A financial and tax data intelligent early warning method and system based on data analysis
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- YONYOU NETWORK TECH CO LTD
- Filing Date
- 2026-05-20
- Publication Date
- 2026-08-04
AI Technical Summary
[0007]本发明的目的是解决现有技术中静态阈值误报率高、各科目独立检测割裂勾稽关系、异常源头与传导节点难以区分的问题,为此提出的一种基于数据分析的财税数据智能预警方法及系统
[0019] This invention acquires chronological accounting data of enterprises and constructs a directed graph of accounting subjects based on debit and credit entries. It deeply integrates the principle of double-entry bookkeeping with graph data structure, and can automatically incorporate all accounting subjects into a unified topology network, thereby achieving a deep integration of financial and tax data with data analysis technology.
Smart Images

Figure CN122510035A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data analysis technology, and in particular to an intelligent early warning method and system for financial and tax data based on data analysis. Background Technology
[0002] Currently, common methods for detecting anomalies in financial and tax data mainly rely on preset fixed thresholds and empirical rules. For example, a warning line is set by the percentage fluctuation above or below the industry average value-added tax burden rate; when a company's current tax burden rate exceeds this range, an alarm is triggered. Alternatively, a threshold is set for the year-on-year change in gross profit margin; when the gross profit margin decreases by more than a preset percentage compared to the same period last year, a notification is issued. These methods have the following technical problems.
[0003] First, static thresholds are difficult to adapt to dynamic business environments. Fiscal and tax data are affected by various factors such as seasonality, industry cycles, and the stage of business operations. Fixed thresholds cannot distinguish between normal seasonal fluctuations and real abnormal risks, resulting in a high false alarm rate.
[0004] Second, independent indicator detection disrupts the inherent interrelationships between accounting items. Existing methods typically set thresholds for each financial and tax indicator and detect them independently. However, accounting items have a close interrelationship formed by double-entry bookkeeping, and a single economic transaction often affects multiple items simultaneously. Independent detection methods cannot identify the transmission relationships between anomalies in multiple items, resulting in redundant alerts and failing to pinpoint the root cause of risks.
[0005] Third, existing methods only output a list of abnormal indicators, without providing analysis of the causes of the abnormalities or actionable suggestions for handling them. After receiving an alert, financial and tax management personnel still need to manually review accounting vouchers, verify business documents, and search for tax law provisions in order to determine the cause of the abnormality and formulate countermeasures, resulting in low response efficiency.
[0006] Therefore, this invention proposes an intelligent early warning method and system for financial and tax data based on data analysis. Summary of the Invention
[0007] The purpose of this invention is to solve the problems of high false alarm rate of static threshold in the prior art, fragmented interrelationship of independent detection of each subject, and difficulty in distinguishing the source of anomalies from the transmission nodes. To this end, an intelligent early warning method and system for financial and tax data based on data analysis is proposed.
[0008] In a first aspect, the present invention provides a method for intelligent early warning of financial and tax data based on data analysis, comprising the following steps:
[0009] Step S1: Obtain the enterprise's chronological accounting data and construct a directed graph of accounting subjects with accounting subjects as nodes and fund flows as directed edges based on the debit and credit entries. The edge weights are determined by the linear regression slope of the source subject and the target subject's transaction amounts.
[0010] Step S2: Perform a graph Fourier transform on the graph signal composed of the balance of each node account in the current period, decompose the graph signal into graph components of different frequencies, and extract the graph component nodes corresponding to the feature vectors whose feature values are greater than the preset feature threshold as candidate abnormal nodes.
[0011] Step S3: For each candidate anomalous node, perform forward tracing along the directed edge, calculate the product of the weights of each edge on the tracing path as the risk transmission coefficient, and distinguish between primary anomalous nodes and transmissive anomalous nodes based on the risk transmission coefficient.
[0012] Step S4: Aggregate the transmissive anomaly nodes and their corresponding source anomaly nodes on the same transmission path into a single early warning event, mark the accounting subject corresponding to the source anomaly node as the risk source, generate risk warning information and push it to the front-end interactive interface.
[0013] Secondly, the present invention provides a data analysis-based intelligent early warning system for financial and tax data, comprising:
[0014] The topology graph construction module is used to obtain the enterprise's accounting chronological ledger data and construct a directed graph of accounting subjects with accounting subjects as nodes and fund flows as directed edges based on the debit and credit entries. The edge weights are determined by the linear regression slope of the source subject and the target subject's transaction amount.
[0015] The graph decomposition module is used to perform graph Fourier transform on the graph signal composed of the balance of each node account in the current period, decompose the graph signal into graph components of different frequencies, and extract the graph component nodes corresponding to the feature vectors whose feature values are greater than the preset feature threshold as candidate abnormal nodes.
[0016] The risk localization module is used to perform forward tracking along the directed edges for each candidate abnormal node, calculate the product of the weights of each edge on the tracking path as the risk transmission coefficient, and distinguish between primary abnormal nodes and transmissive abnormal nodes based on the risk transmission coefficient.
[0017] The aggregation and push module is used to aggregate transmissive anomaly nodes and their corresponding source anomaly nodes on the same transmission path into a single early warning event, mark the accounting subject corresponding to the source anomaly node as the risk source, generate risk warning information and push it to the front-end interactive interface.
[0018] The beneficial effects of the technical solution provided by this invention include at least the following:
[0019] This invention acquires chronological accounting data of enterprises and constructs a directed graph of accounting subjects based on debit and credit entries. It deeply integrates the principle of double-entry bookkeeping with graph data structure, and can automatically incorporate all accounting subjects into a unified topology network, thereby achieving a deep integration of financial and tax data with data analysis technology.
[0020] This invention performs graph Fourier transform on the graph signal composed of the balances of each subject at each node, extracts the graph component nodes corresponding to the feature vectors whose feature values are greater than a preset feature threshold as candidate abnormal nodes, and can monitor the changes in the balances of each subject in real time. It uses the advanced algorithm of graph signal processing to automatically filter out high-frequency nodes with abnormal fluctuations and establishes a multi-dimensional early warning indicator system covering all subjects.
[0021] This invention determines the edge weights by the linear regression slope of the source and target account amounts, and calculates the quantitative dependence between accounts based on the amount data of multiple consecutive historical periods. This allows for the scientific and reasonable determination of edge weights based on historical data, replacing the static threshold setting method that relies on human experience.
[0022] This invention performs forward tracing along directed edges for each candidate abnormal node, calculates the product of the weights of each edge on the tracing path as a risk transmission coefficient, and distinguishes between originating abnormal nodes and transmissive abnormal nodes based on the risk transmission coefficient. This enables the rapid identification of abnormalities and precise location of risk sources when abnormal fluctuations occur in financial and tax data, and distinguishes between the initiation point of the abnormality and the affected transmission point.
[0023] This invention aggregates transmissive anomaly nodes along the same transmission path with their corresponding primary anomaly nodes into a single early warning event, marks the accounting subject corresponding to the primary anomaly node as the risk source, generates a detailed risk analysis report and response suggestions containing the risk source and risk transmission sub-graph, and pushes it to the front-end interactive interface. This helps financial and tax management personnel to understand the full picture of risks in a timely manner and take targeted measures, effectively prevent financial and tax risks, and ensure the stable operation of financial and tax business. Attached Figure Description
[0024] To more clearly illustrate the technical solutions and advantages in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0025] Figure 1 This is a schematic diagram of the method flow provided in an embodiment of the present invention;
[0026] Figure 2 This is a schematic diagram of the system architecture provided for an embodiment of the present invention. Detailed Implementation
[0027] To further illustrate the technical means and effects adopted by the present invention to achieve its intended purpose, the following, in conjunction with the accompanying drawings and preferred embodiments, details the specific implementation, structure, features, and effects of a data analysis-based intelligent early warning method and system for financial and tax data proposed according to the present invention. In the following description, different "one embodiment" or "another embodiment" do not necessarily refer to the same embodiment. Furthermore, specific features, structures, or characteristics in one or more embodiments can be combined in any suitable form.
[0028] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains.
[0029] The following examples are for illustrative purposes only and are not intended to limit the scope of the invention.
[0030] The following description, in conjunction with the accompanying drawings, details the specific scheme of the intelligent early warning method and system for financial and tax data based on data analysis provided by this invention.
[0031] Please see Figure 1 The diagram illustrates a flowchart of an intelligent early warning method for financial and tax data based on data analysis, according to an embodiment of the present invention, comprising the following steps:
[0032] Step S1: Obtain the enterprise's chronological accounting data and construct a directed graph of accounting subjects with accounting subjects as nodes and fund flows as directed edges based on the debit and credit entries. The edge weights are determined by the linear regression slope of the source subject and the target subject's transaction amounts.
[0033] Step S2: Perform a graph Fourier transform on the graph signal composed of the balance of each node account in the current period, decompose the graph signal into graph components of different frequencies, and extract the graph component nodes corresponding to the feature vectors whose feature values are greater than the preset feature threshold as candidate abnormal nodes.
[0034] Step S3: For each candidate anomalous node, perform forward tracing along the directed edge, calculate the product of the weights of each edge on the tracing path as the risk transmission coefficient, and distinguish between primary anomalous nodes and transmissive anomalous nodes based on the risk transmission coefficient.
[0035] Step S4: Aggregate the transmissive anomaly nodes and their corresponding source anomaly nodes on the same transmission path into a single early warning event, mark the accounting subject corresponding to the source anomaly node as the risk source, generate risk warning information and push it to the front-end interactive interface.
[0036] It should be noted that accounting chronological ledger data refers to the accounting entries recorded by an enterprise in the order of the occurrence of economic transactions within a certain accounting period, including the debit account, credit account, transaction amount, and summary information for each transaction.
[0037] The debit and credit entries refer to the correspondence between debit and credit accounts involved in each economic transaction under the double-entry bookkeeping method, reflecting the path of funds flowing from credit accounts to debit accounts.
[0038] A directed graph of accounting subjects is a directed graph structure constructed with accounting subjects as nodes and the flow of funds in debit and credit entries as directed edges. It is used to represent the flow of funds and the reconciliation relationships between subjects.
[0039] Fund flow refers to the direction in which funds flow from credit accounts to debit accounts in economic transactions. In a directed accounting diagram, this is represented by the direction of the directed edges.
[0040] Edge weights are numerical values labeled on directed edges, representing the degree of influence of changes in the source account amount on the target account amount. They are determined by the linear regression slope of the source and target account amounts in historical data.
[0041] The slope of linear regression refers to the slope coefficient obtained by performing a univariate linear regression with the source account amount as the independent variable and the target account amount as the dependent variable. It reflects the expected change in the target account for every unit change in the source account.
[0042] The signal in a graph refers to the vector formed by the current period's account balances of each node in a directed graph of accounting subjects. The signal value of each node is the ending balance of the corresponding account or its rate of change compared to the previous period.
[0043] The graph Fourier transform is a mathematical transformation that projects a spatial graph signal onto the eigenvector basis of the Laplace matrix, decomposing the graph signal into spectral components of different frequencies.
[0044] Spectral components refer to the signal components corresponding to different eigenvalues obtained after graphical Fourier transform. The smaller the eigenvalue, the lower the frequency component; the larger the eigenvalue, the higher the frequency component.
[0045] The preset feature threshold is a critical feature value used to distinguish between normal spectral components and abnormal fluctuation spectral components. This threshold is dynamically obtained through an adaptive statistical algorithm: construct the magnitude distribution of spectral coefficients using the graph signals from several recent historical stable periods, and calculate its mean μ and standard deviation σ; set the threshold to μ+3σ (or μ+2σ); determine the components whose magnitude of the spectral coefficients after Fourier transform of the current period is greater than this threshold as abnormal fluctuation components, and determine the components whose magnitude is less than this threshold as background normal fluctuation components.
[0046] Candidate abnormal nodes refer to nodes in the abnormal fluctuation graph signal components whose amplitude exceeds a preset amplitude threshold. The accounting items corresponding to the nodes have abnormal fluctuations that do not conform to the overall business trend.
[0047] Forward tracing refers to the process of starting from a candidate anomaly node and searching along the outward edges of the directed graph of accounting subjects to trace related subjects that may be affected by abnormal fluctuations.
[0048] The risk transmission coefficient is the product of the weights of each edge along the path from the starting point of the tracking to the current node. It is used to quantify the remaining strength of the risk after it has decayed along the transmission path.
[0049] A primary abnormal node refers to a candidate abnormal node whose risk transmission coefficient is less than or equal to a preset transmission threshold, indicating that the abnormal fluctuation of this node is the starting point of the risk transmission chain.
[0050] A transmissive anomaly node is a candidate anomaly node whose risk transmission coefficient is greater than a preset transmission threshold. This indicates that the abnormal fluctuation of the node is caused by the ripple effect of the original anomaly node along the transmission path.
[0051] The preset transmission threshold is a critical value used to distinguish between primary and secondary anomalous nodes. It adopts a normal distribution, and the method for determining the critical threshold based on statistical distribution includes: obtaining the maximum path risk transmission coefficient of each candidate anomalous node during transmission tracing within a historical normal period, forming a historical transmission coefficient set; calculating the mean and standard deviation of each value in this set; and using the mean plus k times the standard deviation as the preset transmission threshold, where k is the preset coefficient. When the maximum path risk transmission coefficient of a candidate anomalous node is greater than the preset transmission threshold, it is determined to be a secondary anomalous node; when the maximum path risk transmission coefficient is less than or equal to the preset transmission threshold, it is determined to be a primary anomalous node.
[0052] A risk transmission subgraph is a subgraph with the primary anomaly node as the root node, which includes all the transmission anomaly nodes traced from the root node and the directed edges connecting these nodes. It is used to visualize the complete transmission chain of risk.
[0053] The preset risk model library refers to a pre-established mapping relationship library between subject types and risk disposal suggestions. Each subject type corresponds to one or more typical risk scenarios and disposal solutions.
[0054] The disposal suggestion template refers to the pre-set operation guidance text for different types of risk source accounts, which includes suggested verification steps, adjusting entries and applicable legal provisions.
[0055] In one specific implementation, this method is applied to a monthly financial and tax risk screening scenario for a medium-sized manufacturing enterprise. This enterprise uses Kingdee financial software for accounting, and its account system includes 256 detailed accounts across asset, liability, owner's equity, cost, and profit and loss categories.
[0056] Step S1 implementation: Export the chronological ledger data for the most recent 24 accounting months from the accounting software via direct database connection, and extract the voucher number, accounting period, debit account code, credit account code and transaction amount for each journal entry.
[0057] The accounting chronological ledger data was preprocessed by scanning the voucher summary field of all journal entries and filtering out entries containing keywords such as "reversal," "void," or "test." A total of 156 invalid entries were removed, leaving 58,432 valid entries.
[0058] A node set is constructed using all 256 detailed accounts as nodes. For each valid accounting entry, a directed edge is constructed from the debit account node to the credit account node. For account pairs with multiple directed edges in the same direction, the directed edges are merged and the transaction amounts are accumulated. The accounting element categories to which the source and target accounts belong are obtained. When the source and target accounts belong to different accounting element categories, the directed edge is marked as a cross-element edge; when the source and target accounts belong to the same accounting element category, the directed edge is marked as an intra-element edge. After construction, the directed graph of accounting accounts contains 256 nodes and 1847 directed edges, including 1256 cross-element edges and 591 intra-element edges.
[0059] We calculated the edge weights and determined their validity for cross-factor edges. Taking a directed edge from the Raw Materials account to the Production Costs account as an example, this edge points from the debit account Raw Materials to the credit account Production Costs. The source account represents debit entries, and the target account represents credit entries. We extracted the debit entries sequence of the Raw Materials account over the past 24 periods and the credit entries sequence of the Production Costs account over the same periods. Using the debit entries of Raw Materials as the independent variable and the credit entries of Production Costs as the dependent variable, we used the least squares method to calculate the regression slope and intercept, obtaining a regression slope of 0.73 and a regression intercept of 12580.50. Based on the regression results, we calculated the goodness of fit, which is the ratio of the regression sum of squares to the total sum of squares, and the result was 0.89. The goodness of fit of 0.89 is greater than the preset goodness threshold of 0.7, indicating a stable linear transmission relationship between the two accounts. Therefore, the regression slope of 0.73 was used as the weight of this cross-factor edge.
[0060] Taking a directed edge from the Raw Materials account to the Manufacturing Expenses account as an example, this edge points from the debit account Raw Materials to the credit account Manufacturing Expenses. The source account represents the debit amount, and the target account represents the credit amount. The transaction amounts for the past 24 periods of both accounts were extracted, and a linear regression was performed with the debit amount of Raw Materials as the independent variable and the credit amount of Manufacturing Expenses as the dependent variable. The goodness of fit was calculated to be 0.52. A goodness of fit of 0.52 is less than or equal to the preset goodness of fit threshold of 0.7, indicating that there is no stable linear transmission relationship between the two accounts. Therefore, this cross-element edge is marked as an invalid edge.
[0061] Taking a directed edge from the Raw Materials account to the Accounts Payable account as an example, this edge points from the debit account Raw Materials to the credit account Accounts Payable. The source account takes the debit amount, and the target account takes the credit amount. Linear regression is performed on the transaction series of the two accounts over the past 24 periods. The goodness of fit is calculated to be 0.81, which is greater than the preset goodness of fit threshold of 0.7. The regression slope of 0.41 is used as the weight of this cross-factor edge.
[0062] We calculate edge weights and determine validity for each inner edge of an element. Taking a directed edge from the input VAT account to the output VAT account as an example, this edge points from a debit account to a credit account. The source account represents debit entries, and the target account represents credit entries. We extract the transaction amounts of the two accounts over the past 24 periods and calculate the ratio of the target account's transaction amount to the source account's transaction amount for each period, obtaining a sequence of 24 ratios. The arithmetic mean of this sequence is 0.82, and the standard deviation is 0.15. Dividing the standard deviation by the arithmetic mean yields a coefficient of variation of 0.18. Since the coefficient of variation of 0.18 is less than the preset stability threshold of 0.3, it indicates a stable proportional relationship between the two accounts. Therefore, the arithmetic mean of 0.82 is used as the weight of this inner edge.
[0063] Taking the carry-over edge between the various sub-sub ...
[0064] Calculate the noise threshold and mark untracked edges. A total of 1519 directed edges were not marked as invalid. The lower quartile of the weights of these edges was calculated, yielding a noise threshold of 0.21. Edges with weights less than 0.21 were marked as untracked edges, totaling 328 edges. The final number of valid edges was 1191.
[0065] Step S2: Calculate the directed Laplacian matrix based on the edge weight adjacency matrix and out-degree matrix of the directed graph of accounting subjects. The edge weight adjacency matrix has a dimension of 256 x 256, and the matrix elements are the weight values of the corresponding directed edges. Node pairs without edge connections have elements of 0. The out-degree matrix is a 256 x 256 diagonal matrix, and the diagonal elements are the out-degree values of each subject node. The directed Laplacian matrix equals the out-degree matrix minus the edge weight adjacency matrix.
[0066] The directed Laplacian matrix is decomposed into eigenvectors, yielding an eigenvector matrix and 256 eigenvalues. These eigenvalues are arranged in ascending order, ranging from 0.02 to 4.85. Each column of the eigenvector matrix corresponds to an eigenvector of one eigenvalue, serving as the basis functions for the graphical Fourier transform.
[0067] Obtain the ending balances of each account for the current period and the previous period, and calculate the rate of change of each account balance compared to the previous period. The ending balance of the Raw Materials account was RMB 3,856,000 in the previous period and RMB 4,627,200 in the current period, a change of 20%. The ending balance of the Main Business Revenue account was RMB 8,560,000 in the previous period and RMB 7,123,000 in the current period, a change of -16.8%. The change rate of the Cost of Goods Sold account was 8.5%. The ending balance of Taxes Payable account was RMB 425,000 in the previous period and RMB 386,000 in the current period, a change of -9.2%. The change rate of the Selling Expenses account was 6.0%. The change rate of the Administrative Expenses account was 4.0%. The change rate of the Accounts Receivable account was 14%. The change rate of the Cash and Cash Equivalents account was 5%.
[0068] The rates of change were weighted according to the accounting materiality level of each account. Revenue, cost of goods sold, and taxes were classified as first materiality accounts, assigned a preset first weighting coefficient of 1.0. Other profit and loss accounts (excluding revenue, cost of goods sold, and taxes) were classified as second materiality accounts, assigned a preset second weighting coefficient of 0.6. Other accounts (excluding profit and loss accounts) were classified as third materiality accounts, assigned a preset third weighting coefficient of 0.3. Revenue, cost of goods sold, and taxes payable were classified as first materiality accounts, with weighted rates of change of -16.8%, 8.5%, and -9.2%, respectively. Selling expenses and administrative expenses were classified as second materiality accounts, with weighted rates of change of 3.6% and 2.4%, respectively. Raw materials, accounts receivable, and cash and cash equivalents were classified as third materiality accounts, with weighted rates of change of 6.0%, 4.2%, and 1.5%, respectively. The weighted rates of change for all 256 accounts were used to create a graphical signal vector.
[0069] A graphical Fourier transform is performed on the graphical signal vector using the eigenvector matrix, projecting the 256-dimensional graphical signal vector onto the eigenvector basis to obtain a 256-dimensional graphical coefficient vector. Each graphical coefficient component corresponds to an eigenvector.
[0070] The median of the eigenvalue sequence, 2.15, is used as the preset eigenvalue threshold. The spectral coefficient components corresponding to eigenvectors with eigenvalues greater than 2.15 are extracted as abnormal fluctuation components, totaling 128 components. An inverse graphical Fourier transform is performed on the abnormal fluctuation components, transforming the spectral domain components back to the spatial domain through the eigenvector matrix to obtain the abnormal fluctuation graph signal. The abnormal fluctuation graph signal is a 256-dimensional vector, with each dimension corresponding to the abnormal fluctuation amplitude of a subject node.
[0071] The mean and standard deviation of the abnormal fluctuation signal amplitudes over 12 historical periods were calculated. The mean plus three times the standard deviation was used as the preset amplitude threshold, which was 0.6. Nodes with amplitudes exceeding 0.6 in the abnormal fluctuation signal were marked as candidate abnormal nodes. Upon inspection, the amplitudes of the raw materials node (0.85), accounts receivable node (0.72), and main business revenue node (0.68) all exceeded the preset amplitude threshold of 0.6 and were therefore marked as candidate abnormal nodes. The amplitudes of the remaining 253 node values were all less than 0.6 and were determined to be normal.
[0072] Step S3: Obtain the set of candidate abnormal nodes output in step S2, including raw material account nodes, accounts receivable account nodes, and main business revenue account nodes. Use each candidate abnormal node as the starting point for tracing, and perform a breadth-first search along the outgoing edges from the starting point.
[0073] During the search process, the attenuation factor is dynamically determined based on the company's current operating environment. The company's current credit cycle stage identifier is obtained; currently, it is in a stable credit period, and the corresponding first adjustment factor is 1.0. The operating cycle stage identifier is also obtained; currently, it is peak season, and the corresponding second adjustment factor is 1.2. The basic first attenuation factor is 0.9, and the basic second attenuation factor is 0.5. The preset first attenuation factor is the product of the basic first attenuation factor, the first adjustment factor, and the second adjustment factor, calculated as 0.9 x 1.0 x 1.2 = 1.08. The preset second attenuation factor is the product of the basic second attenuation factor, the first adjustment factor, and the second adjustment factor, calculated as 0.5 x 1.0 x 1.2 = 0.60. For the current edge found in the search, the edge type is obtained. When the edge type is a cross-feature edge, the preset first attenuation factor of 1.08 is used; when the edge type is an intra-feature edge, the preset second attenuation factor of 0.60 is used.
[0074] We begin by tracing the raw materials account. The outgoing edges of the raw materials account point to the production cost account and the accounts payable account, both of which are cross-element edges.
[0075] For each production cost item node found in the search, the path risk transmission coefficient from raw materials to production cost is calculated. This path contains only one cross-element edge from raw materials to production cost, with an edge weight of 0.73 and a corresponding attenuation factor of 1.08. The transmission contribution of this edge is 0.73 multiplied by 1.08, which equals 0.79. The path risk transmission coefficient is 0.79, which is greater than the preset transmission threshold of 0.5. Therefore, the search continues along the outgoing edge of production cost.
[0076] For each account payable node found in the search, the path risk transmission coefficient from raw materials to accounts payable is calculated. This path contains only one cross-element edge from raw materials to accounts payable, with an edge weight of 0.41 and a corresponding attenuation factor of 1.08. The transmission contribution of this edge is 0.41 multiplied by 1.08, which equals 0.44. The path risk transmission coefficient is 0.44, which is less than the preset transmission threshold of 0.5, so the search along the accounts payable direction is terminated.
[0077] The outgoing edges of the production cost account point to both the inventory and main business cost accounts, both of which are cross-factor edges. Along the path from production cost to inventory, the edge weight is 0.85, the decay factor is 1.08, and the transmission contribution of this edge is 0.85 multiplied by 1.08, which equals 0.92. The cumulative path risk transmission coefficient is 0.79 multiplied by 0.92, which equals 0.73, exceeding the preset transmission threshold of 0.5, so the search continues.
[0078] Along the path from production cost to main business cost, the edge weight is 0.78, the attenuation factor is 1.08, and the transmission contribution of this edge is 0.78 multiplied by 1.08, which equals 0.84. The cumulative path risk transmission coefficient is 0.79 multiplied by 0.84, which equals 0.66, exceeding the preset transmission threshold of 0.5, so the search continues.
[0079] The outgoing edges of the Inventory Goods account point to both the Cost of Goods Sold and Goods Issued accounts, both of which are cross-element edges. Along the path from Inventory Goods to Cost of Goods Sold, the edge weight is 0.72, the decay factor is 1.08, and the transmission contribution of this edge is 0.72 multiplied by 1.08, equaling 0.78. The cumulative path risk transmission coefficient is 0.73 multiplied by 0.78, equaling 0.57, which is greater than the preset transmission threshold of 0.5, so the search continues.
[0080] Along the path from inventory to shipped goods, the edge weight is 0.18, the decay factor is 1.08, and the transmission contribution of this edge is 0.18 multiplied by 1.08, which equals 0.19. The cumulative path risk transmission coefficient is 0.73 multiplied by 0.19, which equals 0.14. This is less than the preset transmission threshold of 0.5, so the search is terminated.
[0081] Continue searching along the main operating cost boundary until the current year's profit item node is reached. Since the current year's profit item is a transitional item between the retained earnings item and the pre-defined risk threshold, this node is recorded, and the search along the current path is terminated.
[0082] Secondly, the starting point for tracking is the main business revenue item. The outgoing edge of the main business revenue item points to both accounts receivable and cash and cash equivalents, both being cross-element edges. Along the path from main business revenue to accounts receivable, the edge weight is 0.76, the decay factor is 1.08, and the transmission contribution of this edge is 0.76 x 1.08 = 0.82. The path risk transmission coefficient is 0.82, which is greater than the preset transmission threshold of 0.5, so the search continues. The outgoing edge of the accounts receivable item points to the cash and cash equivalents item. Along the path from accounts receivable to cash and cash equivalents, the edge weight is 0.56, the decay factor is 1.08, and the transmission contribution of this edge is 0.56 x 1.08 = 0.60. The cumulative path risk transmission coefficient is 0.82 x 0.60 = 0.49, which is less than the preset transmission threshold of 0.5, so the search terminates. Simultaneously, the cash and cash equivalents item is a preset risk sink node; this node is recorded, and the search terminates.
[0083] Again, we use accounts receivable as the starting point for tracking. The outgoing edge of accounts receivable points to cash and cash equivalents, which is a cross-element edge. Along the path from accounts receivable to cash and cash equivalents, the edge weight is 0.56, the decay factor is 1.08, and the transmission contribution of this edge is 0.56 multiplied by 1.08, which equals 0.60. The path risk transmission coefficient is 0.60, which is greater than the preset transmission threshold of 0.5. The cash and cash equivalents account is the preset risk sink node; this node is recorded and the search is terminated.
[0084] For the Raw Materials account, among all search paths starting from it, the path risk transmission coefficient to the Production Costs account is 0.79, to the Inventory account is 0.73, and to the Cost of Goods Sold account are 0.66 and 0.57 respectively. The maximum path risk transmission coefficient is 0.79, which is greater than the preset transmission threshold of 0.5. Since the Raw Materials account, as the starting point for tracking, has no path originating from other nodes, it is identified as a source-causing abnormal node. The Production Costs account and the Inventory account, accessed by the Raw Materials account and with transmission coefficients exceeding the threshold, are identified as transmission-causing abnormal nodes.
[0085] For the main business revenue item, among all search paths starting from it, the path risk transmission coefficient leading to the accounts receivable item is 0.82, and the path risk transmission coefficient leading to the cash and cash equivalents item is 0.49. The maximum path risk transmission coefficient is 0.82, which is greater than the preset transmission threshold of 0.5. Therefore, the main business revenue item, as the starting point for tracking, is identified as a source of abnormality. The accounts receivable item being accessed through searches of the main business revenue item is also identified as a transmission abnormality node.
[0086] For the accounts receivable account, the maximum path risk transmission coefficient starting from it is 0.60, which is greater than the preset transmission threshold of 0.5. However, the accounts receivable account has already been searched and identified as an abnormal transmission node by the main business revenue account, so it will not be re-evaluated.
[0087] For accounts receivable accounts identified as transmission anomaly nodes, the path traced back to the primary business revenue account (the originating anomaly node) in the directed accounting graph is marked as a risk transmission link. This link includes a cross-element edge from primary business revenue to accounts receivable. For production cost accounts and inventory accounts, the risk transmission link is the path from raw materials accounts through production cost accounts to inventory accounts.
[0088] Step S4 implementation: Aggregate the transmissive anomaly nodes and their corresponding source anomaly nodes along the same transmission path into a single warning event. Using the raw materials account as the source anomaly node, and the transmissive anomaly nodes including production cost and inventory accounts, aggregate them into the first single warning event, identified as W001. Using the main business revenue account as the source anomaly node, and the transmissive anomaly node being accounts receivable, aggregate them into the second single warning event, identified as W002.
[0089] Using the primary anomaly node as the root node, extract the root node and all transitive anomaly nodes traced from it, and extract the directed edges connecting these nodes to form a risk transmission subgraph for the warning event. For warning event W001, using the raw materials account as the root node, extract the root node and the transitive anomaly nodes production cost and inventory accounts, and extract the directed edges connecting these nodes to form a risk transmission subgraph. The subgraph contains 3 nodes and 2 directed edges; the first edge points from raw materials to production cost, and the second edge points from production cost to inventory. The maximum depth of the subgraph is 2 levels. For warning event W002, using the main business revenue account as the root node, extract the root node and the transitive anomaly node accounts receivable, and extract the directed edge from main business revenue to accounts receivable to form a risk transmission subgraph. The subgraph contains 2 nodes and 1 directed edge, and the maximum depth of the subgraph is 1 level.
[0090] Extract the account type of the originating anomaly node, match the account type with the preset risk model library, and obtain the corresponding handling suggestion template. For warning event W001, the account type of the originating anomaly node is raw materials. Match the raw materials account type with the preset risk model library, and it matches the inventory backlog risk model. Obtain the corresponding handling suggestion template for this model, which includes: First, immediately count the actual inventory quantity of raw materials and verify whether the book balance is consistent with the actual inventory; Second, check whether the current period's procurement plan exceeds the limit, and compare the current period's procurement quantity with the historical period and the production plan's demand; Third, check whether there are any production material requisition forms that have been issued but not recorded, and verify the production department's material requisition records with the financial accounting records; Fourth, assess whether the inventory write-down provision is sufficient, and calculate the difference between the net realizable value and the book value of raw materials; the applicable regulations are Enterprise Accounting Standard No. 1 Inventory.
[0091] For warning event W002, the account type of the originating abnormal node is the main business revenue account. The main business revenue account type is matched with the preset risk model library, and the abnormal revenue recognition risk model is matched. The corresponding handling suggestion template is obtained, which includes: First, verify whether the revenue recognition timing of the current period complies with accounting standards requirements and check whether the revenue recognition meets the conditions for transfer of control; Second, check the key terms of large sales contracts to verify whether the delivery method, acceptance conditions, payment terms, etc., affect the revenue recognition timing; Third, verify whether the sales amount in the VAT return is consistent with the book main business revenue and analyze the reasons for the tax-accounting differences; Fourth, check the post-period return situation to determine whether there is a situation of rushing to recognize revenue at the end of the period and concentrated returns at the beginning of the period; Applicable laws and regulations are Enterprise Accounting Standard No. 14 Revenue and Article 19 of the Provisional Regulations on Value-Added Tax.
[0092] The accounting items corresponding to the primary abnormal nodes are marked as risk sources. The risk sources, risk transmission sub-graphs, and disposal suggestion templates are assembled into risk warning information and pushed to the front-end interactive interface.
[0093] For warning event W001, the raw materials item, which is the source of the anomaly, is marked as the risk source. The risk source raw materials item, the risk transmission sub-diagram, and the inventory backlog disposal suggestion template are assembled into a risk warning message and pushed to the front-end interactive interface. The risk transmission sub-diagram is displayed on the left side of the interface in the form of a force-directed graph. The raw materials item node is highlighted in red, while the production cost item node and inventory item node are highlighted in orange. The two directed edges are marked with bold arrows to indicate the transmission direction. The information panel on the right side of the interface displays the risk source as the raw materials item, the number of affected items as 2, the maximum transmission depth as 2 levels, the four-step verification content of the disposal suggestion template, and the applicable legal provisions.
[0094] For warning event W002, the primary abnormal node, the main business revenue item, is marked as the risk source. The risk source's main business revenue item, the risk transmission sub-diagram, and the revenue recognition anomaly handling suggestion template are assembled into a risk warning message and pushed to the front-end interactive interface. The left side of the interface displays the transmission link from the main business revenue item to the accounts receivable item, with main business revenue nodes highlighted in red and accounts receivable nodes highlighted in orange. Directed edges are marked with bold arrows. The information panel on the right side of the interface displays the risk source as the main business revenue item, the number of affected items as one, the four-step verification content of the handling suggestion template, and the applicable legal provisions.
[0095] After logging into the workbench, the finance manager viewed the list of alert events, which showed two pending alerts: W001 Inventory Backlog Risk and W002 Revenue Recognition Anomaly Risk. Clicking on W001 to enter the details page, the manager reviewed the risk transmission sub-diagram and confirmed that the raw materials account was abnormal and had already been transmitted to production costs and finished goods inventory. Following the suggested handling template, the manager immediately arranged for a warehouse inventory check and verified the procurement plan. Clicking on W002 to enter the details page, the manager reviewed the transmission chain and confirmed that the abnormal main business revenue had affected accounts receivable. Following the suggested handling template, the manager verified the revenue recognition timing and sales contract terms. The alert event and its handling results were then saved to the historical case database.
[0096] Step S1 further includes the following sub-steps:
[0097] S1-1, preprocess the accounting chronological ledger data, and remove journal entries containing preset invalid keywords in the voucher summary. Preset invalid keywords include reversal, void, and test.
[0098] S1-2, when constructing directed edges, obtain the accounting element categories to which the source account and the target account belong. When the source account and the target account belong to different accounting element categories, the directed edge will be marked as a cross-element edge. When the source account and the target account belong to the same accounting element category, the directed edge will be marked as an intra-element edge. Accounting element categories include asset, liability, owner's equity, revenue and expense categories.
[0099] S1-3, For cross-element edges, calculate the weight of the cross-element edge based on the transaction amounts of the source account and the target account in the N consecutive historical periods. When there is no stable linear transmission relationship between the source account and the target account, the cross-element edge is marked as an invalid edge.
[0100] S1-4, For the inner edge of an element, calculate the weight of the inner edge of the element based on the transaction amount of the source account and the target account in the N consecutive historical periods. When there is no stable proportional relationship between the source account and the target account, the inner edge of the element is marked as an invalid edge.
[0101] S1-5: Calculate the lower quartile of the edge weights of all directed edges that are not marked as invalid edges as the noise threshold, and mark edges whose edge weights are less than the noise threshold as untracked edges.
[0102] Furthermore, in sub-steps S1-3, the step of calculating the cross-factor edge weights based on the transaction amounts of the source and target accounts over N consecutive historical periods includes:
[0103] The direction of retrieval for the source account and the target account is determined based on the debit and credit directions of the accounting entries. When the directed edge points from the debit account to the credit account, the source account takes the debit amount and the target account takes the credit amount. When the directed edge points from the credit account to the debit account, the source account takes the credit amount and the target account takes the debit amount.
[0104] Extract the source account's occurrence sequence in a specified direction over N consecutive historical periods and the target account's occurrence sequence in the same direction over the same period;
[0105] Using the source account transaction sequence as the independent variable and the target account transaction sequence as the dependent variable, the least squares method was used to calculate the regression slope and regression intercept.
[0106] The goodness of fit is calculated based on the regression slope and the regression intercept. The goodness of fit is the ratio of the regression sum of squares to the total sum of squares.
[0107] When the goodness of fit is greater than the preset goodness of fit threshold, the regression slope is used as the weight of the cross-factor edge; when the goodness of fit is less than or equal to the preset goodness of fit threshold, the cross-factor edge is marked as an invalid edge.
[0108] Furthermore, in sub-steps S1-4, the step of calculating the inner edge weights of elements based on the transaction amounts of the source and target accounts over N consecutive historical periods includes:
[0109] The direction of retrieval for the source account and the target account is determined based on the debit and credit directions of the accounting entries. When the directed edge points from the debit account to the credit account, the source account takes the debit amount and the target account takes the credit amount. When the directed edge points from the credit account to the debit account, the source account takes the credit amount and the target account takes the debit amount.
[0110] Extract the source account's occurrence sequence in a specified direction over N consecutive historical periods and the target account's occurrence sequence in the same direction over the same period;
[0111] Calculate the ratio of the target account amount to the source account amount for each period to obtain a ratio sequence containing N ratios;
[0112] Calculate the arithmetic mean and standard deviation of the ratio series, and divide the standard deviation by the arithmetic mean to obtain the coefficient of variation;
[0113] When the coefficient of variation is less than the preset stability threshold, the arithmetic mean is used as the weight of the inner edge of the element. When the coefficient of variation is greater than or equal to the preset stability threshold, the inner edge of the element is marked as an invalid edge.
[0114] It should be noted that preset invalid keywords refer to a pre-defined set of terms used to identify invalid or non-recurring accounting entries, including reversal, voiding, and testing.
[0115] Accounting element categories refer to the classification of accounting subjects according to enterprise accounting standards, including five basic types: assets, liabilities, owner's equity, revenue, and expenses.
[0116] A cross-element edge is a directed edge that connects source accounts and target accounts belonging to different accounting element categories, representing the flow of funds between accounts of different natures.
[0117] An internal edge of an element refers to a directed edge connecting a source account and a target account that belong to the same accounting element category, representing the transfer or reclassification of funds within the same type of account.
[0118] Linear transmission relationship refers to a stable linear quantitative dependency between changes in the source account and changes in the target account.
[0119] An invalid edge is a directed edge that is marked as invalid because there is no stable transmission relationship or stable proportional relationship. This edge does not participate in the edge weight calculation and subsequent transmission tracing.
[0120] The proportional relationship refers to the ratio of the amount of the target account to the amount of the source account between two accounts connected by an element, which remains relatively stable over historical periods.
[0121] The noise threshold is a critical value determined based on the statistical distribution of edge weights. It is used to distinguish between effective edges with a transmission effect and weakly related edges generated by occasional small transactions. Edges with weights less than this threshold are marked as untracked edges. This threshold is dynamically obtained through a quantile statistical algorithm: the edge weights of all directed edges in the current accounting subject's directed graph that have not been marked as invalid edges are obtained to form an edge weight sequence; the lower quartile of this sequence is calculated and used as the noise threshold; the lower quartile is the value at the quarter position after arranging the edge weight sequence in ascending order, i.e., the 25th percentile.
[0122] Untracked edges are directed edges whose weights are less than the noise threshold and are therefore marked as not participating in subsequent propagation tracing.
[0123] The specified direction of the transaction amount refers to the debit or credit amount to be extracted based on the debit or credit direction of the directed edge. When the directed edge points from a debit account to a credit account, the source account takes the debit amount and the target account takes the credit amount. When the directed edge points from a credit account to a debit account, the source account takes the credit amount and the target account takes the debit amount.
[0124] Goodness of fit is the ratio of the regression sum of squares to the total sum of squares. It is used to measure how well a linear regression model fits historical data. The higher the value, the more stable the linear transmission relationship.
[0125] The preset fitting threshold is a critical goodness-of-fit value used to determine whether a stable linear transmission relationship exists across cross-element edges. The rules for obtaining this threshold include: obtaining the goodness-of-fit values of each cross-element edge during a historical period; using subject pairs with a clear business causal relationship as positive samples; and using the lower quartile of the goodness-of-fit values of the positive samples or a preset empirical value as the preset fitting threshold. When the goodness-of-fit is greater than this threshold, a stable linear transmission relationship is considered to exist; when the goodness-of-fit is less than or equal to this threshold, a stable linear transmission relationship is considered not to exist.
[0126] The coefficient of variation is the ratio of the standard deviation to the arithmetic mean of a ratio series. It measures the dispersion of ratios within a factor across different periods. A smaller value indicates a more stable proportional relationship. Calculation steps: First, calculate the ratio of the target account amount to the source account amount for each period to obtain the ratio series. Then, calculate the arithmetic mean and standard deviation of this series. Finally, divide the standard deviation by the arithmetic mean to obtain the coefficient of variation. Value range: The coefficient of variation is a non-negative number, with a minimum value of zero, indicating that the ratios are completely equal across periods. A larger value indicates more drastic fluctuations in the ratio. In financial and tax data, it is usually distributed between 0.05 and 0.8.
[0127] The preset stability threshold is a critical value of the coefficient of variation used to determine whether a stable proportional relationship exists between edges within an element. When the coefficient of variation is less than this threshold, a stable proportional relationship is determined to exist; otherwise, the edge is marked as invalid. This threshold is dynamically obtained through an adaptive statistical algorithm: acquiring all edge data of elements for several historical periods within a historical stable period, calculating the coefficient of variation of the ratio sequence for each edge of the element period by period, obtaining a sample set of coefficients of variation; statistically analyzing the distribution of this sample set, calculating the mean and standard deviation of the coefficients of variation; setting the preset stability threshold to the mean plus one standard deviation; when the coefficient of variation of an edge within an element is less than this threshold, a stable proportional relationship is determined to exist for that edge.
[0128] The proposed solution overcomes the problems of fragmented relationships between accounts and interference with detection results caused by invalid associations in existing financial and tax data processing methods by constructing a directed graph of accounting subjects and classifying and filtering the directed edges.
[0129] First, the accounting chronological ledger data is preprocessed to remove entries containing preset invalid keywords such as "reversal," "void," and "test" in the voucher summary. These entries belong to accounting correction operations or test data and do not represent the company's actual business activities. Removing them improves the data quality for subsequent graph construction.
[0130] Next, when constructing directed edges, the accounting element categories to which the source and target accounts belong are obtained. Directed edges connecting different accounting element categories are marked as cross-element edges, and directed edges connecting the same accounting element category are marked as intra-element edges. Cross-element edges correspond to fund flows between accounts of different natures, such as the transfer between raw materials and production costs; these relationships typically exhibit causal transmission characteristics. Intra-element edges correspond to fund transfers within accounts of the same nature, such as the reclassification between various sub-categories of taxes payable; these relationships typically exhibit fixed proportion characteristics. Distinguishing between these two edge types provides a foundation for subsequent differential processing.
[0131] For cross-factor edges, the weights are calculated based on the transaction amounts of the source and target accounts over N consecutive historical periods. Specifically, the direction of transaction amount extraction is determined according to the lending direction of the directed edge. The historical transaction amount sequences of the two accounts are extracted, and a linear regression is performed with the transaction amount of the source account as the independent variable and the transaction amount of the target account as the dependent variable. The regression slope and goodness of fit are calculated. When the goodness of fit is greater than a preset goodness of fit threshold, it indicates that there is a stable linear transmission relationship between the two accounts, and the regression slope is used as the edge weight. When the goodness of fit is less than or equal to the preset goodness of fit threshold, it indicates that the quantitative relationship between the two accounts is unstable, and the edge is marked as an invalid edge.
[0132] For internal edges within an element, the weight of the internal edge is calculated based on the transaction amounts of the source and target accounts over N consecutive historical periods. Specifically, the transaction amount extraction direction is determined according to the lending direction, the historical transaction amount sequences of the two accounts are extracted, and the ratio of the target account's transaction amount to the source account's transaction amount in each period is calculated to obtain a ratio sequence. The arithmetic mean and coefficient of variation of the ratio sequence are calculated. When the coefficient of variation is less than a preset stability threshold, it indicates that the proportional relationship between the two accounts is stable, and the arithmetic mean is used as the edge weight; when the coefficient of variation is greater than or equal to the preset stability threshold, it indicates that the proportional relationship fluctuates greatly, and the edge is marked as an invalid edge.
[0133] Finally, the lower quartile of the edge weights of all directed edges not marked as invalid is calculated as the noise threshold, and edges with weights less than the noise threshold are marked as untracked edges. The noise threshold corresponds to weakly correlated edges generated by occasional small transactions. Filtering these edges can reduce the computational overhead of subsequent propagation tracking, while avoiding interference from weak correlations in the calculation of propagation coefficients.
[0134] Step S2 further includes the following sub-steps:
[0135] S2-1, Calculate the directed Laplacian matrix based on the edge weight adjacency matrix and out-degree matrix of the directed graph of accounting subjects;
[0136] S2-2, Perform eigenvalue decomposition on the directed Laplace matrix to obtain the eigenvector matrix and the eigenvalue sequence, in which the eigenvalues are arranged in ascending order;
[0137] S2-3, obtain the change rate of the account balance of each node in the current period compared with the previous period, weight the change rate according to the accounting importance level of the corresponding account in each node, and form the weighted change rate into a graph signal vector;
[0138] S2-4, use the eigenvector matrix to perform a graph Fourier transform on the graph signal vector to obtain the graph spectral coefficient vector;
[0139] S2-5, extract the spectral coefficient components corresponding to the feature vectors whose feature values are greater than the preset feature threshold as abnormal fluctuation components, and perform inverse graph Fourier transform on the abnormal fluctuation components to obtain the abnormal fluctuation graph signal.
[0140] S2-6, mark nodes in the abnormal fluctuation graph signal whose amplitude exceeds the preset amplitude threshold as candidate abnormal nodes.
[0141] Furthermore, in sub-step S2-3, the accounting materiality level is determined according to the following rules:
[0142] Revenue items, operating cost items, and tax items are classified as the first importance level and assigned a preset first weighting coefficient;
[0143] Other profit and loss items, excluding revenue, operating cost, and taxes, are classified as the second most important category and assigned a preset second weighting coefficient.
[0144] All accounts other than profit and loss accounts are classified as the third importance level and assigned a preset third weighting coefficient;
[0145] The first preset weighting coefficient is greater than the second preset weighting coefficient, and the second preset weighting coefficient is greater than the third preset weighting coefficient.
[0146] It should be noted that the edge weight adjacency matrix is a matrix composed of the weights of each edge in the directed graph of accounting subjects. The rows of the matrix correspond to the source subject nodes, the columns correspond to the target subject nodes, and the element values are the weights of the corresponding directed edges.
[0147] The out-degree matrix is a diagonal matrix with the out-degree of each node as its diagonal elements. The out-degree refers to the number of directed edges originating from a node and pointing to other nodes.
[0148] The directed Laplace matrix is the matrix obtained by subtracting the edge weight adjacency matrix from the degree matrix. It is used to characterize the signal variation characteristics on a directed graph and to perform graph Fourier transform.
[0149] The eigenvector matrix is a matrix composed of eigenvectors as columns, obtained by performing eigenvalue decomposition on the directed Laplacian matrix, and serves as the basis function for the graph Fourier transform.
[0150] An eigenvalue sequence is a sequence of all eigenvalues obtained after the eigenvalue decomposition of a directed Laplacian matrix, arranged in ascending order. The magnitude of the eigenvalues corresponds to the frequency of the signal.
[0151] The rate of change of account balance compared to the previous period refers to the ratio of the difference between the ending balance of the current period and the ending balance of the previous accounting period to the ending balance of the previous period, which is used to reflect the relative change in account balance.
[0152] Accounting materiality rating refers to a classification of accounts based on their importance to financial and tax risk warnings. Accounts with higher materiality are assigned a greater weighting factor in anomaly detection.
[0153] The first importance level refers to the level to which revenue items, operating cost items, and tax items belong. These items directly reflect the company's operating results and tax obligations, and are assigned the highest weighting coefficient.
[0154] The second importance level refers to the level of other profit and loss accounts besides revenue, cost of goods sold, and taxes. These accounts indirectly affect profits and are assigned a medium weighting factor.
[0155] The third importance level refers to the level of accounts other than profit and loss accounts, including asset, liability and owner's equity accounts, which are assigned the lowest weighting coefficient.
[0156] A graph signal vector is a vector composed of weighted components representing the rate of change of each node in a directed graph of accounting subjects. Each component corresponds to the signal value of a subject node.
[0157] The graph coefficient vector refers to the graph signal vector represented in the graph spectral domain after undergoing graph Fourier transform, with each component corresponding to the coefficient of an eigenvector.
[0158] Abnormal fluctuation components refer to the spectral coefficient components corresponding to feature vectors whose eigenvalues are greater than a preset feature threshold, corresponding to the drastically changing local abnormal parts in the graph signal.
[0159] The inverse graphical Fourier transform refers to the operation of transforming the spectral coefficient components in the graphical domain back to the spatial domain through the eigenvector matrix, which is used to reconstruct the graphical signal of the corresponding frequency components.
[0160] An abnormal fluctuation graph signal refers to the spatial domain graph signal obtained by performing an inverse graph Fourier transform on the abnormal fluctuation components, reflecting the intensity of abnormal fluctuations at each node that do not conform to the overall business trend.
[0161] The preset amplitude threshold is a critical value used to determine whether a node has abnormal fluctuations. Nodes in the abnormal fluctuation graph signal whose amplitude exceeds this threshold are marked as candidate abnormal nodes. This threshold is dynamically obtained through an adaptive statistical algorithm: using historical abnormal fluctuation graph signals from several recent historical stable periods, the distribution of amplitudes of all nodes is statistically analyzed; the mean μ and standard deviation σ of the amplitudes are calculated, and the threshold is set to μ+3σ; nodes in the current period's abnormal fluctuation graph signal whose amplitude is greater than this threshold are judged as candidate abnormal nodes, and nodes whose amplitude is less than or equal to this threshold are judged as normal nodes.
[0162] The proposed solution overcomes the limitations of existing financial and tax anomaly detection methods, which rely on independent analysis of each item and cannot utilize the interrelationships between items for holistic detection, by constructing a directed Laplace matrix and performing a graph Fourier transform on the graph signal.
[0163] First, the directed Laplace matrix is calculated based on the edge weight adjacency matrix and out-degree matrix of the directed graph of accounting subjects. The directed Laplace matrix characterizes the mathematical structure of signal changes on the directed graph of accounting subjects, and its eigenvectors constitute the basis functions of the graph Fourier transform. Eigenvalue decomposition is performed on the directed Laplace matrix to obtain the eigenvector matrix and the sequence of eigenvalues arranged in ascending order. In graph signal processing, smaller eigenvalues correspond to low-frequency components, representing smooth changes in the graph signal globally; larger eigenvalues correspond to anomalous fluctuation components, representing sharp jumps in the graph signal locally.
[0164] Next, the change rate of the account balances at each node in the current period compared to the previous period is obtained. To make anomaly detection more focused on the core concerns of financial and tax risks, the change rates are weighted according to the accounting materiality level of the corresponding accounts at each node. Revenue accounts, operating cost accounts, and tax accounts are classified as first materiality and assigned the highest weighting coefficient. These accounts directly reflect the company's operating results and tax obligations, and their abnormal changes have the most direct impact on financial and tax risks. Other profit and loss accounts are classified as second materiality and assigned a medium weighting coefficient. Balance sheet accounts are classified as third materiality and assigned the lowest weighting coefficient. Weighting effectively amplifies small changes in important accounts while moderately suppressing drastic changes in minor accounts, improving the targeting and accuracy of anomaly detection. The weighted change rates are then used to construct a graphical signal vector.
[0165] Then, a graphical Fourier transform is performed on the graph signal vector using the eigenvector matrix, projecting the spatial graph signal onto the eigenvector basis to obtain the graph coefficient vector. The graph coefficient components corresponding to eigenvectors with eigenvalues greater than a preset threshold are extracted as abnormal fluctuation components. Under normal operating conditions, the graph signal exhibits a smooth distribution on the graph, corresponding to low-frequency components; when an item experiences abnormal fluctuations that do not conform to the reconciliation relationship, the graph signal shows drastic jumps locally, corresponding to abnormal fluctuation components. Therefore, extracting abnormal fluctuation components can effectively locate abnormal items.
[0166] An inverse graphical Fourier transform is performed on the abnormal fluctuation components to obtain an abnormal fluctuation graph signal. The amplitude of each node in the abnormal fluctuation graph signal reflects the intensity of the abnormal fluctuation of the corresponding subject. Nodes with amplitudes exceeding a preset amplitude threshold are marked as candidate abnormal nodes, completing the complete detection process from graph signal to anomaly location.
[0167] Step S3 further includes the following sub-steps:
[0168] S3-1, Obtain the set of candidate abnormal nodes, take each candidate abnormal node as the starting point of the tracking, and perform the search along the direction of the directed edge from the starting point of the tracking;
[0169] S3-2, For the current edge found, obtain the edge type of the edge. When the edge type is a cross-feature edge, a preset first attenuation factor is used. When the edge type is an intra-feature edge, a preset second attenuation factor is used. The preset first attenuation factor is greater than the preset second attenuation factor.
[0170] S3-3, calculate the path risk transmission coefficient from the tracking starting point to the current node. When the path risk transmission coefficient is less than the preset transmission threshold, terminate the search along the current path. The path risk transmission coefficient is the accumulation of the product of the weight of each edge on the path and the corresponding decay factor.
[0171] S3-4 When the search reaches the preset risk point node, record the risk point node and terminate the search along the current path. The preset risk point nodes include the cash and cash equivalents account node, the retained earnings account node, and the taxes payable account node.
[0172] S3-5, For each candidate abnormal node, obtain the maximum path risk transmission coefficient on all search paths with it as the starting point of the tracking. When the maximum path risk transmission coefficient is greater than the preset transmission threshold, the candidate abnormal node is determined to be a transmission abnormal node; otherwise, the candidate abnormal node is determined to be a source abnormal node.
[0173] S3-6 For candidate abnormal nodes that are determined to be transmission abnormal nodes, the path that traces them back to the source abnormal node in the directed graph of accounting subjects is marked as a risk transmission link.
[0174] Furthermore, in sub-step S3-2, the preset first attenuation factor and the preset second attenuation factor are dynamically adjusted according to the following rules:
[0175] Obtain the current credit cycle stage identifier and operating cycle stage identifier of the enterprise. The credit cycle stage includes the credit expansion period, the credit stability period and the credit contraction period. The operating cycle stage includes the peak season, the average season and the off-season.
[0176] The first adjustment factor is determined based on the stage of the credit cycle, wherein the first adjustment factor during the credit expansion period is greater than that during the credit stability period, and the first adjustment factor during the credit stability period is greater than that during the credit contraction period.
[0177] The second adjustment coefficient is determined based on the stage of the operating cycle, with the second adjustment coefficient for peak season being greater than that for off-peak season, and the second adjustment coefficient for off-peak season being greater than that for low-peak season.
[0178] The preset first attenuation factor is set as the product of the basic first attenuation factor, the first adjustment coefficient, and the second adjustment coefficient, and the preset second attenuation factor is set as the product of the basic second attenuation factor, the first adjustment coefficient, and the second adjustment coefficient.
[0179] It should be noted that the starting point of the tracking refers to the node that takes the candidate abnormal node as the starting point of the search, and the path search is performed starting from the direction of the edge outward.
[0180] Edge type refers to the type of directed edge that is classified according to the accounting element category to which the source account and the target account belong during construction, including cross-element edges and intra-element edges.
[0181] The preset first attenuation factor refers to the attenuation coefficient applied across the element edge, reflecting the degree of intensity retention when risk is transmitted along the element edge.
[0182] The preset second attenuation factor is an attenuation coefficient applied to the inner edge of an element, reflecting the degree of intensity retention when risk propagates along the inner edge of an element. Its value is less than the preset first attenuation factor.
[0183] The path risk transmission coefficient refers to the cumulative value of the product of the weights of each edge on the path from the starting point to the current node and the corresponding attenuation factor. It is used to quantify the residual strength of the risk after it has been transmitted along the path.
[0184] Risk confluence points refer to the final convergence points of risk transmission. After reaching this point, the risk will no longer continue to be transmitted. These include cash and cash equivalents, retained earnings, and taxes payable.
[0185] The maximum path risk transmission coefficient refers to the maximum value of the path risk transmission coefficient among all valid search paths starting from the candidate anomaly node.
[0186] The risk transmission link refers to the directed edge path from the primary abnormal node to the transmissive abnormal node, representing the direction of risk transmission in the directed graph of accounting subjects.
[0187] Credit cycle stage markers refer to the stage markings determined based on a company's current credit environment and credit policies, including the credit expansion period, the credit stability period, and the credit contraction period.
[0188] Operating cycle stage markers refer to stage markings determined based on the current level of business activity and seasonal characteristics of an enterprise, including peak season, off-season, and slow season.
[0189] The first adjustment factor is a coefficient used to adjust the attenuation factor, determined based on the credit cycle stage identifier. Its value ranges from 0.8 to 1.2, and the rules for setting it include: using the credit stability period as the baseline stage and setting its adjustment factor as the baseline value; increasing the adjustment factor for the credit expansion period based on the baseline value, and decreasing the adjustment factor for the credit contraction period based on the baseline value; and determining the quantitative value based on the cycle stage as follows: obtaining the current credit cycle stage identifier of the enterprise; when the credit cycle stage identifier is a credit stability period, the first adjustment factor takes the baseline value of 1.0; when the credit cycle stage identifier is a credit expansion period, the first adjustment factor takes 1.2; and when the credit cycle stage identifier is a credit contraction period, the first adjustment factor takes 0.8.
[0190] The second adjustment factor is a coefficient used to adjust the attenuation factor, determined based on the operating cycle stage identifier. Its value ranges from 0.8 to 1.2, and the rules for its selection are as follows: The adjustment factor is set as the baseline value for a flat season; the adjustment factor for a peak season is increased based on the baseline value, and the adjustment factor for a low season is decreased based on the baseline value. The method for determining the quantitative value based on the cycle stage is to obtain the current operating cycle stage identifier of the enterprise. When the operating cycle stage identifier is a flat season, the second adjustment factor is the baseline value of 1.0; when the operating cycle stage identifier is a peak season, the second adjustment factor is 1.2; and when the operating cycle stage identifier is a low season, the second adjustment factor is 0.8.
[0191] The basic first attenuation factor refers to the attenuation coefficient of the cross-element edge under the reference state. After adjustment coefficient correction, the preset first attenuation factor for actual use is obtained.
[0192] The basic second attenuation factor refers to the attenuation coefficient of the inner edge of the element under the reference state. After adjustment coefficient correction, the preset second attenuation factor for actual use is obtained.
[0193] The proposed solution overcomes the limitations of existing tax and financial anomaly detection methods by forward tracing candidate abnormal nodes along directed edges and calculating the path risk transmission coefficient. These methods cannot distinguish between the risk source and the affected nodes, nor can they identify the risk transmission path.
[0194] First, obtain the set of candidate abnormal nodes output in step S2. Use each candidate abnormal node as the starting point for tracking, and perform a search along the direction of the directed edges from the starting point. The direction of the directed edges in the accounting subject directed graph represents the flow of funds from credit accounts to debit accounts, that is, the direction of risk transmission. Searching along the outgoing edges can track the subsequent accounts that may be affected by abnormal fluctuations.
[0195] During the search process, for each found edge, its type is determined. A preset first attenuation factor is used when the edge type is a cross-element edge, and a preset second attenuation factor is used when the edge type is an intra-element edge. The preset first attenuation factor is greater than the preset second attenuation factor. Cross-element edges correspond to fund flows between different types of accounts, exhibiting causal transmission characteristics; risk attenuation is relatively small when transmitted along such edges. Intra-element edges correspond to fund transfers within the same type of account, often involving reclassification or proportional allocation; risk attenuation is relatively large when transmitted along such edges. By setting differentiated attenuation factors, the transmission patterns of risk across different edge types can be simulated more accurately.
[0196] Furthermore, the attenuation factor is dynamically adjusted based on the company's current credit cycle stage and operating cycle stage. The current credit cycle stage and operating cycle stage are identified. During credit expansion, companies have ample funds and loose credit, leading to smoother risk transmission and a higher first adjustment coefficient. During credit contraction, companies face tight funds and restricted credit, hindering risk transmission and resulting in a lower first adjustment coefficient. During peak seasons, companies are active and transact frequently, accelerating risk transmission and resulting in a higher second adjustment coefficient. During off-seasons, companies experience slower operations and sparse transactions, weakening risk transmission and resulting in a lower second adjustment coefficient. Multiplying the basic attenuation factor by the two adjustment coefficients yields the actual attenuation factor used, allowing the calculation of the risk transmission coefficient to adapt to changes in the company's operating environment.
[0197] During the search process, the path risk transmission coefficient from the tracking starting point to the current node is calculated. The path risk transmission coefficient is the cumulative product of the weights of each edge on the path and their corresponding attenuation factors. The edge weights reflect the quantitative dependence between subjects, and the attenuation factors reflect the nature of the transmission path. The product of the two comprehensively characterizes the transmission contribution of a single edge, and the cumulative transmission contribution of each edge on the path reflects the remaining strength of the risk transmitted from the source to the current node. When the path risk transmission coefficient is less than a preset transmission threshold, it indicates that the risk along the path has attenuated to a negligible level, and the search along the current path is terminated.
[0198] Simultaneously, when the search reaches a preset risk convergence node, the node is recorded and the search along the current path is terminated. The cash and cash equivalents account is the endpoint of the cash cycle, the retained earnings account represents the final attribution of operating results, and the taxes payable account represents the final manifestation of tax obligations. These three types of nodes are the final convergence points of financial and tax risks; once reached, the risks cease to propagate.
[0199] For each candidate anomaly node, the maximum path risk transmission coefficient is obtained across all search paths originating from that node. When the maximum path risk transmission coefficient exceeds a preset transmission threshold, it indicates that the node's abnormal fluctuations can effectively transmit to downstream subjects and have an impact, thus classifying it as a transmission-related anomaly node. Otherwise, it indicates that the node's abnormal fluctuations cannot be effectively transmitted or that it is itself the starting point of a transmission link, thus classifying it as a source-related anomaly node.
[0200] For candidate abnormal nodes identified as transmission abnormal nodes, the path traced back to the source abnormal node in the directed graph of accounting subjects is marked as a risk transmission link, providing path data for the generation and visualization of subsequent early warning information.
[0201] Step S4 further includes the following sub-steps:
[0202] S4-1 aggregates the transmissive anomaly nodes and their corresponding source anomaly nodes on the same transmission path into a single early warning event;
[0203] S4-2, taking the primary anomaly node as the root node, extract the root node and all the transitive anomaly nodes traced from the root node, and extract the directed edges connecting these nodes to form the risk transmission subgraph of the early warning event;
[0204] S4-3, Extract the subject type of the primary abnormal node, match the subject type with the preset risk model library, and obtain the corresponding handling suggestion template;
[0205] S4-4 marks the accounting subject corresponding to the primary abnormal node as the risk source, assembles the risk source, risk transmission sub-diagram and disposal suggestion template into risk warning information, and pushes it to the front-end interactive interface.
[0206] It should be noted that the same transmission path refers to the set of paths that start from the same primary anomaly node and reach each other along the directed edge direction. These paths share the same source of risk.
[0207] Aggregation refers to merging transmissive anomaly nodes and originating anomaly nodes belonging to the same risk source into a single processing operation, thereby avoiding the generation of multiple duplicate alerts for the same risk event.
[0208] A single early warning event refers to a unique early warning record formed by merging all relevant abnormal nodes on the same transmission path, corresponding to an independent risk event.
[0209] The root node refers to the originating abnormal node that serves as the starting point in the risk transmission subgraph; it is the source of the risk transmission chain.
[0210] Account type refers to the category attribute of the accounting account corresponding to the original abnormal node, such as raw materials account, operating revenue account, tax payable account, etc., which is used to match the corresponding risk disposal suggestions.
[0211] The source of risk refers to the name of the accounting subject corresponding to the initial abnormal node, which serves as the starting point identifier of the risk event in the early warning information.
[0212] Risk warning information refers to the complete warning content pushed to financial and tax management personnel, which includes three parts: risk source, risk transmission sub-diagram, and disposal suggestion template.
[0213] The front-end interactive interface refers to the workbench interface for financial and tax management personnel to view and process early warning information, supporting the visual display of risk transmission sub-graphs and the viewing and confirmation of disposal suggestions.
[0214] The proposed solution overcomes the limitations of existing financial and tax early warning methods, which suffer from fragmented output information and lack of operational guidance, by aggregating and processing transmissible and originating abnormal nodes and generating complete early warning information containing disposal suggestions.
[0215] First, transitive anomaly nodes along the same transmission path are aggregated with their corresponding source anomaly nodes into a single warning event. During the transmission tracing process in step S3, a source anomaly node may affect multiple transitive anomaly nodes along multiple paths. Without aggregation, each anomaly node would generate an independent alarm, leading to a large number of redundant alarms for the same risk event, increasing the identification burden on tax and financial management personnel. By aggregating at the source anomaly node level, all abnormal manifestations of the same risk source are merged into a single warning event, significantly reducing redundant alarms.
[0216] Next, using the originating anomaly node as the root node, we extract this root node and all subsequent anomaly nodes traced from it, and extract the directed edges connecting these nodes to form a risk transmission subgraph for the warning event. This risk transmission subgraph, in graph structure, fully presents the path and hierarchical relationship of risk transmission from the source account to all affected accounts. Nodes represent the affected accounting accounts, and directed edges represent the transmission direction and relationship, enabling financial and tax managers to intuitively understand the risk transmission chain and its scope of impact.
[0217] Next, the account types of the originating anomaly nodes are extracted, and these account types are matched with a pre-defined risk model library to obtain corresponding handling suggestion templates. The pre-defined risk model library establishes a mapping relationship between account types and typical risk scenarios. For example, the raw materials account corresponds to inventory backlog or abnormal procurement risks, the main business revenue account corresponds to revenue recognition or overstatement risks, and the taxes payable account corresponds to tax declaration or input tax deduction risks. The matched handling suggestion templates include specific verification steps for the risk scenario, suggested adjusting entries, and applicable accounting standards or tax laws, providing financial and tax management personnel with immediately actionable operational guidance.
[0218] Finally, the accounting items corresponding to the primary anomaly nodes are marked as risk sources. The risk sources, risk transmission sub-diagrams, and disposal suggestion templates are assembled into risk warning information and pushed to the front-end interactive interface. The front-end interactive interface displays the risk transmission sub-diagram graphically, distinguishing primary and transmission nodes with different colors and indicating the transmission direction with arrows. Simultaneously, the information panel displays the specific content of the disposal suggestion template. The entire process forms a complete closed loop from anomaly node aggregation, sub-diagram construction, suggestion matching to visual push, enabling financial and tax management personnel to quickly understand the overall risk picture and take targeted measures.
[0219] Please see Figure 2 The diagram illustrates a system architecture of a data-based intelligent early warning system for financial and tax data, according to an embodiment of the present invention, comprising:
[0220] The topology graph construction module is used to obtain the enterprise's accounting chronological ledger data and construct a directed graph of accounting subjects with accounting subjects as nodes and fund flows as directed edges based on the debit and credit entries. The edge weights are determined by the linear regression slope of the source subject and the target subject's transaction amount.
[0221] The graph decomposition module is used to perform graph Fourier transform on the graph signal composed of the balance of each node account in the current period, decompose the graph signal into graph components of different frequencies, and extract the graph component nodes corresponding to the feature vectors whose feature values are greater than the preset feature threshold as candidate abnormal nodes.
[0222] The risk localization module is used to perform forward tracking along the directed edges for each candidate abnormal node, calculate the product of the weights of each edge on the tracking path as the risk transmission coefficient, and distinguish between primary abnormal nodes and transmissive abnormal nodes based on the risk transmission coefficient.
[0223] The aggregation and push module is used to aggregate transmissive anomaly nodes and their corresponding source anomaly nodes on the same transmission path into a single early warning event, mark the accounting subject corresponding to the source anomaly node as the risk source, generate risk warning information and push it to the front-end interactive interface.
[0224] It should be noted that the system in this application transforms financial and tax data analysis from traditional independent indicator detection to holistic anomaly identification based on a directed graph of accounting subjects. The four modules work together to form a complete closed loop from data collection, graph construction, anomaly detection, transmission tracking to early warning push.
[0225] The system first leverages the inherent correlation between debit and credit entries in double-entry bookkeeping to organize scattered account data into a directed graph structure. The edge weights employ linear regression slopes to accurately capture the quantitative dependencies of unit changes between accounts. Building upon this, the system introduces graph signal processing into financial and tax anomaly detection. Utilizing the differences between low-frequency characteristics of coordinated changes in accounts under normal operating conditions and abnormal fluctuations, the system accurately locates anomalous accounts while considering global reconciliation relationships. Subsequently, the system traces forward along the flow of funds, simulating the gradual attenuation of risk transmission through the product of edge weights. By comparing the transmission coefficient with a threshold, it distinguishes between the initiation point and the affected point of the anomaly, solving the technical challenge of existing systems being unable to locate the root cause of risk. Finally, the system aggregates transmission nodes at the source node level, merging multiple manifestations of the same risk event into a single warning, and mapping account types to actionable handling suggestions. This upgrades the warning information from simple anomaly alerts to comprehensive decision support including root cause analysis and countermeasures.
[0226] The entire system's design incorporates the unique principles of the financial and tax field: the reconciliation relationships of double-entry bookkeeping are transformed into graph structure constraints, the quantitative dependencies between accounts are quantified as edge weights, the flow of funds determines the direction of risk transmission, and the importance level of accounts guides the sensitivity allocation for anomaly detection. This deep integration enables the system to accurately identify anomalies, trace their root causes, and output recommendations from massive amounts of financial and tax data, achieving an intelligent closed loop from data to decision-making.
[0227] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be included within the protection scope of this application.
Claims
1. A method for intelligent early warning of financial and tax data based on data analysis, characterized in that, Includes the following steps: Step S1: Obtain the enterprise's chronological accounting data and construct a directed graph of accounting subjects with accounting subjects as nodes and fund flows as directed edges based on the debit and credit entries. The edge weights are determined by the linear regression slope of the source subject and the target subject's transaction amounts. Step S2: Perform a graph Fourier transform on the graph signal composed of the balance of each node account in the current period, decompose the graph signal into graph components of different frequencies, and extract the graph component nodes corresponding to the feature vectors whose feature values are greater than the preset feature threshold as candidate abnormal nodes. Step S3: For each candidate anomalous node, perform forward tracing along the directed edge, calculate the product of the weights of each edge on the tracing path as the risk transmission coefficient, and distinguish between primary anomalous nodes and transmissive anomalous nodes based on the risk transmission coefficient. Step S4: Aggregate the transmissive anomaly nodes and their corresponding source anomaly nodes on the same transmission path into a single early warning event, mark the accounting subject corresponding to the source anomaly node as the risk source, generate risk warning information and push it to the front-end interactive interface.
2. The intelligent early warning method for financial and tax data based on data analysis according to claim 1, characterized in that: Step S1 further includes the following sub-steps: S1-1, Preprocess the accounting chronological ledger data, and remove journal entries containing preset invalid keywords in the voucher summary. The preset invalid keywords include reversal, void, and test. S1-2, When constructing directed edges, obtain the accounting element categories to which the source account and the target account belong. When the source account and the target account belong to different accounting element categories, the directed edge is marked as a cross-element edge. When the source account and the target account belong to the same accounting element category, the directed edge is marked as an intra-element edge. The accounting element categories include asset category, liability category, owner's equity category, revenue category and expense category. S1-3, For cross-element edges, calculate the weight of the cross-element edge based on the transaction amounts of the source account and the target account in the N consecutive historical periods. When there is no stable linear transmission relationship between the source account and the target account, the cross-element edge is marked as an invalid edge. S1-4, For the inner edge of an element, calculate the weight of the inner edge of the element based on the transaction amount of the source account and the target account in the N consecutive historical periods. When there is no stable proportional relationship between the source account and the target account, the inner edge of the element is marked as an invalid edge. S1-5: Calculate the lower quartile of the edge weights of all directed edges that are not marked as invalid edges as the noise threshold, and mark edges whose edge weights are less than the noise threshold as untracked edges.
3. The intelligent early warning method for financial and tax data based on data analysis according to claim 2, characterized in that, In sub-steps S1-3, the step of calculating the cross-factor edge weights based on the transaction amounts of the source and target accounts over N consecutive historical periods includes: The direction of retrieval for the source account and the target account is determined based on the debit and credit directions of the accounting entries. When the directed edge points from the debit account to the credit account, the source account takes the debit amount and the target account takes the credit amount. When the directed edge points from the credit account to the debit account, the source account takes the credit amount and the target account takes the debit amount. Extract the source account's occurrence sequence in a specified direction over N consecutive historical periods and the target account's occurrence sequence in the same direction over the same period; Using the source account transaction sequence as the independent variable and the target account transaction sequence as the dependent variable, the least squares method was used to calculate the regression slope and regression intercept. The goodness of fit is calculated based on the regression slope and the regression intercept, whereby the goodness of fit is the ratio of the regression sum of squares to the total sum of squares. When the goodness of fit is greater than the preset goodness of fit threshold, the regression slope is used as the weight of the cross-factor edge; when the goodness of fit is less than or equal to the preset goodness of fit threshold, the cross-factor edge is marked as an invalid edge.
4. The intelligent early warning method for financial and tax data based on data analysis according to claim 2, characterized in that, In sub-steps S1-4, the step of calculating the inner edge weight of the element based on the transaction amounts of the source account and the target account over N consecutive historical periods includes: The direction of retrieval for the source account and the target account is determined based on the debit and credit directions of the accounting entries. When the directed edge points from the debit account to the credit account, the source account takes the debit amount and the target account takes the credit amount. When the directed edge points from the credit account to the debit account, the source account takes the credit amount and the target account takes the debit amount. Extract the source account's occurrence sequence in a specified direction over N consecutive historical periods and the target account's occurrence sequence in the same direction over the same period; Calculate the ratio of the target account amount to the source account amount for each period to obtain a ratio sequence containing N ratios; Calculate the arithmetic mean and standard deviation of the ratio series, and divide the standard deviation by the arithmetic mean to obtain the coefficient of variation; When the coefficient of variation is less than the preset stability threshold, the arithmetic mean is used as the weight of the inner edge of the element. When the coefficient of variation is greater than or equal to the preset stability threshold, the inner edge of the element is marked as an invalid edge.
5. The intelligent early warning method for financial and tax data based on data analysis according to claim 1, characterized in that: Step S2 further includes the following sub-steps: S2-1, Calculate the directed Laplacian matrix based on the edge weight adjacency matrix and out-degree matrix of the directed graph of accounting subjects; S2-2, Perform eigenvalue decomposition on the directed Laplacian matrix to obtain an eigenvector matrix and an eigenvalue sequence, wherein the eigenvalues in the eigenvalue sequence are arranged in ascending order; S2-3, obtain the change rate of the account balance of each node in the current period compared with the previous period, weight the change rate according to the accounting importance level of the corresponding account in each node, and form the weighted change rate into a graph signal vector; S2-4, use the eigenvector matrix to perform a graph Fourier transform on the graph signal vector to obtain the graph spectral coefficient vector; S2-5, extract the spectral coefficient components corresponding to the feature vectors whose feature values are greater than the preset feature threshold as abnormal fluctuation components, and perform inverse graph Fourier transform on the abnormal fluctuation components to obtain the abnormal fluctuation graph signal. S2-6, mark nodes in the abnormal fluctuation graph signal whose amplitude exceeds the preset amplitude threshold as candidate abnormal nodes.
6. The intelligent early warning method for financial and tax data based on data analysis according to claim 5, characterized in that, In sub-steps S2-3, the accounting materiality level is determined according to the following rules: Revenue items, operating cost items, and tax items are classified as the first importance level and assigned a preset first weighting coefficient; Other profit and loss items, excluding revenue, operating cost, and taxes, are classified as the second most important category and assigned a preset second weighting coefficient. All accounts other than profit and loss accounts are classified as the third importance level and assigned a preset third weighting coefficient; The first preset weighting coefficient is greater than the second preset weighting coefficient, and the second preset weighting coefficient is greater than the third preset weighting coefficient.
7. The intelligent early warning method for financial and tax data based on data analysis according to claim 1, characterized in that: Step S3 further includes the following sub-steps: S3-1, Obtain the set of candidate abnormal nodes, take each candidate abnormal node as the starting point of the tracking, and perform the search along the direction of the directed edge from the starting point of the tracking; S3-2, For the current edge found, obtain the edge type of the edge. When the edge type is a cross-feature edge, a preset first attenuation factor is used. When the edge type is an intra-feature edge, a preset second attenuation factor is used. The preset first attenuation factor is greater than the preset second attenuation factor. S3-3, calculate the path risk transmission coefficient from the tracking starting point to the current node. When the path risk transmission coefficient is less than the preset transmission threshold, terminate the continued search along the current path. The path risk transmission coefficient is the accumulation of the product of the weight of each edge on the path and the corresponding attenuation factor. S3-4, When the search reaches the preset risk point node, record the risk point node and terminate the search along the current path. The preset risk point node includes the cash and cash equivalents account node, the undistributed profit account node, and the tax payable account node. S3-5, For each candidate abnormal node, obtain the maximum path risk transmission coefficient on all search paths with it as the starting point of the tracking. When the maximum path risk transmission coefficient is greater than the preset transmission threshold, the candidate abnormal node is determined to be a transmission abnormal node; otherwise, the candidate abnormal node is determined to be a source abnormal node. S3-6 For candidate abnormal nodes that are determined to be transmission abnormal nodes, the path that traces them back to the source abnormal node in the directed graph of accounting subjects is marked as a risk transmission link.
8. The intelligent early warning method for financial and tax data based on data analysis according to claim 7, characterized in that, In sub-step S3-2, the preset first attenuation factor and the preset second attenuation factor are dynamically adjusted according to the following rules: Obtain the current credit cycle stage identifier and operating cycle stage identifier of the enterprise. The credit cycle stage includes the credit expansion period, the credit stability period and the credit contraction period. The operating cycle stage includes the peak season, the average season and the off-season. The first adjustment factor is determined based on the stage of the credit cycle, wherein the first adjustment factor during the credit expansion period is greater than that during the credit stability period, and the first adjustment factor during the credit stability period is greater than that during the credit contraction period. The second adjustment coefficient is determined based on the stage of the operating cycle, with the second adjustment coefficient for peak season being greater than that for off-peak season, and the second adjustment coefficient for off-peak season being greater than that for low-peak season. The preset first attenuation factor is set as the product of the basic first attenuation factor, the first adjustment coefficient, and the second adjustment coefficient, and the preset second attenuation factor is set as the product of the basic second attenuation factor, the first adjustment coefficient, and the second adjustment coefficient.
9. The intelligent early warning method for financial and tax data based on data analysis according to claim 1, characterized in that: Step S4 further includes the following sub-steps: S4-1 aggregates the transmissive anomaly nodes and their corresponding source anomaly nodes on the same transmission path into a single early warning event; S4-2, taking the primary anomaly node as the root node, extract the root node and all the transitive anomaly nodes traced from the root node, and extract the directed edges connecting these nodes to form the risk transmission subgraph of the early warning event; S4-3, Extract the subject type of the primary abnormal node, match the subject type with the preset risk model library, and obtain the corresponding handling suggestion template; S4-4 marks the accounting subject corresponding to the primary abnormal node as the risk source, assembles the risk source, risk transmission sub-diagram and disposal suggestion template into risk warning information, and pushes it to the front-end interactive interface.
10. A data-driven intelligent early warning system for financial and tax data, characterized in that: include: The topology graph construction module is used to obtain the enterprise's accounting chronological ledger data and construct a directed graph of accounting subjects with accounting subjects as nodes and fund flows as directed edges based on the debit and credit entries. The edge weights are determined by the linear regression slope of the source subject and the target subject's transaction amount. The graph decomposition module is used to perform graph Fourier transform on the graph signal composed of the balance of each node account in the current period, decompose the graph signal into graph components of different frequencies, and extract the graph component nodes corresponding to the feature vectors whose feature values are greater than the preset feature threshold as candidate abnormal nodes. The risk localization module is used to perform forward tracking along the directed edges for each candidate abnormal node, calculate the product of the weights of each edge on the tracking path as the risk transmission coefficient, and distinguish between primary abnormal nodes and transmissive abnormal nodes based on the risk transmission coefficient. The aggregation and push module is used to aggregate transmissive anomaly nodes and their corresponding source anomaly nodes on the same transmission path into a single early warning event, mark the accounting subject corresponding to the source anomaly node as the risk source, generate risk warning information and push it to the front-end interactive interface.