Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Remarks
This Office Action is responsive to Applicants' Amendment filed on April 6, 2026, in which claims 1, 9, 12, and 17 are currently amended. Claims 1-20 are currently pending.
Information Disclosure Statement
The information disclosure statements (IDS) submitted on December 26, 2025, February 24, 2026, and April 28, 2026 are in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Response to Arguments
Applicant’s arguments with respect to rejection of claims 1-20 under 35 U.S.C. 103 based on amendment have been considered and are persuasive. The argument is moot in view of a new ground of rejection set forth below.
Applicant’s arguments with respect to rejection of claims 1-20 under 35 U.S.C. 101 based on amendment have been considered, however, are not persuasive.
With respect to Applicant’s arguments on p. 3 of the Remarks submitted 4/6/2026 that the mental processes recited in the claims are integrated into a practical application because “Without the “communicating”, the “shuffling” would be counterproductive. Without the “communicating”, it is not possible to obtain […]”, Examiner notes that “communicating” as recited in the claims is recited at a very high abstract level that appear to be inclusive of abstract mental processes of standard human communication including oral and/or written communication. Examiner notes that even if the claims were interpreted narrowly as not being inclusive of an abstract concept, the MPEP is explicit that gathering and outputting of data is insignificant extra-solution activity (See MPEP 2106.05(g)) that is well-understood, routine, and conventional in the art (See MPEP 2106.05(d)(II)(i) and MPEP 2106.05(d)(II)(iv)) and does not integrate the judicial exception into a practical application. The remaining elements of claim 1 are directed entirely to mental processes which can readily and practically be performed entirely in the mind. For at least these reasons Examiner asserts that it is reasonable and appropriate to maintain the rejection under 35 U.S.C. 101.
Examiner notes that Applicant’s arguments do not address independent claims 12 and 17 which are significantly broader than claim 1 and should be rejected for the reasons detailed below.
Claim Objections
Claim 1 objected to because of the following informalities: "generating, by the computing device based at least in part on the third results" should read "generating, by the computing device, based at least in part on the third results". Appropriate correction is required.
Claim 2 objected to because of the following informalities: "the computing device is configured communicate" should read "the computing device is configured to communicate". Appropriate correction is required.
Claim Interpretation
"Same computational operation" is interpreted as simply a compound pronoun broadly describing any operation. For example, in claim 17, there is no operation introduced before "a same operation" such that "same" could import additional meaning. For this reason "same computational operation" is interpreted as simply a named computational operation.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 1-11 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Regarding claim 1, "generating [...] a first result of applying the same operation to the first data sample in computations of the artificial neural network processing the first input data" is grammatically indefinite. Grammatically, the phrase "in computations of the artificial neural network processing the first input data" could modify "applying", "the first data sample", "a first result", "generating", or the entire "result of" phrase. It's similarly unclear if "and a second result" is tied to "generating, by the computing device" or to "applying the same operation". Similarly, the relationship between "a second result of applying the same operation to the second data sample in computations of the artificial neural network" is grammatically indefinite in the same way as "in computations of the artificial neural network processing the first input data". In the case the claim is interpreted as generating first and second results by applying a "same operation" to respective first and second data samples, this would make the claim contradictory as the claim previously recites "receiving [...] third results of applying the same operation to the third parts" where "the third parts identified according to the map to include a first subset from the first parts and a second subset from the second parts" where the parts are parts of the first and second data sample. So it's unclear how the "same operation" could be applied to the whole sample level first and second data sample "based at least in part" on applying the "same operation" to third parts which comprise subsets of both the first and second data sample. The only apparent construction that would make the limitation technically coherent is to treat the "third parts" as collectively representing the first and second data samples transmitted for computation. However, that construction improperly collapses distinct claim terms, disregards the recited derivation of parts from samples, and imports unclaimed transmission/reconstruction concepts. In the interest of further examination the claim limitation is interpreted as "generating, by the computing device, based at least in part on the third results and the map, first and second results of applying the same operation".
Claims 2-11 are rejected with respect to their dependence on rejected claim 1.
Claim Rejections - 35 USC § 101
101 Rejection
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-20 are rejected under 35 USC § 101 because the claimed invention is directed to non-statutory subject matter.
Regarding Claim 1: Claim 1 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Step 1 Analysis: Claim 1 is directed to a method, which is directed to a process, one of the statutory categories.
Step 2A Prong One Analysis: Claim 1 under its broadest reasonable interpretation is a series of mental processes. For example, but for the generic computer components language, the above limitations in the context of this claim encompass neural network processing, including the following:
generating, […], a plurality of first parts from a first data sample of deep learning, wherein the first data sample represents a first input to an artificial neural network (observation, evaluation, and judgement),
generating, […], a plurality of second parts from a second data sample of deep learning, wherein the second data sample represents a second input to the artificial neural network (observation, evaluation, and judgement)
shuffling, […] according to a map, at least the first parts and the second parts to mix parts generated from the first data sample and the second data sample (observation, evaluation, and judgement)
communicating, […] to a first entity, third parts to request the first entity to apply a same operation of computing to each of the third parts, the third parts identified according to the map to include a first subset from the first parts and a second subset from the second parts (observation, evaluation, and judgement)
generating, […] based at least in part on the third results and the map, a first result of applying the same operation to the first data sample in computations of the artificial neural network processing the first input and a second result of applying the same operation to the second data sample in computations of the artificial neural network processing the second input (observation, evaluation, and judgement)
Therefore, claim 1 recites an abstract idea which is a judicial exception.
Step 2A Prong Two Analysis: Claim 1 recites additional elements “by a computing device”, . However, these additional features are computer components recited at a high-level of generality, such that they amount to no more than mere instructions to apply the judicial exception using a generic computer component. An additional element that merely recites the words “apply it” (or an equivalent) with the judicial exception, or merely includes instructions to implement an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea, does not integrate the judicial exception into a practical application. Claim 1 also recites additional elements “receiving, by the computing device from the first entity, third results of applying the same operation to the third parts respectively” which amounts to gathering data which is insignificant extra-solution activity that does not integrate the judicial exception into a practical application (See MPEP 2106.05(g)). As noted above, “communicating, by a computing device, to a first entity, third parts to request the first entity to apply a same operation of computing to each of the third parts, the third parts identified according to the map to include a first subset from the first parts and a second subset from the second parts” could also be interpreted as gathering and outputting data which is insignificant extra-solution activity. Therefore, claim 1 is directed to a judicial exception.
Step 2B Analysis: Claim 1 does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to the lack of integration of the abstract idea into a practical application, the additional elements recited in claim 1 amount to no more than mere instructions to apply the judicial exception using a generic computer component and insignificant extra-solution activity. The gathering of data is considered well-understood, routine, and conventional in the art (See MPEP 2106.05(d)(II)).
For the reasons above, claim 1 is rejected as being directed to non-patentable subject matter under §101. This rejection applies equally to dependent claims 2-11. The additional limitations of the dependent claims are addressed briefly below:
Dependent claim 2 recites additional insignificant extra-solution activity of gathering and outputting data “communicate to the first entity parts from the first parts and the second parts but without communicating to the first entity at least one of the first parts and at least one of the second parts.” Which is well-understood, routine, and conventional in the art (see MPEP 2106.05(d)(II))
Dependent claim 3 recites additional observation, evaluation, and judgement “wherein each of the first parts is based on random numbers; and a sum of the first parts is equal to the first data sample.”
Dependent claim 4 recites additional observation, evaluation, and judgement “wherein the generating of the plurality of first parts includes generating a set of random numbers as one of the plurality of first parts”.
Dependent claim 5 recites additional observation, evaluation, and judgement “identifying, by the computing device according to the map, fourth results of applying the same operation to the first parts respectively; and summing, by the computing device, the fourth results to obtain the first result”
Dependent claim 6 recites additional observation, evaluation, and judgement “communicating, […], the at least one of the first parts to request the second entity to apply the same operation of computing to each of the at least one of the first parts” and “wherein the first result is generated based on the respective at least one result of applying the same operation to the at least one of the first parts” as well as additional insignificant extra-solution activity of gathering data “receiving, by the computing device from the second entity, respective at least one result of applying the same operation to the at least one of the first parts” which is well-understood, routine, and conventional in the art.
Dependent claim 7 recites additional observation, evaluation, and judgement “wherein the first parts are provided at a same precision level as the first data sample”
Dependent claim 8 recites additional observation, evaluation, and judgement “wherein each respective data item in the first data sample has a corresponding data item in each of the first parts; and the respective data item and the corresponding data item are specified via a same number of bits”
Dependent claim 9 recites additional elements “wherein the same operation is representative of a computation in the artificial neural network” which amounts to generally linking the judicial exception to a particular field or technology (See MPEP 2106.05(h))
Dependent claim 10 recites additional elements “the same operation is configured to be performed via multiply-accumulate units” which amounts to instructions to apply the judicial exception using generic computer components
Dependent claim 11 recites additional observation, evaluation, and judgement “generating, […] from a description of a first artificial neural network, a description of a second artificial neural network describing the same operation to be performed using a deep learning accelerator of the first entity”
Regarding Claim 12: Claim 12 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Step 1 Analysis: Claim 12 is directed to a device, which is directed to a product, one of the statutory categories.
Step 2A Prong One Analysis: Claim 12 under its broadest reasonable interpretation is a series of mental processes. For example, but for the generic computer components language, the above limitations in the context of this claim encompass neural network processing, including the following:
generate a plurality of first parts from a first data sample, wherein the first data sample represents a first input to an artificial neural network (observation, evaluation, and judgement),
generate a plurality of second parts from a second data sample, wherein the second data sample represents a second input to the artificial neural network (observation, evaluation, and judgement)
shuffle, according to a map, at least the first parts and the second parts to mix parts generated from the first data sample and the second data sample (observation, evaluation, and judgement)
communicate, to a first entity, third parts to request the first entity to apply a same operation of computing to each of the third parts, the third parts identified according to the map to include a first subset from the first parts and a second subset from the second parts (observation, evaluation, and judgement)
Therefore, claim 12 recites an abstract idea which is a judicial exception.
Step 2A Prong Two Analysis: Claim 12 recites additional elements “memory”, “at least one microprocessor coupled to the memory and configured via instructions to”. However, these additional features are computer components recited at a high-level of generality, such that they amount to no more than mere instructions to apply the judicial exception using a generic computer component. An additional element that merely recites the words “apply it” (or an equivalent) with the judicial exception, or merely includes instructions to implement an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea, does not integrate the judicial exception into a practical application. Therefore, claim 12 is directed to a judicial exception.
Step 2B Analysis: Claim 12 does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to the lack of integration of the abstract idea into a practical application, the additional elements recited in claim 12 amount to no more than mere instructions to apply the judicial exception using a generic computer component.
For the reasons above, claim 12 is rejected as being directed to non-patentable subject matter under §101. This rejection applies equally to dependent claims 13-16. The additional limitations of the dependent claims are addressed briefly below:
Dependent claim 13 recites additional insignificant extra-solution activity of gathering and outputting data “receive, from the first entity, third results of applying the same operation to the third parts respectively.” Which is well-understood, routine, and conventional in the art (see MPEP 2106.05(d)(II)) as well as additional observation, evaluation, and judgement “generate, based at least in part on the third results and the map, a first result of applying the same operation to the first data sample and a second result of applying the same operation to the second data sample”
Dependent claim 14 recites additional observation, evaluation, and judgement “wherein the first data sample is equal to a sum of the first parts; and the first result is generated from a sum of results of applying the same operation to the first parts respectively.”
Dependent claim 15 recites additional observation, evaluation, and judgement “to exclude communication of at least one of the first parts and at least one of the second parts to the first entity”.
Dependent claim 16 recites additional observation, evaluation, and judgement “to generate, for each respective data item in the first data sample, a corresponding data item in each of the first parts; and the respective data item and the corresponding data item are specified via a same number of bits”
Regarding Claim 17: Claim 17 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Step 1 Analysis: Claim 17 is directed to a device, which is directed to a product, one of the statutory categories.
Step 2A Prong One Analysis: Claim 17 under its broadest reasonable interpretation is a series of mental processes. For example, but for the generic computer components language, the above limitations in the context of this claim encompass neural network processing, including the following:
generating, based at least in part on the third results and a map used to shuffle the first parts and the second parts, a first result of applying the same operation to the first data sample and a second result of applying the same operation to the second data sample (observation, evaluation, and judgement),
Therefore, claim 17 recites an abstract idea which is a judicial exception.
Step 2A Prong Two Analysis: Claim 17 recites additional elements “A non-transitory computer storage medium storing instructions which, when executed in a computing device, cause the computing device to perform a method, comprising”. However, these additional features are computer components recited at a high-level of generality, such that they amount to no more than mere instructions to apply the judicial exception using a generic computer component. An additional element that merely recites the words “apply it” (or an equivalent) with the judicial exception, or merely includes instructions to implement an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea, does not integrate the judicial exception into a practical application. Dependent claim 17 also recites additional elements “receiving, from a first entity, third results of applying a same operation to third parts respectively, wherein the first entity is provided with the third parts selected from a shuffled collection of first parts generated from a first data sample representing a first input to an artificial neural network and second parts generated from a second data sample representing a second input to the artificial neural network” which amounts to gathering data which is insignificant extra-solution activity (See MPEP 2106.05(g)). Therefore, claim 17 is directed to a judicial exception.
Step 2B Analysis: Claim 17 does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to the lack of integration of the abstract idea into a practical application, the additional elements recited in claim 17 amount to no more than mere instructions to apply the judicial exception using a generic computer component and insignificant extra-solution activity. The gathering of data is considered well-understood, routine, and conventional in the art (See MPEP 2106.05(d)(II)).
For the reasons above, claim 17 is rejected as being directed to non-patentable subject matter under §101. This rejection applies equally to dependent claims 18-20. The additional limitations of the dependent claims are addressed briefly below:
Dependent claim 18 recites additional observation, evaluation, and judgement “generating the first parts from the first data sample and random numbers”, “generating the second parts from the second data sample and random numbers”, “shuffling, according to the map, at least the first parts and the second parts to mix parts generated from the first data sample and the second data sample”, and “communicating, to the first entity, the third parts to request the first entity to apply the same operation of computing to each of the third parts, the third parts identified according to the map to include a first subset from the first parts and a second subset from the second parts”
Dependent claim 19 recites additional observation, evaluation, and judgement “wherein the first data sample is equal to a sum of the first parts; and the first result is generated from a sum of results of applying the same operation to the first parts respectively.”
Dependent claim 20 recites additional observation, evaluation, and judgement “excluding at least one of the first parts and at least one of the second parts from being communicated to the first entity”.
Therefore, when considering the elements separately and in combination, they do not add significantly more to the inventive concept. Accordingly, claims 1-20 are rejected under 35 U.S.C. § 101.
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claims 1-5, 12-15, and 17-20 are rejected under U.S.C. §102(a)(1) as being anticipated by Liu (“DataMix: Efficient Privacy-Preserving Edge-Cloud Inference”, 2020).
PNG
media_image1.png
352
890
media_image1.png
Greyscale
FIG. 3 of Liu
PNG
media_image2.png
292
1118
media_image2.png
Greyscale
FIG. 5 of Liu
Regarding claim 1, Liu teaches A method, comprising: generating, by a computing device, a plurality of first parts from a first data sample of deep learning, wherein the first data sample represents a first input to an artificial neural network([p. 5 §3] "As shown in Figure 3, the two raw images of a cat A and a dog B are mixed with a pair of coefficients c = [0.7,0.3]T. We denote the mixture as: m(c) = [A,B]·c = 0.7A+0.3B. When fed with the mixed images, a neural network trained for the dataset with mixup can output the mixed probabilities ˜ym(c) for the classes with the same coefficients c" A interpreted as first input to an artificial neural network. FIG. 3 shows a plurality of first parts (.7A and .6A) from the first data sample A. More specifically, the coefficient weighted fractional parts generated by Liu are interpreted as first parts (such that .7A of A also corresponds to a .3A part that is not mixed))
generating, by the computing device, a plurality of second parts from a second data sample of deep learning, wherein the second data sample represents a second input to the artificial neural network ([p. 5 §3] "As shown in Figure 3, the two raw images of a cat A and a dog B are mixed with a pair of coefficients c = [0.7,0.3]T. We denote the mixture as: m(c) = [A,B]·c = 0.7A+0.3B. When fed with the mixed images, a neural network trained for the dataset with mixup can output the mixed probabilities ˜ym(c) for the classes with the same coefficients c" B interpreted as second input to the artificial neural network. FIG. 3 shows a plurality of second parts (.3B and .4B) from the second data sample)
shuffling, by the computing device according to a map, at least the first parts and the second parts to mix parts generated from the first data sample and the second data sample;([p. 5] ".7A+.3B […] .6A+.4B […] a pair of coefficients c = [0.7,0.3]T. We denote the mixture as: m(c) = [A,B]·c" coefficient matrix c interpreted as a map.)
communicating, by the computing device to a first entity, third parts to request the first entity to apply a same operation of computing to each of the third parts, the third parts identified according to the map to include a first subset from the first parts and a second subset from the second parts;([pp. 5-6] "The mixing and de-mixing operation lead to an effective and efficient protocol for privacy-preserving inference on the cloud. Using the operation, we can offload the model trained with mixup to the cloud and only transmit mixed inputs and outputs for model inference" cloud interpreted as first entity. Third parts interpreted as Liu's mixed inputs sent to the cloud. The cloud neural network is explicitly the same model trained with mixup)
receiving, by the computing device from the first entity, third results of applying the same operation to the third parts respectively; ([p. 8] "During the inference, the edge first runs the preprocess model on the raw inputs and sends its output (i.e., intermediate input) to the cloud; then, the cloud runs the main model and transmits its output (i.e., intermediate output) back to the edge" See also FIG. 5)
and generating, by the computing device based at least in part on the third results and the map, a first result of applying the same operation to the first data sample and a second result of applying the same operation to the second data sample.([p. 8] "During the inference, the edge first runs the preprocess model on the raw inputs and sends its output (i.e., intermediate input) to the cloud; then, the cloud runs the main model and transmits its output (i.e., intermediate output) back to the edge. finally, the edge executes the postprocess model to obtain the final output. [...] we apply the mixing after the preprocess model and de-mixing before the postprocess model on the intermediate features (inputs and outputs)" See FIG. 5 where the result of de-mixing is generated on the edge and then used to generate the final result).
Regarding claim 2, Liu teaches The method of claim 1, wherein the computing device is configured communicate to the first entity parts from the first parts and the second parts but without communicating to the first entity at least one of the first parts and at least one of the second parts.(Liu [p. 6] "only transmit mixed inputs" [p. 8] "the attackers can only access to the intermediate input" [p. 8] "The mixing and de-mixing operation are both computed on the edge so that only the mixed data are exposed to public, protecting the privacy of original data").
Regarding claim 3, Liu teaches The method of claim 2, wherein each of the first parts is based on random numbers; (Liu [p. 8] "we then mix images in each group with coefficients randomly sampled from orthogonal matrix group" [p. 9] "the coefficients are randomly generated by the users and kept private")
and a sum of the first parts is equal to the first data sample.(Liu [p. 5] "m(c) = [A,B]·c = 0.7A+0.3B" Mathematically A=.7A+.3A where .3A is one of the first parts withheld from the cloud).
Regarding claim 4, Liu teaches The method of claim 3, wherein the generating of the plurality of first parts includes generating a set of random numbers as one of the plurality of first parts.(Liu [p. 8] "we then mix images in each group with coefficients randomly sampled from orthogonal matrix group" [p. 9] "the coefficients are randomly generated by the users and kept private" The set of coefficients of the first and second parts is explicitly randomly generated).
Regarding claim 5, Liu teaches The method of claim 3, wherein the generating of the first result includes: identifying, by the computing device according to the map, fourth results of applying the same operation to the first parts respectively; and summing, by the computing device, the fourth results to obtain the first result.(Liu [p. 5] "m(c) = [A,B]·c = 0.7A+0.3B […] ˜ ym(c) = [˜yA, ˜yB] · c […] [ ˜yA, ˜yB] = [˜ym(c), ˜ym(c)] · C−1" Results of de-mixing interpreted as fourth results. Using Liu's example in FIG. 3 m1=.7A+.3B, m2=.6A+.4B where C=[(.7, .6),(.3,.4)] and C^-1=[(4, -6),(-3,7)] where the recovered first sample for A becomes A=4(.7A+.3B)-3(.6A+.4B) = 2.8A+1.2B-1.8A-1.2B = (2.8A-1.8A)+(1.2B-1.2B)=A+0B so Liu's inverse matrix de-mixing is explicitly a weighted summation that cancels the second samples contribution and recovers the first sample according to the "map" (coefficient matrix C)).
Regarding claim 12, Liu teaches A computing device, comprising: memory; and at least one microprocessor coupled to the memory and configured via instructions to:([p. 4] "Computation (on edge) […] GPU utilization")
generate a plurality of first parts from a first data sample, wherein the first data sample represents a first input to an artificial neural network([p. 5 §3] "As shown in Figure 3, the two raw images of a cat A and a dog B are mixed with a pair of coefficients c = [0.7,0.3]T. We denote the mixture as: m(c) = [A,B]·c = 0.7A+0.3B. When fed with the mixed images, a neural network trained for the dataset with mixup can output the mixed probabilities ˜ym(c) for the classes with the same coefficients c" A interpreted as first input to an artificial neural network. FIG. 3 shows a plurality of first parts (.7A and .6A) from the first data sample A. More specifically, the coefficient weighted fractional parts generated by Liu are interpreted as first parts (such that .7A of A also corresponds to a .3A part that is not mixed))
generate a plurality of second parts from a second data sample, wherein the second data sample represents a second input to the artificial neural network;([p. 5 §3] "As shown in Figure 3, the two raw images of a cat A and a dog B are mixed with a pair of coefficients c = [0.7,0.3]T. We denote the mixture as: m(c) = [A,B]·c = 0.7A+0.3B. When fed with the mixed images, a neural network trained for the dataset with mixup can output the mixed probabilities ˜ym(c) for the classes with the same coefficients c" B interpreted as second input to the artificial neural network. FIG. 3 shows a plurality of second parts (.3B and .4B) from the second data sample)
shuffle, according to a map, at least the first parts and the second parts to mix parts generated from the first data sample and the second data sample; and([p. 5] ".7A+.3B […] .6A+.4B […] a pair of coefficients c = [0.7,0.3]T. We denote the mixture as: m(c) = [A,B]·c" coefficient matrix c interpreted as a map.)
communicate, to a first entity, third parts to request the first entity to apply a same operation of computing to each of the third parts, the third parts identified according to the map to include a first subset from the first parts and a second subset from the second parts.([pp. 5-6] "The mixing and de-mixing operation lead to an effective and efficient protocol for privacy-preserving inference on the cloud. Using the operation, we can offload the model trained with mixup to the cloud and only transmit mixed inputs and outputs for model inference" cloud interpreted as first entity. Third parts interpreted as Liu's mixed inputs sent to the cloud. The cloud neural network is explicitly the same model trained with mixup).
Regarding claim 13, Liu teaches The computing device of claim 12, wherein the at least one microprocessor is further configured via the instructions to: receive, from the first entity, third results of applying the same operation to the third parts respectively; and generate, based at least in part on the third results and the map, a first result of applying the same operation to the first data sample and a second result of applying the same operation to the second data sample.(Liu [p. 8] "During the inference, the edge first runs the preprocess model on the raw inputs and sends its output (i.e., intermediate input) to the cloud; then, the cloud runs the main model and transmits its output (i.e., intermediate output) back to the edge. finally, the edge executes the postprocess model to obtain the final output. [...] we apply the mixing after the preprocess model and de-mixing before the postprocess model on the intermediate features (inputs and outputs)" See FIG. 5 where the result of de-mixing is generated on the edge and then used to generate the final result).
Regarding claim 14, Liu teaches The computing device of claim 13, wherein the first data sample is equal to a sum of the first parts; (Liu [p. 5] "m(c) = [A,B]·c = 0.7A+0.3B" Mathematically A=.7A+.3A where .3A is one of the first parts withheld from the cloud)
and the first result is generated from a sum of results of applying the same operation to the first parts respectively.(Liu [p. 5] "m(c) = [A,B]·c = 0.7A+0.3B […] ˜ ym(c) = [˜yA, ˜yB] · c […] [ ˜yA, ˜yB] = [˜ym(c), ˜ym(c)] · C−1" Results of de-mixing interpreted as fourth results. Using Liu's example in FIG. 3 m1=.7A+.3B, m2=.6A+.4B where C=[(.7, .6),(.3,.4)] and C^-1=[(4, -6),(-3,7)] where the recovered first sample for A becomes A=4(.7A+.3B)-3(.6A+.4B) = 2.8A+1.2B-1.8A-1.2B = (2.8A-1.8A)+(1.2B-1.2B)=A+0B so Liu's inverse matrix de-mixing is explicitly a weighted summation that cancels the second samples contribution and recovers the first sample according to the "map" (coefficient matrix C)).
Regarding claim 15, Liu teaches The computing device of claim 14, wherein the at least one microprocessor is further configured via the instructions to exclude communication of at least one of the first parts and at least one of the second parts to the first entity.(Liu [p. 6] "only transmit mixed inputs" [p. 8] "the attackers can only access to the intermediate input" [p. 8] "The mixing and de-mixing operation are both computed on the edge so that only the mixed data are exposed to public, protecting the privacy of original data").
Regarding claim 17, Liu teaches A non-transitory computer storage medium storing instructions which, when executed in a computing device, cause the computing device to perform a method, comprising:([p. 4] "Computation (on edge) […] GPU utilization")
receiving, from a first entity, third results of applying a same operation to third parts respectively, wherein the first entity is provided with the third parts selected from a shuffled collection of first parts generated from a first data sample and second parts generated from a second data sample; ([p. 8] "During the inference, the edge first runs the preprocess model on the raw inputs and sends its output (i.e., intermediate input) to the cloud; then, the cloud runs the main model and transmits its output (i.e., intermediate output) back to the edge. finally, the edge executes the postprocess model to obtain the final output. [...] we apply the mixing after the preprocess model and de-mixing before the postprocess model on the intermediate features (inputs and outputs)" See FIG. 5 where the result of de-mixing is generated on the edge and then used to generate the final result)
and generating, based at least in part on the third results and a map used to shuffle the first parts and the second parts, a first result of applying the same operation to the first data sample and a second result of applying the same operation to the second data sample.([p. 8] "During the inference, the edge first runs the preprocess model on the raw inputs and sends its output (i.e., intermediate input) to the cloud; then, the cloud runs the main model and transmits its output (i.e., intermediate output) back to the edge. finally, the edge executes the postprocess model to obtain the final output. [...] we apply the mixing after the preprocess model and de-mixing before the postprocess model on the intermediate features (inputs and outputs)" See FIG. 5 where the result of de-mixing is generated on the edge and then used to generate the final result).
Regarding claim 18, Liu teaches The non-transitory computer storage medium of claim 17, wherein the method further comprises: generating the first parts from the first data sample and random numbers;(Liu [p. 8] "we then mix images in each group with coefficients randomly sampled from
orthogonal matrix group" [p. 9] "the coefficients are randomly generated by the users and kept private" The set of coefficients of the first and second parts is explicitly randomly generated)
generating the second parts from the second data sample and random numbers;(Liu [p. 8] "we then mix images in each group with coefficients randomly sampled from orthogonal matrix group" [p. 9] "the coefficients are randomly generated by the users and kept private" The set of coefficients of the first and second parts is explicitly randomly generated)
shuffling, according to the map, at least the first parts and the second parts to mix parts generated from the first data sample and the second data sample; and(Liu [p. 5] ".7A+.3B […] .6A+.4B […] a pair of coefficients c = [0.7,0.3]T. We denote the mixture as: m(c) = [A,B]·c" coefficient matrix c interpreted as a map.)
communicating, to the first entity, the third parts to request the first entity to apply the same operation of computing to each of the third parts, the third parts identified according to the map to include a first subset from the first parts and a second subset from the second parts.(Liu [pp. 5-6] "The mixing and de-mixing operation lead to an effective and efficient protocol for privacy-preserving inference on the cloud. Using the operation, we can offload the model trained with mixup to the cloud and only transmit mixed inputs and outputs for model inference" cloud interpreted as first entity. Third parts interpreted as Liu's mixed inputs sent to the cloud. The cloud neural network is explicitly the same model trained with mixup).
Regarding claim 19, Liu teaches The non-transitory computer storage medium of claim 18, wherein the first data sample is equal to a sum of the first parts; (Liu [p. 5] "m(c) = [A,B]·c = 0.7A+0.3B" Mathematically A=.7A+.3A where .3A is one of the first parts withheld from the cloud)
and the first result is generated from a sum of results of applying the same operation to the first parts respectively.(Liu [p. 5] "m(c) = [A,B]·c = 0.7A+0.3B […] ˜ ym(c) = [˜yA, ˜yB] · c […] [ ˜yA, ˜yB] = [˜ym(c), ˜ym(c)] · C−1" Results of de-mixing interpreted as fourth results. Using Liu's example in FIG. 3 m1=.7A+.3B, m2=.6A+.4B where C=[(.7, .6),(.3,.4)] and C^-1=[(4, -6),(-3,7)] where the recovered first sample for A becomes A=4(.7A+.3B)-3(.6A+.4B) = 2.8A+1.2B-1.8A-1.2B = (2.8A-1.8A)+(1.2B-1.2B)=A+0B so Liu's inverse matrix de-mixing is explicitly a weighted summation that cancels the second samples contribution and recovers the first sample according to the "map" (coefficient matrix C)).
Regarding claim 20, Liu teaches The non-transitory computer storage medium of claim 19, wherein the method further comprises: excluding at least one of the first parts and at least one of the second parts from being communicated to the first entity.(Liu [p. 6] "only transmit mixed inputs" [p. 8] "the attackers can only access to the intermediate input" [p. 8] "The mixing and de-mixing operation are both computed on the edge so that only the mixed data are exposed to public, protecting the privacy of original data").
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims 6, 7, 8, 9, and 16 are rejected under U.S.C. §103 as being unpatentable over the combination of Liu and Ma (“Privacy-Preserving Object Detection for Medical Images With Faster R-CNN”, 2022).
Regarding claim 6, Liu teaches The method of claim 5.
However, Liu doesn't explicitly teach, further comprising: communicating, by the computing device to a second entity, the at least one of the first parts to request the second entity to apply the same operation of computing to each of the at least one of the first parts; and
receiving, by the computing device from the second entity, respective at least one result of applying the same operation to the at least one of the first parts; wherein the first result is generated based on the respective at least one result of applying the same operation to the at least one of the first parts.
Ma, in the same field of endeavor, teaches The method of claim 5, further comprising: communicating, by the computing device to a second entity, the at least one of the first parts to request the second entity to apply the same operation of computing to each of the at least one of the first parts; and([p. 70] "In SecRCNN, we adopt a modified fixed point format [13] to store and transmit random shares. In this format, an arbitrary fixed-point number x is represented as x = (−1)s · ˆx · 10−c, where s ∈ {0,1} is the sign of x. For the original data (i.e., medical image pixels) and the random share, ˆx belongs to two different groups with different prime orders" [p. 71] "Data split is then used to split medical images into random shares. For most cases, each pixel of an image is stored as a number of integers [...] two edge servers S1 and S2" [p. 71] "S1 and S2 are two outsourced edge servers’ which are responsible for the intensive computation task. In SecRCNN, they complete all the computations of Faster R-CNN without knowing any plaintext of medical images. The final outputs O and O are simultaneously sent to H1,H2,...,Hn using secure communication channels." See FIG. 1)
receiving, by the computing device from the second entity, respective at least one result of applying the same operation to the at least one of the first parts; wherein the first result is generated based on the respective at least one result of applying the same operation to the at least one of the first parts.([p. 71] "S1 and S2 are two outsourced edge servers’ which are responsible for the intensive computation task. In SecRCNN, they complete all the computations of Faster R-CNN without knowing any plaintext of medical images. The final outputs O and O are simultaneously sent to H1,H2,...,Hn using secure communication channels.").
Liu as well as Ma are directed towards distributed convolutional neural networks for privacy preserving. Therefore, Liu as well as Ma are analogous art in the same field of endeavor. It would have been obvious before the effective filing date of the claimed invention to combine Liu's mixed/withheld parts with Ma's secret sharing. The combination predictably yields stronger privacy against adversarial attacks without undermining either respective arts workflow. Ma provides as additional motivation for combination ([p. 81] “As shown in Fig. 11(c), Fig. 11(g) and Fig. 11(k), the runtime needed by SDiv, SLog or SExp is obviously less than the previous secure sub-protocols. The decrease is because the messages exchanged in our CORDIC based protocols are greatly reduced”). This motivation for combination also applies to the remaining claims which depend on this combination.
Regarding claim 7, the combination of Liu, and Ma teaches The method of claim 6, wherein the first parts are provided at a same precision level as the first data sample.(Ma [p. 3] "is a fixed integer that controls the representation precision […] Note that all random shares are represented as the modified fixed-point data format in the paper.").
Regarding claim 8, the combination of Liu, and Ma teaches The method of claim 6, wherein each respective data item in the first data sample has a corresponding data item in each of the first parts; (Liu [p. 5] ".7A+.3B […] .6A+.4B […] a pair of coefficients c = [0.7,0.3]T. We denote the mixture as: m(c) = [A,B]·c")
and the respective data item and the corresponding data item are specified via a same number of bits.(Ma [p. 80] "assume that the size of input images is w ×h and the data storage length is . After the feature extraction and region proposal stages, w 16 × h 16 features and w 16 × h 16 ×9 anchors are obtained. As mentioned in Section V, three sub-protocols are invoked in SRPN, which takes 6 × 18 × w 16 × h 16 × bits communication overhead. Therefore, it theoretically requires O(wh) bits to run SRPN. Then, suppose the mini-batch size to be Ncls and the number of anchors proposed by SPRN to be Nreg. O((Ncls+Nreg)) bits are exchanged during the secure classification and bounding box regression stages" Ma explicitly splits each pixel into random shares, shows that corresponding random shares recover the original image by addition, and analyzes communication using a fixed data storage length l per item, supporting that each respective data item has a corresponding data item in each of the first parts and that the corresponding item is represented with the same number of bits (l)).
Regarding claim 9, the combination of Liu, and Ma teaches The method of claim 6, wherein the same operation is representative of a computation in an artificial neural network.(Liu [p. 8] "Fig.5. Partitioning the neural network into three parts [...] During the inference, the edge first runs the preprocess model on the raw inputs and sends its output (i.e., intermediate input) to the cloud; then, the cloud runs the main model and transmits its output (i.e., intermediate output) back to the edge; finally, the edge executes the postprocess model to obtain the final output.").
Regarding claim 16, Liu teaches The computing device of claim 14, wherein the at least one microprocessor is further configured via the instructions to generate, for each respective data item in the first data sample, a corresponding data item in each of the first parts; (Liu [p. 5] ".7A+.3B […] .6A+.4B […] a pair of coefficients c = [0.7,0.3]T. We denote the mixture as:
m(c) = [A,B]·c").
However, Liu doesn't explicitly teach and the respective data item and the corresponding data item are specified via a same number of bits..
Ma, in the same field of endeavor, teaches and the respective data item and the corresponding data item are specified via a same number of bits.([p. 80] "assume that the size of input images is w ×h and the data storage length is . After the feature extraction and region proposal stages, w 16 × h 16 features and w 16 × h 16 ×9 anchors are obtained. As mentioned in Section V, three sub-protocols are invoked in SRPN, which takes 6 × 18 × w 16 × h 16 × bits communication overhead. Therefore, it theoretically requires O(wh) bits to run SRPN. Then, suppose the mini-batch size to be Ncls and the number of anchors proposed by SPRN to be Nreg. O((Ncls+Nreg)) bits are exchanged during the secure classification and bounding box regression stages" Ma explicitly splits each pixel into random shares, shows that corresponding random shares recover the original image by addition, and analyzes communication using a fixed data storage length l per item, supporting that each respective data item has a corresponding data item in each of the first parts and that the corresponding item is represented with the same number of bits (l)).
Liu as well as Ma are directed towards distributed convolutional neural networks for privacy preserving. Therefore, Liu as well as Ma are analogous art in the same field of endeavor. It would have been obvious before the effective filing date of the claimed invention to combine Liu's mixed/withheld parts with Ma's secret sharing. The combination predictably yields stronger privacy against adversarial attacks without undermining either respective arts workflow. Ma provides as additional motivation for combination ([p. 81] “As shown in Fig. 11(c), Fig. 11(g) and Fig. 11(k), the runtime needed by SDiv, SLog or SExp is obviously less than the previous secure sub-protocols. The decrease is because the messages exchanged in our CORDIC based protocols are greatly reduced”). This motivation for combination also applies to the remaining claims which depend on this combination.
Claims 10 and 11 are rejected under U.S.C. §103 as being unpatentable over the combination of Liu and Ma and in further view of Ghodrati (US 20220350662 A1).
Regarding claim 10, the combination of Liu, and Ma teaches The method of claim 9.
However, the combination of Liu, and Ma doesn't explicitly teach, wherein the same operation is configured to be performed via multiply-accumulate units.
Ghodrati, in the same field of endeavor, teaches The method of claim 9, wherein the same operation is configured to be performed via multiply-accumulate units.([¶0032] "the large majority of DNN operations belong to convolution and fully-connected layers. Table 1 shows percentage of operations in different layers of various DNN models. Normally, the convolution and fully-connected layers are broken down into a series of vector dot-products that generate a scalar and comprise a set of Multiply-Accumulate (MACC) operations. Certain digital and mixed-signal accelerators use a large array of stand-alone MACC units to perform the necessary computations. When moving to the mixed-signal domain, this stand-alone arrangement of MACC operations imposes significant overhead in the form of Analog-to-Digital (A/D) and Digital-to-Analog (D/A) conversions for each operation due to the high cost of converting the operands and outputs of each MACC to and from the analog domain" [¶0077] "Evaluated benchmarked DNNs [...]ResNet-18").
The combination of Liu and Ma as well as Ghodrati are directed towards convolutional neural networks. Therefore, the combination of Liu and Ma as well as Ghodrati are reasonably pertinent analogous art. It would have been obvious before the effective filing date of the claimed invention to use the hardware accelerator in Ghodrati for executing the ResNet-18 model in Liu. Ghodrati explicitly uses their hardware for private results on ResNet-18. Ghodrati provides as additional motivation for combination ([¶0085] “FIG. 7 shows example performance and energy reduction of the BIHIWE accelerator over the TETRIS accelerator under the same on-chip power budget in accordance with one or more embodiments of the present technology. On average, BIHIWE delivers a 4.5 times speedup over TETRIS. This significant speedup over TETRIS is attributed to the use of wide mixed-signal MS-BPMACC units in BIHIWE as opposed to PEs in TETRIS. The wide bit-partitioned mixed-signal design of MS-BPMACC in the BIHIWE architecture enables us to cram around 5 times more compute units within the same on-chip power budget as TETRIS. The highest speedup is observed in CIFAR-10, where its network configurations enable the BIHIWE architecture to better utilize the on-chip compute resources” See also Table 5 for ResNet-18 specific performance).
Regarding claim 11, the combination of Liu, Ma, and Ghodrati teaches The method of claim 10, further comprising: generating, by the computing device from a description of a first artificial neural network, a description of a second artificial neural network describing the same operation to be performed using a deep learning accelerator of the first entity.(Liu [p. 8] "Fig.5. Partitioning the neural network into three parts [...] During the inference, the edge first runs the preprocess model on the raw inputs and sends its output (i.e., intermediate input) to the cloud; then, the cloud runs the main model and transmits its output (i.e., intermediate output) back to the edge; finally, the edge executes the postprocess model to obtain the final output." See also FIG. 5).
Conclusion
THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to SIDNEY VINCENT BOSTWICK whose telephone number is (571)272-4720. The examiner can normally be reached M-F 7:30am-5:00pm EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Miranda Huang can be reached on (571)270-7092. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/SIDNEY VINCENT BOSTWICK/Examiner, Art Unit 2124 /MIRANDA M HUANG/Supervisory Patent Examiner, Art Unit 2124