- The paper introduces LineMVGNN, which propagates transaction features through a line graph before node updates so models can compare linked payments and receipts from the first layer.
- LineMVGNN-cat achieves state-of-the-art illicit-account F1 across Ethereum benchmarks and the FPT dataset, reaching 0.9954 on FPT and improving over digraph baselines by 10.79% on average.
- The results show that shared in- and out-neighbor parameters reduce model complexity without sacrificing accuracy, while practical runtime, synthetic anomalies, and adversarial robustness remain important limitations.
Motivation and problem setting
The paper addresses node classification on directed, attributed transaction graphs for anti-money laundering (AML), where nodes are accounts and edges are transactions carrying multi-dimensional attributes. The authors argue that existing GNNs for digraphs are poorly matched to this task along two axes. Spectral methods such as DiGCN, MagNet, SigMaNet, and FaberNet do not natively support multi-dimensional edge features and require full-graph propagation whose cost scales with the polynomial filter degree, limiting scalability. Spatial methods either ignore in-neighbors or edge features entirely (GGS-NNs), impose structural constraints (DAGNN), or, as in Dir-GNN, use separate parameter sets for in- and out-neighbor aggregation that the authors contend is redundant for transaction data.
A more specific deficiency motivates the core contribution: detecting suspicious accounts that act as temporary repositories of funds requires comparing a receipt transaction with subsequent payment transactions—i.e., direct transaction-to-transaction information exchange. Stacking standard GNN layers propagates edge information only indirectly through nodes, and the first message-passing round aggregates raw edge attributes without any comparison against related transactions. The paper's remedy is to propagate edge features on the line graph before each round of node message passing.
Method
The architecture has two components built within the Dir-GNN framework.
MVGNN (two-way message passing). MVGNN aggregates messages from both in- and out-neighbors, concatenating neighbor embeddings with edge features before a fully connected message function. Two combination mechanisms are proposed: MVGNN-add, which combines the two message streams with a learnable scalar α (generalizing Dir-GNN's fixed hyperparameter weighting), and MVGNN-cat, which concatenates the two messages and applies a linear layer, capturing element-wise interactions between payment-side and receipt-side information. A key design choice is parameter sharing: the aggregation maps Min and Mout share weights across both neighbor types, halving parameters relative to Dir-GNN. Final embeddings use a personalized PageRank-style weighted sum over layers to mitigate over-smoothing.
Line graph view. LineMVGNN transforms G into its line graph L(G) via the non-backtracking matrix, where each node corresponds to an original edge and adjacency encodes payee-of-one-is-payer-of-the-next relations. Following cross-stitch network ideas, separate MVGNN layers operate on L(G) and G, with updated edge embeddings injected into G (with residual connections) before every node propagation round. This makes money-flow information available from the very first layer rather than after indirect multi-hop diffusion.
Complexity. Naive line graph construction costs O(∣E∣2) in the worst case. A refined variant avoids explicit construction by treating edges as first-class entities and aggregating directly over edges sharing endpoints, reducing asymptotic complexity to O(L∣E∣)—the same order as GCN—on sparse graphs, though with higher practical runtime overhead from edge propagation.
Experimental results
Evaluation uses five dataset configurations: ETH-Small and ETH-Large subsets of the Ethereum Phishing Transaction Network (with and without structural node features derived from in/out-degrees) and a proprietary Financial Payment Transaction (FPT) e-wallet dataset (~1.05M nodes, ~1.09M edges per day) with synthetic laundering patterns (paths, cycles, cliques, multipartite structures) injected because real data are assumed anomaly-free. The illicit-class F1 score is the metric.
| Dataset |
Best baseline |
Best LineMVGNN |
| ETH-Small (w/ SNF) |
0.9352 (PNA / FaberNet-cat) |
0.9441 |
| ETH-Small (w/o SNF) |
0.9393 (FaberNet-cat) |
0.9455 |
| ETH-Large (w/ SNF) |
0.9476 (FaberNet-cat) |
0.9598 |
| ETH-Large (w/o SNF) |
0.9460 (FaberNet-max) |
0.9565 |
| FPT |
0.9945 (FaberNet-max) |
0.9954 |
LineMVGNN-cat achieves state-of-the-art on nearly all configurations, improving over non-digraph baselines by an average of 9.68% F1 and over digraph baselines by 10.79%. Notably, it exceeds 99% F1 on FPT without structural node features. Several spectral baselines fail outright at scale: DiGCN runs out of memory on FPT even with over 1500 GB of CPU memory, and SigMaNet drops to 0.5033 F1 there—empirical support for the scalability critique of spectral digraph methods.
Three ablation findings carry weight:
- Both views contribute. Removing the line graph view degrades performance consistently; removing two-way message passing (in-neighbor aggregation only) causes larger drops, e.g., from 0.9954 to 0.8188 on FPT.
- Parameter sharing suffices. Despite halved parameters, MVGNN variants consistently outperform Dir-GCN/Dir-GAT variants, by margins up to +21.48% (ETH-Small w/o SNF). This challenges the assumption that separate in-/out-aggregation parameters are necessary for transaction graphs.
- Concatenation beats weighted summation but is less robust. LineMVGNN-cat outperforms add generally and is less sensitive to missing SNFs, yet hyperparameter studies show add degrades more gracefully under learning-rate variation on the complex FPT dataset, while cat requires tuning around a learning rate of 0.01 (ETH) or 0.001 (FPT).
An embedding-size study on FPT shows best results at dimension 64, with diminishing returns beyond 32 (+0.17% and +0.07% going from 32 to 64); no embedding study was run on the ETH datasets due to their sparse feature sets.
Limitations and open questions
The paper concedes several constraints. First, although asymptotic complexity matches GCN, the refined model incurs higher practical runtime from edge propagation, and full-batch training remains infeasible for extremely large graphs without sampling. Second, no adversarial training or graph purification is applied, leaving robustness to adversarial transaction manipulation untested—a material concern in fraud settings where actors actively evade detection. Third, the strongest result (99%+ F1 on FPT) rests on synthetically injected anomalies following known structural templates; whether the model retains this performance on genuine, unlabeled laundering patterns cannot be verified from this data, and the dataset itself is unavailable due to privacy regulations. Fourth, the claimed interpretability from explicit edge-level modeling is asserted rather than demonstrated with XAI techniques, which the authors defer to future work. Finally, the parameter-sharing conclusion is drawn from transaction data specifically; its generality to other attributed digraph domains remains open.
Conclusion
LineMVGNN couples lightweight two-way message passing with shared aggregation parameters to a line-graph view that propagates transaction features prior to node updates, directly targeting the cash-flow reasoning that AML detection requires. It delivers consistent state-of-the-art illicit-class F1 across public Ethereum benchmarks and a large industrial payment dataset while using fewer parameters than Dir-GNN-based competitors, though its headline industrial result depends on synthetic anomalies and its runtime overhead and adversarial robustness remain unresolved questions.