Interpretable Feature-Scenario Analysis for Ethereum Transaction Anomaly Detection Using Random Forest and XGBoost
DOI:
https://doi.org/10.63158/journalisi.v8i4.1727Keywords:
Anomaly Detection, Ethereum Transaction Analysis, LIME, Random Forest, SHAPAbstract
The substantial and imbalanced volume of Ethereum transactions presents significant challenges for anomaly detection, especially when labels serve as proxies for execution errors rather than confirmed fraud. An interpretable feature-scenario framework was developed utilizing Logistic Regression, Random Forest, and XGBoost on 4,604,555 unique transactions. The isError attribute was employed as a proxy anomaly label. Data splitting occurred prior to address encoding; encoders were trained exclusively on the training set, unseen wallets were assigned a reserved code, and Random Under Sampling (RUS) was applied solely to training data. Evaluation incorporated both an imbalanced random test set and future-block validation. Among 920,911 random-test transactions (3.59% anomalies), Random Forest, excluding the Hour feature and without resampling, achieved optimal operational performance: 0.8204 precision, 0.6716 recall, 0.7386 F1-score, 0.7820 PR-AUC, 0.7338 MCC, and a 0.0055 false-positive rate. Application of RUS increased recall to 0.9035 but reduced precision to 0.3088, resulting in 69.12% of 96,703 alerts being false positives. Future-block validation further reduced PR-AUC to 0.0177 and MCC to 0.0678, indicating a substantial distribution shift. SHAP identified destination-wallet encoding and BlockHeight as the most influential model features, while LIME provided local, non-causal explanations. The primary contribution is an interpretable feature-scenario and validation framework; however, verified malicious labels and dynamic graph representations are still required for operational deployment.
Downloads
References
[1] N. T. Anthony, M. Shafik, F. Kurugollu, and H. F. Atlam, “Anomaly Detection System for Ethereum Blockchain Using Machine Learning,” in Volume 25: Advances in Manufacturing Technology XXXV, 2022. doi: 10.3233/ATDE220608.
[2] M. Kezadri Hamiaz and M. Driss, “Ethereum Smart Contracts Under Scrutiny: A Survey of Security Verification Tools, Techniques, and Challenges,” Computers, vol. 14, no. 6, p. 226, Jun. 2025, doi: 10.3390/computers14060226.
[3] F. Jumani and M. Raza, “Machine Learning for Anomaly Detection in Blockchain: A Critical Analysis, Empirical Validation, and Future Outlook,” Computers, vol. 14, no. 7, p. 247, Jun. 2025, doi: 10.3390/computers14070247.
[4] R. Shevchuk, V. Martsenyuk, B. Adamyk, V. Benson, and A. Melnyk, “Anomaly Detection in Blockchain: A Systematic Review of Trends, Challenges, and Future Directions,” Applied Sciences, vol. 15, no. 15, p. 8330, Jul. 2025, doi: 10.3390/app15158330.
[5] S. Farrugia, J. Ellul, and G. Azzopardi, “Detection of illicit accounts over the Ethereum blockchain,” Expert Syst. Appl., vol. 150, p. 113318, Jul. 2020, doi: 10.1016/j.eswa.2020.113318.
[6] R. M. Aziz, M. F. Baluch, S. Patel, and A. H. Ganie, “LGBM: a machine learning approach for Ethereum fraud detection,” International Journal of Information Technology, vol. 14, no. 7, pp. 3321–3331, Dec. 2022, doi: 10.1007/s41870-022-00864-6.
[7] M. Hasan, M. S. Rahman, H. Janicke, and I. H. Sarker, “Detecting anomalies in blockchain transactions using machine learning classifiers and explainability analysis,” Blockchain: Research and Applications, vol. 5, no. 3, p. 100207, Sep. 2024, doi: 10.1016/j.bcra.2024.100207.
[8] M. Ndiaye, T. A. Diallo, and K. Konate, “ADEFGuard: Anomaly detection framework based on Ethereum smart contracts behaviours,” Blockchain: Research and Applications, vol. 4, no. 3, p. 100148, Sep. 2023, doi: 10.1016/j.bcra.2023.100148.
[9] Z. Chen, S.-Z. Liu, J. Huang, Y.-H. Xiu, H. Zhang, and H.-X. Long, “Ethereum Phishing Scam Detection Based on Data Augmentation Method and Hybrid Graph Neural Network Model,” Sensors, vol. 24, no. 12, p. 4022, Jun. 2024, doi: 10.3390/s24124022.
[10] V. Chithanuru and M. Ramaiah, “Proactive detection of anomalous behavior in Ethereum accounts using XAI-enabled ensemble stacking with Bayesian optimization,” PeerJ Comput. Sci., vol. 11, p. e2630, Mar. 2025, doi: 10.7717/peerj-cs.2630.
[11] Z. Gu and O. Dib, “Enhancing fraud detection in the Ethereum blockchain using ensemble learning,” PeerJ Comput. Sci., vol. 11, p. e2716, Feb. 2025, doi: 10.7717/peerj-cs.2716.
[12] Haibo He and E. A. Garcia, “Learning from Imbalanced Data,” IEEE Trans. Knowl. Data Eng., vol. 21, no. 9, pp. 1263–1284, Sep. 2009, doi: 10.1109/TKDE.2008.239.
[13] B. Pan, N. Stakhanova, and Z. Zhu, “EtherShield: Time-interval Analysis for Detection of Malicious Behavior on Ethereum,” ACM Trans. Internet Technol., vol. 24, no. 1, pp. 1–30, Feb. 2024, doi: 10.1145/3633514.
[14] B. Han, Y. Wei, Q. Wang, F. M. De Collibus, and C. J. Tessone, “MT2AD: multi-layer temporal transaction anomaly detection in ethereum networks with GNN,” Complex & Intelligent Systems, vol. 10, no. 1, pp. 613–626, Feb. 2024, doi: 10.1007/s40747-023-01126-z.
[15] D. R. Roberts et al., “Cross‐validation strategies for data with temporal, spatial, hierarchical, or phylogenetic structure,” Ecography, vol. 40, no. 8, pp. 913–929, Aug. 2017, doi: 10.1111/ecog.02881.
[16] G. E. A. P. A. Batista, R. C. Prati, and M. C. Monard, “A study of the behavior of several methods for balancing machine learning training data,” ACM SIGKDD Explorations Newsletter, vol. 6, no. 1, pp. 20–29, Jun. 2004, doi: 10.1145/1007730.1007735.
[17] L. Breiman, “Random forests,” Mach. Learn., vol. 45, no. 1, pp. 5–32, 2001, doi: 10.1023/A:1010933404324.
[18] T. Chen and C. Guestrin, “XGBoost: A Scalable Tree Boosting System,” in Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, New York, NY, USA: ACM, Aug. 2016, pp. 785–794. doi: 10.1145/2939672.2939785.
[19] S. Sathyanarayanan, “Confusion Matrix-Based Performance Evaluation Metrics,” African Journal of Biomedical Research, pp. 4023–4031, Nov. 2024, doi: 10.53555/AJBR.v27i4S.4345.
[20] D. Chicco and G. Jurman, “The advantages of the Matthews correlation coefficient (MCC) over F1 score and accuracy in binary classification evaluation,” BMC Genomics, vol. 21, no. 1, pp. 1–13, 2020, doi: 10.1186/s12864-019-6413-7.
[21] T. Saito and M. Rehmsmeier, “The Precision-Recall Plot Is More Informative than the ROC Plot When Evaluating Binary Classifiers on Imbalanced Datasets,” PLoS One, vol. 10, no. 3, p. e0118432, Mar. 2015, doi: 10.1371/journal.pone.0118432.
[22] S. Kruschel, N. Hambauer, S. Weinzierl, S. Zilker, M. Kraus, and P. Zschech, “Challenging the Performance-Interpretability Trade-Off: An Evaluation of Interpretable Machine Learning Models,” Business & Information Systems Engineering, vol. 68, no. 1, pp. 159–183, Feb. 2026, doi: 10.1007/s12599-024-00922-2.
[23] M. T. Ribeiro, S. Singh, and C. Guestrin, “‘Why Should I Trust You?’: Explaining the Predictions of Any Classifier,” in Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, New York, NY, USA: ACM, Aug. 2016, pp. 1135–1144. doi: 10.1145/2939672.2939778.
[24] A. Barredo Arrieta et al., “Explainable Artificial Intelligence (XAI): Concepts, taxonomies, opportunities and challenges toward responsible AI,” Information Fusion, vol. 58, pp. 82–115, Jun. 2020, doi: 10.1016/j.inffus.2019.12.012.
[25] A. Pareja et al., “EvolveGCN: Evolving Graph Convolutional Networks for Dynamic Graphs,” Proceedings of the AAAI Conference on Artificial Intelligence, vol. 34, no. 04, pp. 5363–5370, Apr. 2020, doi: 10.1609/aaai.v34i04.5984.
[26] Kusnawi, M. A. Wibowo, and Ridwan Sanjaya, “Real-Time Explainable Concept Drift Detection for Eco-Driving in Mining Trucks using KSWIN and Event-Triggered SHAP,” Journal of Information Systems and Informatics, vol. 8, no. 2, pp. 1534–1556, Apr. 2026, doi: 10.63158/journalisi.v8i2.1551.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Journal of Information Systems and Informatics

This work is licensed under a Creative Commons Attribution 4.0 International License.
Authors Declaration
- The Authors certify that they have read, understood, and agreed to the Journal of Information Systems and Informatics (JournalISI) submission guidelines, policies, and submission declaration. The submission has been prepared using the provided template.
- The Authors certify that all authors have approved the publication of this manuscript and that there is no conflict of interest.
- The Authors confirm that the manuscript is their original work, has not received prior publication, is not under consideration for publication elsewhere, and has not been previously published.
- The Authors confirm that all authors listed on the title page have contributed significantly to the work, have read the manuscript, attest to the validity and legitimacy of the data and its interpretation, and agree to its submission.
- The Authors confirm that the manuscript is not copied from or plagiarized from any other published work.
- The Authors declare that the manuscript will not be submitted for publication in any other journal or magazine until a decision is made by the journal editors.
- If the manuscript is finally accepted for publication, the Authors confirm that they will either proceed with publication immediately or withdraw the manuscript in accordance with the journal’s withdrawal policies.
- The Authors agree that, upon publication of the manuscript in this journal, they transfer copyright or assign exclusive rights to the publisher, including commercial rights














