DETAILED ACTION
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114 was filed in this application after a decision by the Patent Trial and Appeal Board, but before the filing of a Notice of Appeal to the Court of Appeals for the Federal Circuit or the commencement of a civil action. Since this application is eligible for continued examination under 37 CFR 1.114 and the fee set forth in 37 CFR 1.17(e) has been timely paid, the appeal has been withdrawn pursuant to 37 CFR 1.114 and prosecution in this application has been reopened pursuant to 37 CFR 1.114. Applicant’s submission filed on 8/24/2026 has been entered.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This action is in response to the request for continued examination (RCE) filed on 8/24/2026. In the RCE, no claims were amended, cancelled or added. As such, claims 1-20 are pending and have been examined. Claims 1-20 are rejected.
Response to Arguments
The RCE filed 8/24/2026 requested consideration of remarks in the Reply Brief previously filed on 9/9/2025 (hereinafter “Reply Br.”).
As noted in the Examiner's Answer, mailed 7/9/2025 (hereinafter, “Ans.”), Applicant’s previously-submitted arguments in the Appeal Brief dated 4/14/2025 (hereinafter “Appeal Brief”) with respect to the invocation of 35 U.S.C. 112(f) have been considered and are persuasive. Thus, claims 1, 8, and 14 are no longer being interpreted under 35 U.S.C. § 112(f).
As noted in the Final Office Action mailed 12/02/2024 (hereinafter, “Final Action”), Applicant's arguments previously filed on 10/29/2024 with respect to the previous objection to the specification have been fully considered and are persuasive. However, as documented in the Final Action and below, objections to the specification remain. With respect to the previous objection to the specification, applicant’s entire argument filed on 10/29/2024 consisted of stating “The disclosure is objected to due to informalities.” before concluding that “The objections are overcome based on amendments.” (applicant’s 10/29/2024 remarks, page 7). However, the examiner again notes that no specification or drawing amendments were filed to address previous objections to the drawings. As documented in the Final Action and below, the specification is objected to based on the previous objections to the drawings.
Applicant's arguments filed 10/29/2024 with respect to the objections to the drawings in the Final Action have been fully considered but are not persuasive. In particular, as discussed in the Final Action and below, the previous objections to the drawings are maintained
With respect to the previous objections to the drawings, applicant’s entire argument consisted of stating “The drawings are objected to as failing to comply with 37 CFR 1.84(p)(4).” before concluding that “The objections are overcome based on amendments.” (applicant’s 10/29/2024 remarks, page 7). First, in the non-final Office Action preceding the Final Action, the drawings were objected to as failing to comply with 37 CFR 1.84(p)(4) and 37 CFR 1.84(p)(5). Second, the examiner again notes that no replacement drawings or amendments to the specification were filed to address previous objections to the drawings. As such, the previous objections to the drawings are maintained.
Applicant's arguments in the Reply Br. with respect to the rejections of claims 1-20 under 35 U.S.C. 101 have been fully considered, but are not persuasive.
As discussed below, the rejections of claims 1-20 under 35 U.S.C. 101 remain and are being maintained.
In the Reply Br., with reference to Example 47 of the July 2024 Subject Matter Eligibility Examples (“Examples”) provided by the Office in conjunction with the 2024 Guidance Update on Patent Subject Matter Eligibility, Including on Artificial Intelligence, 89 Fed. Reg. 58128-58138 (July 17, 2024) (“2024 AI SME Update”), applicant “admits that claim 3 of Example 47 is more akin than claim 1, but that does not change the 101 analysis. While, the Applicant admits that the claim scope is entirely different between the example and the claims”. (Reply Br., page 2).
Next, with continued reference to example 47, and apparent reference to independent claims 1, 8 and 14, applicant asserts “that is not the point of the comparison for the allowance. Instead, the analysis of the technical improvement that the USPTO lays out in the analysis on page 12-13 of the MPEP Guidelines aligns with our instant claims: The consideration of whether the claim as a whole includes an improvement to a computer or to a technological field requires an evaluation of the specification and the claim to ensure that a technical explanation of the asserted improvement is present in the specification, and that the claim reflects the asserted improvement. See MPEP 2106.04(d)(1).” (Id., emphasis in original).
Examiner’s Response:
Examiner respectfully disagrees with applicant’s assertions in the Reply Br. regarding the section 101 rejections and purported eligibility of the instant claims.
Applicant’s above-noted assertions vis-à-vis Example 47 in the Examples is misplaced.
In contrast to Applicant’s claims, per the Examples, claim 3 of Example 47 is eligible “because it recites a judicial exception (abstract idea), but the claim as a whole integrates the judicial exception into a practical application” and because in the Step 2A Prong One analysis, “Limitations (d)-(f) do not recite mental processes because they cannot be practically performed in the human mind. That is, the human mind is not equipped to detect a source address associated with malicious network packets, drop the malicious network packets in real time, and block future traffic as recited in the claim.” (Examples, pages 2 and 11). In contrast to the eligible claim from example 47 and contrary to the above-noted arguments in the Reply Br., the instant claims are not, by their terms, limited to machine learning applications of data that cannot be mentally manipulated or cannot be practically performed in the human mind.
As noted by the Patent Trial and Appeal Board in the Decision affirming the rejections of claims 1-20 under section 101 in the Final Action and regarding applicant’s arguments vis-à-vis example 47 in the Appeal Brief, “We agree with the Examiner. Although the pending claims recite limitations related to machine learning applications, including for example, "training a machine-learning network," "generating an input data set," "send the input data set to a robustifier," "removing perturbations associated with the input data set to create a modified input data set," "training the robustifier to obtain a trained robustifier utilizing the modified input data set," and "in response to convergence of the trained robustifier to a first threshold, output the trained robustifier," these limitations do not make the claim patent eligible.” (Decision, page 9).
Regarding Example 47 and applicant’s claims, the Decision further notes “With respect to the claims of Example 47 of the July 2024 Subject Matter Eligibility Examples, which are incorporated into the Manual of Patent Examining Procedure (MPEP) § 2106 and discussed in the 2024 Guidance Update on Patent Subject Matter Eligibility, Including on Artificial Intelligence, we find, for example, that pending claim 1 is similar to claim 2 of Example 47, which recites a method of using an artificial neural network (ANN) comprising the steps of
(a) receiving, at a computer, continuous training data;
(b) discretizing, by the computer, the continuous training data to
generate input data;
( c) training, by the computer, the ANN based on the input data and
a selected training algorithm to generate a trained ANN, wherein
the selected training algorithm includes a backpropagation
algorithm and a gradient descent algorithm;
(d) detecting one or more anomalies in a data set using the trained
ANN;
(e) analyzing the one or more detected anomalies using the trained
ANN to generate anomaly data; and
(f) outputting the anomaly data from the trained ANN.
Claim 2 of Example 4 7 is patent ineligible because the broadest reasonable interpretation of this claim is a method that receives continuous training data at a computer, uses the computer to discretize the continuous training data to generate input data, trains the neural network using the input data and a selected algorithm to detect and analyze anomalies in the data set using the trained network, and outputs the anomaly data from the trained network. The claimed discretizing, detecting, and analyzing steps encompass mental choices or evaluations, and the claimed discretizing and training using an algorithm encompasses performing mathematical calculations.
Here, pending claim 1 under its broadest reasonable interpretation is a similar method implemented on a computer to receive input data from a sensor, generate an input data set using the received data, sending the data set to a robustifier to remove perturbations (e.g. noise, errors) to create a modified data set, sending the modified data set to a pretrained learning task, training the robustifier with the modified data set, which may include adversarial training using a projected gradient descent (see use of gradient descent algorithm from claim 2, Example 4 7, above), and in response to a threshold, outputting the trained robustifier.
Like claim 2 of Example 47, pending claim 1 is patent ineligible because it recites a judicial exception, here the abstract idea of using certain mental processes that can be performed in the human mind, such as making observations, evaluations, judgements, or opinions about data using a computer, where the claim as a whole does not integrate the exception into a practical application and is thus directed to an abstract idea. Moreover, pending claim 1 does not provide "significantly more" than the judicial exception, i.e., pending claim 1 does not provide "an inventive concept."” (Decision, pages 9-11).
Next, applicant asserts, without pointing to claim language, but citing embodiments from the specification, that “the Specification states that the instant claims are related to certifying robustness in deep neural networks, including those with pre-trained classifiers. (Specification paragraph 3-6, and 22-24.) The instant Specification and claims thus describe a specific way that the machine learning network "eliminates the need for multiple queries per sample but may also provide better results than denoised smoothing." (Specification, at paragraph 24.) Even further, the practical application is highlighted that the instant invention has government support under DARPA. (Specification at paragraph 1.)” (Reply Br., page 3).
Applicant, then concludes, based on the above-noted portions of the specification, “Thus, the claims are geared to utilizing a machine learning task with training a robustifier by cleaning a generated input data set utilizing project gradient descent, which is a specific manner to train a robustifier and certify it. As such, and for the reasons already stated in the Appeal Brief, the claims are in condition for allowance.” Id.
Examiner’s Response:
Examiner respectfully disagrees with applicant’s assertions in the Reply Br. regarding the section 101 rejections and purported eligibility of the instant claims based on the cited portions of applicant’s specification.
Regarding the above-noted argument in the Reply Br, as discussed in the Final Action, no details of the “robustifier” or its training are recited in the claims, and the claimed robustifier is recited at a high level of generality and can be constructed by hand with pen and paper. The “robustifier”, under the broadest reasonable interpretation (BRI), in light of the specification, could be constructed and then modified/trained by hand with pen and paper based on a reasonable amount of observed data (i.e., the received “input data” and “modified input data set”). As further noted in the Final Action, “wherein the training may include adversarial training via projected gradient descent” recited in claims 1 and 8 (but not independent claim 14), as drafted, implies that the recited “adversarial training via projected gradient descent” is optional (“may include”) and no actual training of the generically-recited robustifier using “adversarial training via projected gradient descent” is positively recited in the claims. See, e.g., page 21 of the Final Action addressing these limitations of representative claim 1.
As detailed by the Patent Trial and Appeal Board in the Decision affirming the rejections of claims 1-20 under section 101 in the Final Action and regarding applicant’s arguments vis-à-vis the claimed robustifier, “Examiner noted, for example, that the recited "robustifier" of the pending claims "could be constructed and then modified/trained by hand with pen and paper based on a reasonable amount of observed data (i.e., the received 'input data' and 'modified input data set')." Final Act. 21. We agree with the Examiner.” (Decision, page 9).
As further noted in the Decision, “We agree with the Examiner's finding that the pending claims under their broadest reasonable interpretation are directed to an abstract idea because they recite activities that can be performed in the human mind using mental processes such as observation, evaluation, judgement, or opinion. For example, claim 1 recites "generate an input data set utilizing the input data, wherein the input data set includes perturbed data." We agree with the Examiner that this limitation is directed to an abstract idea because the activity of generating an input data set using input data, including perturbed data, is something that the human mind can do using observation, evaluation, and judgement, even with the assistance of simple tools such as a pencil and paper.” (Decision, pages 14-15).
As additionally detailed in the Decision, “We agree with the Examiner that the pending claims are ineligible because they are directed to the judicial exception of mental processes, and the claims as a whole do not integrate the exception into a practical application. As the Examiner points out, the limitations "computer-implemented method for training a machine-learning network," "wherein the robustifier is configured to clean the input data set by removing perturbations associated with the input data set to create a modified input data set," "training the robustifier to obtain a trained robustifier utilizing the modified input data set, wherein the training may include adversarial training via projected gradient descent” and “in response to convergence of the trained robustifier to a first threshold, output the trained robustifier," are instructions to apply the exception using the generically-recited machine-learning network.” See Final Act. 20-21. “We also agree with the Examiner that the recited "receiving an input data from a sensor, wherein the input data is indicative of image, radar, sonar, or sound information," "send the input data set to a robustifier," and "send the modified input data set to a pretrained machine learning task associated with a robustifier," amount to data gathering and transmitting, which are extra-solution activities that do not integrate a judicial exception into a practical application. (Decision, page 17).
For at least the reasons detailed in the Final Office Action mailed 12/02/2024 (hereinafter, “Final Action”), the Examiner's Answer mailed 7/9/2025 (hereinafter, “Ans.”) and the Decision on Appeal issued 6/24/2026 by the Patent Trial and Appeal Board Decision (hereinafter, “Decision”) the examiner disagrees with applicant’s above-noted assertions and allegations regarding the eligibility independent claims and the purported shortcomings of rejections of the claims under section 101.
Applicant's arguments in the Reply Br. with respect to the rejections of claims 1-20 under 35 U.S.C. 103 have been fully considered, but are not persuasive.
As discussed below, the rejections of claims 1-20 under 35 U.S.C. 103 remain and are being maintained.
With apparent reference to the robustifier recited in independent claims 1, 8 and 14 and the primary Ryu reference applied in the section 103 rejections, applicant acknowledges that “"none of the claims recite or require prepending a robustifier "to a machine learning task, such as a classifier", using the robustifier "to make a model or algorithm more robust against variations or outliers in data, such as noise, adversarial attacks, or unexpected deviations" or requires use of the robustifier for "making the model more resilient to noise or perturbations it may encounter during the training of inference."” (Reply Br., page 3).
Applicant then asserts “While it is true that the claims do not EXPLICITLY some these things, by the claimed invention focusing on a robustifier (rather than Ryu's denoiser), one of skill in the art understands these [sic – this] distinction of WHY the claimed robustifier is not a denoiser, let alone Ryu's denoiser.” (Id., emphasis in original).
With continued reference to Ryu, Applicant next asserts “Applicant's point simply emphasizes why Ryu's denoiser is not the same as the claimed trained robustifier which is accomplished by "send the input data set to a robustifier, wherein the robustifier is configured to clean the input data set by removing perturbations associated with the input data set to create a modified input data set; send the modified input data set to a pretrained machine learning task associated with a robustifier; training the robustifier to obtain a trained robustifier utilizing the modified input data set, wherein the training may include adversarial training via projected gradient descent." However, the claims also prepending the robustifier to a machine learning task since the claims explicitly require to "send the modified input data set to a pretrained machine learning task associated with a robustifier," which is thus absent in Ryu.” (Reply Br., pages 3-4).
With reference to Ryu and the secondary Behnia reference, applicant alleges, which Examiner does not concede, “Applicant makes the argument that references to the Specification support that Ryu's denoiser is the same as the claimed robustifier, but the Applicant has never ignored the Specification in its Appeal Brief (Examiner's Answer, pp. 22-23.) If anything, the Examiner's argument and the instant Specification support the Applicant's position, … While Applicant's Specification indeed explains that a denoiser can be utilized as a robustifier, the prior art of Ryu fails to show this, which is Applicant's argument. The prior art fails to make the model more resilient to noise or perturbations, and hence "training the robustifier."” before concluding “Examiner simply fails to show prior art that "trains the robustifier" and instead focuses on a references [sic - on references] (Ryu and Behnia) that either alone in combination train the network by focusing on training of the networks classifiers.” (Reply Br., page 4).
With reference to Ryu, Applicant generally alleges, which Examiner does not acquiesce to, “If Ryu truly trains the robustifier as claimed, why would the title focus on a system with a "Properly Trained Denoiser." ? This is the fundamental distinction that Applicant has made throughout the prosecution and appeal brief that the Examiner fails to appreciate, with respect to both the training of the robustifier as claimed and the prepending requirement of the robustifier. Even further, while the Applicant utilizes "BRI" to interpret the prior art, BRI is utilized in the context of claims and not the prior art Specification.” before concluding “As discussed, the claims are in condition for allowance.” (Reply Br, page 5, emphasis in original).
Examiner’s Response:
Examiner respectfully disagrees with applicant’s assertions in the Reply Br. regarding the section 103 rejections and purported novelty of the instant claims.
Examiner disagrees with applicant’s assertions in the Reply Br. vis-à-vis the purported distinctions between applicant’s characterization of the prior art and applicant’s claimed robustifier. As discussed below in the section 103 rejections of the independent claims, the recited “robustifier” has been interpreted as any combination of software and/or hardware capable of performing the claimed functions.
As detailed by the Patent Trial and Appeal Board in the Decision affirming the rejections of claims 1-20 under section 103 in the Final Action and regarding applicant’s arguments vis-à-vis the claimed robustifier, the denosier of Ryu and the applied combination of Ryu and Behnia, “First, with respect to Appellant's argument that "the Examiner conflates the term denoiser and robustifier," the Examiner points out that the Specification explains that "[a]ny image-to-image architecture could be utilized as a robustifier, such as ... image denoisers." Spec. ¶¶ 29, 44. Thus, Appellant's argument that denoisers and robustifiers are fundamentally different and that it is improper to use a prior art's teaching of a denoiser to meet a claim limitation reciting a robustifier is inconsistent with the express teachings of the Specification.” and “Second, we disagree with Appellant's argument that Ryu is "structurally and functionally different from the claimed invention" and does not meet the sequence of the recited limitations. Appeal Br. 13. Appellant's argument is misplaced because the Examiner uses the combined teachings of Ryu and Behina [sic – Behnia] to meet this limitation, not Ryu alone.” (Decision, page 19).
As noted in the Ans. regarding similar arguments presented in the Appeal Brief (and referenced and/or repeated in the Reply Br.), “many of Appellant’s arguments are directed to features not recited in the claims. In particular, when pointing out purported distinctions between the claimed robustifier and the denoiser in Ryu, Appellant alleges the “denoiser in the prior art is not prepended to a machine learning task, such as a classifier”, “a robustifier is utilized to make a model or algorithm more robust against variations or outliers in data, such as noise, adversarial attacks, or unexpected deviations” and “a robustifier focus on making the model more resilient to noise or perturbations it may encounter during training of inference.” Appeal Brief at 12-13. However, contrary to Appellant’s assertions, none of the claims recite or require prepending a robustifier “to a machine learning task, such as a classifier”, using the robustifier “to make a model or algorithm more robust against variations or outliers in data, such as noise, adversarial attacks, or unexpected deviations” or require use of the robustifier for “making the model more resilient to noise or perturbations it may encounter during training of inference.” (Ans., page 22).
As also detailed in the Ans. responding to similar arguments presented in the Appeal Brief (and referenced and/or repeated in the Reply Br.) regarding “arguments pointing out distinctions between the claimed robustifier and the denoiser of Ryu, Appellant acknowledges that “both concepts deal with noisy or corrupted data”. … Appellant then generally asserts that a “denoiser focus[es] on cleaning the data before it is fed into a model while a robustifier focus[es] on making the model more resilient to noise or perturbations it may encounter during training of inference.” … as noted in the Final Action, the instant specification discloses “Any image-to-image architecture could be utilized as a robustifier, such as a Variational Autoenecoder (VAEs), image denoisers, or semantic segmentation networks (e.g., U-Net style architecture)” and “Generally speaking, any image-to-image architecture could be used as the robustifier, such as Variational Autoencoders (VAEs), image denoisers, or semantic segmentation networks (we will ultimately use a U-Net style architecture for this task).” (See, specification, paragraphs 29 and 44 – emphasis added). That is, contrary to Appellant’s apparent argument that conflating “the term denoiser and robustifier” is erroneous … Appellant’s own specification discloses that these terms are somewhat interchangeable. As such, … Ryu’s denoising model corresponds to a robustifier that removes perturbations (noises) from a sent (given) data set to create a modified (clean) data set (See, e.g., pages 54-55 of the Final Action, addressing robustifier limitations of representative claim 1). Further … none of the alleged and relied-upon distinctive features of the robustifier are actually recited in the pending claims.” (Ans., pages 22-23).
All arguments are addressed in the 35 U.S.C. 103 rejections of the claims below.
For at least the reasons detailed in the Final Office, the Ans. and the Decision, the examiner disagrees with applicant’s above-noted assertions and allegations regarding the independent claims and the purported shortcomings of the cited references.
Drawings
The drawings are objected to as failing to comply with 37 CFR 1.84(p)(4) because reference character “100” has been used to designate a “system 100 for training a neural network” (See, e.g., Specification, [0025]), but is also shown in Fig. 7 as a “manufacturing machine” (See, e.g., Fig. 7 and [0088]). Reference number “200” has been used to designate a “computer-implemented method 200 for training a neural network” (See, e.g., [0011]), but is also shown in Fig. 9 as an “automated personal assistant” (See Fig. 9, [0092]). Reference number “300” has been used to designate a “data annotation system 300” (See, e.g., [0012]), but also appears in Fig. 11 as an “imaging system” (Compare Fig. 11 and [0098]).
The drawings are also objected to as failing to comply with 37 CFR 1.84(p)(5) because they do not include the following reference signs mentioned in the description: 900, 902, 904, 1100 (see, paragraphs [0093]- [0094] describing FIG. 9).
The drawings are further objected to as failing to comply with 37 CFR 1.84(p)(5) because they include the following reference characters not mentioned in the description: 202, 204 (see, reference characters 202 and 204 in FIG. 9).
Corrected drawing sheets in compliance with 37 CFR 1.121(d) are required in reply to the Office action to avoid abandonment of the application. Any amended replacement drawing sheet should include all of the figures appearing on the immediate prior version of the sheet, even if only one figure is being amended. The figure or figure number of an amended drawing should not be labeled as “amended.” If a drawing figure is to be canceled, the appropriate figure must be removed from the replacement sheet, and where necessary, the remaining figures must be renumbered and appropriate changes made to the brief description of the several views of the drawings for consistency. Additional replacement sheets may be necessary to show the renumbering of the remaining figures. Each drawing sheet submitted after the filing date of an application must be labeled in the top margin as either “Replacement Sheet” or “New Sheet” pursuant to 37 CFR 1.121(d). If the changes are not accepted by the examiner, the applicant will be notified and informed of any required corrective action in the next Office action. The objection to the drawings will not be held in abeyance.
Specification
The disclosure is objected to because of the following informalities:
Reference characters 202 and 204 shown in Figure 9 are not described in applicant’s specification (see, e.g., paragraphs [0092]-[0094] describing FIG. 9).
Appropriate correction is required.
Claim Objections
Claims 1-13 are objected to because of the following informalities:
As noted in the Final Action, independent claim 1 recites “send the modified input data set to a pretrained machine learning task associated with a robustifier” (see, lines 10-11 of claim 1). This claim previously introduced “send the input data set to a robustifier, wherein the robustifier is configured to clean the input data” (see, lines 7-8 of claim 1). As such, it appears that the subsequent recitation of “a robustifier” should read “[[a]] the robustifier”. Appropriate correction is required.
Lines 2-3 of dependent claim 3 recite “wherein the machine learning network includes an optimizer includes a stochastic gradient descent optimizer”. This recitation is grammatically incorrect and should read “wherein the machine learning network includes an optimizer including , which includes a stochastic gradient descent optimizer …”. Appropriate correction is required.
In the amendment filed 10/29/2024, the status identifier for claim 4 indicates “Original”. However, this claim was amended in the 10/29/2024 amendment. As such, the status identifier for claim 4 should have been “Currently Amended”. Appropriate correction is required.
The penultimate operation/step of independent claim 8 recites “gradient descent;;” (see, line 17 of claim 8). This recitation contains a typographical error and “gradient descent;;” should read “gradient descent;[[;]]”. Appropriate correction is required.
Also, claims 2-7 and 9-13, which depend directly from claims 1 and 8, respectively, are objected to based on their respective dependencies from claims 1 and 8.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. The analysis below of the claims’ subject matter eligibility follows the 2019 Revised Patent Subject Matter Eligibility Guidance, 84 Fed. Reg. 50-57 (January 7, 2019) (“2019 PEG”) and the 2024 Guidance Update on Patent Subject Matter Eligibility, Including on Artificial Intelligence, 89 Fed. Reg. 58128-58138 (July 17, 2024) (“2024 AI SME Update”).
When considering subject matter eligibility under 35 U.S.C. 101, it must be determined whether the claim is directed to one of the four statutory categories of invention, i.e., process, machine, manufacture, or composition of matter (Step 1). If the claim does fall within one of the statutory categories, the second step in the analysis is to determine whether the claim is directed to a judicial exception (Step 2A). The Step 2A analysis is broken into two prongs. In the first prong (Step 2A, Prong 1), it is determined whether or not the claims recite a judicial exception (e.g., mathematical concepts, mental processes, certain methods of organizing human activity). If it is determined in Step 2A, Prong 1 that the claims recite a judicial exception, the analysis proceeds to the second prong (Step 2A, Prong 2), where it is determined whether or not the claims integrate the judicial exception into a practical application. If it is determined at step 2A, Prong 2 that the claims do not integrate the judicial exception into a practical application, the analysis proceeds to determining whether the claim is a patent-eligible application of the exception (Step 2B). If an abstract idea is present in the claim, any element or combination of elements in the claim must be sufficient to ensure that the claim integrates the judicial exception into a practical application, or else amounts to significantly more than the abstract idea itself.
Regarding independent claim 1, this claim is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Step 1 Analysis: Claim 1 is directed to a method, corresponding to a process, one of the statutory categories.
Step 1 Analysis: Claim 1 is directed to a method, i.e., a process, one of the statutory categories.
Step 2A Prong One Analysis: The limitation:
• “generate an input data set utilizing the input data, wherein the input data set includes perturbed data”
As drafted, under its broadest reasonable interpretation, covers concepts performed in the human mind (including an observation, evaluation, judgement, or opinion, e.g., generating a data set based on observed input data). The above limitation in the context of this claim encompasses, inter alia, generating a data set including perturbed data (corresponding to mental processes which can be done mentally or by pen and paper).
Step 2A Prong Two Analysis: The judicial exceptions are not integrated into a practical application.
The limitations:
• “A computer-implemented method for training a machine-learning network”
• “wherein the robustifier is configured to clean the input data1 set by removing perturbations associated with the input data set to create a modified input data set”
• “training the robustifier to obtain a trained robustifier utilizing the modified input data set, wherein the training may include adversarial training via projected gradient descent”
• “in response to convergence of the trained robustifier to a first threshold, output the trained robustifier”
As drafted, are additional elements that amount to no more than mere instructions to apply the exception for the abstract ideas. See MPEP 2106.05(f). Specifically, they amount to mere instructions to apply the exception using the generically-recited machine-learning network (e.g., by using this element as a tool).
Regarding the “robustifier”, no details of the robustifier or its training are recited, and the robustifier is recited at a high level of generality and can be constructed by hand with pen and paper. The generically-recited “robustifier” has been interpreted as any combination of software and/or hardware capable of performing the claimed functions. The “robustifier”, under the broadest reasonable interpretation (BRI), in light of the specification, could be constructed and then modified/trained by hand with pen and paper based on a reasonable amount of observed data (i.e., the received “input data” and “modified input data set”). Further, “wherein the training may include adversarial training via projected gradient descent”, as drafted, implies that the recited “adversarial training via projected gradient descent” is optional (“may include”) and no actual training of the generically-recited robustifier using “adversarial training via projected gradient descent” is positively recited.
The limitations:
• “receiving an input data from a sensor, wherein the input data is indicative of image, radar, sonar, or sound information”
• “send the input data set to a robustifier”
• “send the modified input data set to a pretrained machine learning task associated with a robustifier2”
As drafted, amount to insignificant extra-solution activities, which do not integrate a judicial exception into a practical application. In particular, the additional elements of “receiving an input data from a sensor, wherein the input data is indicative of image, radar, sonar, or sound information”, “send the input data set to a robustifier” and “send the modified input data set to a pretrained machine learning task associated with a robustifier” amount to mere data gathering and transmitting, which are insignificant extra-solution activities that do not integrate a judicial exception into a practical application. See MPEP 2106.05(g). That is, these limitations are adding insignificant extra-solution activity (amount to necessary data gathering) to the judicial exception, as discussed in MPEP § 2106.05(g).
Also, the “output the trained robustifier” limitation is adding insignificant extra-solution activity (amounts to necessary data outputting) to the judicial exception, as discussed in MPEP § 2106.05(g).
Step 2B Analysis: The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception.
As discussed above with respect to integration of the abstract idea into a practical application, all of the additional elements mere instructions to apply an exception (i.e., the additional element describes a unit for applying the abstract ideas) or insignificant extra-solution activities. Mere instructions to apply an exception and insignificant extra-solution activities cannot provide an inventive concept.
The above noted “receiving an input data from a sensor, wherein the input data is indicative of image, radar, sonar, or sound information” limitation is adding insignificant extra-solution activity (amount to necessary data gathering) to the judicial exception, as discussed in MPEP § 2106.05(g).
The above noted “output the trained robustifier” limitation is adding insignificant extra-solution activity (amounts to necessary data outputting) to the judicial exception, as discussed in MPEP § 2106.05(g).
Moreover, receiving, communicating, and storing data are insignificant extra-solution activities that are well-understood, routine, and conventional. See MPEP2106.05(d)(II) (“The courts have recognized the following computer functions as well‐understood, routine, and conventional functions… i. Receiving or transmitting data over a network…iv. Storing and retrieving information in memory”) (citing OIP Techs., Inc., v. Amazon.com, Inc., 788 F.3d 1359, 1363, 115 USPQ2d 1090, 1093 (Fed. Cir. 2015)). Therefore, recitations of “receiving an input data from a sensor, wherein the input data is indicative of image, radar, sonar, or sound information”, “send the input data set to a robustifier”, “send the modified input data set to a pretrained machine learning task associated with a robustifier” and “output the trained robustifier” are the well-understood, routine, conventional activities of receiving or transmitting data over a network, as discussed in MPEP § 2106.05(d).
The claim is not patent eligible.
Regarding Claim 2,
Claim 2 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Step 1 Analysis: Claim 2 is directed to a method, i.e., a process, one of the statutory categories. Claim 2 is directed to a method as depending from claim 1, thus the analysis for patent eligibility of claim 1 is incorporated herein.
Step 2A Prong One Analysis: Please see corresponding analysis of Claim 1.
Step 2A Prong Two Analysis: The judicial exceptions are not integrated into a practical application.
The limitation:
• “the machine learning task includes a classifier, an object detector, a semantic segmentation, or speech recognition”
As drafted, is an additional element that amounts to no more than an additional limitation which does not meaningfully limit the judicial exception. See MPEP 2106.05(e). Specifically, the claim recites “the machine learning task includes a classifier, an object detector, a semantic segmentation, or speech recognition”, which is simply additional information regarding the characteristics of the task; the element does not apply the exception in a meaningful way (MPEP 2106.05(e)). Therefore, the additional element does not integrate the abstract ideas into a practical application.
Step 2B Analysis: The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional element represents an additional limitation which does not meaningfully limit the judicial exception. Additional limitations which do not meaningfully limit the judicial exception cannot provide an inventive concept. The claim is not patent eligible.
Regarding Claim 3,
Claim 3 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Step 1 Analysis: Claim 3 is directed to a method, i.e., a process, one of the statutory categories. Claim 3 is directed to a method as depending from claim 1, thus the analysis for patent eligibility of claim 1 is incorporated herein.
Step 2A Prong One Analysis: Please see corresponding analysis of Claim 1.
Step 2A Prong Two Analysis: The judicial exceptions are not integrated into a practical application.
The limitation:
• “wherein the machine learning network includes an optimizer includes a stochastic gradient descent optimizer, or an adaptive optimizer3”
As drafted, is an additional element that amounts to no more than an additional limitation which does not meaningfully limit the judicial exception. See MPEP 2106.05(e). Specifically, the claim recites “an optimizer includes a stochastic gradient descent optimizer, or an adaptive optimizer”, which is simply additional information regarding the characteristics of the optimizer; the element does not apply the exception in a meaningful way (MPEP 2106.05(e)). Therefore, the additional element does not integrate the abstract ideas into a practical application.
Step 2B Analysis: The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional element represents an additional limitation which does not meaningfully limit the judicial exception. Additional limitations which do not meaningfully limit the judicial exception cannot provide an inventive concept. The claim is not patent eligible.
Regarding Claim 4,
Claim 4 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Step 1 Analysis: Claim 4 is directed to a method, i.e., a process, one of the statutory categories. Claim 4 is directed to a method as depending from claim 1, thus the analysis for patent eligibility of claim 1 is incorporated herein.
Step 2A Prong One Analysis: Please see corresponding analysis of Claim 1.
Step 2A Prong Two Analysis: The judicial exceptions are not integrated into a practical application.
The limitation:
• “wherein paired cleaned-perturbed data are sent to the robustifier in parallel”
As drafted, is an additional element that amounts to no more than an additional limitation which does not meaningfully limit the judicial exception. See MPEP 2106.05(e). Specifically, the claim recites “the paired cleaned-perturbed data are sent to the robustifier in parallel”, which is simply additional information regarding the characteristics of the data transmission; the element does not apply the exception in a meaningful way (MPEP 2106.05(e)). Therefore, the additional element does not integrate the abstract ideas into a practical application.
Step 2B Analysis: The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional element represents an additional limitation which does not meaningfully limit the judicial exception. Additional limitations which do not meaningfully limit the judicial exception cannot provide an inventive concept. The claim is not patent eligible.
Regarding Claim 5,
Claim 5 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Step 1 Analysis: Claim 5 is directed to a method, i.e., a process, one of the statutory categories. Claim 5 is directed to a method as depending from claim 1, thus the analysis for patent eligibility of claim 1 is incorporated herein.
Step 2A Prong One Analysis: Please see corresponding analysis of Claim 1.
Step 2A Prong Two Analysis: The judicial exceptions are not integrated into a practical application.
The limitation:
• “the first threshold includes an amount of loss of the input data”
As drafted, is an additional element that amounts to no more than an additional limitation which does not meaningfully limit the judicial exception. See MPEP 2106.05(e). Specifically, the claim recites “the first threshold includes an amount of loss of the input data”, which is simply additional information regarding the characteristics of the threshold; the element does not apply the exception in a meaningful way (MPEP 2106.05(e)). Therefore, the additional element does not integrate the abstract ideas into a practical application.
Step 2B Analysis: The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional element represents an additional limitation which does not meaningfully limit the judicial exception. Additional limitations which do not meaningfully limit the judicial exception cannot provide an inventive concept. The claim is not patent eligible.
Regarding Claim 6,
Claim 6 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Step 1 Analysis: Claim 6 is directed to a method, i.e., a process, one of the statutory categories. Claim 6 is directed to a method as depending from claim 1, thus the analysis for patent eligibility of claim 1 is incorporated herein.
Step 2A Prong One Analysis: Please see corresponding analysis of Claim 1.
Step 2A Prong Two Analysis: The judicial exceptions are not integrated into a practical application.
The limitation:
• “the perturbed data is generated utilizing a projected gradient descent attack”
As drafted, is an additional element that amounts to no more than an additional limitation which does not meaningfully limit the judicial exception. See MPEP 2106.05(e). Specifically, the claim recites “the perturbed data is generated utilizing a projected gradient descent attack”, which is simply additional information regarding the characteristics of the data; the element does not apply the exception in a meaningful way (MPEP 2106.05(e)). Therefore, the additional element does not integrate the abstract ideas into a practical application.
Step 2B Analysis: The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional element represents an additional limitation which does not meaningfully limit the judicial exception. Additional limitations which do not meaningfully limit the judicial exception cannot provide an inventive concept. The claim is not patent eligible.
Regarding Claim 7,
Claim 7 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Step 1 Analysis: Claim 7 is directed to a method, i.e., a process, one of the statutory categories. Claim 7 is directed to a method as depending from claim 1, thus the analysis for patent eligibility of claim 1 is incorporated herein.
Step 2A Prong One Analysis: Please see corresponding analysis of Claim 1.
Step 2A Prong Two Analysis: The judicial exceptions are not integrated into a practical application.
The limitation:
• “the input data includes video information obtained from a camera”
As drafted, is an additional element that amounts to no more than an additional limitation which does not meaningfully limit the judicial exception. See MPEP 2106.05(e). Specifically, the claim recites “the input data includes video information obtained from a camera”, which is simply additional information regarding the characteristics of the data; the element does not apply the exception in a meaningful way (MPEP 2106.05(e)). Therefore, the additional element does not integrate the abstract ideas into a practical application.
Step 2B Analysis: The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional element represents an additional limitation which does not meaningfully limit the judicial exception. Additional limitations which do not meaningfully limit the judicial exception cannot provide an inventive concept. The claim is not patent eligible.
Regarding Independent Claim 8,
Claim 8 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Step 1 Analysis: Claim 8 is directed to a system, i.e., a machine, one of the statutory categories.
Step 2A Prong One Analysis: The limitation:
• “generate an input data set utilizing the input data, wherein the input data set includes perturbed data”
As drafted, under its broadest reasonable interpretation, covers concepts performed in the human mind (including an observation, evaluation, judgement, or opinion, e.g., generating a data set based on observed input data). The above limitation in the context of this claim encompasses, inter alia, generating a data set including perturbed data (corresponding to mental processes which can be done mentally or by pen and paper).
Step 2A Prong Two Analysis: The judicial exceptions are not integrated into a practical application.
The limitations:
• “a system including a machine-learning network”
• “an input interface configured to receive input data from a sensor, wherein the sensor includes a camera, a radar, a sonar, or a microphone”
• “a processor, in communication with the input interface, wherein the processor is programmed to”
• “wherein the robustifier is configured to clean the input data4 set by removing perturbations associated with the input data set to create a modified input data set”
• “train the robustifier utilizing the modified input data set to obtain a trained robustifier, wherein the training of the robustifier includes adversarial training via projected gradient descent”
• “output the trained robustifier and the machine learning task in response to convergence to a first threshold”
As drafted, are additional elements that amount to no more than mere instructions to apply the exception for the abstract ideas. See MPEP 2106.05(f). Specifically, they amount to mere instructions to apply the exception using the system (e.g., by using this element as a tool).
Regarding the “robustifier”, no details of the robustifier or its training are recited, and the robustifier is recited at a high level of generality and can be constructed by hand with pen and paper. As discussed above, the generically-recited “robustifier” has been interpreted as any combination of software and/or hardware capable of performing the claimed functions. The “robustifier”, under the BRI, in light of the specification, could be constructed and then modified/trained by hand with pen and paper based on a reasonable amount of observed data (i.e., the received “input data” and “modified input data set”).
The limitations:
• “receive the input data, wherein the input data is indicative of image, radar, sonar, or sound information”
• “send the input data set to a robustifier”
• “send the modified input data set to a machine learning task”
As drafted, amounts to insignificant extra-solution activities, which do not integrate a judicial exception into a practical application. In particular, the additional elements of “receive the input data, wherein the input data is indicative of image, radar, sonar, or sound information”, “send the input data set to a robustifier” and “send the modified input data set to a machine learning task” amount to mere data gathering and transmitting, which are insignificant extra-solution activities that do not integrate a judicial exception into a practical application. See MPEP 2106.05(g). That is, these limitations are adding insignificant extra-solution activity (amount to necessary data gathering) to the judicial exception, as discussed in MPEP § 2106.05(g).
Also, the “output the trained robustifier” limitation is adding insignificant extra-solution activity (amounts to necessary data outputting) to the judicial exception, as discussed in MPEP § 2106.05(g).
Step 2B Analysis: The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception.
As discussed above with respect to integration of the abstract idea into a practical application, all of the additional elements mere instructions to apply an exception (i.e., the additional element describes a unit for applying the abstract ideas) or insignificant extra-solution activities. Mere instructions to apply an exception and insignificant extra-solution activities cannot provide an inventive concept.
The above noted “receive the input data, wherein the input data is indicative of image, radar, sonar, or sound information” limitation is adding insignificant extra-solution activity (amount to necessary data gathering) to the judicial exception, as discussed in MPEP § 2106.05(g).
The above noted “output the trained robustifier” limitation is adding insignificant extra-solution activity (amounts to necessary data outputting) to the judicial exception, as discussed in MPEP § 2106.05(g).
Moreover, receiving, communicating, and storing data are insignificant extra-solution activities that are well-understood, routine, and conventional. See MPEP2106.05(d)(II) (“The courts have recognized the following computer functions as well‐understood, routine, and conventional functions… i. Receiving or transmitting data over a network…iv. Storing and retrieving information in memory”) (citing OIP Techs., Inc., v. Amazon.com, Inc., 788 F.3d 1359, 1363, 115 USPQ2d 1090, 1093 (Fed. Cir. 2015)). Therefore, recitations of “receive the input data, wherein the input data is indicative of image, radar, sonar, or sound information”, “send the input data set to a robustifier”, “send the modified input data set to a machine learning task” and “output the trained robustifier” are the well-understood, routine, conventional activities of receiving or transmitting data over a network, as discussed in MPEP § 2106.05(d).
The claim is not patent eligible.
Regarding Claim 9,
Claim 9 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Step 1 Analysis: Claim 9 is directed to a system, i.e., a machine, one of the statutory categories. Claim 9 is directed to a system as depending from claim 8, thus the analysis for patent eligibility of claim 8 is incorporated herein.
Step 2A Prong One Analysis: The limitation:
• “randomly sample a base classifier”
As drafted, under its broadest reasonable interpretation, covers concepts performed in the human mind (including an observation, evaluation, judgement, or opinion, e.g., sampling data). The above limitation in the context of this claim encompasses, inter alia, randomly sampling data (corresponding to mental processes which can be done mentally or by pen and paper based on observed classifications from the generically-recited “base classifier”).
Regarding the “base classifier”, no details of the classifier or its training are recited, and the classifier is recited at a high level of generality and can be constructed by hand with pen and paper. The “base classifier”, under the BRI, in light of the specification, could be constructed by hand with pen and paper based on a reasonable amount of observed data (i.e., the received “input data”).
Step 2A Prong Two Analysis: Please see corresponding analysis of Claim 8.
Step 2B Analysis: The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. The claim is not patent eligible.
Regarding Claim 10,
Claim 10 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Step 1 Analysis: Claim 10 is directed to a system, i.e., a machine, one of the statutory categories. Claim 10 is directed to a system as depending from claim 8, thus the analysis for patent eligibility of claim 8 is incorporated herein.
Step 2A Prong One Analysis: Please see corresponding analysis of Claim 8.
Step 2A Prong Two Analysis: The judicial exceptions are not integrated into a practical application.
The limitation:
• “the input data set includes perturbed data, wherein the perturbed data is generated utilizing a projected gradient descent attack”
As drafted, is an additional element that amounts to no more than an additional limitation which does not meaningfully limit the judicial exception. See MPEP 2106.05(e). Specifically, the claim recites “the input data set includes perturbed data, wherein the perturbed data is generated utilizing a projected gradient descent attack”, which is simply additional information regarding the characteristics of the data; the element does not apply the exception in a meaningful way (MPEP 2106.05(e)). Therefore, the additional element does not integrate the abstract ideas into a practical application.
Step 2B Analysis: The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional element represents an additional limitation which does not meaningfully limit the judicial exception. Additional limitations which do not meaningfully limit the judicial exception cannot provide an inventive concept. The claim is not patent eligible.
Regarding Claim 11,
Claim 11 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Step 1 Analysis: Claim 11 is directed to a system, i.e., a machine, one of the statutory categories. Claim 11 is directed to a system as depending from claim 8, thus the analysis for patent eligibility of claim 8 is incorporated herein.
Step 2A Prong One Analysis: Please see corresponding analysis of Claim 8.
Step 2A Prong Two Analysis: The judicial exceptions are not integrated into a practical application.
The limitation:
• “the perturbed data set is computer-generated data corresponding to a clean data set”
As drafted, is an additional element that amounts to no more than an additional limitation which does not meaningfully limit the judicial exception. See MPEP 2106.05(e). Specifically, the claim recites “the perturbed data set is computer-generated data corresponding to a clean data set”, which is simply additional information regarding the characteristics of the data; the element does not apply the exception in a meaningful way (MPEP 2106.05(e)). Therefore, the additional element does not integrate the abstract ideas into a practical application.
Step 2B Analysis: The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional element represents an additional limitation which does not meaningfully limit the judicial exception. Additional limitations which do not meaningfully limit the judicial exception cannot provide an inventive concept. The claim is not patent eligible.
Regarding Claim 12,
Claim 12 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Step 1 Analysis: Claim 12 is directed to a system, i.e., a machine, one of the statutory categories. Claim 12 is directed to a system as depending from claim 8, thus the analysis for patent eligibility of claim 8 is incorporated herein.
Step 2A Prong One Analysis: Please see corresponding analysis of Claim 8.
Step 2A Prong Two Analysis: The judicial exceptions are not integrated into a practical application.
The limitation:
• “the machine learning task is training a deep neural network”
As drafted, is an additional element that amounts to no more than an additional limitation which does not meaningfully limit the judicial exception. See MPEP 2106.05(e). Specifically, the claim recites “the machine learning task is training a deep neural network”, which is simply additional information regarding the characteristics of the task; the element does not apply the exception in a meaningful way (MPEP 2106.05(e)). Therefore, the additional element does not integrate the abstract ideas into a practical application.
Regarding the “deep neural network”, no details of the neural network or its training are recited, and the network is recited at a high level of generality and can be constructed by hand with pen and paper. The “deep neural network”, under the BRI, in light of the specification, could be constructed and then modified/trained by hand with pen and paper based on a reasonable amount of observed data (i.e., the received “input data” and “modified input data set”).
Step 2B Analysis: The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional element represents an additional limitation which does not meaningfully limit the judicial exception. Additional limitations which do not meaningfully limit the judicial exception cannot provide an inventive concept. The claim is not patent eligible.
Regarding Claim 13,
Claim 13 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Step 1 Analysis: Claim 13 is directed to a system, i.e., a machine, one of the statutory categories. Claim 13 is directed to a system as depending from claim 8, thus the analysis for patent eligibility of claim 8 is incorporated herein.
Step 2A Prong One Analysis: Please see corresponding analysis of Claim 8.
Step 2A Prong Two Analysis: The judicial exceptions are not integrated into a practical application.
The limitation:
• “the machine learning task includes a classifier, an object detector, a semantic segmentation, or speech recognition”
As drafted, is an additional element that amounts to no more than an additional limitation which does not meaningfully limit the judicial exception. See MPEP 2106.05(e). Specifically, the claim recites “the machine learning task includes a classifier, an object detector, a semantic segmentation, or speech recognition”, which is simply additional information regarding the characteristics of the task; the element does not apply the exception in a meaningful way (MPEP 2106.05(e)). Therefore, the additional element does not integrate the abstract ideas into a practical application.
Step 2B Analysis: The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional element represents an additional limitation which does not meaningfully limit the judicial exception. Additional limitations which do not meaningfully limit the judicial exception cannot provide an inventive concept. The claim is not patent eligible.
Regarding Claim 14,
Claim 14 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Step 1 Analysis: Claim 14 is directed to a computer program product, corresponding to an article of manufacture, one of the statutory categories.
Step 2A Prong One Analysis: The limitation:
• “generate an input data set utilizing the input data, wherein the input data set includes perturbed data”
As drafted, under its broadest reasonable interpretation, covers concepts performed in the human mind (including an observation, evaluation, judgement, or opinion, e.g., generating a data set based on observed input data). The above limitation in the context of this claim encompass, inter alia, generating a data set including certain data (corresponding to mental processes which can be done mentally or by pen and paper).
Step 2A Prong Two Analysis: The judicial exceptions are not integrated into a practical application.
The limitations:
• “A computer-program product storing instructions which, when executed by a computer, cause the computer to”
• “wherein the robustifier is configured to clean the input data5 set by removing perturbations associated with the input data set to create a modified input data set”
• “train the robustifier utilizing the modified input data set”
• “output a trained robustifier upon convergence to a first threshold”
As drafted, are additional elements that amount to no more than mere instructions to apply the exception for the abstract ideas. See MPEP 2106.05(f). Specifically, they amount to mere instructions to apply the exception using the network (e.g., by using this element as a tool).
Regarding the “robustifier”, no details of the robustifier or its training are recited, and the robustifier is recited at a high level of generality and can be constructed by hand with pen and paper. As discussed above, the generically-recited “robustifier” has been interpreted as any combination of software and/or hardware capable of performing the claimed functions. The “robustifier”, under the BRI, in light of the specification, could be constructed and then modified/trained by hand with pen and paper based on a reasonable amount of observed data (i.e., the received “input data” and “modified input data set”).
The limitations:
• “receive an input data from a sensor, wherein the sensor includes a camera, a radar, a sonar, or a microphone”
• “send the input data set to a robustifier”
• “send the modified input data set to a pretrained machine learning task”
As drafted, amounts to insignificant extra-solution activities, which do not integrate a judicial exception into a practical application. In particular, the additional elements of “receive an input data from a sensor, wherein the sensor includes a camera, a radar, a sonar, or a microphone”, “send the input data set to a robustifier” and “send the modified input data set to a pretrained machine learning task” amount to mere data gathering and transmitting, which are insignificant extra-solution activities that do not integrate a judicial exception into a practical application. See MPEP 2106.05(g). That is, these limitations are adding insignificant extra-solution activity (amount to necessary data gathering) to the judicial exception, as discussed in MPEP § 2106.05(g).
Also, the “output the trained robustifier” limitation is adding insignificant extra-solution activity (amounts to necessary data outputting) to the judicial exception, as discussed in MPEP § 2106.05(g).
Step 2B Analysis: The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception.
As discussed above with respect to integration of the abstract idea into a practical application, all of the additional elements mere instructions to apply an exception (i.e., the additional element describes a unit for applying the abstract ideas) or insignificant extra-solution activities. Mere instructions to apply an exception and insignificant extra-solution activities cannot provide an inventive concept.
The above noted “receive an input data from a sensor, wherein the sensor includes a camera, a radar, a sonar, or a microphone” limitation is adding insignificant extra-solution activity (amount to necessary data gathering) to the judicial exception, as discussed in MPEP § 2106.05(g).
The above noted “output the trained robustifier” limitation is adding insignificant extra-solution activity (amounts to necessary data outputting) to the judicial exception, as discussed in MPEP § 2106.05(g).
Moreover, receiving, communicating, and storing data are insignificant extra-solution activities that are well-understood, routine, and conventional. See MPEP2106.05(d)(II) (“The courts have recognized the following computer functions as well‐understood, routine, and conventional functions… i. Receiving or transmitting data over a network…iv. Storing and retrieving information in memory”) (citing OIP Techs., Inc., v. Amazon.com, Inc., 788 F.3d 1359, 1363, 115 USPQ2d 1090, 1093 (Fed. Cir. 2015)). Therefore, recitations of ““receive an input data from a sensor, wherein the sensor includes a camera, a radar, a sonar, or a microphone”, “send the input data set to a robustifier”, “send the modified input data set to a pretrained machine learning task” and “output the trained robustifier” are the well-understood, routine, conventional activities of receiving or transmitting data over a network, as discussed in MPEP § 2106.05(d).
The claim is not patent eligible.
Regarding Claim 15,
Claim 15 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Step 1 Analysis: Claim 15 is directed to a computer program product, i.e., a manufacture, one of the statutory categories. Claim 15 is directed to a computer program product as depending from claim 14, thus the analysis for patent eligibility of claim 14 is incorporated herein.
Step 2A Prong One Analysis: Please see corresponding analysis of Claim 14.
Step 2A Prong Two Analysis: The judicial exceptions are not integrated into a practical application.
The limitation:
• “the input data includes an image received from the camera in communication with the computer”
As drafted, is an additional element that amounts to no more than an additional limitation which does not meaningfully limit the judicial exception. See MPEP 2106.05(e). Specifically, the claim recites “the input data includes an image received from the camera in communication with the computer”, which is simply additional information regarding the characteristics of the input data; the element does not apply the exception in a meaningful way (MPEP 2106.05(e)). Therefore, the additional element does not integrate the abstract ideas into a practical application.
Step 2B Analysis: The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional element represents an additional limitation which does not meaningfully limit the judicial exception. Additional limitations which do not meaningfully limit the judicial exception cannot provide an inventive concept. The claim is not patent eligible.
Regarding Claim 16,
Claim 16 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Step 1 Analysis: Claim 16 is directed to a computer program product, i.e., a manufacture, one of the statutory categories. Claim 16 is directed to a computer program product as depending from claim 14, thus the analysis for patent eligibility of claim 14 is incorporated herein.
Step 2A Prong One Analysis: Please see corresponding analysis of Claim 14.
Step 2A Prong Two Analysis: The judicial exceptions are not integrated into a practical application.
The limitation:
• “the computer includes instructions that cause the computer to output the trained robustifier in response to a single forward pass”
As drafted, is an additional element that amounts to no more than an additional limitation which does not meaningfully limit the judicial exception. See MPEP 2106.05(e). Specifically, the claim recites “the computer includes instructions that cause the computer to output the trained robustifier in response to a single forward pass”, which is simply additional information regarding the characteristics of the output; the element does not apply the exception in a meaningful way (MPEP 2106.05(e)). Therefore, the additional element does not integrate the abstract ideas into a practical application.
Step 2B Analysis: The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional element represents an additional limitation which does not meaningfully limit the judicial exception. Additional limitations which do not meaningfully limit the judicial exception cannot provide an inventive concept. The claim is not patent eligible.
Regarding Claim 17,
Claim 17 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Step 1 Analysis: Claim 17 is directed to a computer program product, i.e., a manufacture, one of the statutory categories. Claim 17 is directed to a computer program product as depending from claim 14, thus the analysis for patent eligibility of claim 14 is incorporated herein.
Step 2A Prong One Analysis: Please see corresponding analysis of Claim 14.
Step 2A Prong Two Analysis: The judicial exceptions are not integrated into a practical application.
The limitation:
• “the machine learning task includes a classifier, an object detector, a semantic segmentation, or speech recognition”
As drafted, is an additional element that amounts to no more than an additional limitation which does not meaningfully limit the judicial exception. See MPEP 2106.05(e). Specifically, the claim recites “the machine learning task includes a classifier, an object detector, a semantic segmentation, or speech recognition”, which is simply additional information regarding the characteristics of the task; the element does not apply the exception in a meaningful way (MPEP 2106.05(e)). Therefore, the additional element does not integrate the abstract ideas into a practical application.
Step 2B Analysis: The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional element represents an additional limitation which does not meaningfully limit the judicial exception. Additional limitations which do not meaningfully limit the judicial exception cannot provide an inventive concept. The claim is not patent eligible.
Regarding Claim 18,
Claim 18 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Step 1 Analysis: Claim 18 is directed to a computer program product, i.e., a manufacture, one of the statutory categories. Claim 18 is directed to a computer program product as depending from claim 14, thus the analysis for patent eligibility of claim 14 is incorporated herein.
Step 2A Prong One Analysis: Please see corresponding analysis of Claim 14.
Step 2A Prong Two Analysis: The judicial exceptions are not integrated into a practical application.
The limitation:
• “the input data set includes perturbed data, wherein the perturbed data is generated utilizing a projected gradient descent attack”
As drafted, is an additional element that amounts to no more than an additional limitation which does not meaningfully limit the judicial exception. See MPEP 2106.05(e). Specifically, the claim recites “the input data set includes perturbed data, wherein the perturbed data is generated utilizing a projected gradient descent attack”, which is simply additional information regarding the characteristics of the data; the element does not apply the exception in a meaningful way (MPEP 2106.05(e)). Therefore, the additional element does not integrate the abstract ideas into a practical application.
Step 2B Analysis: The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional element represents an additional limitation which does not meaningfully limit the judicial exception. Additional limitations which do not meaningfully limit the judicial exception cannot provide an inventive concept. The claim is not patent eligible.
Regarding Claim 19,
Claim 19 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Step 1 Analysis: Claim 19 is directed to a computer program product, i.e., a manufacture, one of the statutory categories. Claim 19 is directed to a computer program product as depending from claim 19, thus the analysis for patent eligibility of claim 14 is incorporated herein.
Step 2A Prong One Analysis: Please see corresponding analysis of Claim 14.
Step 2A Prong Two Analysis: The judicial exceptions are not integrated into a practical application.
The limitation:
• “a weight associated with the machine learning task is fixed but parameters of the robustifier are changed”
As drafted, is an additional element that amounts to no more than an additional limitation which does not meaningfully limit the judicial exception. See MPEP 2106.05(e). Specifically, the claim recites “a weight associated with the machine learning task is fixed but parameters of the robustifier are changed”, which is simply additional information regarding the characteristics of the parameters; the element does not apply the exception in a meaningful way (MPEP 2106.05(e)). Therefore, the additional element does not integrate the abstract ideas into a practical application.
Step 2B Analysis: The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional element represents an additional limitation which does not meaningfully limit the judicial exception. Additional limitations which do not meaningfully limit the judicial exception cannot provide an inventive concept. The claim is not patent eligible.
Regarding Claim 20,
Claim 20 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Step 1 Analysis: Claim 20 is directed to a computer program product, i.e., a manufacture, one of the statutory categories. Claim 20 is directed to a computer program product as depending from claim 14, thus the analysis for patent eligibility of claim 14 is incorporated herein.
Step 2A Prong One Analysis: Please see corresponding analysis of Claim 14.
Step 2A Prong Two Analysis: The judicial exceptions are not integrated into a practical application.
The limitation:
• “the input data includes sound information obtained from the microphone”
As drafted, is an additional element that amounts to no more than an additional limitation which does not meaningfully limit the judicial exception. See MPEP 2106.05(e). Specifically, the claim recites “the input data includes sound information obtained from the microphone”, which is simply additional information regarding the characteristics of input data; the element does not apply the exception in a meaningful way (MPEP 2106.05(e)). Therefore, the additional element does not integrate the abstract ideas into a practical application.
Step 2B Analysis: The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional element represents an additional limitation which does not meaningfully limit the judicial exception. Additional limitations which do not meaningfully limit the judicial exception cannot provide an inventive concept. The claim is not patent eligible.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The text of those sections of Title 35, U.S. Code not included in this action can be found in a prior Office action.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention.
Claims 1-3, 6, 8-15, and 17-19 are rejected under 35 U.S.C. 103 as being unpatentable over non-patent literature Ryu et al. (“Plug-and-Play Methods Provably Converge with Properly Trained Denoisers”, hereinafter “Ryu”) in view of non-patent literature Behnia et al. (“Code-Bridged Classifier (CBC): A Low or Negative Overhead Defense for Making a CNN Classifier Robust Against Adversarial Attacks”, hereinafter “Behnia”).
With respect to claim 1, Ryu discloses the invention as claimed including A computer-implemented method (See, e.g., Ryu, Section 4.3: “On an Nvidia GTX 1080 Ti, DnCNN took 4.08 hours and realSN-DnCNN took 5.17 hours to train, so the added cost of realSN is mild.”) for training a machine-learning network, comprising:
receiving an input data from a sensor, wherein the input data is indicative of image, radar, sonar, or sound information (See, e.g., Ryu, Section 4.1: “We use a deep denoising model called DnCNN (Zhang et al., 2017a), which learns the residual mapping with a 17-layer CNN and reports state-of-the-art results on natural image denoising.”; Section 6: “Single photon imaging. Consider single photon imaging with quanta image sensors (QIS)[.]” [Under the BRI, Ryu receives original images via image sensors, e.g., typical camera sensors or quanta image sensors.]);
generate an input data set utilizing the input data, wherein the input data set includes perturbed data (See, e.g., Ryu, Section 4.3: “We refer to SimpleCNN and DnCNN regularized by realSN as RealSN-SimpleCNN and RealSN-DnCNN, respectively. We train them in the setting of Gaussian de-noising with known fixed noise levels σ = 5, 15, 40. We used σ = 5, 15 for CS-MRI and single photon imaging, and σ = 40 for Poisson denoising. The regularized denoisers are trained to have Lipschitz constant (no more than) 1. The training data consists of images from the BSD500 dataset, divided into 40 × 40 patches.” [Under the broadest reasonable interpretation (BRI), Ryu’s generation of training data images with added (or applied) fixed noise levels corresponds to generating an input data set utilizing the input data (e.g., the imaging input from the camera sensor or QIS), wherein the data set includes perturbed data.]);
send the input data set to a robustifier, wherein the robustifier is configured to clean the input data6 set by removing perturbations associated with the input data set to create a modified input data set (See, e.g., Ryu, Section 4.1: “[AltContent: textbox (−)]We use a deep denoising model called DnCNN (Zhang et al., 2017a), which learns the residual mapping with a 17-layer CNN and reports state-of-the-art results on natural image denoising. Given a noisy observation y = x + e, where x is the clean image and e is noise, the residual mapping R outputs the noise, i.e., R(y) = e so that y - R(y) is the clean recovery.” [Under the BRI, Ryu’s DnCNN denoising model corresponds to a robustifier that removes perturbations (noises) from a sent (given) data set to create a modified (clean) data set.]); …
a … machine learning task associated with a robustifier7 (See, e.g., Ryu, Section 4.1: “[AltContent: textbox (−)]We use a deep denoising model called DnCNN (Zhang et al., 2017a), which learns the residual mapping with a 17-layer CNN and reports state-of-the-art results on natural image denoising”) [Under the BRI, Ryu’s DnCNN denoising model which learns the residual mapping corresponds to a machine learning task associated with a robustifier]);
training the robustifier to obtain a trained robustifier utilizing the modified input data set (See, e.g., Ryu, Section 4.3: “We refer to SimpleCNN and DnCNN regularized by realSN as RealSN-SimpleCNN and RealSN-DnCNN, respectively. We train them in the setting of Gaussian de-noising with known fixed noise levels σ = 5, 15, 40. We used σ = 5, 15 for CS-MRI and single photon imaging, and σ = 40 for Poisson denoising. The regularized denoisers are trained to have Lipschitz constant (no more than) 1.”; Section 6: “We compare PnP-ADMM and PnP-FBS respectively with the denoisers BM3D, RealSN-DnCNN, and RealSNSimpleCNN. … the PSNRs achieved at the 50th iteration, the 100th iteration, and the best PSNR values achieved within the first 100 iterations.” [Under the BRI, Ryu’s denoiser (robustifier) DnCNN is iteratively trained, i.e., it is repeatedly re-trained based on the previous output from the machine learning model (which, in turn, is based on the modified input data set.]); and
in response to convergence of the trained robustifier to a first threshold, output the trained robustifier (See, e.g., Ryu, Section 3: “We now present conditions that ensure the PnP methods are contractive and thereby convergent ... It is straightforward to modify Theorems 1 and 2 to establish local convergence when Assumption (A) holds locally”; Section 5: “Convergence. We first examine which denoisers satisfy Assumption (A) with small ε. In Figure 1, we run PnP iterations of Poisson denoising on a single image (flag of (Rond et al., 2016)) with different models … Figure 2 qualitatively shows that PnP-ADMM exhibits more stable convergence than PnP- FBS … Our theory only concerns convergence and says nothing about the recovery performance of the output the methods converge to. We empirically verify that the PnP methods with RealSN, for which we analyzed convergence, yield competitive denoising results.” [Under the BRI, Ryu uses the converged denoiser once it converges, i.e., Ryu “outputs” (e.g., saves, uses, applies, examples described in the specification at [0060]) the plug-and-play denoiser in response to convergence. Making any decision on convergence (i.e., identifying data as sufficiently convergent) necessarily requires a threshold by which to split the data.)].
Although Ryu substantially discloses the claimed invention and Ryu discloses “A wide range of denoisers have been used … and deep projection model based on generative adversarial networks (Chang et al., 2017) have also been considered. … Regularizing Lipschitz continuity stabilizes training, improves the final performance, and enhances robustness to adversarial attacks” (see, Ryu, Section 1.1), Ryu does not explicitly disclose sending the modified input data set to a pretrained machine learning task and,
wherein the training may include adversarial training via projected gradient descent.
Nevertheless, Behnia, in the same field of endeavor (denoising), teaches sending the modified input data set to a pretrained machine learning task (See, e.g., Behnia, Fig. 5 (showing a base classifier, i.e., a pretrained machine learning task); Fig. 7 (showing the performance of a machine learning classification task for denoised images); Section VI(B): “For the CNN protected with DAE, we provide two sets of results: 1) DAE- CNN Model accuracy: DAE and CNN are separately trained and paired together; 2) Retrained-DAC-CNN model accuracy: The CNN is incrementally trained using the refined images produced at the output of the DAE (denoted by Retraind-DAE- CNN).” [Under the BRI, Behnia’s refined (clean) images are sent to the CNN for a pretrained machine learning task, e.g., classification.]),
wherein the training may include adversarial training via projected gradient descent (See, e.g., Behnia, Section I: “The main idea is to add a noise vector containing small values to the original image in the opposite or same direction of the gradient calculated by the target network to produce adversarial samples. … Adversarial training is a data augmentation technique in which by generating a large number of adversarial samples and including them with correct labels in the training set, the robustness of network against adversarial attacks improves”; Section II(A): “Many effective attacks have been introduced in the literature. Some of the most notable attacks include Fast Gradient Sign Method (fgsm)[.]” [Under the BRI, producing adversarial training samples for adversarial training and adding noise in the direction of the gradient (e.g., via the fast gradient sign method attack) corresponds to adversarial training via projected gradient descent]).
Ryu and Behnia are analogous because they are both directed to denoising data (See Ryu, Abstract; See Behnia, Abstract). One of ordinary skill in the art would be motivated to combine Behnia with Ryu, as Behnia explicitly teaches that their approach protects machine learning models while reducing complexity (See, e.g., Behnia, Section I: “We illustrate that CBC is 1) more robust against adversarial attacks compared to a similar CNN solution that is protected by a denoising AE, and has substantially less computational complexity compared to such models.”).
Regarding Claim 2, as discussed above, Ryu in view of Behnia teach the method of claim 1.
Although Ryu substantially discloses the claimed invention, Ryu does not explicitly disclose wherein the machine learning task includes a classifier, an object detector, a semantic segmentation, or speech recognition.
However, in the same field, analogous art Behnia teaches wherein the machine learning task includes a classifier, an object detector, a semantic segmentation, or speech recognition (See, e.g., Behnia, Section IV: “Using DAEs to refine perturbed input samples before feeding them into the classifier is a typical defense mechanism against adversarial examples.”).
Ryu and Behnia are analogous because they are both directed to denoising data (See Ryu, Abstract; See Behnia, Abstract). One of ordinary skill in the art would be motivated to combine Behnia with Ryu, as Behnia explicitly teaches that their approach protects machine learning models while reducing complexity (See, e.g., Behnia, Section I: “We illustrate that CBC is 1) more robust against adversarial attacks compared to a similar CNN solution that is protected by a denoising AE, and has substantially less computational complexity compared to such models.”).
Regarding Claim 3, as discussed above, Ryu in view of Behnia teach the method of claim 1.
Ryu further discloses wherein the machine learning network includes an optimizer includes a stochastic gradient descent optimizer, or an adaptive optimizer8 (See, e.g., Ryu, Section 4.3: “The CNN weights were initialized … We train all networks using the ADAM optimizer for 50 epochs, with a mini-batch size of 128.” [i.e., the machine learning network/CNN includes an adaptive/ADAM optimizer).
Regarding Claim 6, as discussed above, Ryu in view of Behnia teach the method of claim 1.
Although Ryu substantially discloses the claimed invention, Ryu does not explicitly disclose wherein perturbed data is generated utilizing a project gradient descent attack.
However, in the same field, analogous art Behnia teaches wherein perturbed data is generated utilizing a project gradient descent attack (See, e.g., Behnia, Section I: “The main idea is to add a noise vector containing small values to the original image in the opposite or same direction of the gradient calculated by the target network to produce adversarial samples.”; Section II(A): “Many effective attacks have been introduced in the literature. Some of the most notable attacks include Fast Gradient Sign Method (fgsm)[.]” [Under the BRI, adding noise in the direction of the gradient (e.g., via the fast gradient sign method attack) corresponds to generating perturbed data using a projected gradient descent attack.]).
Ryu and Behnia are analogous because they are both directed to denoising data (See Ryu, Abstract; See Behnia, Abstract). One of ordinary skill in the art would be motivated to combine Behnia with Ryu, as Behnia explicitly teaches that their approach protects machine learning models while reducing complexity (See, e.g., Behnia, Section I: “We illustrate that CBC is 1) more robust against adversarial attacks compared to a similar CNN solution that is protected by a denoising AE, and has substantially less computational complexity compared to such models.”).
Regarding independent Claim 8:
Claim 8 is the system embodiment of Claim 1, with similar limitations to Claim 1. As such, claim 8 is substantially similar to claim 1, and therefore is rejected on the same ground and reasoning as claim 1, discussed above.
Ryu further discloses an input interface configured to receive input data from a sensor, wherein the sensor includes a camera, a radar, a sonar, or a microphone (Section 6: “Single photon imaging. Consider single photon imaging with quanta image sensors (QIS) … Compressed sensing MRI. Magnetic resonance imaging (MRI) is a widely-used imaging technique with a slow data acquisition. Compressed sensing MRI (CS-MRI) accelerates MRI by acquiring less data through downsampling.” [Under the BRI, the QIS corresponds to a sensor of a camera device; alternatively or additionally, the MRI apparatus can be considered as including a camera with a sensor.]), and a processor, in communication with the input interface (See, e.g., Ryu, Section 4.3: “On an Nvidia GTX 1080 Ti, DnCNN took 4.08 hours and realSN-DnCNN took 5.17 hours to train, so the added cost of realSN is mild.”).
Regarding Claim 9, as discussed above, Ryu in view of Behnia teach the system of Claim 8. Ryu further discloses wherein the processor is further programmed to randomly sample a base classifier (See, e.g., Ryu, Table 3 (showing random sampling) and Section 6: “Fp: Cd → Ck is the linear measurement model … We take Fp as the Fourier k-domain subsampling (partial Fourier operator). We tested random, radial, and Cartesian sampling (Eksioglu, 2016) with a sampling rate of 30%. The noise level σe is taken as 15/255 ... For BM3D-MRI, we set the “final noise level (the noise level in the last iteration) as 2 σe[.]” [Under the BRI, Ryu’s iterative process randomly samples a base classifier, e.g., the linear measurement model.]).
Regarding Claims 10 and 13:
Claims 10 and 13 are the system embodiments of Claims 6 and 2, respectively, with similar limitations to Claims 6 and 2. As such, claims 10 and 13 are substantially similar to claims 6 and 2, and therefore are rejected on the same grounds and reasoning as claims 6 and 2, discussed above.
Regarding Claim 11, as discussed above, Ryu in view of Behnia teach the system of Claim 8.
Although Ryu substantially discloses the claimed invention, Ryu does not explicitly disclose wherein the perturbed data set is computer-generated data corresponding to a clean data set.
However, in the same field, analogous art Behnia teaches wherein the perturbed data set is computer-generated data corresponding to a clean data set (See, e.g., Behnia, Section I: “[C]onvolutional neural networks are prone to adversarial attacks through simple perturbation of their input images [10-13]. The algorithms proposed by [10-13] have demonstrated how easily the normal images can be perturbed with adding a small noise in order to fool neural networks.”; Section V: “In this section, we investigate the effectiveness of our proposed solution against adversarial examples prepared for FashionMNIST [30] and CIFAR-10 [31] datasets.” [Under the BRI, using algorithms to add noise to normal images corresponds to creating a computer generated-perturbed data set corresponding to a clean set.]).
Ryu and Behnia are analogous because they are both directed to denoising data (See Ryu, Abstract; See Behnia, Abstract). One of ordinary skill in the art would be motivated to combine Behnia with Ryu, as Behnia explicitly teaches that their approach protects machine learning models while reducing complexity (See, e.g., Behnia, Section I: “We illustrate that CBC is 1) more robust against adversarial attacks compared to a similar CNN solution that is protected by a denoising AE, and has substantially less computational complexity compared to such models.”).
Regarding Claim 12, as discussed above, Ryu in view of Behnia teach the system of Claim 8.
Although Ryu substantially discloses the claimed invention, and Ryu discloses “We then propose real spectral normalization, a technique for training deep learning-based denoisers” (see, Ryu, Abstract) Ryu does not explicitly disclose wherein the machine learning task is a deep neural network.
However, in the same field, analogous art Behnia teaches wherein the machine learning task is training a deep neural network (See, e.g., Behnia, Section II: “The vulnerability of deep neural networks to adversarial examples was first investigated in [14]. Since this early work, many new algorithms for generating adversarial examples, and a verity [sic, variety] of solutions for defending against these attacks are proposed. Following is a summary of the attack and defense models related to our proposed solution … adversarial examples that can cause a model to misclassify, can have the same influence on another model that is trained for the same task … adversarial training is proposed to enhance the robustness of the model.” [i.e., the machine learning task is training a deep neural network]).
Ryu and Behnia are analogous because they are both directed to denoising data (See Ryu, Abstract; See Behnia, Abstract). One of ordinary skill in the art would be motivated to combine Behnia with Ryu, as Behnia explicitly teaches that their approach protects machine learning models while reducing complexity (See, e.g., Behnia, Section I: “We illustrate that CBC is 1) more robust against adversarial attacks compared to a similar CNN solution that is protected by a denoising AE, and has substantially less computational complexity compared to such models.”).
Regarding independent Claim 14:
Claim 14 is the computer program product embodiment of Claim 1, with similar limitations to Claim 1. As such, claim 14 is substantially similar to claim 1, and therefore is rejected on the same ground and reasoning as claim 1, discussed above.
Ryu further discloses a computer-program product storing instructions (See, e.g., Ryu, Section 4.2: “[V]ectors ul ϵ Rm; vl ϵ Rm are initialized randomly and maintained in the memory to estimate the leading first left and right singular vector of Wl respectively.”; Section 4.3: “On an Nvidia GTX 1080 Ti, DnCNN took 4.08 hours and realSN-DnCNN took 5.17 hours to train, so the added cost of realSN is mild.” [Under the BRI, a memory corresponds to a computer-program product storing instructions, e.g., the instructions for training the DnCNN.]), and a sensor including a camera, radar, sonar, or microphone (See, e.g., Ryu, Section 4.1: “We use a deep denoising model called DnCNN (Zhang et al., 2017a), which learns the residual mapping with a 17-layer CNN and reports state-of-the-art results on natural image denoising.”; Section 6: “Single photon imaging. Consider single photon imaging with quanta image sensors (QIS) … Compressed sensing MRI (CS-MRI) accelerates MRI by acquiring less data through downsampling. PnP is useful in medical imaging as we do not have a large amount of data for end-to-end training[.]” [Under the BRI, Ryu receives original images via image sensors, e.g., typical camera sensors, images from an MRI apparatus, or quanta image sensors.]).
Regarding Claim 15, as discussed above, Ryu in view of Behnia teach the computer program product of Claim 14.
Ryu further discloses wherein the input data includes an image received from the camera in communication with the computer (See, e.g., Ryu, Section 4.1: “We use a deep denoising model called DnCNN (Zhang et al., 2017a), which learns the residual mapping with a 17-layer CNN and reports state-of-the-art results on natural image denoising.”; Section 6: “Single photon imaging. Consider single photon imaging with quanta image sensors (QIS) … Compressed sensing MRI (CS-MRI) accelerates MRI by acquiring less data through downsampling. PnP is useful in medical imaging as we do not have a large amount of data for end-to-end training[.]” [Under the BRI, Ryu receives original images via image sensors, e.g., typical camera sensors, images from an MRI apparatus, or quanta image sensors.]).
Regarding Claims 17 and 18:
Claims 17 and 18 are the computer program product embodiments of Claims 2 and 6, respectively, with similar limitations to Claims 2 and 6. As such, claims 17 and 18 are substantially similar to claims 2 and 6, and therefore are rejected on the same grounds and reasoning as claims 2 and 6, discussed above.
Regarding Claim 19, as discussed above, Ryu in view of Behnia teach the computer program product of Claim 14.
Although Ryu substantially discloses the claimed invention, Ryu does not explicitly disclose wherein a weight associated with the machine learning task is fixed but parameters of the robustifier are changed.
However, in the same field, analogous art Behnia teaches wherein a weight associated with the machine learning task is fixed but parameters of the robustifier are changed (See Behnia, Section IV: “An improved version of such defense is when the training is done serially, where in the first stage, the DAE is trained, and then the CNN classifier is trained using the output of DAE as input sample”. [Under the BRI, the serial training means that the weights associated with the machine learning task (classifier) are fixed while the weights of the robustifier (i.e., the denoiser, the DAE) are changed via training.]).
Ryu and Behnia are analogous because they are both directed to denoising data (See Ryu, Abstract; See Behnia, Abstract). One of ordinary skill in the art would be motivated to combine Behnia with Ryu, as Behnia explicitly teaches that their approach protects machine learning models while reducing complexity (See, e.g., Behnia, Section I: “We illustrate that CBC is 1) more robust against adversarial attacks compared to a similar CNN solution that is protected by a denoising AE, and has substantially less computational complexity compared to such models.”).
Claims 4 and 5 are rejected under 35 U.S.C. 103 as being unpatentable over Ryu in view of Behnia as applied to claim 1, and further in view of Gao (U.S. Publication No. 2021/0145393 A1, hereinafter “Gao”).
Regarding Claim 4, as discussed above, Ryu in view of Behnia teach the method of claim 1. However, Ryu in view of Behnia does not explicitly teach wherein paired cleaned-perturbed data are sent to the robustifier in parallel.
Nevertheless, Gao, in the same field of endeavor (denoising), teaches wherein paired cleaned-perturbed data are sent to the robustifier in parallel (See, e.g., Gao, [0014]: “[A] neural network model, such as the neural network model depicted in FIGS. 3 and 4, is trained with pairs of noisy images and clean, target images, such as the pair of images depicted in FIG. 5[.]”; [0060]-[0061]: “As the sub-routine 710 relates to acquiring a single pair of images for training the neural network model, method 700 may repeat the sub-routine 710 to generate a plurality of image pairs for the training dataset … At 720, method 700 trains the neural network model with the training dataset to map the plurality of noisy images to the plurality of clean images.”. [Under the BRI, Gao sends cleaned-perturbed images in pairs for training, i.e., in parallel; the pair is sent to a denoising model, i.e., a denoiser/robustifier.])
Ryu, Behnia, and Gao are analogous because they are all directed to denoising data (See Ryu, Abstract; See Behnia, Abstract; See Gao, Abstract.). One of ordinary skill in the art would be motivated to combine Gao with Ryu in view of Behnia, as Gao explicitly discloses that their approach can improve image quality (See, e.g., Gao, [0003]: “In this way, row-correlated noise artifacts caused by electromagnetic interference at the x-ray detector are eliminated or cancelled in real time and image quality is improved.”).
Regarding Claim 5, as discussed above, Ryu in view of Behnia teach the method of claim 1. Although Ryu in view of Behnia substantially discloses the claimed invention, Ryu in view of Behnia do not explicitly teach wherein the first threshold includes an amount of loss of the input data.
Nevertheless, Gao, in the same field of endeavor (denoising), teaches wherein the first threshold includes an amount of loss of the input data (See, e.g., Gao, [0054]: “Further, to train the neural network model, a goal for the converging criterion is set. For example, a target mean squared error (MSE) may be established.” [Under the BRI, the mean squared error corresponds to a loss of the input data (compare with Specification, [0028]); a target (or “goal”) value thereof corresponds to a threshold.]).
Ryu, Behnia, and Gao are analogous because they are all directed to denoising data (See Ryu, Abstract; See Behnia, Abstract; See Gao, Abstract.). One of ordinary skill in the art would be motivated to combine Gao with Ryu in view of Behnia, as Gao explicitly discloses that their approach can improve image quality (See, e.g., Gao, [0003]: “In this way, row-correlated noise artifacts caused by electromagnetic interference at the x-ray detector are eliminated or cancelled in real time and image quality is improved.”).
Claims 7, 16, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Ryu in view of Behnia as applied to claims 1, 8 and 14 above, and further in view of Tang et al. (U.S. Publication No. 2020/0065940 A1, hereinafter “Tang”).
Regarding Claim 7, as discussed above, Ryu in view of Behnia teach the method of claim 1. Although Ryu in view of Behnia substantially discloses the claimed invention, Ryu in view of Behnia do not explicitly teach wherein the input data includes video information obtained from a camera.
Nevertheless, Tang, in the same field of endeavor (denoising), teaches wherein the input data includes video information obtained from a camera (See, e.g., Tang, [0124]: “[O]ne or more input devices 1722 are connected to the interface circuit 1720. The input device(s) 1722 permit(s) a user to enter data and commands into the processor 1712. The input device(s) can be implemented by, for example, a sensor, a microphone, a camera (still or video), a keyboard, a button, a mouse, a touchscreen, a track-pad, a trackball, isopoint and/or a voice recognition system.”).
Ryu, Behnia, and Tang are analogous because they are each directed to denoising data (See Ryu, Abstract; See Behnia, Abstract; See Tang, Abstract.). One of ordinary skill in the art would be motivated to combine Tang with Ryu in view of Behnia, as Tang explicitly teaches that their approach can help improve denoising capabilities (See, e.g., Tang, [0129]: “The disclosed methods, apparatus and articles of manufacture improve the operation of a computing device by expanding it with a capability to denoise images through incorporation of a deep neural network model trained on a single patient image rather than a large, multi-patient data set.”).
Regarding Claim 16, as discussed above, Ryu in view of Behnia teach the computer program product of Claim 14. Although Ryu in view of Behnia substantially discloses the claimed invention, Ryu in view of Behnia do not explicitly teach outputting the trained robustifier in response to a single forward pass.
Nevertheless, Tang, in the same field of endeavor (denoising), teaches outputting the trained robustifier in response to a single forward pass (See, e.g., Tang, [0094]: “For training, the noisy images are used as input to the neural network and the ground truth of noise is used as training target output/result. A mean squared error (MSE) loss function and stochastic gradient descent Adam optimizer can be used, for example, and the training can stop after pre-set epochs are reached. Thus, the CNN can be used in iterative training to pass through the training data set followed by testing with a verification set to form a single epoch. Multiple epochs can be executed to train the network model for denoising deployment.” [Under the BRI, Tang outputs (saves) the trained robustifier during each forward pass (epoch) for testing and verification; alternatively, the fact that multiple epochs “can” be executed to train the network implies that a single pass is also an option. More generally, however, the claim language is being interpreted as outputting the denoiser at each single forward pass; otherwise, it not seen how a network is trained in a single pass (i.e., there is no output to compare against.]).
Ryu, Behnia, and Tang are analogous because they are each directed to denoising data (See Ryu, Abstract; See Behnia, Abstract; See Tang, Abstract.). One of ordinary skill in the art would be motivated to combine Tang with Ryu in view of Behnia, as Tang explicitly teaches that their approach can help improve denoising capabilities (See, e.g., Tang, [0129]: “The disclosed methods, apparatus and articles of manufacture improve the operation of a computing device by expanding it with a capability to denoise images through incorporation of a deep neural network model trained on a single patient image rather than a large, multi-patient data set.”).
Regarding Claim 20, as discussed above, Ryu in view of Behnia teach the computer program product of claim 14. Although Ryu in view of Behnia substantially discloses the claimed invention, Ryu in view of Behnia do not explicitly teach wherein the input data includes sound information obtained from the microphone.
Nevertheless, Tang, in the same field of endeavor (denoising), teaches wherein the input data includes sound information obtained from the microphone (See, e.g., Tang, [0124]: “[O]ne or more input devices 1722 are connected to the interface circuit 1720. The input device(s) 1722 permit(s) a user to enter data and commands into the processor 1712. The input device(s) can be implemented by, for example, a sensor, a microphone, a camera (still or video), a keyboard, a button, a mouse, a touchscreen, a track-pad, a trackball, isopoint and/or a voice recognition system.”).
Ryu, Behnia, and Tang are analogous because they are all directed to denoising data (See Ryu, Abstract; See Behnia, Abstract; See Tang, Abstract.). One of ordinary skill in the art would be motivated to combine Tang with Ryu in view of Behnia, as Tang explicitly teaches that their approach can help improve denoising capabilities (See, e.g., Tang, [0129]: “The disclosed methods, apparatus and articles of manufacture improve the operation of a computing device by expanding it with a capability to denoise images through incorporation of a deep neural network model trained on a single patient image rather than a large, multi-patient data set.”).
Conclusion
The prior art made of record, listed on form PTO-892, and not relied upon, is considered pertinent to applicant's disclosure.
For example, Baker (U.S. Publication No. 2020/0143240A1, hereinafter “Baker”) discloses “Systems and methods to improve the robustness of a network that has been trained … splitting the training data based upon the gradient direction, and making other intentionally adversarial changes to the input of the neural network.” by “splitting data based on the direction of gradients in a network 106; and making additional changes, particularly to the input, to enhance the anti-adversarial response of the network” in order to “make the machine learning system 100 more robust. Robustness of a machine learning system 100 can be defined as making a correct classification less likely to be disturbed by random or even intentionally adversarial changes in the input values.” where “the system attempts to do the corresponding denoising. In one aspect, there is a denoising autoencoder for each of the classifiers” and “the method further includes denoising data from the plurality of operational classifiers and training a K-select classifier: (see, Abstract and paragraphs 21, 23, 85 and 220).
The examiner requests, in response to this office action, support be shown for language added to any original claims on amendment and any new claims. That is, indicate support for newly added claim language by specifically pointing to page(s) and line no(s) in the specification and/or drawing figure(s). This will assist the examiner in prosecuting the application.
When responding to this office action, Applicant is advised to clearly point out the patentable novelty which he or she thinks the claims present, in view of the state of the art disclosed by the reference cited or the objections made. He or she must also show how the amendments avoid such references or objections See 37 CFR 1.111 (c).
Any inquiry concerning this communication or earlier communications from the examiner should be directed to RANDY K BALDWIN whose telephone number is (571)270-5222. The examiner can normally be reached on Mon - Fri 9:00-6:00.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/RANDALL K. BALDWIN/Primary Examiner, Art Unit 2125
1 Under the broadest reasonable interpretation (BRI), in view of the specification, the “robustifier” is any combination of software and/or hardware capable of performing the claimed functions.
2 As indicated in the objection to this claim above, it appears “a robustifier” should read “the robustifier”
3 As indicated above in the objection to this claim “wherein the machine learning network includes an optimizer includes a stochastic gradient descent optimizer …” is grammatically incorrect and should read “wherein the machine learning network includes an optimizer including , which includes a stochastic gradient descent optimizer …”
4 As discussed above, the “robustifier”, under the BRI, in view of the specification, is any combination of software and/or hardware capable of performing the claimed functions.
5 As discussed above, under the BRI, in view of the specification, the “robustifier” is any combination of software and/or hardware capable of performing the claimed functions.
6 As discussed above, under the BRI, in view of the specification, the “robustifier” is any combination of software and/or hardware capable of performing the claimed functions.
7 As indicated in the objection to this claim above, it appears “a robustifier” should read “the robustifier”
8 As indicated above in the objection to this claim “wherein the machine learning network includes an optimizer includes a stochastic gradient descent optimizer …” is grammatically incorrect and should read “wherein the machine learning network includes an optimizer including , which includes a stochastic gradient descent optimizer …”