Explainable Hybrid AI for Detecting Ledger Manipulation in SME Accounting Systems: A Cyber-Forensic Framework Using Deep Autoencoders, XGBoost and SHAP

This working paper develops and evaluates an explainable hybrid artificial-intelligence framework for detecting anomalous general-ledger transactions in small and medium-sized enterprise (SME) accounting systems. A synthetic SME general ledger comprising 50,000 transactions across 400 accounts and 80 users was generated over the period 2022–2024, with approximately 2% controlled behavioural anomalies representing amount spikes, unusual posting hours, rare debit-credit account relationships and suspiciously round amounts.The framework combines Isolation Forest, a Deep Autoencoder, supervised XGBoost refinement and SHAP-based explainability. Ground-truth anomaly variables, anomaly categories, transaction descriptions, transaction identifiers and transaction-type labels were excluded from predictive model inputs. The models therefore operated on behavioural characteristics rather than descriptive anomaly indicators. Experimental evaluation used a chronological 70/15/15 training-validation-test design.On the held-out test set, the Hybrid Autoencoder–XGBoost model achieved precision of 0.646, recall of 0.329, F1 of 0.436 and PR-AUC of 0.359, with a final alert rate of 1.09%. Compared with the standalone Autoencoder, hybrid refinement reduced false-positive alerts from 118 to 29 while retaining 53 of 61 Autoencoder-detected anomalies.SHAP analysis identified credit-account frequency, debit-credit pair rarity, debit-account frequency and Autoencoder reconstruction error among the strongest contributors to model decisions. The study positions explainable hybrid AI as an auditor decision-support mechanism rather than as an autonomous determination of fraud.Supporting materials include synthetic data, experimental results, transaction-level test predictions, feature documentation, run metadata and explainability outputs. No real organisational records, confidential financial information or personal data were used.

Authors

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-10-01
DOI
https://doi.org/10.5281/zenodo.23068696
Primary Topic
Financial Distress and Bankruptcy Prediction
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Explainable Hybrid AI for Detecting Ledger Manipulation in SME Accounting Systems: A Cyber-Forensic Framework Using Deep Autoencoders, XGBoost and SHAP

Seow Woo Edmund Chua
Zenodo (CERN European Organization for Nuclear Research)
Financial Distress and Bankruptcy Prediction
article

Explainable Hybrid AI for Detecting Ledger Manipulation in SME Accounting Systems: A Cyber-Forensic Framework Using Deep Autoencoders, XGBoost and SHAP

Seow Woo Edmund Chua
article en

Abstract

This working paper develops and evaluates an explainable hybrid artificial-intelligence framework for detecting anomalous general-ledger transactions in small and medium-sized enterprise (SME) accounting systems. A synthetic SME general ledger comprising 50,000 transactions across 400 accounts and 80 users was generated over the period 2022–2024, with approximately 2% controlled behavioural anomalies representing amount spikes, unusual posting hours, rare debit-credit account relationships and suspiciously round amounts.The framework combines Isolation Forest, a Deep Autoencoder, supervised XGBoost refinement and SHAP-based explainability. Ground-truth anomaly variables, anomaly categories, transaction descriptions, transaction identifiers and transaction-type labels were excluded from predictive model inputs. The models therefore operated on behavioural characteristics rather than descriptive anomaly indicators. Experimental evaluation used a chronological 70/15/15 training-validation-test design.On the held-out test set, the Hybrid Autoencoder–XGBoost model achieved precision of 0.646, recall of 0.329, F1 of 0.436 and PR-AUC of 0.359, with a final alert rate of 1.09%. Compared with the standalone Autoencoder, hybrid refinement reduced false-positive alerts from 118 to 29 while retaining 53 of 61 Autoencoder-detected anomalies.SHAP analysis identified credit-account frequency, debit-credit pair rarity, debit-account frequency and Autoencoder reconstruction error among the strongest contributors to model decisions. The study positions explainable hybrid AI as an auditor decision-support mechanism rather than as an autonomous determination of fraud.Supporting materials include synthetic data, experimental results, transaction-level test predictions, feature documentation, run metadata and explainability outputs. No real organisational records, confidential financial information or personal data were used.

Zenodo (CERN European Organization for Nuclear Research)
Peace, Justice and strong institutions
Openalex Percentile: Top 4%
Financial Distress and Bankruptcy Prediction
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

Explainable Hybrid AI for Detecting Ledger Manipulation in SME Accounting Systems: A Cyber-Forensic Framework Using Deep Autoencoders, XGBoost and SHAP — Seow Woo Edmund Chua · Zenodo (CERN European Organization for Nuclear Research) (2026) | TGRS Research Map | TGRS