TY - JOUR
T1 - FlashShield
T2 - Detecting Flash Loan Attacks in DeFi Using Hypergraph Neural Network
AU - Huang, Xinpeng
AU - Qiu, Wangjie
AU - Jie, Wanqing
AU - Xia, Qing
AU - Zhang, Qinnan
AU - Sun, Yuqiang
AU - Xie, Maoyi
AU - Liu, Yang
AU - Zheng, Zhiming
N1 - Publisher Copyright:
© 2004-2012 IEEE.
PY - 2026
Y1 - 2026
N2 - The rapid growth of decentralized finance (DeFi) has spurred innovation but also exposed blockchain systems to severe security threats. As of November 2025, cumulative losses from blockchain security incidents have exceeded {\}36.89 billion. Flash loan attacks account for 135 reported cases and rank fourth among all attack methods. Existing detection approaches either analyze contract source code, which is unavailable for many deployed contracts, or use transaction pattern matching tailored to specific scenarios, and therefore generalize poorly to diverse flash loan attacks. In this paper, we present FlashShield, a general flash loan attack detection framework based on Hypergraph Neural Networks (HGNNs). We construct comprehensive datasets containing attack and benign transactions across multiple chains, and systematically analyze flash loan attack mechanisms along four DeFi protocol layers: code implementation, business logic, economic mechanisms, and cross protocol interactions. FlashShield represents each transaction as a hypergraph of transfer actions and semantic relations, and employs a hybrid architecture that integrates spectral, spatial, and original features together with both node level and graph level representations. Experiments show that FlashShield improves recall by 29% over leading methods and identifies 43 previously unknown malicious or suspicious activities (18 confirmed flash loan-related exploits and 25 suspected address poisoning incidents), demonstrating its effectiveness and scalability for automated DeFi security monitoring.
AB - The rapid growth of decentralized finance (DeFi) has spurred innovation but also exposed blockchain systems to severe security threats. As of November 2025, cumulative losses from blockchain security incidents have exceeded {\}36.89 billion. Flash loan attacks account for 135 reported cases and rank fourth among all attack methods. Existing detection approaches either analyze contract source code, which is unavailable for many deployed contracts, or use transaction pattern matching tailored to specific scenarios, and therefore generalize poorly to diverse flash loan attacks. In this paper, we present FlashShield, a general flash loan attack detection framework based on Hypergraph Neural Networks (HGNNs). We construct comprehensive datasets containing attack and benign transactions across multiple chains, and systematically analyze flash loan attack mechanisms along four DeFi protocol layers: code implementation, business logic, economic mechanisms, and cross protocol interactions. FlashShield represents each transaction as a hypergraph of transfer actions and semantic relations, and employs a hybrid architecture that integrates spectral, spatial, and original features together with both node level and graph level representations. Experiments show that FlashShield improves recall by 29% over leading methods and identifies 43 previously unknown malicious or suspicious activities (18 confirmed flash loan-related exploits and 25 suspected address poisoning incidents), demonstrating its effectiveness and scalability for automated DeFi security monitoring.
KW - Attack detection
KW - blockchain
KW - DeFi
KW - flash loan
KW - hypergraph
UR - https://www.scopus.com/pages/publications/105041756107
U2 - 10.1109/TDSC.2026.3698115
DO - 10.1109/TDSC.2026.3698115
M3 - 文章
AN - SCOPUS:105041756107
SN - 1545-5971
JO - IEEE Transactions on Dependable and Secure Computing
JF - IEEE Transactions on Dependable and Secure Computing
ER -