Integrated Machine Learning and Deep Learning Framework Using Time-Interval Features for Binary and Multiclass Ethereum Threat Detection
DOI:
https://doi.org/10.70917/ijcisim-2026-2015Keywords:
Ethereum Security, Time-Interval Analysis, Machine Learning, Binary Classification, Multiclass Classification, Hybrid Models, Blockchain AnalyticsAbstract
Ethereum, the most popular programmable blockchain platform in the world, is now the main object of an ever-growing variety of many malicious organizations, such as phishing attacks, Ponzi scams, cryptocurrency mixers, and fraudulent smart contracts. The ever-growing complexity and scale of on-chain malicious activities require smart and automated detection systems that can simultaneously perform binary threat detection, i.e. identify malicious and benign accounts, and fine-grained multi-category threat detection, i.e. different attack types. The paper describes an Integrated Machine Learning Framework using which the time-interval behavioural features based on the EtherShield dataset are systematically used to provide comprehensive detection of two types of Ethereum threats. The single architecture proposal will avoid the use of different pipeline architectures because it can support binary and multiclass classification paradigms of classification in a single system. Time-interval characteristics are learned over four time windows, which are 1-day, 3-day, 7-day, and 30-day aggregations, to learn time-varying dynamics of Ethereum address behavior. An envelope of monitored machine learning frameworks, comprising of the Random Forest, Gradient Boosting, XGBoost, and Support Vector machine, and deep learning designs, including Convolutional Neural Networks (CNN), Long Short-Term Memory (LSTM), and Bidirectional LSTM (BiLSTM) are carefully assessed. New hybrid models are suggested: An Isolation Forest enhanced with random Forest model (anomaly-enhanced classification), and a CNN-BiLSTM fusion model (binary sequential analysis). Isolation Forest anomaly scores provide a strengthening of the feature space by the use of unsupervised behavioural signals. It has been experimentally demonstrated that the hybrid CNN+BiLSTM model with binary classification yields 98.89% accuracy whereas the ISO+RF hybrid with multiclass threat detection yields 96.12 % accuracy providing a state of the art standard with blockchain threat intelligence systems.