A Novel Feature Extraction and Detection Model for Phishing Scam on Ethereum Using Machine Learning

0Citations
Citations of this article
15Readers
Mendeley users who have this article in their library.
Get full text

Abstract

The proliferation of phishing scam tokens on the Ethereum blockchain, including honeypot, rug pull, and impersonation schemes, poses a grave threat to financial security. Although earlier studies have documented detection accuracies that exceed 95%, they frequently depend on random train-test partitions. These partitions frequently overestimate real-world performance by disregarding the temporal progression of phishing behaviors. This study addresses the methodological gap by employing a temporally validated evaluation. A labeled dataset comprising 5408 Ethereum token contracts was constructed. This dataset was verified through a two-stage process that integrated cyber threat intelligence and on-chain evidence. A total of 16 discriminative features were extracted, reflecting transaction volume, network structure, and temporal behavior. In lieu of employing random partitioning, temporal validation (70% training, 15% validation, and 15% testing) was adopted to assess generalizability to emerging threats. Six machine learning models (LightGBM, XGBoost, Random Forest, Gradient Boosting, Decision Tree, and MLP) were tuned via GridSearchCV. LightGBM demonstrated optimal performance, attaining 85.59% accuracy, 81.63% F1-score, and 92.02% AUC on temporally held-out data. The feature ablation process yielded the identification of transaction volume as the most discriminative factor, with a corresponding increase in performance of 13.09 points on the performance scale. Conversely, temporal features exhibited a marginal decline in performance, with a decrease of 0.87 points. Temporal validation resulted in a 3.95-point-percentage decrease compared to random splitting, thereby exposing the optimistic bias present in prior studies. Despite the fact that the resulting F1-score of 81.63% falls short of the 85% threshold stipulated in the literature, it is indicative of a realistic deployment expectation. This work underscores the importance of temporal validation for reliable fraud detection research.

Cite

CITATION STYLE

APA

Ertam, F., Kucuk, D., & Kilincer, I. F. (2026). A Novel Feature Extraction and Detection Model for Phishing Scam on Ethereum Using Machine Learning. Concurrency and Computation: Practice and Experience, 38(1). https://doi.org/10.1002/cpe.70503

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free