A Novel Feature Extraction and Detection Model for Phishing Scam on Ethereum Using Machine Learning

dc.contributor.authorErtam, Fatih
dc.contributor.authorKucuk, Duzgun
dc.contributor.authorKilincer, Ilhan Firat
dc.date.accessioned2026-08-12T17:11:21Z
dc.date.issued2026
dc.departmentFırat Üniversitesi
dc.description.abstractThe proliferation of phishing scam tokens on the Ethereum blockchain, including honeypot, rug pull, and impersonation schemes, poses a grave threat to financial security. Although earlier studies have documented detection accuracies that exceed 95%, they frequently depend on random train-test partitions. These partitions frequently overestimate real-world performance by disregarding the temporal progression of phishing behaviors. This study addresses the methodological gap by employing a temporally validated evaluation. A labeled dataset comprising 5408 Ethereum token contracts was constructed. This dataset was verified through a two-stage process that integrated cyber threat intelligence and on-chain evidence. A total of 16 discriminative features were extracted, reflecting transaction volume, network structure, and temporal behavior. In lieu of employing random partitioning, temporal validation (70% training, 15% validation, and 15% testing) was adopted to assess generalizability to emerging threats. Six machine learning models (LightGBM, XGBoost, Random Forest, Gradient Boosting, Decision Tree, and MLP) were tuned via GridSearchCV. LightGBM demonstrated optimal performance, attaining 85.59% accuracy, 81.63% F1-score, and 92.02% AUC on temporally held-out data. The feature ablation process yielded the identification of transaction volume as the most discriminative factor, with a corresponding increase in performance of 13.09 points on the performance scale. Conversely, temporal features exhibited a marginal decline in performance, with a decrease of 0.87 points. Temporal validation resulted in a 3.95-point-percentage decrease compared to random splitting, thereby exposing the optimistic bias present in prior studies. Despite the fact that the resulting F1-score of 81.63% falls short of the 85% threshold stipulated in the literature, it is indicative of a realistic deployment expectation. This work underscores the importance of temporal validation for reliable fraud detection research.
dc.description.sponsorshipScientific Research Projects Coordination Unit of Firat University, Turkiye [ADEP.25.28, TEKF.25.13]
dc.description.sponsorshipThis work is supported by the Scientific Research Projects Coordination Unit of Firat University, Turkiye (Project Numbers: TEKF.25.13 andADEP.25.28).
dc.identifier.doi10.1002/cpe.70503
dc.identifier.issn1532-0626
dc.identifier.issn1532-0634
dc.identifier.issue1
dc.identifier.orcid0000-0001-8090-4998
dc.identifier.scopus2-s2.0-105024538317
dc.identifier.scopusqualityQ1
dc.identifier.urihttps://doi.org/10.1002/cpe.70503
dc.identifier.urihttps://hdl.handle.net/11508/51121
dc.identifier.volume38
dc.identifier.wosWOS:001668039900041
dc.identifier.wosqualityQ3
dc.indekslendigikaynakWeb of Science
dc.indekslendigikaynakScopus
dc.language.isoen
dc.publisherWiley
dc.relation.ispartofConcurrency and Computation-Practice & Experience
dc.relation.publicationcategoryMakale - Uluslararası Hakemli Dergi - Kurum Öğretim Elemanı
dc.rightsinfo:eu-repo/semantics/openAccess
dc.snmzKA_WoS_20260511
dc.subjectblockchain fraud
dc.subjectcryptocurrency forensics
dc.subjectfeature ablation
dc.subjectphishing detection
dc.subjecttemporal validation
dc.titleA Novel Feature Extraction and Detection Model for Phishing Scam on Ethereum Using Machine Learning
dc.typeArticle

Dosyalar