对性的隐私威胁模型,覆盖多个潜在受攻击场景。
原文摘要 · Abstract (English)
Decentralised applications (dApps) that run on public blockchains have the benefit of trustworthiness and transparency as every activity that happens on the blockchain can be publicly traced through the transaction data. However, this introduces a potential privacy problem as this data can be tracked and analysed, which can reveal user-behaviour information. A user behaviour analysis pipeline was proposed to present how this type of information can be extracted and analysed to identify separate behavioural clusters that can describe how users behave in the game. The pipeline starts with the collection of transaction data, involving smart contracts, that is collected from a blockchain-based game called Planet IX. Both the raw transaction information and the transaction events are considered in the data collection. From this data, separate game actions can be formed and those are leveraged to present how and when the users conducted their in-game activities in the form of user flows. An extended version of these user flows also presents how the Non-Fungible Tokens (NFTs) are being leveraged in the user actions. The latter is given as input for a Graph Neural Network (GNN) model to provide graph embeddings for these flows which then can be leveraged by clustering algorithms to cluster user behaviours into separate behavioural clusters. We benchmark and compare well-known clustering algorithms as a part of the proposed method. The user behaviour clusters were analysed and visualised in a graph format. It was found that behavioural information can be extracted regarding the users that belong to these clusters. Such information can be exploited by malicious users to their advantage. To demonstrate this, a privacy threat model was also presented based on the results that correspond to multiple potentially affected areas.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。