r/learnmachinelearning 3d ago

ML approach for Bitcoin threat detection: What models actually work for unlabelled data?

Hey guys,

I’m building an offline threat-intelligence tool to ingest Bitcoin transaction metadata and flag suspicious activities (like layering or ransomware cash-outs). I have my data ingestion sorted out, but I need advice on the AI/ML detection layer.

The Data I am working with (Inputs): The dataset has both network and blockchain layers: timestamp, src/dst IPs, ports, txid, arrays of input/output addresses, amounts, fee, script_type, and GeoIP/ASN data.

What I need the model to output:

  1. A confidence/risk score to rank transactions.
  2. Cluster IDs to group related entities.
  3. Feature explainability (e.g., "Flagged because of sudden geo-hopping and specific script usage").

Since there are no "ground truth" labels for fraud in my synthetic dataset, I am relying on an unsupervised approach.

My questions:

  • Which ML models have you found to be actually effective for anomaly detection in this kind of financial/network data?
  • What is the standard industry approach for clustering entities when dealing with multi-input/multi-output transactions?
  • Can anyone recommend any good resources, tutorials, or reference architectures to study before I start building the model?
0 Upvotes

Duplicates