Supply chain multi-level penetration type risk control method and system empowered by large language model

By constructing a dynamic knowledge graph and using a large language model to parse unstructured data, the problem of the inability to dynamically quantify the probability of multi-level supply chain risk propagation in existing technologies has been solved. This enables multi-level monitoring of supply chain risks and determination of alternative paths, thereby improving the depth and timeliness of risk management.

CN122453183APending Publication Date: 2026-07-24SHENZHEN MINGXIN DIGITAL TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SHENZHEN MINGXIN DIGITAL TECH CO LTD
Filing Date
2026-06-25
Publication Date
2026-07-24

AI Technical Summary

Technical Problem

Existing supply chain risk management systems are unable to dynamically quantify the probability of multi-level propagation and determine alternative paths, especially when risks are transmitted at deep nodes, they cannot be detected and dealt with in a timely manner.

Method used

By integrating multi-source heterogeneous data to construct a dynamic knowledge graph, using a large language model to parse unstructured data, quantifying risk factors, simulating multi-level transmission paths with a risk propagation model, and determining target alternative paths through a path search algorithm.

Benefits of technology

It enables dynamic quantification of risks at multi-level supply chain nodes and determination of alternative paths, improving the depth and timeliness of risk monitoring and supporting the tracing of deep nodes and supply chain adjustments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122453183A_ABST
    Figure CN122453183A_ABST
Patent Text Reader

Abstract

The application relates to the technical field of large language models, and provides a supply chain multistage penetration type risk control method and system empowered by a large language model, which comprises the following steps: fusing multi-source heterogeneous data of a supply chain, constructing a dynamic knowledge graph comprising multistage upstream and downstream tracing paths; performing semantic analysis on unstructured data by using a large language model, extracting risk events and quantifying risk factors; determining the vulnerability weight of each supply chain node according to the risk factors and hierarchical attributes in the structured data; simulating the multistage conduction path of the risk along the knowledge graph based on a risk propagation model, and calculating the risk probability of each supply chain node; and determining a target alternative path by using a path search algorithm according to the risk probability, the knowledge graph and transaction attributes in the structured data. The application simulates the multistage conduction path of the risk along the knowledge graph and calculates the risk probability of each node, thereby realizing dynamic quantification of the risk propagation probability between multistage nodes.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of large language model technology, and in particular to a multi-level penetration risk control method and system for supply chain empowered by large language models. Background Technology

[0002] Among existing supply chain risk management systems, one type of system only collects structured data (such as supplier level and order volume) from the Enterprise Resource Planning (ERP) system and performs risk monitoring based on preset rules; the other type of system collects unstructured data (such as equity relationship text, global public opinion news, and sanctions lists) and extracts risk signals for risk monitoring.

[0003] However, both types of systems suffer from insufficient depth in supply chain hierarchy. Their risk transmission analysis relies on static data and cannot dynamically simulate the propagation path of risks across multiple supply chain nodes. This is especially true when risks occur at deeper nodes, often failing to be detected in a timely manner. The systems cannot quantify the probability of the risk propagating to downstream nodes, nor can they quickly search for feasible alternative suppliers based on the current supply chain topology. Summary of the Invention

[0004] Based on this, it is necessary to address the technical problem that existing technologies cannot dynamically quantify the probability of multi-level propagation and determine alternative paths, and propose a supply chain multi-level penetration risk control method and system empowered by a large language model.

[0005] Firstly, a multi-level penetration-based risk control method for the supply chain empowered by a large language model is provided, comprising: integrating multi-source heterogeneous data from the supply chain to construct a dynamic knowledge graph including multi-level upstream and downstream traceability paths, wherein the multi-source heterogeneous data includes structured data and unstructured data; using a large language model to perform semantic parsing on the unstructured data, extracting risk events and quantifying risk factors; determining the vulnerability weight of each supply chain node based on the risk factors and the hierarchical attributes in the structured data; simulating the multi-level transmission path of risk along the knowledge graph based on a risk propagation model, and calculating the risk probability of each supply chain node; and determining the target alternative path using a path search algorithm based on the risk probability, the knowledge graph, and the transaction attributes in the structured data.

[0006] Secondly, a supply chain multi-level penetration risk control system empowered by a large language model is provided. The system includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the steps of the aforementioned supply chain multi-level penetration risk control method empowered by a large language model.

[0007] Thirdly, a computer device is provided, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the aforementioned supply chain multi-level penetration risk control method empowered by the large language model.

[0008] Fourthly, a computer-readable storage medium is provided, which stores a computer program that, when executed by a processor, implements the steps of the aforementioned supply chain multi-level penetration risk control method empowered by a large language model.

[0009] The supply chain multi-level penetration risk control method provided in this application, powered by a large language model, constructs a dynamic knowledge graph containing multi-level upstream and downstream traceability paths by integrating multi-source heterogeneous data from the supply chain. This allows risk transmission analysis to move beyond the limitations of first- or second-tier suppliers and support the tracing of deeper nodes. By using a large language model to perform semantic parsing on unstructured data to extract risk events and quantify risk factors, textual risk signals are transformed into calculable numerical inputs, providing a basis for subsequent quantification. The vulnerability weight of each supply chain node is determined based on risk factors and hierarchical attributes in structured data, reflecting the differences in the influence of different levels of nodes in risk propagation. By simulating the multi-level transmission path of risk along the knowledge graph based on a risk propagation model and calculating the risk probability of each node, dynamic quantification of the probability of risk propagation among multi-level nodes is achieved. Finally, by using a path search algorithm based on risk probability, the knowledge graph, and transaction attributes in structured data to determine target alternative paths, executable supply adjustment plans are directly output based on the obtained propagation probabilities. Therefore, the supply chain multi-level penetration risk control method provided in this application can solve the technical problem of not being able to dynamically quantify the multi-level propagation probability and determine alternative paths when the supply chain contains multiple levels of upstream and downstream nodes. Attached Figure Description

[0010] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0011] in: Figure 1 A flowchart of a supply chain multi-level penetration risk control method empowered by a large language model in an embodiment of the present invention; Figure 2 A schematic diagram of the modules of the supply chain multi-level penetrating risk control system empowered by a large language model in an embodiment of the present invention; Figure 3 This is a structural block diagram of the computer device in an embodiment of the present invention; Figure 4 This is a structural block diagram of a computer device in an embodiment of the present invention. Detailed Implementation

[0012] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0013] Please see Figure 1 As shown, Figure 1 A flowchart illustrating the supply chain multi-level penetration risk control method empowered by a large language model provided in this embodiment of the invention includes the following steps: Step 01: Integrate multi-source heterogeneous data from the supply chain to construct a dynamic knowledge graph that includes multi-level upstream and downstream traceability paths. The multi-source heterogeneous data includes both structured and unstructured data. Step 02: Use a large language model to perform semantic parsing on unstructured data, extract risk events, and quantify risk factors; Step 03: Determine the vulnerability weight of each supply chain node based on risk factors and hierarchical attributes in structured data; Step 04: Based on the risk propagation model, simulate the multi-level transmission path of risk along the knowledge graph and calculate the risk probability of each supply chain node; Step 05: Based on risk probability, knowledge graph, and transaction attributes in structured data, use a path search algorithm to determine the target alternative path.

[0014] In this application, "multi-level penetrating risk control" refers to the ability to monitor and analyze risks that are not limited to first- or second-tier suppliers, but can trace upstream along the knowledge graph of the supply chain to multiple levels (such as third-, fourth-, or even deeper levels of suppliers), and can simulate the process of risk transmission from deep nodes to downstream level by level.

[0015] Specifically, in step 01, multi-source heterogeneous data can include data from different data sources with different structures. For example, structured data can refer to supplier hierarchy information and order volume information stored in a fixed-field format in an Enterprise Resource Planning (ERP) system, while unstructured data can refer to free-format information such as equity relationship text, multilingual news text, and sanctions list text. The dynamic knowledge graph can be a supply chain network model organized in the form of a graph database, where nodes represent supply chain participants (such as suppliers, logistics providers, and manufacturers), edges represent the relationships between nodes (such as controlling relationships, supply relationships, and substitution relationships), and multi-level upstream and downstream traceability paths refer to the topological connections that trace multiple levels of suppliers upstream from the end manufacturer or transmit influence downstream.

[0016] In step 02, the Large Language Model (LLM) can be a deep learning model pre-trained on a large scale of text, capable of understanding the meaning of natural language. Semantic parsing can include operations such as sentiment analysis and event extraction. Risk events can include sanctions, strikes, trade restrictions, etc., and risk factors can be numerical values ​​that map the severity of events, such as production capacity risk coefficients or supply disruption probabilities.

[0017] In step 02, the large language model parses the unstructured data, transforming textual information that could not be directly used in numerical calculations into quantitative risk factors, enabling external events to be injected into the risk quantification system in numerical form.

[0018] In step 03, the hierarchy attribute can represent the supplier's hierarchical position in the supply chain (such as first-tier supplier, second-tier supplier), and the vulnerability weight can be a comprehensive value used to quantify the inherent sensitivity of each supply chain node in the risk propagation process and the degree to which it is affected by external events. The higher the value, the more vulnerable the node is and the more likely it is to experience or transmit risks.

[0019] In step 03, the method combines risk factors with the inherent hierarchical attributes of nodes to calculate the vulnerability weight of each node, which reflects the initial vulnerability of the node in the spread of risk.

[0020] In step 04, based on the risk propagation model, the multi-level transmission path of risk along the knowledge graph is simulated, and the risk probability of each supply chain node is calculated. The risk propagation model can be a mathematical model used to describe the diffusion pattern of risk on a network.

[0021] In step 04, the risk propagation model uses a knowledge graph as its network structure and the vulnerability weights of each node as initial parameters. It calculates the risk propagation probability level by level according to the multi-level transmission path, and finally obtains the probability value of each node being affected by the risk.

[0022] In step 05, the transaction attributes may include order volume information, historical logistics costs, and the path search algorithm may be a computational method for finding the optimal path in a graph, such as a heuristic path search algorithm (e.g., A* algorithm).

[0023] In step 05, the method integrates risk probability, knowledge graph topology, and transaction attributes, and uses a path search algorithm to find an alternative path from the current supply source to the target manufacturer in the graph. This path avoids high-risk nodes while satisfying transaction constraints, thereby outputting an executable supply adjustment plan.

[0024] The beneficial effects of the implementation method of this application are as follows: by integrating multi-source heterogeneous data to construct a multi-level upstream and downstream knowledge graph, the depth of risk analysis is extended from level one and two to more levels; risk factors are obtained by parsing unstructured data through a large language model, enabling text-based risk signals to participate in quantitative calculations; by combining risk factors and hierarchical attributes to determine vulnerability weights, the differentiated impact of nodes at different levels in risk propagation is reflected; by simulating multi-level transmission paths through a risk propagation model and calculating the risk probability of each node, dynamic quantification of the probability of risk propagation between multi-level nodes is achieved; and by searching for target alternative paths based on risk probability, knowledge graph, and transaction attributes, a supply adjustment plan is directly output after obtaining the propagation probability.

[0025] Figure 2 This is a schematic diagram of the modules of a supply chain multi-level penetration risk control system empowered by a large language model in this embodiment of the invention, including a fusion module, a large language model parsing module, and an output module. The fusion module is configured to fuse multi-source heterogeneous data from the supply chain to construct a dynamic knowledge graph including multi-level upstream and downstream traceability paths. The multi-source heterogeneous data includes structured and unstructured data. The large language model parsing module is configured to use a large language model to perform semantic parsing on the unstructured data, extract risk events, and quantify risk factors; determine the vulnerability weight of each supply chain node based on the risk factors and hierarchical attributes in the structured data; and simulate the multi-level transmission path of risk along the knowledge graph based on a risk propagation model to calculate the risk probability of each supply chain node. The output module is configured to determine the target alternative path using a path search algorithm based on the risk probability, the knowledge graph, and the transaction attributes in the structured data.

[0026] In some embodiments, step 01 above includes: Obtain supplier hierarchy information and order volume information from the enterprise resource planning system through application programming interfaces (APIs) as structured data; Obtain equity relationship text from the equity database and multilingual news text and sanctions list text from the global public opinion database as unstructured data; Based on structured and unstructured data, a dynamic knowledge graph is constructed with suppliers, logistics providers, and manufacturers as nodes and holding relationships, supply relationships, and substitution relationships as edges. The knowledge graph supports upstream and downstream traceability queries at multiple levels.

[0027] Specifically, an Application Programming Interface (API) can be a protocol specification for data exchange between different software modules. An Enterprise Resource Planning (ERP) system can be a management platform that integrates business information such as procurement, production, inventory, and finance. Supplier hierarchy information can represent the supplier's tier number in the supply chain. Order volume information can represent the quantity or value of goods shipped by the buyer to the supplier within a specific time period. Equity relationship text from an equity database and multilingual news text and sanctions list text from a global public opinion database are obtained as unstructured data.

[0028] An equity database can be a collection of data specifically storing corporate equity structures, shareholder information, and investment relationships. Equity relationship texts can include paragraphs describing shareholding percentages and control rights. A global public opinion database can be an information repository aggregating news media, social media platforms, and government announcements from various countries. Multilingual news texts can refer to news reports written in different languages. Sanctions list texts can include the names of entities restricted by international or national regulations and descriptions of the corresponding restrictive measures.

[0029] In step 01, a data connection is established with the enterprise resource planning system via an application programming interface (API) to automatically retrieve supplier hierarchy information and order volume information, eliminating the need for manual export and import. Simultaneously, equity relationship text is extracted from the equity database, and multilingual news text and sanctions list text are extracted from the global public opinion database. These unstructured data, along with the aforementioned structured data, serve as input for subsequent knowledge graph construction. Due to the use of the API, data acquisition can be performed automatically at a preset frequency, ensuring the timeliness of information. Equity relationship text is used to identify holding chains between enterprises, multilingual news text is used to capture risk signals from around the world, and sanctions list text is used to mark restricted entities. The introduction of these data sources enables the method to cover a wider range of supply chain risk types.

[0030] When constructing a dynamic knowledge graph, the acquired structured and unstructured data are first parsed to extract three types of nodes: suppliers, logistics providers, and manufacturers. For each record, the system creates a corresponding node object in the graph database based on the entity name or unique identifier. Then, edges are established based on the relationship descriptions in the data: supply relationships are extracted from order data in the enterprise resource planning system, i.e., directed edges are created between the buyer and supplier nodes, pointing from the supplier to the buyer. Controlling relationships are extracted from equity relationship text, i.e., directed edges are created between the shareholder and invested node, pointing from the shareholder to the invested party. Undirected or bidirectional edges for substitution relationships are created from substitution relationship descriptions (such as the list of substitute materials marked in the supplier master data). All nodes and edges are accompanied by timestamps and confidence labels to support subsequent updates.

[0031] The implementation of multi-level upstream and downstream traceability queries is as follows: The graph database employs a depth-first or breadth-first graph traversal algorithm. When a user or upper-level module initiates a query, specifying the starting node (e.g., a manufacturer), the tracing direction (upstream or downstream), and the number of levels to be traced (e.g., 5 levels), the query engine starts from the starting node and jumps layer by layer along the supply relationship edges (for upstream tracing, along the in-line direction of the edge, from manufacturer to supplier; for downstream tracing, along the out-line direction of the edge, from supplier to manufacturer). Each time an edge is traversed, the count level increases by 1 until the preset level is reached or no more nodes are accessible. For holding relationships and substitution relationships, these can be returned synchronously as additional attributes during the traversal. Because the graph database optimizes relational queries with indexes, this query operation can be completed within milliseconds to seconds, supporting real-time risk analysis. The dynamic nature of the knowledge graph is reflected in the fact that when new data arrives, the system uses an incremental update mechanism to insert, delete, or modify the weights of only the affected nodes and edges, without rebuilding the entire graph, thus ensuring timely query response.

[0032] The beneficial effects of the implementation method of this application are as follows: By directly obtaining supplier level information and order volume information from the enterprise resource planning system through the application programming interface, the automatic and real-time collection of structured data is realized, reducing the delay and error of manual data entry; by obtaining equity relationship text in the equity database, the capital control relationship between enterprises can be included in the analysis, avoiding risk omissions due to insufficient equity penetration; by obtaining multilingual news text and sanctions list text in the global public opinion database, unstructured risk information across regions and languages ​​can enter the processing flow, expanding the language and geographical scope of risk perception.

[0033] In some embodiments, step 02 above includes: Sentiment analysis of multilingual news texts is performed based on a large language model to obtain sentiment scores; Based on a large language model, events are extracted from equity relationship texts and sanctions list texts to identify sanctions, strikes, and trade restrictions. Emotional scores and event types are mapped to capacity risk coefficients or supply disruption probabilities as risk factors.

[0034] Specifically, multilingual news text can refer to news reports written in different languages ​​(such as English, Chinese, Vietnamese, and Malay); sentiment analysis can be a natural language processing operation that judges the emotional tendency expressed in the text; sentiment score can be a numerical value used to indicate the degree of positivity or negativity of the text content towards a specific subject (such as a supplier or a region) (for example, a higher negative score indicates higher risk). Based on a large language model, event extraction is performed on equity relationship texts and sanctions list texts to identify sanctions, strikes, and trade restrictions.

[0035] Event extraction can be the operation of identifying predefined types of events and their participating elements (such as time, place, subject, and object) from unstructured text; sanction events can refer to events in which an entity is restricted from trading or has its assets frozen due to violations of regulations; strike events can refer to events in which workers collectively stop working to express their demands; trade restriction events can refer to trade barriers such as tariffs imposed between countries or regions and bans on imports and exports.

[0036] Sentiment scores and event types are mapped to capacity risk coefficients or supply disruption probabilities as risk factors. The mapping process can involve converting sentiment scores and event types into quantitative values ​​according to preset rules or functions. The capacity risk coefficient can be a numerical value representing the degree of negative impact of the event on the supplier's production capacity (the higher the value, the greater the risk of capacity decline). The supply disruption probability can be a value between 0 and 1, representing the likelihood that a supply chain node will be unable to supply normally due to the event.

[0037] The large language model takes multilingual news text as input. It converts the text into a vector representation through its internal word embedding layer. The vector representation is then processed through multiple self-attention layers and feedforward network layers. Finally, a sentiment classification head is connected to the output, which outputs a sentiment score that is between negative and positive.

[0038] For equity relationship text and sanctions list text, the large language model, in the same reasoning process, uses an event extraction decoder to locate trigger words in the text, extract event types and related entities, and output structured event records by using predefined event patterns (such as "[subject] is sanctioned", "[location] has a strike", "[country] restricts [goods] exports").

[0039] The sentiment scores and event records output by the model are fed into a mapping module: for sentiment scores, they are mapped to the corresponding increment of production capacity risk coefficient or supply disruption probability based on the threshold range of the score (e.g., negative scores above 0.6); for event types, they are converted according to a pre-established correspondence table (e.g., strike events are mapped to an increase of 0.3 in production capacity risk coefficient, and sanctions events are mapped to an increase of 0.5 in supply disruption probability). Finally, the above results are combined or weighted to obtain the comprehensive risk factor for each risk event. Because the large language model has multilingual understanding capabilities, its sentiment analysis and event extraction of texts in different languages ​​are based on a shared semantic space, eliminating the need to train separate models for each language.

[0040] The beneficial effects of the implementation method of this application are as follows: By performing sentiment analysis on multilingual news texts using a large language model, sentiment scores can be calculated uniformly across language boundaries, avoiding the complexity of processing multiple languages ​​separately; by extracting events from equity relationship texts and sanctions list texts using a large language model, sanctions, strikes, and trade restriction events can be accurately located from unstructured texts, avoiding false positives and false negatives caused by keyword matching; by mapping sentiment scores and event types to capacity risk coefficients or supply disruption probabilities, risk signals in the text are transformed into standardized values ​​that can directly participate in the subsequent calculation of vulnerability weights.

[0041] In some embodiments, step 03 above includes: Based on the hierarchical attributes in the structured data, a baseline vulnerability weight is set for each level of the supply chain node; The risk factor is used as a correction coefficient and multiplied by the baseline vulnerability weight of the corresponding node to obtain the final vulnerability weight of each supply chain node.

[0042] Specifically, the hierarchical attribute represents the node's level number in the supply chain, such as Tier 1, Tier 2, and Tier 3 suppliers. The baseline vulnerability weight is a preset value used to represent the basic sensitivity of the node at that level in risk propagation, independent of specific risk events. The risk factor is used as a correction coefficient and multiplied by the corresponding node's baseline vulnerability weight to obtain the final vulnerability weight for each supply chain node. Here, the correction coefficient is a multiplier factor obtained from parsing unstructured data using a large language model in the previous steps; the multiplication operation refers to performing arithmetic multiplication of the baseline weight and the correction coefficient, with the product being the final output vulnerability weight.

[0043] Suppliers closer to the end-product manufacturer (i.e., higher in the hierarchy) have a more direct impact on final production from risks they encounter, and therefore should be assigned a higher baseline vulnerability weight. Suppliers farther away have longer impact transmission paths and a greater possibility of attenuation, so their baseline weight should be lowered accordingly. At the same time, the impact of external public opinion events (such as strikes and sanctions) on nodes is dynamic, and the baseline weight needs to be adjusted in real time through correction coefficients.

[0044] The principle behind multiplication is that the baseline weight represents the inherent vulnerability of a node, and the correction coefficient represents the additional vulnerability increment caused by the event. Multiplying the two is equivalent to proportionally adding the impact of the event to the inherent vulnerability. For example, for a Tier 1 supplier with a baseline weight of 0.7, if the correction coefficient for a strike event is 1.3, the final weight will be 0.91, indicating a 30% increase in risk. However, for a Tier 3 supplier with a baseline weight of 0.3, the final weight after the same correction coefficient is 0.39, a smaller absolute increase, which aligns with the physical intuition that risk decreases progressively as it propagates through multiple levels.

[0045] In one specific implementation, the system predefines baseline vulnerability weights for the three-tier supply chain: 0.7 for Tier 1 suppliers, 0.5 for Tier 2 suppliers, and 0.3 for Tier 3 suppliers. From the risk factors obtained in step 02, the capacity risk coefficient mapped to a strike event associated with a supplier is 0.3, so the correction coefficient is (1+0.3)=1.3. The system queries the supplier's tier attribute; assuming it's a Tier 1 supplier, it retrieves the baseline weight of 0.7 and calculates the final vulnerability weight = 0.7 × 1.3 = 0.91. If the same strike event affects a Tier 3 supplier, the baseline weight is 0.3, and the final vulnerability weight = 0.3 × 1.3 = 0.39. The system stores the calculated final vulnerability weights in the node attributes of the graph.

[0046] For nodes without event triggers, the correction coefficient is set to 1.0 by default, and the final weight equals the baseline weight. The implementation also allows configuring correction coefficient mapping tables for different event types; for example, the correction coefficient for a sanctions event is (1+0.5), and the correction coefficient for a trade restriction event is (1+0.2). The system supports dynamic updates to the correction coefficients; when a geopolitical event occurs, the correction coefficients for all nodes in a specific country or region can be adjusted in batches.

[0047] In some implementations, step 04 above includes: The susceptible-infection-removal model was adopted as the risk transmission model. The vulnerability weight of each supply chain node is used as the initial infection probability; Following the transmission direction from upstream to downstream in the knowledge graph, the probability of each node being affected by the risk is calculated sequentially, and the final risk probability of each supply chain node is output.

[0048] Specifically, the Susceptible-Infected-Removed (SIR) model is adopted as the risk propagation model. This model divides supply chain nodes into three states: susceptible (not yet affected by the risk but potentially susceptible to its spread), infected (affected by the risk and capable of propagating downstream), and removed (out of the propagation chain and no longer affecting other nodes). The vulnerability weight of each supply chain node is used as the initial infection probability, meaning the probability that each node directly enters the infected state at the start of propagation is equal to its determined vulnerability weight. Following the propagation direction from upstream to downstream in the knowledge graph, the probability of each level of node being affected by the risk is calculated sequentially, outputting the final risk probability for each supply chain node. The propagation direction is limited to from supplier (upstream) to manufacturer (downstream), and the final risk probability is the probability that the node is in the infected state after the propagation process ends.

[0049] It should be noted that, in the supply chain risk propagation scenario of this application, the "removal" status in the SIR model does not mean risk elimination, but rather that a risk event (such as production stoppage or supply disruption) has occurred at that node, and its impact on downstream processes has already occurred and been transmitted. Therefore, it is no longer considered a new risk source in the current propagation round. Once the risk probability of a node reaches the removal status, it is considered that a risk has occurred, and this status will be persisted for use in the final risk assessment report.

[0050] When a node experiences a risk, the risk propagates downstream along the supply chain, similar to how a virus spreads through contact. The vulnerability weight, as the initial infection probability, reflects the inherent likelihood of a node experiencing a risk; the higher the weight, the greater the initial infection probability.

[0051] The reason for adopting the susceptible-infected-removed model is that, in risk propagation, once a node is affected by a risk and has completed its impact on downstream processes, it typically does not trigger repeated risks (e.g., after a supplier's production stoppage leads to a supply disruption, the node itself no longer generates new risks), corresponding to the removal state. The propagation direction is strictly limited to upstream to downstream, which aligns with the actual characteristics of supply chain risks being transmitted along the material flow (downstream risks generally do not trigger upstream risks in the opposite direction). In the sequential calculation, upstream nodes first determine their infected state, and then influence downstream nodes with a certain propagation probability. After being infected, downstream nodes continue to influence their downstream nodes, forming a cascading transmission. The final risk probability is obtained through multiple simulations and statistics, quantifying the likelihood of each node being affected in the global risk propagation.

[0052] In one specific implementation, the system first sets propagation parameters: the initial infection propagation probability can be obtained statistically based on the frequency of risk propagation from upstream nodes to downstream nodes in historical supply chain risk events; the removal probability can be set based on the ratio of the average duration of the risk event to the simulation time step. When historical data is unavailable, empirical values ​​can be preset, such as an infection propagation probability of 0.8 and a removal probability of 0.2. The vulnerability weights of each node (e.g., 0.91 for Tier 1 suppliers, 0.65 for Tier 2 suppliers, and 0.39 for Tier 3 suppliers) are directly used as the initial infection probability.

[0053] The system performs 1000 Monte Carlo simulations. At the start of each simulation, all nodes are traversed, and an initial infected node is randomly labeled with a probability based on its vulnerability weight. Propagation then proceeds round by round from upstream to downstream: the currently infected node attempts to infect each downstream neighbor with a probability of 0.8; successfully infected downstream nodes become new sources of infection in the next round. After one time step, an infected node transitions to a removed state with a probability of 0.2 and no longer participates in subsequent propagation. Propagation continues until no new infected nodes are generated. The final risk probability is obtained by calculating the frequency of each node being infected at least once in the 1000 simulations and dividing by 1000. For example, if a manufacturer's node is infected 850 times in 1000 simulations, its final risk probability is 0.85. This probability value is stored for subsequent alternative path searches. Propagation parameters can be calibrated and adjusted based on historical industry data.

[0054] In some implementations, step 05 above includes: Order volume information and historical logistics costs from structured data are used as path cost parameters; Using risk probability as a path blocking factor; A heuristic path search algorithm is used to mine the optimal order transfer path from the current supplier to the target manufacturer in the knowledge graph, which serves as the target alternative path.

[0055] Specifically, order volume information and historical logistics costs from structured data are used as path cost parameters. Order volume information represents the quantity or value of goods supplied by suppliers to buyers, serving as the basis for prioritizing high-volume routes during path selection. Historical logistics costs represent the actual transportation expenses (including warehousing, customs clearance, etc.) from suppliers to target manufacturers in the past, serving as a quantitative measure of path cost. Risk probability is used as a path blocking factor. Risk probability is the likelihood (range 0 to 1) of each node being affected by risk, as output in step 04. The blocking factor indicates whether the node is prohibited or has a high cost of passage; the higher the risk probability, the greater the cost of the path passing through that node.

[0056] The heuristic path search algorithm used can be the A* algorithm. The A* algorithm is a shortest path algorithm that uses an evaluation function to guide the search direction. It mines the optimal transfer path from the current supplier to the target manufacturer in the knowledge graph as the target alternative path. The optimal transfer path refers to one or more edge sequences from the current supplier node to the target manufacturer node under the conditions of minimizing cost and avoiding high-risk nodes.

[0057] Heuristic pathfinding algorithms utilize an evaluation function to estimate the remaining cost from the current node to the target node, thus prioritizing the exploration of promising paths and reducing the search space. In a knowledge graph, the algorithm starts from the current supplier node, progressively expanding to neighboring nodes, comparing the cumulative cost of each path until it reaches the target manufacturer node, and outputs the path with the minimum cumulative cost as the optimal transfer path. Because knowledge graphs support multi-level tracing, this algorithm can traverse multiple intermediate nodes to find alternative routes that bypass high-risk areas.

[0058] First, order volume information (e.g., supplier A supplies manufacturer M with 1 million yuan worth of goods per month) and historical logistics costs (e.g., the land transportation cost from supplier A to manufacturer M is 50,000 yuan per batch) are obtained from structured data. Based on this, the edge cost formula is defined as: Edge Cost = Logistics Cost / (Order Volume Normalized Value + 1), which reduces the edge cost when the order volume is high. The order volume normalized value refers to the value obtained by normalizing the order volume of the current edge with the maximum order volume of all edges in the knowledge graph, and its value ranges from [0, 1].

[0059] Simultaneously, the risk probabilities of each node are obtained: Supplier A risk probability 0.9, Supplier B risk probability 0.2, Supplier C risk probability 0.6, and Manufacturer M risk probability 0.1. A risk threshold of 0.8 is set. Supplier A's risk probability of 0.9 exceeds the threshold, so it is marked as a blocked node, and its edge cost is set to infinity.

[0060] The A* algorithm is used to search the knowledge graph: the current supplier node is set as supplier B (unblocked), and the target node is manufacturer M. The evaluation function uses Euclidean distance or hierarchical difference (e.g., the number of intermediate nodes from supplier B to manufacturer M). The algorithm starts from supplier B and traverses its downstream neighbor nodes (e.g., logistics provider L, supplier C), calculating the cumulative cost of each path (edge ​​cost + congestion factor weighted, where a risk probability of 0.6 × penalty coefficient is added when passing through node C).

[0061] The final search yields one path: Supplier B → Logistics Provider L → Manufacturer M, with a cumulative cost of 2.3; another path, Supplier B → Supplier C → Manufacturer M, has a cumulative cost of 3.8. The algorithm selects the path with the lowest cost as the optimal transfer route. The node sequence and estimated logistics cost of this path are output. If no alternative path is found, an empty string is returned and manual intervention is triggered. This implementation supports dynamically adjusting the risk threshold and penalty coefficient, for example, setting a lower blocking threshold (e.g., 0.5) for critical components.

[0062] In some implementations, the method includes: after determining the target alternative path, using a large language model to conduct a compliance review of the target alternative path. The compliance review includes: automatically matching the export control regulations of the target country or region to generate a compliance assessment report that marks potential legal risk points; when the compliance assessment report shows no high risk, outputting the target alternative path as a contingency plan.

[0063] Specifically, compliance review refers to checking whether the various nodes involved in the path (suppliers, logistics providers, manufacturers) and their transactions comply with the laws and regulations of the target country or region. The compliance review specifically includes: automatically matching export control regulations of the target country or region and generating a compliance assessment report that identifies potential legal risks. Export control regulations, EU dual-use item control regulations, etc., are legal documents by which countries restrict the export of specific goods, technologies, or entities. When the compliance assessment report indicates no high risk, an alternative target path is output as a contingency plan. "No high risk" means that there are no legal obstacles prohibiting the transaction in the report, or that any existing risks are determined to be at an acceptable low-risk level.

[0064] In one specific implementation, assume the target alternative path is: Supplier B (Vietnam) → Logistics Provider L (Singapore) → Manufacturer M (USA). The method first extracts path information: the supplier name is "Vietnam XX Company," the product is "XX Capacitor," and the destination is the United States. A large language model fine-tuned with legal text is trained on an export control regulations dataset. The model receives the following instruction: "Please check if the following path complies with US export control regulations: Supplier Vietnam XX Company, Product XX Capacitor, End-user Manufacturer M." Based on the export control knowledge contained in its training data, the model infers that XX Capacitor typically does not require a license.

[0065] The model outputs a compliance assessment report, which includes the following: Risk point: The supplier, Vietnam XX Company, is not on the Entity List, and the goods fall under the category of goods without specific controls. However, according to the end-use terms, if the buyer, manufacturer M, is involved in a military contract, a license is required. Further verification of the intended use is recommended.

[0066] The overall risk level is medium. Since the risk level is not "no high risk", this method does not output this path as a contingency plan. Instead, it returns to the search module to find other paths (such as bypassing manufacturer M or changing the product).

[0067] In some implementations, the method further includes dynamically adjusting the baseline vulnerability weights corresponding to the hierarchical attributes in the structured data based on geopolitical events. Specifically, when a specific trade friction event occurs, the baseline vulnerability weights of the supply chain nodes located in the corresponding country or region are increased by a preset percentage.

[0068] Specifically, under normal circumstances, the vulnerability of supply chain nodes primarily depends on their hierarchical position (the higher the level, the more vulnerable). However, when geopolitical events occur, nodes located in the countries or regions involved in the event experience additional external pressure, independent of their hierarchical position. For example, a third-tier supplier, even though located at a higher level, may face a greater risk of supply disruption if it is located in a country subject to tariffs than a first-tier supplier in a neutral country. By dynamically increasing the baseline vulnerability weights of these nodes, this method enables subsequent risk propagation models to perceive geopolitical impacts: after the weights are increased, the initial probability of infection for the node increases, making it more likely to be identified as a risk source or a risk amplification node in the simulation. The preset percentage adjustment method allows for rapid response without recalculating the entire knowledge graph topology. The adjustment operation is reversible: when the event subsides or ends, the weights can be restored to their original values.

[0069] In some implementations, the large language model is trained in multiple languages ​​based on the scenario of industrial overseas expansion, and the types of languages ​​include Vietnamese and Malay; Semantic parsing of unstructured data using large language models includes: using a large language model trained in multiple languages ​​to perform semantic parsing of news texts and extract risk events.

[0070] Specifically, general-purpose language models have limited coverage of low-resource languages ​​(such as Vietnamese and Malay), and directly using them for risk analysis in these languages ​​can lead to a high false positive rate. Through multilingual training in the context of industrial export scenarios, the model learns localized expressions related to supply chain risks. When receiving news texts in less commonly spoken languages, the trained model can accurately identify risk keywords and contextual logic, thereby extracting standardized risk events. Because the training data covers industrial scenarios, the model can also understand local industry terminology and legal expressions, avoiding underreporting of risks due to language barriers.

[0071] In one specific implementation, 100,000 Vietnamese news articles and 50,000 Malay news articles are collected, and risk events (strikes, sanctions, customs clearance delays, etc.) are labeled within them. The basic large language model is then trained using a low-rank adaptation method. The trained model is deployed on a risk control platform. When a Vietnamese news article (Samsung Thai Nguyen factory workers strike demanding higher wages) is received, the model outputs the event type "strike," the risk level "high," and extracts the location "Thai Nguyen Province" and the subject "Samsung factory." This event is quantified as a risk factor and enters the subsequent vulnerability weight calculation stage. Similarly, for Malay news articles about the government imposing export restrictions on rubber products, the model outputs the event type "trade restriction," and the risk factor is updated accordingly.

[0072] In one embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 3 As shown, the computer device includes a processor, memory, network interface, and database connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile and / or volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and database. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage media. The network interface is used to communicate with external clients via a network connection. When the computer program is executed by the processor, it implements the server-side functions or steps of a large language model-enabled supply chain multi-level penetration risk control method.

[0073] In one embodiment, a computer device is provided, which may be a client, and its internal structure diagram may be as follows: Figure 4 As shown, the computer device includes a processor, memory, network interface, display screen, and input devices connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage media. The network interface is used to communicate with an external server via a network connection. When the computer program is executed by the processor, it implements client-side functions or steps of a large language model-enabled supply chain multi-level penetration risk control method.

[0074] It should be noted that the functions or steps that can be implemented by the computer-readable storage medium or computer device described above can be referred to the relevant descriptions on the server side and client side in the foregoing method embodiments. To avoid repetition, they will not be described one by one here.

[0075] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.

[0076] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is used as an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.

[0077] The above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included within the protection scope of the present invention.

Claims

1. A multi-level penetration-based risk control method for supply chain empowered by a large language model, characterized in that, include: By integrating multi-source heterogeneous data from the supply chain, a dynamic knowledge graph is constructed that includes multi-level upstream and downstream traceability paths. The multi-source heterogeneous data includes both structured and unstructured data. The unstructured data is semantically parsed using a large language model to extract risk events and quantify risk factors; Based on the risk factors and the hierarchical attributes in the structured data, the vulnerability weight of each supply chain node is determined; The susceptible-infection-removal model was adopted as the risk transmission model. The vulnerability weight of each of the aforementioned supply chain nodes is used as the initial infection probability; According to the transmission direction from upstream suppliers to downstream manufacturers in the knowledge graph, the probability of each node being affected by the risk is calculated in turn, and the risk probability of each node in the supply chain is output. Based on the risk probability, the knowledge graph, and the transaction attributes in the structured data, a path search algorithm is used to determine the target alternative path.

2. The supply chain multi-level penetration risk control method empowered by a large language model according to claim 1, characterized in that, The integrated multi-source heterogeneous data of the supply chain is used to construct a dynamic knowledge graph including multi-level upstream and downstream traceability paths, including: Supplier hierarchy information and order volume information from the enterprise resource planning system are obtained through the application programming interface and used as the structured data. Obtain equity relationship text from the equity database and multilingual news text and sanctions list text from the global public opinion database as the unstructured data; Based on the structured and unstructured data, a dynamic knowledge graph is constructed with suppliers, logistics providers, and manufacturers as nodes and holding relationships, supply relationships, and substitution relationships as edges. The knowledge graph supports upstream and downstream traceability queries at multiple levels.

3. The supply chain multi-level penetration risk control method empowered by a large language model according to claim 1, characterized in that, The step of using a large language model to perform semantic parsing on the unstructured data, extracting risk events, and quantifying risk factors includes: Based on the aforementioned large language model, sentiment analysis is performed on multilingual news texts to obtain sentiment scores; Based on the large language model, event extraction is performed on equity relationship text and sanctions list text to identify sanctions, strikes, and trade restriction events; The sentiment score and the event type are mapped to a capacity risk coefficient or a supply disruption probability, which serves as the risk factor.

4. The supply chain multi-level penetration risk control method empowered by a large language model according to claim 1, characterized in that, The step of determining the vulnerability weight of each supply chain node based on the risk factors and the hierarchical attributes in the structured data includes: Based on the hierarchical attributes in the structured data, a baseline vulnerability weight is set for each level of the supply chain node; The risk factor is used as a correction coefficient and multiplied by the baseline vulnerability weight of the corresponding node to obtain the final vulnerability weight of each supply chain node.

5. The supply chain multi-level penetration risk control method empowered by a large language model according to claim 1, characterized in that, The step of determining the target alternative path using a path search algorithm based on the risk probability, the knowledge graph, and the transaction attributes in the structured data includes: The order volume information and historical logistics costs in the structured data are used as path cost parameters; The risk probability is used as the path blocking factor; A heuristic path search algorithm is used to mine the optimal order transfer path from the current supplier to the target manufacturer in the knowledge graph, which serves as the target alternative path.

6. The supply chain multi-level penetration risk control method empowered by a large language model according to claim 1, characterized in that, The method further includes: After determining the target alternative path, the target alternative path is subjected to a compliance review using the large language model; The compliance review includes: automatically matching export control regulations of the target country or region and generating a compliance assessment report that marks potential legal risk points; When the compliance assessment report shows no high risk, the target alternative path is output as a contingency plan.

7. The supply chain multi-level penetration risk control method empowered by a large language model according to claim 1, characterized in that, The method further includes: The baseline vulnerability weights corresponding to the hierarchical attributes in the structured data are dynamically adjusted based on geopolitical events. Specifically, when a specific trade friction event occurs, the baseline vulnerability weight of the supply chain node located in the corresponding country or region will be increased by a preset percentage.

8. The supply chain multi-level penetration risk control method empowered by a large language model according to claim 1, characterized in that, The large language model is trained in multiple languages ​​based on the scenario of industrial overseas expansion, and the types of multiple languages ​​include Vietnamese and Malay. The step of using a large language model to perform semantic parsing on the unstructured data includes: using the large language model trained in multiple languages ​​to perform semantic parsing on the news text and extracting the risk events.

9. A supply chain multi-level penetration risk control system empowered by a large language model, characterized in that, It includes a processor and a memory, the memory storing a computer program, and the processor executing the computer program to implement the supply chain multi-level penetration risk control method empowered by the large language model as described in any one of claims 1 to 8.