DETAILED ACTION
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This action is responsive to pending claims 1-4, 7, 11-13 filed 6/10/2025.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claim(s) 1-4, 7, 11-13 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. The 35 U.S.C. 101 subject matter eligibility analysis first asks whether the claim is directed to one of the four statutory categories (Step 1). It next asks whether the claim is directed to an abstract idea (Step 2A), via Prong 1, whether an abstract idea (e.g., mathematical concept, mental process, certain methods of organizing human activity) is recited, and Prong 2, whether it is integrated into a practical application. It finally asks whether the claim as a whole includes additional elements that amount to significantly more than the judicial exception (Step 2B). See MPEP 2106.
STEP 1: The claims falls within one of the four statutory categories:
All claims are directed to methods (4) and hardware devices (1, 7) and hence fall within one of the four statutory categories.
STEP 2A PRONG 1: The claims recite a judicial exception:
The claims are directed to a technique of tuning a heuristic model via adjusting of quantization parameters. However, a person may, in the mind and introspectively, consider a scenario, apply various changes to the scenario (image, story, etc.), and consider whether these changes confuse or revise the mental heuristic. Such changes may take on orders of magnitude. The mental heuristic may be revised, for example, to eliminate consideration of such minor changes, as a matter of principle, e.g., for increased impartiality or accuracy. One might consider how much revision would necessarily take place for the cumulative effect to cause acceptable change.
The additional elements are underlined below and analyzed subsequently.
For claim 1: A robustness setting device comprising:
at least one memory configured to store storing instructions; and
at least one processor configured to execute the instructions to:
generate an adversarial sample based on a trained model, an input signal, and each perturbation level of a perturbation for inducing an erroneous determination by the trained model (Generating adversarial samples meant to confuse the mental heuristic, the mental heuristic trained upon experience, the adversarial sample having various levels of difference from a known input, may be performed in the mind);
specify a robustness level required in a computation device using the trained model (specifying a robustness requirement may be performed in the mind, e.g., specifying how much uncertainty these changes need cause the mental heuristic when considering the perturbed additional data);
acquire a perturbation level corresponding to the specified robustness level based on a comparison of the specified robustness level with a change in an output accuracy of the adversarial sample at each perturbation level relative to the output accuracy of the input signal to which no perturbation is added (acquiring various perturbation levels based on a specified robustness levels, based on introspectively comparing the robustness level with a change in certainty, i.e., to determine an acceptable change, the change relative to a baseline original sample, may be performed in the mind), and determine a noise removal level for the input signal, which indicates a quantization parameter or filter weights, based on the acquired perturbation level (Determining a magnitude of noise that would remove this perturbation may be performed in the mind); and
output the determined noise removal level to the computation device, and cause the computation device to perform a noise removal of the input signal in accordance with the quantization parameter or the filter weights (determining a noise removal level and removing noise beneath that level from consideration so as to more impartially consider primary signal may be performed in the mind).
For claim 2: The robustness setting device according to claim 1,
wherein the at least one processor is configured to execute the instructions to specify the robustness level based on the perturbation level of the perturbation in the adversarial sample (Specifying a robustness level based on perturbation levels, such as for comparison, may be performed in the mind).
For claim 3: The robustness setting device according to claim 1,
wherein the at least one processor is further configured to execute the instructions to:
determine, as the noise removal level, a quantization width based on a value that is twice the acquired perturbation level (Determining a quantization width based on a perturbation level may be performed in the mind), and
cause the computation device to perform the noise removal of the input signal in accordance with the determined quantization width (determining a noise removal level and removing noise beneath that level from consideration so as to consider primary signal may be performed in the mind).
Claim 4 recites a method analogous to the device of claim 1 and is hence likewise rejected.
For claim 7: A robustness evaluation method performed by a computer and comprising:
specifying, based on a trained model, a perturbation level of a perturbation in an adversarial sample which is an input signal to which the perturbation is added for inducing an erroneous determination by the trained model (Generating adversarial samples meant to confuse the mental heuristic, the mental heuristic trained upon experience, the adversarial sample having various levels of perturbed difference from a known input, may be performed in the mind);
determining a noise removal level for the input signal, which indicates a quantization parameter or filter weights, based on the specified perturbation level (Determining a noise removal level corresponding to the perturbation level may be performed in the mind); and
outputting the determined noise removal level to a computation device, and causing the computation device to perform a noise removal of the input signal in accordance with the quantization parameter or the filter weights (determining a noise removal level and removing noise beneath that level from consideration so as to consider primary signal may be performed in the mind).
For claim 11: The robustness evaluation method according to claim 7, wherein
in the determining, a quantization width based on a value that is twice the specified perturbation level is determined as the noise removal level (determining a quantizing width based on perturbation level may be performed in the mind), and
in causing the computation device to perform the noise removal, the noise removal of the input signal in accordance with the determined quantization width is performed (determining a noise removal level and removing noise beneath that level from consideration so as to consider primary signal may be performed in the mind).
For claim 12. The robustness setting device according to claim 1,
wherein the at least one processor is configured to execute the instructions to
repeat the comparison while increasing the perturbation level by a predetermined amount until the change exceeds the specified robustness level (Evaluating perturbation levels until a robustness metric is exceeded may be performed in the mind), and acquire the perturbation level at which the change exceeds the specified robustness level (Taking note of a level may be performed in the mind).
For claim 13. The robustness setting device according to claim 1,
wherein the at least one processor is configured to execute the instructions to
receive, from the computation device, an output signal calculated by the computation device using the adversarial sample of each perturbation level (Receiving an output may be performed in the mind), and acquire the output accuracy based on the received output signal to acquire the change (Determining accuracy of output may be performed in the mind).
STEP 2A PRONG 2: The claims do not integrate the exception into a practical application:
For claim(s) 1-4, 12-13, the additional elements comprise computing elements including a memory, processor, as well as the output to a computing device and the performing of removal on a computing device. However, these are mere instructions to implement the technique in a general-purpose computing environment and hence does not constitute can integration into a practical application.
STEP 2B: The claim as a whole do not include additional elements that amount to significantly more than the abstract idea:
For claim(s) 1-4, 12-13, the additional elements comprise computing elements including a memory, processor, as well as the output to a computing device and the performing of removal on a computing device. However, the use of general-purpose computing devices is well-understood, routine, and conventional in the field of data processing and hence does not constitute significantly more.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
Claim(s) 2 are rejected under 35 U.S.C. 112(b) as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor, or for pre-AIA the applicant regards as the invention.
In claim 2, “the perturbation level” ambiguously references “each perturbation level” (c.1¶4) and “a perturbation level” (c.1¶6); hence, the claim is indefinite. For purposes of examination “each” perturbation level (c.1¶4) will be understood as the intended antecedent.
Claim Rejections - 35 USC § 102
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale or otherwise available to the public before the effective filing date of the claimed invention.
Claim(s) 7, 11 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Panda ("Discretization based solutions for secure machine learning against adversarial attacks", published 2/11/2019).
For claim 7, Panda discloses: a robustness evaluation method performed by a computer and comprising:
specifying, based on a trained model, a perturbation level of a perturbation in an adversarial sample which is an input signal to which the perturbation is added for inducing an erroneous determination by the trained model (§IV.A: various perturbation level (epsilon-balls) are assigned for generating adversarial attacks, see §III, the adversarial attacks being applied to the input space, see §IV.A);
determining a noise removal level for the input signal, which indicates a quantization parameter or filter weights, based on the specified perturbation level (fig.4: for each perturbation level, various noise removal levels are performed based on quantization parameter, see §IV.A: eq.2); and
outputting the determined noise removal level to a computation device (ibid: quantization levels are output to a computing device for experiment execution, such as on CIFAR10, MNIST data sets), and causing the computation device to perform a noise removal of the input signal in accordance with the quantization parameter or the filter weights (ibid: tests are performed).
For claim 11, Panda discloses the method of claim 7, as discussed above. Panda further discloses: wherein
in the determining, a quantization width based on a value that is twice the specified perturbation level is determined as the noise removal level (§IV.A, fig.4: for each epsilon ball, quantization of twice the perturbation level is performed; e.g., epsilon = 8 yielding a bit width of 4 for noise removal corresponding to twice the epsilon size, i.e., interval width of 16), and
in causing the computation device to perform the noise removal, the noise removal of the input signal in accordance with the determined quantization width is performed (ibid: various experiments are carried out based on the noise removal).
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1-4, 12-13 are rejected under 35 U.S.C. 103 as being unpatentable over Panda ("Discretization based solutions for secure machine learning against adversarial attacks", published 2/11/2019) in view of Wang (US 20200311549 A1).
For claim 1, Panda discloses: a robustness setting device comprising:
generate an adversarial sample based on a trained model, an input signal, and each perturbation level of a perturbation for inducing an erroneous determination by the trained model (§IV:A: various adversarial input samples are generated, based on a trained model via algorithm of §III, the sample being generated for variety of perturbation levels for inducing error classifications, see fig.4);
determine a noise removal level for the input signal, which indicates a quantization parameter or filter weights, based on the acquired perturbation level (§IV:A, fig.4: various noise removal levels (x-axis) are determined based on the perturbation level); and
output the determined noise removal level to the computation device, and cause the computation device to perform a noise removal of the input signal in accordance with the quantization parameter or the filter weights (§IV:A, fig.4: noise levels are provided to the computation device for execution).
Panda does not disclose: at least one memory configured to store storing instructions; and at least one processor configured to execute the instructions;
specify a robustness level required in a computation device using the trained model;
acquire a perturbation level corresponding to the specified robustness level based on a comparison of the specified robustness level with a change in an output accuracy of the adversarial sample at each perturbation level relative to the output accuracy of the input signal to which no perturbation is added.
Wang discloses: at least one memory configured to store storing instructions (0094); and at least one processor configured to execute the instructions (0094);
specify a robustness level required in a computation device using the trained model (0010, 0084-92, 0097, fig.5:520: setting accuracy loss threshold, combination with Panda §IV.A yielding application to the trained model);
acquire a perturbation level corresponding to the specified robustness level based on a comparison of the specified robustness level with a change in an output accuracy (fig.5: levels are interactively acquired in fig.5:530-550 while accounting for accuracy loss threshold, combination with Panda §IV.A fig.4 yielding application to perturbation levels) of the adversarial sample at each perturbation level (Wang fig.5: a variety of optimization levels are contemplated in the optimization technique, hence, combination with Panda yielding consideration of accuracy for multiple perturbation levels of adversarial samples) relative to the output accuracy of the input signal to which no perturbation is added (Wang fig.5:520, 540 contemplates specifying of acceptable change in output accuracy, hence, combination with Panda §IV.A, fig.4 yielding application change being relative to epsilon = 0 / no perturbation state).
It would have been obvious before the effective filing date to a person of ordinary skill in the art to modify the method of Panda by incorporating the optimization technique of Wang. Both concern the art of neural network optimization and quantization (Panda 0003), and the incorporation would have, according to Panda, allow optimization according to acceptable accuracy loss (0076).
For claim 2, Panda modified by Wang discloses the device of claim 1, as described above. Panda further discloses: specify the robustness level based on the perturbation level of the perturbation in the adversarial sample (Panda §IV.A, fig.4, Wang fig.5:520, 540: robustness threshold level is specified in each cycle of the optimization loop of fig.5 for comparison and threshold assurance, based on the current optimization level, with Wang disclosing application to perturbation levels of the adversarial samples).
For claim 3, Panda modified by Wang discloses the device of claim 1, as described above. Panda further discloses: determine, as the noise removal level, a quantization width based on a value that is twice the acquired perturbation level (§IV.A, fig.4: for each epsilon ball, quantization of twice the perturbation level is performed; e.g., epsilon = 8 yielding a bit width of 4 for noise removal corresponding to twice the epsilon size, i.e., interval width of 16), and
cause the computation device to perform the noise removal of the input signal in accordance with the determined quantization width (ibid: various experiments are carried out based on the noise removal).
Claim 4 recites a method analogous to the device of claim 1 and is hence rejected for similar reasons.
For claim 12, Panda modified by Wang discloses the method of claim 1, as discussed above. Panda modified by Wang further discloses: repeat the comparison while increasing the perturbation level by a predetermined amount (§IV.A, fig.4 discloses repeating calculation of accuracy level when increasing perturbation level by set amounts in the x-axis) until the change exceeds the specified robustness level (§IV.A, fig.4: experiments are conducted until significant drop-offs in accuracy occur, hence, exceeding minimal accuracy thresholds), and acquire the perturbation level at which the change exceeds the specified robustness level (ibid: perturbation levels at which change exceeds the accuracy level are acquired, such as for further testing; Wang fig.5:540).
For claim 13, Panda modified by Wang discloses the method of claim 1, as discussed above. Panda further discloses: receive, from the computation device, an output signal calculated by the computation device using the adversarial sample of each perturbation level (§IV.A, fig.4: output signals are calculated and acquired using the respective adversarial samples to calculate y-axis values), and acquire the output accuracy based on the received output signal to acquire the change (§IV.A, fig.4: output accuracy is calculated).
Response to Arguments
Applicant’s arguments have been fully considered. In the remarks, the following arguments were made:
1. Regarding the 101 rejections: the amended elements of claim 1 are not directed to a mental process. Furthermore, the claims make it easy to determine noise removal level that should e set, and hence, is integrated into a practical application.
Examiner appreciates Applicant’s explanation of technical application of the invention as determining levels to decrease efficacy of adversarial attacks while maintaining accuracy.
However, per the Ex Parte Desjardins application of the 101 analysis, Examiner submits that even though “claims directed to an improvement in the functioning of a computer, or an improvement to other technology or technical field are patent eligible” (p.8¶1), “an assertion in the Specification alone [of the improvement] is insufficient to support a patent eligibility determination, absent a subsequent determination that the claim itself reflects the disclosed improvement” (p.8¶3).
However, the claims as a whole are directed merely to the consideration of particular perturbed samples and the nullification of particular samples via noise removal, and hence cannot be said to reflect the improvement to the machine learning model itself such as described in the Specifications, e.g., such as refining its resistance to adversarial attacks while maintaining accuracy. Hence, the claims are not integrated into a practical application.
2. Regarding the art rejections: Pouya fails to disclose the method of claim 1.
Applicant’s arguments are moot in view of newly applied art.
3. Further, Panda fails to disclose the limitations of claim 7.
Examiner respectfully disagrees. A matrix of perturbation levels and nullification levels are determined in order to carry out the testing of §IV.A and generate the graph of fig.4, hence, a noise removal level for each input signal and based on the perturbation level is determined, as claimed.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Roy (US 20200257978 A1) discloses discretization techniques for network security.
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to LIANG LI whose telephone number is (303)297-4263. The examiner can normally be reached Mon-Fri 9-12p, 3-11p MT (11-2p, 5-1a ET).
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. The examiner is available for interviews Mon-Fri 6-11a, 2-7p MT (8-1p, 4-9p ET).
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor Jennifer Welch can be reached on (571)272-7212. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from Patent Center and the Private Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from Patent Center or Private PAIR. Status information for unpublished applications is available through Patent Center or Private PAIR to authorized users only. Should you have questions about access to Patent Center or the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free).
/LIANG LI/
Primary examiner AU 2143