An artificial intelligence-based enterprise financial management auxiliary method and system

By combining hierarchical data processing and dynamic threshold models with anomaly detection, an adaptive risk warning system is constructed, which solves the problem of low efficiency in risk assessment in existing technologies and enables precise monitoring and efficient management of corporate financial risks.

CN121563701BActive Publication Date: 2026-05-08MINXI VOCATIONAL & TECHN COLLEGE
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
MINXI VOCATIONAL & TECHN COLLEGE
Filing Date
2026-01-26
Publication Date
2026-05-08

AI Technical Summary

Technical Problem

Existing financial monitoring systems struggle to adapt to the inherent patterns of different levels of financial data and the differences in actual business needs when faced with multi-level financial data. This results in low efficiency in risk assessment, an inability to effectively identify potential risks, and a tendency for underreporting or false reporting.

Method used

By combining hierarchical data processing, threshold optimization, and anomaly detection, a dynamic threshold model is established to monitor and adjust risk judgment criteria in real time, update early warning parameters according to changes in the business environment, and build an adaptive risk early warning system.

Benefits of technology

It enables real-time monitoring and intelligent adjustment of risks in complex business environments, improving the accuracy of risk identification and control efficiency, and reducing missed and false alarms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121563701B_ABST
    Figure CN121563701B_ABST
Patent Text Reader

Abstract

The application belongs to the technical field of information technology, and specifically discloses an enterprise financial management auxiliary method and system based on artificial intelligence, wherein the method comprises the following steps: obtaining multi-layer data from transaction records, processing characteristic differences according to hierarchical classification, and obtaining hierarchical financial data sets; analyzing distribution rules by using the hierarchical financial data sets, adjusting a unified threshold range if the distribution shows loose and missed report signs, and determining an optimized threshold group; monitoring strict false report conditions according to the optimized threshold group, fusing time evolution factors by using a self-adaptive threshold algorithm, and obtaining a dynamic threshold model; and obtaining risk degree indexes in the dynamic threshold model; the application aims to solve the problem in the prior art that how to establish different abnormal judgment standards that can be continuously self-adjusted with time and detection effect according to the unique distribution characteristics of different hierarchical financial data and specific business scenarios, so as to become a truly intelligent and efficient enterprise financial risk early warning system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the technical field of information technology, specifically to an artificial intelligence-based auxiliary method and system for enterprise financial management. Background Technology

[0002] Corporate financial management, as a core pillar of modern corporate operations, is directly related to capital security, business decisions, and long-term survival and development. With the expansion of enterprise scale and the continuous increase in business complexity, the concealment, cascading effects, and cross-level propagation characteristics of financial anomalies are becoming increasingly prominent, making timely detection and effective risk control a major challenge that all enterprises must face.

[0003] Most current financial monitoring methods face a common and unavoidable contradiction when dealing with multi-level financial data: applying the same judgment criteria to all anomalies is either too lenient, causing a large number of genuine risks to be missed, or too strict, resulting in a massive influx of false alarms that overwhelm valid information. This "one-size-fits-all" threshold setting approach struggles to adapt to the inherent patterns of different data levels and the differences in actual business needs. Transaction records, accounting subjects, departmental reports, and overall corporate reports—these four levels each carry completely different information granularity, fluctuation characteristics, and risk implications, yet they are often processed under the same monitoring framework. The result is either a slow-responding system or frequent alarms, severely impacting the efficiency of financial personnel in judging true risks.

[0004] A more critical issue is that the true level of risk associated with financial anomalies dynamically changes over time, depending on the business environment and historical performance. Transaction amounts that were previously considered normal may become high-risk signals at certain periods; fluctuating expenses in a department over several consecutive months may indicate that management loopholes are gradually widening; and even if certain key indicators for the entire company are still within the so-called "safe range," early signs of potential problems may already be emerging. These changes are not accidental but rather an inevitable result driven by multiple factors, including business rhythms, seasonal patterns, policy adjustments, and market fluctuations. Fixed thresholds cannot keep up with this continuously evolving reality, often causing the system to malfunction at critical moments.

[0005] Therefore, the key issue in building a truly intelligent and efficient corporate financial risk early warning system is how to establish differentiated anomaly judgment standards that can continuously adjust themselves over time and based on the unique distribution characteristics and specific business scenarios of financial data at different levels. Summary of the Invention

[0006] This invention provides an artificial intelligence-based enterprise financial management auxiliary method and system. The purpose is to solve the problem in the existing technology of how to establish differentiated anomaly judgment standards that can continuously adjust themselves over time and with the detection effect according to the unique distribution characteristics of financial data at different levels and specific business scenarios, so as to build a truly intelligent and efficient enterprise financial risk early warning system.

[0007] To solve the above-mentioned technical problems, the technical solution adopted by the present invention is as follows:

[0008] An AI-based enterprise financial management assistance method includes: obtaining multi-layered data from transaction records, classifying and processing characteristic differences according to hierarchy to obtain a hierarchical financial dataset; analyzing the distribution patterns of the hierarchical financial dataset, and if the distribution shows signs of lenient underreporting, adjusting the unified threshold range to determine an optimized threshold group; monitoring strict false alarms based on the optimized threshold group, and integrating time evolution factors through an adaptive threshold algorithm to obtain a dynamic threshold model; obtaining risk level indicators from the dynamic threshold model, and if the indicators exceed the business environment limits, triggering an anomaly detection algorithm to identify potential anomalies; extracting massive false alarm features from potential anomalies, filtering irrelevant signals using an anomaly detection algorithm to determine the true risk sequence; tracking the dynamic change trajectory through the true risk sequence, updating the judgment criteria according to business evolution patterns to obtain adaptive early warning parameters; integrating multi-layered data feedback using adaptive early warning parameters, and if the feedback shows time evolution deviations, correcting the early warning system structure to obtain the final risk control output.

[0009] In one aspect of the invention, the step of obtaining a hierarchical financial dataset by acquiring multi-layered data from transaction records and processing differences in hierarchical classification characteristics includes:

[0010] Obtain raw, multi-layered data through transaction records;

[0011] A hierarchical structure partitioning method is used to split multi-level data layer by layer to obtain independent datasets for each layer;

[0012] Perform classification processing on independent datasets at each level to obtain hierarchical classification results;

[0013] Based on the hierarchical classification results, determine the type of inter-level differences and obtain the difference classification labels;

[0014] A hierarchical feature set is obtained by extracting key difference fields from the difference classification labels;

[0015] A preliminary hierarchical financial table is obtained by matching the hierarchical feature set with the independent datasets of each layer;

[0016] Perform a data integrity check on the initial hierarchical financial tables to obtain the final hierarchical financial dataset.

[0017] In one aspect of the invention, the step of analyzing the distribution patterns using hierarchical financial datasets, and if the distribution shows signs of lenient underreporting, adjusting the unified threshold range to determine an optimized threshold group, includes:

[0018] By using hierarchical financial datasets, the distribution characteristics of data at each level are obtained, and preliminary screening is performed based on these distribution characteristics to obtain a set of distribution outliers.

[0019] Based on the set of distribution anomalies, analyze whether there are any signs of leniency. Using a preset judgment rule, if the proportion of anomalies exceeds a preset threshold, it is judged that there are signs of leniency, and a leniency sign identifier is obtained.

[0020] For indicators of laxity, obtain the corresponding underreporting risk data, extract key fields from the underreporting risk data, and determine the potential underreporting range;

[0021] By analyzing the correlation between potential underreporting intervals and financial distribution, a logistic regression model is used to process the mapping between distribution and underreporting intervals to obtain the correlation assessment results.

[0022] Based on the correlation assessment results, the threshold range is adjusted. For the high correlation areas in the assessment results, a unified adjustment strategy is implemented to determine the adjusted threshold range.

[0023] From the adjusted threshold range, obtain the optimized combination scheme, match the corresponding threshold combination for different levels of financial data, and obtain the final optimized threshold group;

[0024] By optimizing the threshold group, updating the data stratification rules, re-analyzing the financial distribution based on the updated rules, and determining the final distribution adjustment plan.

[0025] In one aspect of the invention, the step of monitoring strict false alarms based on an optimized threshold group and obtaining a dynamic threshold model by incorporating time evolution factors through an adaptive threshold algorithm includes:

[0026] By optimizing the threshold set, the monitoring of strict false alarms is continuously tracked, and relevant false alarm data is obtained from historical records using data acquisition tools to determine the preliminary distribution range of false alarms.

[0027] Based on the preliminary distribution range of false alarms and combined with time evolution factors, key change points in the time series are extracted to obtain time-related false alarm fluctuation characteristics.

[0028] To address the time-related false alarm fluctuations, a pre-defined logistic regression model is applied to handle the relationship between fluctuations and thresholds, and to obtain the corresponding adaptive adjustment direction for the thresholds.

[0029] From the threshold adaptive adjustment direction, the adjustment criteria that are highly correlated with strict false alarms are selected. If the adjustment criteria show that the false alarm frequency exceeds the preset threshold, the corresponding dynamic threshold update scheme is generated.

[0030] By using a dynamic threshold update scheme and considering the adaptability requirements, the parameters of the existing threshold algorithm are optimized to determine the updated threshold configuration combination.

[0031] Based on the updated threshold configuration combination, and considering the false alarm analysis results for different time periods, the operating rules of the dynamic model are constructed to obtain the final threshold application framework.

[0032] The final threshold application framework is obtained, and anomalies in the monitoring situation are compared in real time. If the anomaly deviates from the preset range, the threshold adjustment mechanism is triggered to determine the monitoring stability after adjustment.

[0033] In one aspect of the present invention, the step of obtaining the risk level index in the dynamic threshold model, and triggering an anomaly detection algorithm to determine potential anomalies if the index exceeds the business environment limits, includes:

[0034] By obtaining risk level indicators from the dynamic threshold model, preliminary screening of the indicator data is performed to obtain an abnormal candidate set that exceeds the preset limit.

[0035] Based on the candidate set of anomalies, a pre-established classification model is used to classify the data points in the candidate set and identify the key objects of concern that belong to potential anomalies.

[0036] For key targets, extract corresponding environmental boundary data from the business environment, obtain time series information related to abnormal locations, and determine whether there is a continuous deviation.

[0037] If the time series information shows a continuous deviation, the anomaly detection process is initiated to obtain the specific distribution range of the anomaly location and determine the core area of ​​the anomaly point.

[0038] By combining data from the core area with historical records in the detection process, frequency characteristics of anomalies are extracted to obtain periodic patterns of abnormal behavior.

[0039] After obtaining the periodic pattern, a logical judgment tool is applied to the key time points in the pattern. If the indicator value at the key time point exceeds the environmental limit, a corresponding anomaly mark is generated to determine the final anomaly confirmation result.

[0040] By using the anomaly confirmation results, the risk assessment rules in the threshold model are updated to obtain the adjusted indicator monitoring framework, thus completing the continuous tracking of potential anomalies.

[0041] In one aspect of the present invention, the step of extracting massive false alarm features from potential anomalies, filtering irrelevant signals using an anomaly detection algorithm, and determining the true risk sequence includes:

[0042] Abnormal signals are obtained from the business system, and the signals are initially classified using a pre-established classification model to filter out obvious interference information, resulting in a pre-cleaned signal set.

[0043] For the signal set after initial cleanup, anomaly detection algorithm is used to perform in-depth analysis of the signals, identify the false alarm data contained therein, and obtain a refined abnormal signal group;

[0044] Extract key information related to business from the refined abnormal signal group, and use information processing tools to structure and organize the signal group to identify the core signals of potential problems;

[0045] Based on the core signals, obtain the corresponding business environment data. If there is a significant deviation between the core signals and the environment data, mark them as key targets for attention in the risk sequence.

[0046] For key targets, obtain their historical time series information, and use comparative analysis tools to determine whether there is a persistent deviation, and obtain the determination result of the deviation status;

[0047] Based on the results of the deviation assessment, if the assessment results show a continuous deviation, the risk sequences are prioritized and high-priority risk sequences are determined.

[0048] For high-priority risk sequences, information processing tools are used to generate corresponding anomaly markers, and the potential problems are tracked and processed through the marker records.

[0049] In one aspect of the invention, the step of tracking dynamic changes through real risk sequences and updating judgment criteria according to business evolution patterns to obtain adaptive early warning parameters includes:

[0050] Dynamic change data of risk sequences are obtained from the business system, and information extraction tools are used to structure and organize the change paths to obtain preliminary organized path information;

[0051] Based on the initially compiled path information, the business evolution trend is compared with the pre-established business rule base to determine whether the path information conforms to the expected direction of the evolution trend. If it does, it is identified as a critical change path.

[0052] Based on the key change paths, obtain the corresponding business adjustment records, and use data matching tools to analyze the correlation between the change paths and business adjustments to obtain the correlation analysis results;

[0053] If the correlation analysis results show that the change path is consistent with the business adjustment, the evaluation criteria will be updated through the information processing module to obtain the updated evaluation standards.

[0054] Based on the updated evaluation criteria and in accordance with the adaptive requirements, information mapping tools are used to adjust the early warning parameters and determine the adjusted parameter set.

[0055] For the adjusted parameter set, data storage tools are used to bind it with the business evolution trend to obtain the application scope of the bound parameters and determine whether it covers all key change paths;

[0056] Based on the scope of application of the bound parameters, if the coverage meets the needs of business adjustments, the parameters will be updated and applied to the business system through a data synchronization tool to obtain the final adaptive warning parameters.

[0057] In one aspect of the invention, the method of integrating multi-layer data feedback using adaptive early warning parameters, and correcting the early warning system architecture to obtain the final risk control output if the feedback shows a deviation in time evolution, includes:

[0058] Extract multi-layer time series change information from real-time business data streams to obtain the original sequence set;

[0059] For the original sequence set, the time window division method is used to extract the sequence change features of each layer, and a layered change feature set is obtained;

[0060] Based on the set of stratified change characteristics, the time deviation between each stratified sequence and the baseline sequence is calculated to obtain a set of multi-layer deviation indices.

[0061] If at least one deviation value in the multi-layer deviation index set exceeds a preset threshold, the corresponding layer is marked as an abnormal feedback layer, and an abnormal feedback layer set is obtained.

[0062] For the set of abnormal feedback layers, the weight ratio of each layer in the early warning calculation structure is adjusted by a proportional weighting method to obtain the adjusted calculation structure.

[0063] Based on the adjusted calculation structure and combined with the current real-time data stream, the warning parameter values ​​are recalculated to obtain the updated adaptive warning parameters.

[0064] The updated adaptive warning parameters are used to assess the risk of the current real-time business data stream, resulting in the final risk control output.

[0065] In another aspect, the present invention relates to an artificial intelligence-based enterprise financial management auxiliary system, characterized in that the system comprises:

[0066] The data acquisition and hierarchical processing module is used to obtain multi-level data from transaction records, classify and process the differences in hierarchical characteristics, and obtain hierarchical financial datasets.

[0067] The threshold optimization module is used to analyze the distribution patterns of hierarchical financial datasets. If the distribution shows signs of lenient underreporting, the unified threshold range is adjusted to determine the optimized threshold group.

[0068] The dynamic threshold modeling module is used to obtain a dynamic threshold model by integrating time evolution factors through an adaptive threshold algorithm based on the strict false alarm situation of the optimized threshold group monitoring.

[0069] The anomaly detection trigger module is used to obtain the risk level index in the dynamic threshold model. If the index exceeds the business environment limit, the anomaly detection algorithm is triggered to identify potential anomalies.

[0070] The true risk sequence determination module is used to extract massive false alarm features from potential anomalies, filter irrelevant signals using anomaly detection algorithms, and determine the true risk sequence.

[0071] The adaptive early warning parameter generation module is used to track dynamic changes through real risk sequences, update judgment criteria according to business evolution patterns, and obtain adaptive early warning parameters.

[0072] The risk control output module is used to integrate multi-layer data feedback using adaptive early warning parameters. If the feedback shows a deviation in time evolution, the early warning system structure is corrected to obtain the final risk control output.

[0073] Compared with the prior art, the present invention has the following beneficial effects:

[0074] This invention constructs a complete risk early warning and control system through the fusion logic of hierarchical data processing, threshold optimization, and anomaly detection. First, it analyzes the distribution patterns of hierarchical financial datasets and adjusts a unified threshold range to address the issue of lenient underreporting. Then, it utilizes an adaptive threshold algorithm to incorporate time-varying factors, establishing a dynamic threshold model to monitor false alarms. When risk indicators exceed limits, it triggers anomaly detection, extracts the true risk sequence, tracks its changes, and finally updates the early warning parameters based on business evolution patterns, corrects the system architecture, and outputs accurate risk control results. The core innovation of this invention lies in the combination of dynamic thresholds and adaptive early warning, enabling real-time monitoring and intelligent adjustment of risks in complex business environments, effectively improving the accuracy of risk identification and control efficiency. Attached Figure Description

[0075] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained from these drawings without creative effort.

[0076] Figure 1 This is a flowchart of an artificial intelligence-based enterprise financial management auxiliary method according to the present invention.

[0077] Figure 2 This is a step-by-step flowchart of an artificial intelligence-based enterprise financial management auxiliary method according to the present invention.

[0078] Figure 3 This is a flowchart of another step in the artificial intelligence-based enterprise financial management auxiliary method of the present invention. Detailed Implementation

[0079] The present invention will be further described below with reference to embodiments. These embodiments are merely some, not all, of the embodiments of the present invention. Other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are all within the protection scope of the present invention.

[0080] Please see Figures 1-3 As shown in the figure, this embodiment discloses an artificial intelligence-based enterprise financial management auxiliary method and system, wherein the method may specifically include:

[0081] S101. By obtaining multi-level data from transaction records and processing the differences in characteristics according to the hierarchical classification, a hierarchical financial dataset is obtained.

[0082] Multi-layered data refers to a collection of raw data with different granularities or dimensions extracted from enterprise transaction records, including but not limited to fields such as transaction amount, time, account, counterparty, and business type. These data present a hierarchical relationship in the organizational structure, such as transaction layer, account layer, department layer, and enterprise layer.

[0083] The original multi-layered data is obtained by acquiring transaction records. A hierarchical structure partitioning method is used to split the multi-layered data layer by layer to obtain independent datasets for each layer. Classification processing is performed on each independent dataset to obtain hierarchical classification results. Based on the hierarchical classification results, the types of differences between layers are determined to obtain difference classification labels. Key difference fields are extracted from the difference classification labels to obtain a hierarchical feature set. The hierarchical feature set is matched with each independent dataset to obtain a preliminary hierarchical financial table. Data integrity checks are performed on the preliminary hierarchical financial table to obtain the final hierarchical financial dataset.

[0084] Among them, the hierarchical financial dataset refers to a structured data set formed by classifying, normalizing and extracting features from multi-level data according to preset hierarchical division rules (such as transaction amount range, account type, department affiliation, etc.). Each layer of the dataset contains feature fields related to the risk characteristics of that layer.

[0085] Specifically, fields including transaction date, account number, transaction amount, transaction type, counterparty identifier, and business tag are extracted from the original transaction record table. First, the transaction sequence of a single account is obtained by preliminary grouping by account number. Then, the cumulative number of transactions and amount are calculated by rolling forward with a time window of 30 days to form a time series feature. Next, based on the cumulative transaction amount, the data is stratified into three tiers: 0 to 50,000 yuan for the first tier, 50,000 to 500,000 yuan for the second tier, and over 500,000 yuan for the third tier. The characteristics of the transaction data for each tier are calculated as follows: The first tier focuses on extracting transaction frequency and small average value features (e.g., an average of 2.3 transactions per day and an average amount of 1285.67 yuan). The second tier adds transaction cycle volatility analysis (using the standard deviation divided by the mean to obtain a coefficient of variation of 0.78) and counterparty concentration (the top three counterparties account for 67.4%). The third tier further introduces the net capital flow ratio (the inflow-outflow ratio is 1.92) and abnormal peak detection (using the 3x standard deviation rule to identify sudden increases in daily amount exceeding 4.6 times the average, a total of 12 times were detected). Subsequently, different normalization methods were applied to each layer of data. The first layer was normalized to the 0-1 range using min-max normalization. The second layer used z-score normalization to handle the skewness of the amount and frequency distributions. The third layer performed additional logarithmic transformation on the net amount and peak characteristics to compress the impact of extreme values. Finally, three sets of structured hierarchical financial datasets were formed. Each set contains fields such as original amount, normalized amount, frequency, coefficient of variation, concentration, net ratio, and anomaly markers, which facilitates the subsequent model to perform differentiated modeling and analysis for risk characteristics at different levels.

[0086] S102. Analyze the distribution patterns using hierarchical financial datasets. If the distribution shows signs of lenient underreporting, adjust the unified threshold range and determine the optimized threshold group.

[0087] Among them, "lax underreporting indicators" refer to the phenomenon in financial anomaly monitoring where, due to excessively high thresholds or overly lenient judgment standards, transactions or behaviors that should be identified as abnormal are not captured by the system. The criteria for determination include, but are not limited to: the proportion of anomalies being lower than a preset threshold, high-risk transactions not being marked, or the frequency of historical underreporting events exceeding an acceptable range.

[0088] By using a hierarchical financial dataset, the distribution characteristics of data at each level are obtained. Preliminary screening based on these characteristics yields a set of distribution outliers. This set is then analyzed to identify any signs of leniency. Using pre-defined rules, if the proportion of outliers exceeds a preset threshold, leniency is identified, resulting in a leniency indicator. For each leniency indicator, corresponding underreporting risk data is obtained. Key fields are extracted from this data to determine potential underreporting intervals. The correlation between these potential underreporting intervals and the financial distribution is analyzed using a logistic regression model to map the distribution to the underreporting intervals, yielding a correlation assessment result. Based on this assessment, the threshold intervals are adjusted. For highly correlated areas, a unified adjustment strategy is implemented to determine the adjusted threshold range. From this adjusted threshold range, an optimized combination scheme is derived. For different levels of financial data, corresponding threshold combinations are matched to obtain the final optimized threshold group. Using this final optimized threshold group, the data hierarchical rules are updated. The financial distribution is then re-analyzed based on the updated rules to determine the final distribution adjustment scheme.

[0089] Specifically, starting with the stratified financial dataset, statistical analysis of the distribution patterns of the three sets of data was conducted. First, the quantile intervals of each feature were calculated for the first-level dataset, revealing a right-skewed distribution of the original amounts. The 75th percentile was only 3280.45 yuan, while the maximum value reached 48750.12 yuan, indicating a certain degree of lenient underreporting. Subsequently, a joint distribution test of the coefficient of variation and concentration was conducted on the second-level data. The results showed that 41.3% of the samples had a coefficient of variation greater than 0.9, and 29.7% of the accounts had a ratio of less than 40% of the top three counterparties, indicating that the risk distinction boundary of this level was relatively blurred. The third level focused on the combination of net amount ratio and anomaly markers. It was found that 7.6% of the accounts in the normal range of net amount ratio between 0.8 and 1.2 still had 3 or more abnormal peaks, suggesting that the current uniform threshold setting is not sensitive enough to high-amount levels. Based on the above distribution characteristics analysis, it was decided to optimize and adjust the original three-tiered threshold amounts. The upper limit of the first tier was tightened from 50,000 yuan to 38,000 yuan, the range of the second tier was modified to 38,000 yuan to 420,000 yuan, and the starting point of the third tier was raised to 420,000 yuan. After multiple iterative experiments, the optimal threshold group was determined to be 0-38,000 yuan, 38,000-420,000 yuan, and above 420,000 yuan. This threshold group reduced the right skewness of the first tier by about 18.4 percentage points, reduced the proportion of high-variability, low-concentration samples in the second tier to 23.1%, and increased the abnormal overlap rate between abnormal peaks and net amount ratios in the third tier to 84.6%. This significantly enhanced the distinguishability of risk characteristics at each tier and provided a more targeted data foundation for subsequent differentiated risk modeling.

[0090] S103. Based on the strict false alarm situation of the optimized threshold group monitoring, a dynamic threshold model is obtained by integrating time evolution factors through an adaptive threshold algorithm.

[0091] Strict false alarms refer to the phenomenon in financial anomaly monitoring where normal transactions or behaviors are incorrectly marked as abnormal due to excessively low thresholds or overly strict judgment criteria. The criteria for determination include, but are not limited to: false alarm frequency exceeding a preset threshold, normal transactions being frequently marked, or false alarm events being concentrated in specific business models.

[0092] The method described above, based on the optimized threshold group monitoring of false alarms, integrates time evolution factors through an adaptive threshold algorithm to obtain a dynamic threshold model, including: statistically analyzing false alarm events in historical transaction data based on the optimized threshold group to obtain a false alarm frequency time series; extracting trend and periodic terms from the time series, and using a seasonal decomposition algorithm (such as STL) to separate long-term trends from short-term fluctuations; inputting the trend terms into a logistic regression model to predict the relationship between the false alarm rate and time, and obtaining the threshold adjustment coefficient; calculating the mapping relationship between the false alarm rate and the threshold adjustment coefficient within the window based on a sliding window mechanism, with a window length of 30 days and a step size of 7 days; if the false alarm rate within the window exceeds a set upper limit (such as 15%), triggering a threshold reduction mechanism, dynamically correcting the thresholds at each level according to the adjustment coefficient; binding the corrected threshold combination with a timestamp and storing it in a dynamic threshold library to form a threshold model that can be updated over time; verifying the model stability through real-time transaction stream data, and determining that the model has converged if the false alarm rate is below 5% for three consecutive windows, and outputting the final dynamic threshold configuration.

[0093] Among them, the dynamic threshold model is a mathematical model that can automatically adjust the anomaly judgment threshold based on historical data distribution, time evolution trends, and changes in the business environment. This model continuously optimizes the threshold through algorithms (such as logistic regression, time series decomposition, and sliding window mechanisms) to balance the contradiction between false negatives and false positives.

[0094] In some embodiments, the dynamic threshold model obtained by monitoring strict false alarms using an optimized threshold group and integrating time evolution factors through an adaptive threshold algorithm further includes: continuously tracking the monitoring of strict false alarms using the optimized threshold group, acquiring relevant false alarm data from historical records using data acquisition tools, and determining the preliminary false alarm distribution range. Based on the preliminary false alarm distribution range and combined with time evolution factors, key change points in the time series are extracted to obtain time-related false alarm fluctuation characteristics. For the time-related false alarm fluctuation characteristics, a preset logistic regression model is applied to handle the relationship between fluctuations and thresholds to obtain the corresponding threshold adaptive adjustment direction. From the threshold adaptive adjustment direction, adjustment criteria highly correlated with strict false alarms are selected. If the adjustment criteria show that the false alarm frequency exceeds the preset threshold, a corresponding dynamic threshold update scheme is generated. Through the dynamic threshold update scheme, combined with adaptive requirements, the parameters of the existing threshold algorithm are optimized to determine the updated threshold configuration combination. Based on the updated threshold configuration combination, the operating rules of the dynamic model are constructed for the false alarm analysis results of different time periods, resulting in the final threshold application framework. The final threshold application framework is obtained, and anomalies in the monitoring situation are compared in real time. If the anomaly deviates from the preset range, the threshold adjustment mechanism is triggered to determine the monitoring stability after adjustment.

[0095] The threshold adjustment formula is configured as follows:

[0096]

[0097] in, The updated threshold;

[0098] The threshold before the update;

[0099] The learning rate;

[0100] This represents the change in the false alarm rate.

[0101] The dynamic threshold modeling steps are as follows;

[0102] False alarm data collection: Based on the optimized threshold group, the transaction sequences marked as false alarms are extracted from historical transaction records to construct the false alarm frequency time series F(t);

[0103] Time feature extraction: Seasonal decomposition of F(t) yields the time trend term T(t), the periodic term S(t), and the residual term R(t).

[0104] Threshold adjustment coefficient calculation: Use a logistic regression model to fit T(t) to the threshold adjustment amount. The relationship of Th:

[0105]

[0106] in, This is the regression intercept term;

[0107] These are the regression coefficients;

[0108] This is the random error term;

[0109] Sliding window mechanism: The false alarm rate within the window is calculated using a 30-day window and a 7-day step size. If the false alarm rate is greater than 15%, an adjustment is triggered.

[0110] Dynamic update: The adjusted threshold is written to the threshold library with timestamp index, supporting real-time query and update;

[0111] Stability verification: The model is considered stable when the false alarm rate is less than 5% for 3 consecutive windows, and the final threshold group is output.

[0112] Specifically, in the field of financial risk monitoring, for the optimized threshold group, the system first automatically extracts the transaction frequency and amount fluctuation data of each account over the past three months through a data analysis system. To address potential severe false alarms, the system calculates the deviation of each transaction on a daily basis, setting the initial false alarm criterion as the percentage of transactions with a deviation exceeding 2.5 times the standard deviation. If an account's deviation exceeds 15% for seven consecutive days, it is marked as a potential false alarm account. For example, if an account's average daily deviation reaches 18.2% during the analysis period, the system automatically adds it to the observation list. Next, an adaptive threshold algorithm is introduced. The system constructs a time series model based on historical transaction data, incorporating time evolution factors and using the monthly growth rate of transaction volume and amount as a dynamic adjustment factor. Assuming a monthly growth rate of 12.3%, the system weights this factor with a base threshold of 35,000 yuan to arrive at a temporary threshold of 39,000 yuan for that month. Simultaneously, a sliding window algorithm is used to smooth the data from the past 30 days to ensure that the threshold adjustment is not overly sensitive. Ultimately, the system generates a dynamic threshold model that automatically adjusts monitoring parameters based on transaction characteristics in different time periods. For example, during peak trading hours like holidays, the threshold is raised to 42,000 yuan to reduce false alarms, while it remains at 37,000 yuan during normal periods. Simultaneously, the system uses machine learning algorithms to cluster and analyze false alarm-marked accounts, finding that false alarms are mostly concentrated in small-amount, high-frequency trading accounts, accounting for approximately 22.7%. This further optimizes the model parameters, increasing the tolerance range for deviations of small-amount accounts from 2.5 times to 3.0 times, forming a closed-loop adjustment mechanism to ensure the accuracy and adaptability of monitoring.

[0113] S104. Obtain the risk level index in the dynamic threshold model. If the index exceeds the business environment limit, trigger the anomaly detection algorithm to identify potential anomalies.

[0114] By obtaining risk level indicators from a dynamic threshold model, preliminary screening of the indicator data yields a candidate set of anomalies exceeding preset limits. Based on this candidate set, a pre-established classification model categorizes the data points, identifying key areas of concern that may be potential anomalies. For these key areas, corresponding environmental boundary data is extracted from the business environment to obtain time-series information related to the anomaly location, determining if there is a persistent deviation. If the time-series information shows a persistent deviation, an anomaly detection process is initiated to obtain the specific distribution range of the anomaly location, identifying the core area of ​​the anomaly. Using data from the core area, combined with historical records from the detection process, frequency characteristics of anomaly occurrences are extracted to obtain periodic patterns of anomalous behavior. After obtaining these periodic patterns, logical judgment tools are applied to key time points within the patterns. If the indicator value at a key time point exceeds the environmental limits, a corresponding anomaly marker is generated, confirming the final anomaly. Based on the anomaly confirmation result, the risk level assessment rules in the threshold model are updated, resulting in an adjusted indicator monitoring framework, completing the continuous tracking of potential anomalies.

[0115] Specifically, in the field of financial risk monitoring, the system first extracts account fund flow data from the company's internal transaction database over the past six months through an automated data acquisition module. It focuses on analyzing the distribution of daily transaction amounts and calculates a risk level index. For example, assuming an account's average daily transaction amount is 56,000 yuan, the system compares it to the historical average of 42,000 yuan, resulting in a risk level index of 1.33. If this index exceeds the business environment threshold of 1.25, the system automatically triggers an anomaly detection process. Next, the system calls a statistical anomaly detection algorithm, using the Z-score method to calculate a standardized score for each transaction. For instance, if a transaction amount of 89,000 yuan has a Z-score of 3.1, exceeding the preset threshold of 2.8, the system marks it as a potential anomaly. Simultaneously, combined with the account's transaction frequency data over the past 14 days, it finds that the frequency has increased from an average of 3 times per day to 7 times per day, further confirming the possibility of an anomaly. Subsequently, the system uses a time-series decomposition algorithm to perform trend analysis on account transaction data, extracting cyclical fluctuation components. For example, if an account is detected to have an abnormal peak in transaction amount within the last 30 days, reaching 103,000 yuan, exceeding the historical average by more than double, the system automatically generates an anomaly report. It then correlates this account with other business dimensions, such as the credit score of the counterparty, finding that the counterparty's score is below 60 (out of 100), below the normal range of 75, thus strengthening the anomaly judgment. Finally, the system aggregates all potential anomalies into the risk assessment module, calculating a comprehensive risk value based on a weighted scoring model. If an account's comprehensive risk value is 82.5, exceeding the warning line of 70, the system automatically adds it to the key monitoring list and interfaces with other internal business systems to obtain more contextual data, such as the transaction patterns of related parties, ensuring the completeness of the analysis logic and multi-dimensional verification, forming an automated closed-loop monitoring mechanism.

[0116] In some embodiments, the risk indicators obtained from the dynamic threshold model, if exceeding the dynamic business boundary, are used to initiate multimodal anomaly detection to identify potential anomalies, and further include:

[0117] Risk indicators at each level are extracted from the dynamic threshold model, including transaction amount Z-score, frequency variation coefficient, and counterparty concentration score;

[0118] Based on historical business data, the rolling mean and standard deviation of each indicator are calculated to construct a dynamic business boundary:

[0119] Boundary value = rolling mean + k × rolling standard deviation, where k is set according to the business risk tolerance, such as by regression based on historical false alarm rate, or by business experts.

[0120] If an account’s risk indicator exceeds the corresponding level boundary N times (e.g., 3 times) consecutively, the anomaly detection process will be triggered.

[0121] The isolated forest algorithm is used to cluster potential outliers in multiple dimensions, and feature vectors are constructed by combining transaction time, counterparty credit score and industry category.

[0122] Manually label or validate the clustering results to identify high-confidence outliers and record their timestamps, account IDs, and anomaly types.

[0123] The risk indicator calculation rules are updated based on the distribution of outliers, such as adjusting the weight of the coefficient of variation or introducing new features, to form a closed-loop optimization mechanism.

[0124] S105. Extract massive false alarm features from potential anomalies, use anomaly detection algorithms to filter irrelevant signals, and determine the true risk sequence.

[0125] Anomaly signals are acquired from the business system and initially classified using a pre-established classification model to filter out obvious interference, resulting in a pre-cleaned signal set. For this pre-cleaned signal set, anomaly detection algorithms are used for in-depth analysis to identify false alarms, resulting in a refined anomaly signal group. Key business-related information is extracted from this refined anomaly signal group, and the signal group is structured using information processing tools to identify the core signals of potential problems. Based on the core signals, corresponding business environment data is obtained. If there is a significant deviation between the core signals and the environment data, these are marked as key concerns in the risk sequence. For these key concerns, their historical time-series information is obtained, and comparative analysis tools are used to determine if there is a persistent deviation, resulting in a deviation status assessment. Based on the deviation status assessment, if the assessment shows a persistent deviation, these are prioritized to determine high-priority risk sequences. For high-priority risk sequences, information processing tools generate corresponding anomaly tags, and these tags are used to track and process potential problems.

[0126] Specifically, in the field of financial risk monitoring, the system extracts massive false alarm features from potential anomalies through an automated analysis platform. First, it uses feature extraction algorithms to deeply analyze transaction data marked as abnormal over the past 90 days. Assuming an account has 25 marked abnormal transactions, the system extracts the transaction time interval features and finds that the average interval is only 1.5 hours, far lower than the 5.2 hours of normal accounts. Combined with the fluctuation characteristics of transaction amounts, the standard deviation is calculated to be 37,000 yuan, higher than the 18,000 yuan of normal accounts, initially indicating the presence of potential false alarm signals. Next, the system uses machine learning-based anomaly detection algorithms, such as the Isolation Forest algorithm, to classify the extracted features and filter out irrelevant signals. Assuming that after analyzing 1000 anomalies, the system identifies 650 points that are highly similar to historical normal patterns, with their feature vector distance less than a preset threshold of 0.3, these false alarm points are automatically removed, retaining the remaining 350 points as potential risk signals. Subsequently, the system performed multi-dimensional verification on these signals. Through association rule mining algorithms, it analyzed the transaction background data and discovered that 200 points were associated with transactions in high-risk industry categories, accounting for 57.1%, far exceeding the 15.6% of normal transactions. This further narrowed down the range of true risk sequences to these signals. Finally, the system used a clustering algorithm to group these 200 points, assuming they were divided into three risk clusters. One cluster had a transaction concentration score as high as 85.6, exceeding the warning value of 60. The system automatically marked this as a true risk sequence and associated it with the account's industry risk index. This index was found to be 72.3, higher than the average of 45.8, strengthening the logical basis for risk judgment and forming a complete automated process from feature extraction to risk confirmation.

[0127] S106. By tracking dynamic changes through real risk sequences, and updating judgment criteria according to business evolution patterns, adaptive early warning parameters are obtained.

[0128] Among them, the real risk sequence refers to the set of anomalies that have been identified as having actual risk significance after being filtered by anomaly detection algorithms. They usually have characteristics such as persistence, relevance, and business interpretability, and are used for subsequent risk tracking and early warning parameter optimization.

[0129] Adaptive early warning parameters refer to a set of early warning rules that can be automatically adjusted during the risk early warning process based on the dynamic changes of the actual risk sequence, the evolution of business, and multi-level data feedback. These rules include, but are not limited to, early warning thresholds, weighting coefficients, monitoring frequency, and risk level classification standards.

[0130] Dynamic change data of risk sequences are obtained from the business system. Information extraction tools are used to structure and organize the change paths, resulting in preliminary path information. For this preliminary path information, a pre-established business rule base is used to compare it with business evolution trends to determine if the path information aligns with the expected direction of the evolution trend. If it does, it is identified as a critical change path. Based on the critical change paths, corresponding business adjustment records are obtained. Data matching tools are used to analyze the correlation between the change paths and business adjustments, yielding correlation analysis results. If the correlation analysis results show consistency between the change paths and business adjustments, the evaluation criteria are updated through the information processing module, resulting in updated evaluation standards. Based on the updated evaluation standards and adaptive requirements, information mapping tools are used to adjust the warning parameters, determining the adjusted parameter set. For the adjusted parameter set, data storage tools are used to bind it to the business evolution trend, obtaining the application scope of the bound parameters and determining if it covers all critical change paths. If the coverage scope meets the needs of business adjustments, data synchronization tools are used to update and apply the parameters to the business system, resulting in the final adaptive warning parameters.

[0131] Specifically, in the field of financial risk monitoring, the system continuously tracks the dynamic changes of confirmed real risk sequences through a real-time data stream processing module. First, for a high-risk account, a real risk sequence of 128 transactions over the past 60 days is automatically calculated, determining the risk score time series for each transaction. The average daily volatility slope is 0.042, peaking at 0.089 on day 38. Then, an exponentially weighted moving average algorithm with a decay coefficient of 0.94 is used to smooth the score sequence, resulting in a current smoothed risk value of 0.067, which is 34% higher than the system's initial static threshold of 0.05, indicating an accelerating upward trend in risk. Next, the system introduces a dynamic benchmark update mechanism based on business evolution patterns. The average risk score of the entire account group over the past 30 days is used as a reference benchmark, calculating a current benchmark value of 0.031. After adjusting the parameter by 1.18 using the industry cycle factor, an adaptive warning threshold of 0.0366 is formed. The smoothed risk value of this account exceeds this threshold by 82.8 percentage points, triggering an increase in the severity level. Subsequently, the system used the CUSUM method in the change point detection algorithm to identify abrupt change points in the risk score sequence. It discovered a significant positive change point on day 41, with a cumulative deviation of 7.23 standard deviations, confirming that the risk had entered a new high-risk phase. Finally, the system correlated the aforementioned change point information with the account fund flow network graph, extracting that the number of newly associated accounts in the risk sequence rapidly increased from 4 to 19, and the network density increased from 0.17 to 0.41. The system automatically updated the dynamic risk propagation coefficient of this account to 0.76, and accordingly adjusted the subsequent monitoring frequency to once every 2 hours, forming a complete automated process of continuous optimization of closed-loop adaptive early warning parameters.

[0132] S107. Adaptive early warning parameters are used to integrate multi-layer data feedback. If the feedback shows a deviation in time evolution, the early warning system structure is corrected to obtain the final risk control output.

[0133] Among them, time evolution deviation refers to the significant deviation between the trend of change of a certain level or the overall data and the preset benchmark trend in the process of multi-level data monitoring. It is manifested as a continuous shift or sudden change in statistical indicators (such as mean, variance, and slope).

[0134] Multi-layer time series change information is obtained from the real-time business data stream to obtain an original sequence set. For the original sequence set, a time window segmentation method is used to extract the change features of each layer, resulting in a layered change feature set. Based on the layered change feature set, the time deviation value between each layer's sequence and the baseline sequence is calculated, resulting in a multi-layered deviation index set. If at least one deviation value in the multi-layered deviation index set exceeds a preset threshold, the corresponding layer is marked as an anomaly feedback layer, resulting in an anomaly feedback layer set. For the anomaly feedback layer set, the weight ratio of each layer in the early warning calculation structure is adjusted using a proportional weighting method, resulting in an adjusted calculation structure. Based on the adjusted calculation structure and the current real-time data stream, the early warning parameter values ​​are recalculated to obtain updated adaptive early warning parameters. The updated adaptive early warning parameters are used to assess the risk of the current real-time business data stream, resulting in the final risk control output.

[0135] Specifically, in the field of anti-fraud monitoring, the system continuously collects and integrates user behavior sequences, device fingerprint changes, and transaction link information through a multi-source heterogeneous data fusion engine. For a suspected fraudulent account, it automatically extracts core feature sequences, including login time shifts, device migration frequency, and amount fluctuations, based on 217 behavioral trajectories accumulated over the past 90 days. The system calculates the behavioral anomaly time series, with an average linear regression slope of 0.058 / day, peaking at 0.112 on day 52. ​​Subsequently, it uses a double exponential smoothing algorithm with a horizontal smoothing coefficient of 0.89 and a trend smoothing coefficient of 0.76 to process the data, obtaining a current smoothing anomaly of 0.084, which is 86.7% higher than the system's initial fixed threshold of 0.045, indicating a rapid increase in fraudulent intent. Next, the system initiated an adaptive baseline update based on business seasonality and the iterative patterns of fraud methods. Using the median anomaly score of 0.029 for the entire platform's user base over the past 45 days as the baseline, and adding an adjustment coefficient of 1.31 for the current fraud method activity, a dynamic warning threshold of 0.038 was formed. The account's smoothed anomaly score exceeded this threshold by 121.1%, triggering an upgrade of the alarm level from Level 3 to Level 1. Subsequently, the system analyzed the anomaly sequence using a pellytab test combined with Bayesian change point detection. A strong positive change point was detected on day 57, with a posterior probability of 0.937 and a cumulative deviation exceeding 5.84 standard deviations, indicating a structural shift in the fraud pattern. Finally, the system performs graph embedding analysis on the change point and the associated device-payee network. It finds that after the change point, the number of newly added associated devices surged from the initial 7 to 26, the graph modularity increased from 0.21 to 0.46, and the risk contagion intensity coefficient was automatically calculated to be 0.83. Based on this, the real-time monitoring granularity of the account was adjusted to once every 15 minutes, forming a closed-loop optimization of the adaptive early warning system driven by multi-layer data feedback.

[0136] This invention provides an artificial intelligence-based enterprise financial management auxiliary system, which mainly includes:

[0137] The data acquisition and hierarchical processing module is used to obtain multi-level data from transaction records, classify and process the differences in hierarchical characteristics, and obtain hierarchical financial datasets.

[0138] The threshold optimization module is used to analyze the distribution patterns of hierarchical financial datasets. If the distribution shows signs of lenient underreporting, the unified threshold range is adjusted to determine the optimized threshold group.

[0139] The dynamic threshold modeling module is used to obtain a dynamic threshold model by integrating time evolution factors through an adaptive threshold algorithm based on the strict false alarm situation of the optimized threshold group monitoring.

[0140] The anomaly detection trigger module is used to obtain the risk level index in the dynamic threshold model. If the index exceeds the business environment limit, the anomaly detection algorithm is triggered to identify potential anomalies.

[0141] The true risk sequence determination module is used to extract massive false alarm features from potential anomalies, filter irrelevant signals using anomaly detection algorithms, and determine the true risk sequence.

[0142] The adaptive early warning parameter generation module is used to track dynamic changes through real risk sequences, update judgment criteria according to business evolution patterns, and obtain adaptive early warning parameters.

[0143] The risk control output module is used to integrate multi-layer data feedback using adaptive early warning parameters. If the feedback shows a deviation in time evolution, the early warning system structure is corrected to obtain the final risk control output.

[0144] If the technical solution of this application involves personal information, the product using this technical solution has clearly informed the user of the personal information processing rules and obtained the user's voluntary consent before processing the personal information. If the technical solution of this application involves sensitive personal information, the product using this technical solution has obtained the user's separate consent before processing the sensitive personal information, and also meets the requirement of "express consent". For example, at personal information collection devices such as cameras, clear and prominent signs are set up to inform users that they have entered the scope of personal information collection and that personal information will be collected. If an individual voluntarily enters the collection scope, it is deemed that they have agreed to the collection of their personal information; or on the personal information processing device, the personal information processing rules are clearly informed through signs / information, and authorization is obtained through pop-up information or by asking the individual to upload their personal information; wherein, the personal information processing rules may include information such as the personal information processor, the purpose of personal information processing, the processing method, and the types of personal information processed.

[0145] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.

Claims

1. A method for assisting enterprise financial management based on artificial intelligence, characterized in that, include: By obtaining multi-layered data from transaction records and classifying the differences in characteristics according to the hierarchy, a hierarchical financial dataset is obtained. The distribution pattern is analyzed using hierarchical financial datasets. If the distribution shows signs of lenient underreporting, the unified threshold range is adjusted to determine the optimal threshold group. The method employs hierarchical financial dataset analysis to identify distribution patterns. If the distribution indicates lenient underreporting, the unified threshold range is adjusted to determine an optimized threshold group, including: By using hierarchical financial datasets, the distribution characteristics of data at each level are obtained, and preliminary screening is performed based on these distribution characteristics to obtain a set of distribution outliers. Based on the set of distribution anomalies, analyze whether there are any signs of leniency. Using a preset judgment rule, if the proportion of anomalies exceeds a preset threshold, it is judged that there are signs of leniency, and a leniency sign identifier is obtained. For indicators of laxity, obtain the corresponding underreporting risk data, extract key fields from the underreporting risk data, and determine the potential underreporting range; By analyzing the correlation between potential underreporting intervals and financial distribution, a logistic regression model is used to process the mapping between distribution and underreporting intervals to obtain the correlation assessment results. Based on the correlation assessment results, the threshold range is adjusted. For the high correlation areas in the assessment results, a unified adjustment strategy is implemented to determine the adjusted threshold range. From the adjusted threshold range, obtain the optimized combination scheme, match the corresponding threshold combination for different levels of financial data, and obtain the final optimized threshold group; By optimizing the threshold set, updating the data stratification rules, re-analyzing the financial distribution based on the updated rules, and determining the final distribution adjustment plan; Based on the strict false alarm situation of the optimized threshold group monitoring, a dynamic threshold model is obtained by incorporating time evolution factors through an adaptive threshold algorithm; Obtain the risk level index from the dynamic threshold model. If the index exceeds the business environment limit, trigger the anomaly detection algorithm to identify potential anomalies. Extract massive false alarm features from potential anomalies, use anomaly detection algorithms to filter irrelevant signals, and determine the true risk sequence; By tracking dynamic changes in real risk sequences and updating judgment criteria according to business evolution patterns, adaptive early warning parameters are obtained. An adaptive early warning parameter is used to integrate multi-layer data feedback. If the feedback shows a deviation in time evolution, the early warning system structure is corrected to obtain the final risk control output.

2. The enterprise financial management auxiliary method based on artificial intelligence according to claim 1, characterized in that, The process involves obtaining multi-layered data from transaction records, classifying and processing differences based on hierarchical characteristics to obtain a hierarchical financial dataset, including: Obtain raw, multi-layered data through transaction records; A hierarchical structure partitioning method is used to split multi-level data layer by layer to obtain independent datasets for each layer; Perform classification processing on independent datasets at each level to obtain hierarchical classification results; Based on the hierarchical classification results, determine the type of inter-level differences and obtain the difference classification labels; A hierarchical feature set is obtained by extracting key difference fields from the difference classification labels; A preliminary hierarchical financial table is obtained by matching the hierarchical feature set with the independent datasets of each layer; Perform a data integrity check on the initial hierarchical financial tables to obtain the final hierarchical financial dataset.

3. The enterprise financial management auxiliary method based on artificial intelligence according to claim 1, characterized in that, The process of monitoring strict false alarms based on optimized threshold groups, and obtaining a dynamic threshold model by incorporating time evolution factors through an adaptive threshold algorithm, includes: By optimizing the threshold set, the monitoring of strict false alarms is continuously tracked, and relevant false alarm data is obtained from historical records using data acquisition tools to determine the preliminary distribution range of false alarms. Based on the preliminary distribution range of false alarms and combined with time evolution factors, key change points in the time series are extracted to obtain time-related false alarm fluctuation characteristics. To address the time-related false alarm fluctuations, a pre-defined logistic regression model is applied to handle the relationship between fluctuations and thresholds, and to obtain the corresponding adaptive adjustment direction for the thresholds. From the threshold adaptive adjustment direction, the adjustment criteria that are highly correlated with strict false alarms are selected. If the adjustment criteria show that the false alarm frequency exceeds the preset threshold, the corresponding dynamic threshold update scheme is generated. By using a dynamic threshold update scheme and considering the adaptability requirements, the parameters of the existing threshold algorithm are optimized to determine the updated threshold configuration combination. Based on the updated threshold configuration combination, and considering the false alarm analysis results for different time periods, the operating rules of the dynamic model are constructed to obtain the final threshold application framework. The final threshold application framework is obtained, and anomalies in the monitoring situation are compared in real time. If the anomaly deviates from the preset range, the threshold adjustment mechanism is triggered to determine the monitoring stability after adjustment.

4. The enterprise financial management auxiliary method based on artificial intelligence according to claim 1, characterized in that, If the risk level index in the dynamic threshold model exceeds the business environment limit, an anomaly detection algorithm is triggered to identify potential anomalies, including: By obtaining risk level indicators from the dynamic threshold model, preliminary screening of the indicator data is performed to obtain an abnormal candidate set that exceeds the preset limit. Based on the candidate set of anomalies, a pre-established classification model is used to classify the data points in the candidate set and identify the key objects of concern that belong to potential anomalies. For key targets, extract corresponding environmental boundary data from the business environment, obtain time series information related to abnormal locations, and determine whether there is a continuous deviation. If the time series information shows a continuous deviation, the anomaly detection process is initiated to obtain the specific distribution range of the anomaly location and determine the core area of ​​the anomaly point. By combining data from the core area with historical records in the detection process, frequency characteristics of anomalies are extracted to obtain periodic patterns of abnormal behavior. After obtaining the periodic pattern, a logical judgment tool is applied to the key time points in the pattern. If the indicator value at the key time point exceeds the environmental limit, a corresponding anomaly mark is generated to determine the final anomaly confirmation result. By using the anomaly confirmation results, the risk assessment rules in the threshold model are updated to obtain the adjusted indicator monitoring framework, thus completing the continuous tracking of potential anomalies.

5. The enterprise financial management auxiliary method based on artificial intelligence according to claim 1, characterized in that, The process of extracting massive false alarm features from potential anomalies, filtering irrelevant signals using anomaly detection algorithms, and determining the true risk sequence includes: Abnormal signals are obtained from the business system, and the signals are initially classified using a pre-established classification model to filter out obvious interference information, resulting in a pre-cleaned signal set. For the signal set after initial cleanup, anomaly detection algorithm is used to perform in-depth analysis of the signals, identify the false alarm data contained therein, and obtain a refined abnormal signal group; Extract key information related to business from the refined abnormal signal group, and use information processing tools to structure and organize the signal group to identify the core signals of potential problems; Based on the core signals, obtain the corresponding business environment data. If there is a significant deviation between the core signals and the environment data, mark them as key targets for attention in the risk sequence. For key targets, obtain their historical time series information, and use comparative analysis tools to determine whether there is a persistent deviation, and obtain the determination result of the deviation status; Based on the results of the deviation assessment, if the assessment results show a continuous deviation, the risk sequences are prioritized and high-priority risk sequences are determined. For high-priority risk sequences, information processing tools are used to generate corresponding anomaly markers, and the potential problems are tracked and processed through the marker records.

6. The enterprise financial management auxiliary method based on artificial intelligence according to claim 1, characterized in that, The process of tracking dynamic changes through real risk sequences and updating judgment criteria based on business evolution patterns to obtain adaptive early warning parameters includes: Dynamic change data of risk sequences are obtained from the business system, and information extraction tools are used to structure and organize the change paths to obtain preliminary organized path information; Based on the initially compiled path information, the business evolution trend is compared with the pre-established business rule base to determine whether the path information conforms to the expected direction of the evolution trend. If it does, it is identified as a critical change path. Based on the key change paths, obtain the corresponding business adjustment records, and use data matching tools to analyze the correlation between the change paths and business adjustments to obtain the correlation analysis results; If the correlation analysis results show that the change path is consistent with the business adjustment, the evaluation criteria will be updated through the information processing module to obtain the updated evaluation standards. Based on the updated evaluation criteria and in accordance with the adaptive requirements, information mapping tools are used to adjust the early warning parameters and determine the adjusted parameter set. For the adjusted parameter set, data storage tools are used to bind it with the business evolution trend to obtain the application scope of the bound parameters and determine whether it covers all key change paths; Based on the scope of application of the bound parameters, if the coverage meets the needs of business adjustments, the parameters will be updated and applied to the business system through a data synchronization tool to obtain the final adaptive warning parameters.

7. The enterprise financial management auxiliary method based on artificial intelligence according to claim 1, characterized in that, The method of integrating multi-layer data feedback using adaptive early warning parameters, and correcting the early warning system structure if the feedback shows a deviation in time evolution, to obtain the final risk control output, includes: Extract multi-layer time series change information from real-time business data streams to obtain the original sequence set; For the original sequence set, the time window division method is used to extract the sequence change features of each layer, and a layered change feature set is obtained; Based on the set of stratified change characteristics, the time deviation between each stratified sequence and the baseline sequence is calculated to obtain a set of multi-layer deviation indices. If at least one deviation value in the multi-layer deviation index set exceeds a preset threshold, the corresponding layer is marked as an abnormal feedback layer, and an abnormal feedback layer set is obtained. For the set of abnormal feedback layers, the weight ratio of each layer in the early warning calculation structure is adjusted by a proportional weighting method to obtain the adjusted calculation structure. Based on the adjusted calculation structure and combined with the current real-time data stream, the warning parameter values ​​are recalculated to obtain the updated adaptive warning parameters. The updated adaptive warning parameters are used to assess the risk of the current real-time business data stream, resulting in the final risk control output.

8. An artificial intelligence-based enterprise financial management auxiliary system, characterized in that, The system includes: The data acquisition and hierarchical processing module is used to obtain multi-level data from transaction records, classify and process the differences in hierarchical characteristics, and obtain hierarchical financial datasets. The threshold optimization module is used to analyze the distribution patterns of hierarchical financial datasets. If the distribution shows signs of lenient underreporting, the unified threshold range is adjusted to determine the optimized threshold group. The method employs hierarchical financial dataset analysis to identify distribution patterns. If the distribution indicates lenient underreporting, the unified threshold range is adjusted to determine an optimized threshold group, including: By using hierarchical financial datasets, the distribution characteristics of data at each level are obtained, and preliminary screening is performed based on these distribution characteristics to obtain a set of distribution outliers. Based on the set of distribution anomalies, analyze whether there are any signs of leniency. Using a preset judgment rule, if the proportion of anomalies exceeds a preset threshold, it is judged that there are signs of leniency, and a leniency sign identifier is obtained. For indicators of laxity, obtain the corresponding underreporting risk data, extract key fields from the underreporting risk data, and determine the potential underreporting range; By analyzing the correlation between potential underreporting intervals and financial distribution, a logistic regression model is used to process the mapping between distribution and underreporting intervals to obtain the correlation assessment results. Based on the correlation assessment results, the threshold range is adjusted. For the high correlation areas in the assessment results, a unified adjustment strategy is implemented to determine the adjusted threshold range. From the adjusted threshold range, obtain the optimized combination scheme, match the corresponding threshold combination for different levels of financial data, and obtain the final optimized threshold group; By optimizing the threshold set, updating the data stratification rules, re-analyzing the financial distribution based on the updated rules, and determining the final distribution adjustment plan; The dynamic threshold modeling module is used to obtain a dynamic threshold model by integrating time evolution factors through an adaptive threshold algorithm based on the strict false alarm situation of the optimized threshold group monitoring. The anomaly detection trigger module is used to obtain the risk level index in the dynamic threshold model. If the index exceeds the business environment limit, the anomaly detection algorithm is triggered to identify potential anomalies. The true risk sequence determination module is used to extract massive false alarm features from potential anomalies, filter irrelevant signals using anomaly detection algorithms, and determine the true risk sequence. The adaptive early warning parameter generation module is used to track dynamic changes through real risk sequences, update judgment criteria according to business evolution patterns, and obtain adaptive early warning parameters. The risk control output module is used to integrate multi-layer data feedback using adaptive early warning parameters. If the feedback shows a deviation in time evolution, the early warning system structure is corrected to obtain the final risk control output.