Prosecution Insights
Last updated: October 02, 2026
Application No. 17/767,269

Event Detection in a Data Stream

Final Rejection §101§103
Filed
Apr 07, 2022
Priority
Oct 09, 2019 — nonprovisional of PCTEP2019077413
Examiner
GRUSZKA, DANIEL PATRICK
Art Unit
2121
Tech Center
2100 — Computer Architecture & Software
Assignee
Telefonaktiebolaget LM Ericsson
OA Round
3 (Final)
40%
Grant Probability
Moderate
4-5
OA Rounds
0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 40% of resolved cases
40%
Career Allowance Rate
2 granted / 5 resolved
-15.0% vs TC avg
Strong +67% interview lift
Without
With
+66.7%
Interview Lift
resolved cases with interview
Typical timeline
4y 4m
Avg Prosecution
26 currently pending
Career history
44
Total Applications
across all art units

Statute-Specific Performance

§101
34.7%
-5.3% vs TC avg
§103
52.5%
+12.5% vs TC avg
§102
6.9%
-33.1% vs TC avg
§112
5.0%
-35.0% vs TC avg
Black line = Tech Center average estimate • Based on career data from 5 resolved cases

Office Action

§101 §103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Arguments Applicant’s arguments with respect to 35 U.S.C § 101 filed 12/17/2025 have been fully considered but they are not persuasive. Applicant argues the claimed invention are not directed to an abstract idea (applicant’s arguments pages 11-13) because the claim recites a technical improvement. The examiner respectfully disagrees. The claimed invention is directed to detecting an event from concentrated information, generating an evaluation for the event and finally using a reinforcement learning algorithm to refine hyperparameters. Given the broadest reasonable interpretation these are all consider mental processes. Looking at data/concentrated information a human could identify an event. Having an event and a knowledge base one could create an evaluation for the given event. Finally, an algorithm is considered multiple steps/calculation to be performed in a given order and given its broadest reasonable interpretation this could be performed by a human. Applicant states that the “adaptation of hyperparameters improves online event detection with minimal human intervention” (bottom of page 12 of applicant’s arguments). The improvement cannot come from the abstract idea alone. The only additional element of the claim is using a machine learning algorithm to concentrate information. It is unclear how this shows the improvement. Thus, the 101 rejection is maintained. Applicant’s arguments with respect to 35 U.S.C § 103 (specifically the mapping of reference Thing being improper) filed 12/17/2025 have been fully considered but they are not persuasive. Applicant argues that the mapping of Thing to the “hyperparameter” limitation is deficient. Thing is being used to teach using a machine learning algorithm to concentrate information in the data stream, wherein the machine learning algorithm is configured according to at least one hyperparameter. Thing is being used to explicitly teach encoding information using an autoencoder. The parameters cited in the reference and mapping are not hyperparameters but Thing does say “The first hidden layer consists of 256 neurons, and the second hidden layer is made up of 128 neurons, while the third layer is composed of 64 neurons.” Number of neurons are a type of hyperparameter and thus the autoencoder is configured according to a hyperparameter. The rest of applicant’s arguments with respect to 35 U.S.C § 103 filed 12/17/2025 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. Claim Interpretation The following is a quotation of 35 U.S.C. 112(f): (f) Element in Claim for a Combination. – An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof. The following is a quotation of pre-AIA 35 U.S.C. 112, sixth paragraph: An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof. The claims in this application are given their broadest reasonable interpretation using the plain meaning of the claim language in light of the specification as it would be understood by one of ordinary skill in the art. The broadest reasonable interpretation of a claim element (also commonly referred to as a claim limitation) is limited by the description in the specification when 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is invoked. As explained in MPEP § 2181, subsection I, claim limitations that meet the following three-prong test will be interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph: (A) the claim limitation uses the term “means” or “step” or a term used as a substitute for “means” that is a generic placeholder (also called a nonce term or a non-structural term having no specific structural meaning) for performing the claimed function; (B) the term “means” or “step” or the generic placeholder is modified by functional language, typically, but not always linked by the transition word “for” (e.g., “means for”) or another linking word or phrase, such as “configured to” or “so that”; and (C) the term “means” or “step” or the generic placeholder is not modified by sufficient structure, material, or acts for performing the claimed function. Use of the word “means” (or “step”) in a claim with functional language creates a rebuttable presumption that the claim limitation is to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites sufficient structure, material, or acts to entirely perform the recited function. Absence of the word “means” (or “step”) in a claim creates a rebuttable presumption that the claim limitation is not to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is not interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites function without reciting sufficient structure, material or acts to entirely perform the recited function. Claim limitations in this application that use the word “means” (or “step”) are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action. Conversely, claim limitations in this application that do not use the word “means” (or “step”) are not being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action. This application includes one or more claim limitations that do not use the word “means,” but are nonetheless being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, because the claim limitation(s) uses a generic placeholder that is coupled with functional language without reciting sufficient structure to perform the recited function and the generic placeholder is not preceded by a structural modifier. Such claim limitation in claim 44 is: The system configured to… The System is a generic placeholder without definite structure, and is described in purely functional terms using “configured to” language rather than reciting how the functions are performed. As a result, it is interpreted as means-plus-function limitation under 35 U.S.C 112(f). Because this/these claim limitation(s) is/are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, it/they is/are being interpreted to cover the corresponding structure described in the specification as performing the claimed function, and equivalents thereof. If applicant does not intend to have this/these limitation(s) interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, applicant may: (1) amend the claim limitation(s) to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph (e.g., by reciting sufficient structure to perform the claimed function); or (2) present a sufficient showing that the claim limitation(s) recite(s) sufficient structure to perform the claimed function so as to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 27-51 are rejected under 35 U.S.C. 101 because the claimed invention is directed to a judicial exception (i.e., a law of nature, a natural phenomenon, or an abstract idea) without significantly more. 101 Subject Matter Eligibility Analysis Step 1: Claims 27-51 are within the four statutory (a process, machine, manufacture or composition of matter.) Claims 27-43, 50-51 describe a process and 44-49 describe a machine. With respect to claim 27: Step 2A Prong 1: The claim recites an abstract idea enumerated in the 2019 PEG. detecting an event from the concentrated information; (This is an abstract idea of a "Mental Process." The "detecting" step under its broadest reasonable interpretation, covers concepts that can be practically performed in the human mind. The detection could be made manually by an individual.) generating an evaluation of the detected event on the basis of logical compatibility between the detected event and a knowledge base; and (This is an abstract idea of a "Mental Process." The "generating" step under its broadest reasonable interpretation, covers concepts that can be practically performed in the human mind. The generating could be done manually by an individual.) using a Reinforcement Learning (RL) algorithm to refine the at least one hyperparameter of the machine learning algorithm, wherein a reward function of the RL algorithm is calculated on the basis of the generated evaluation (This is an abstract idea of a "Mental Process." The "Reinforcement Learning (RL) algorithm" step under its broadest reasonable interpretation, covers concepts that can be practically performed in the human mind. An algorithm is considered multiple steps/calculation to be performed in a given order and given its broadest reasonable interpretation this could be performed by a human.) Step 2A Prong 2: The judicial exception is not integrated into a practical application Additional elements: using a machine learning algorithm to concentrate information in the data stream, wherein the machine learning algorithm is configured according to at least one hyperparameter; (This amounts to no more than mere instructions to “apply” the exception using a generic computer component.) Step 2B: the claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception The additional element “using a machine learning algorithm…” is recited in a generic level and they represent generic computer components to apply the abstract idea. Mere instructions to apply an exception cannot provide an inventive concept (MPEP 2106.05(f)). Therefore, claim 27 is ineligible. With respect to claim 28: Step 2A Prong 1: claim 28, which incorporates the rejection of claim 28, does not recite an abstract idea. Step 2a Prong 2: The judicial exception is not integrated into a practical application. the machine learning algorithm is an autoencoder and wherein the method further comprises using an Unsupervised Learning (UL) algorithm to determine a number of layers in the autoencoder and a number of neurons in each layer of the autoencoder on the basis of at least one of: a parameter associated with the data stream; or the at least one hyperparameter. (This amounts to no more than mere instructions to “apply” the exception using a generic computer component.) Step 2B: the claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception The additional element is recited in a generic level and they represent generic computer components to apply the abstract idea. Mere instructions to apply an exception cannot provide an inventive concept (MPEP 2106.05(f)). Therefore, claim 28 is ineligible. With respect to claim 29: Step 2A Prong 1: claim 29, which incorporates the rejection of claim 28, does not recite an abstract idea. Step 2a Prong 2: The judicial exception is not integrated into a practical application. the parameter associated with the data stream comprises at least one of: a data transmission frequency associated with the data stream; or a dimensionality associated with the data stream. (this limitation merely limits the judicial exception to a particular field of use.) Step 2B: the claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception The additional element merely limits the judicial exception to a particular field of use and also cannot provide an inventive concept (MPEP 2106.05(h)). Therefore, claim 29 is ineligible. With respect to claim 30: Step 2A Prong 1: claim 30, which incorporates the rejection of claim 27, does not recite an abstract idea. Step 2a Prong 2: The judicial exception is not integrated into a practical application. the at least one hyperparameter comprises: a time interval associated with a window; a scaling factor; a layer number decreasing rate. (This amounts to no more than mere instructions to “apply” the exception using a generic computer component.) Step 2B: the claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception The additional element is recited in a generic level and they represent generic computer components to apply the abstract idea. Mere instructions to apply an exception cannot provide an inventive concept (MPEP 2106.05(f)). Therefore, claim 30 is ineligible With respect to claim 31: Step 2A Prong 1: claim 31, which incorporates the rejection of claim 27, recites an abstract idea. dividing the data stream into one or more sub-streams of data; (This is an abstract idea of a "Mental Process." The "dividing" step under its broadest reasonable interpretation, covers concepts that can be practically performed in the human mind. The dividing could be done manually by an individual.) Step 2a Prong 2: The judicial exception is not integrated into a practical application. the machine learning algorithm comprises a distributed, stacked autoencoder, and wherein using the distributed stacked autoencoder comprises (This amounts to no more than mere instructions to “apply” the exception using a generic computer component.) using a different autoencoder of the distributed stacked autoencoder to concentrate the information in each respective sub-stream; and (This amounts to no more than mere instructions to “apply” the exception using a generic computer component.) providing the concentrated sub-streams to another autoencoder in another level of a hierarchy of the stacked autoencoder. (this limitation amounts to adding insignificant extra-solution activity to the judicial exception). Step 2B: the claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception The additional elements “the machine learning algorithm…” and “using a different autoencoder…” are recited in a generic level and they represent generic computer components to apply the abstract idea. Mere instructions to apply an exception cannot provide an inventive concept (MPEP 2106.05(f)). The additional element “providing…” adds insignificant extra-solution activity to the judicial exception and cannot provide an inventive concept. Storing and retrieving information in memory is directed to a well understood routine conventional activity of data transmission (MPEP 2106.05(d)(II)(iv)) When considered in combination, these additional elements represent insignificant extra-solution activity and mere instructions to apply an expectation, which do not provide an inventive concept. Therefore, claim 31 is ineligible. With respect to claim 32: Step 2A Prong 1: claim 32, which incorporates the rejection of claim 27, recites an additional abstract idea: dividing the accumulated data stream into a plurality of consecutive windows, each window corresponding to a different time interval; and (This is an abstract idea of a "Mental Process." The "dividing" step under its broadest reasonable interpretation, covers concepts that can be practically performed in the human mind. The dividing could be done manually by an individual.) Step 2a Prong 2: The judicial exception is not integrated into a practical application. accumulating data in the data stream; and (this limitation amounts to adding insignificant extra-solution activity to the judicial exception). wherein using the machine learning algorithm comprises concentrating the information in the windowed data. (This amounts to no more than mere instructions to “apply” the exception using a generic computer component.) Step 2B: the claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception The additional element “accumulating…” adds insignificant extra-solution activity to the judicial exception and cannot provide an inventive concept. Storing and retrieving information in memory is directed to a well understood routine conventional activity of data transmission (MPEP 2106.05(d)(II)(iv)) The additional element “wherein using the machine learning algorithm…” is recited in a generic level and they represent generic computer components to apply the abstract idea. Mere instructions to apply an exception cannot provide an inventive concept (MPEP 2106.05(f)). When considered in combination, these additional elements represent insignificant extra-solution activity and mere instructions to apply an expectation, which do not provide an inventive concept. Therefore, claim 32 is ineligible. With respect to claim 33: Step 2A Prong 1: claim 33, which incorporates the rejection of claim 27, recites an additional abstract idea: comparing different portions of the accumulated concentrated data. (This is an abstract idea of a "Mental Process." The "comparing" step under its broadest reasonable interpretation, covers concepts that can be practically performed in the human mind. The comparison could be done manually by an individual.) Step 2a Prong 2: The judicial exception is not integrated into a practical application. accumulating the concentrated information over time; and (this limitation amounts to adding insignificant extra-solution activity to the judicial exception). Step 2B: the claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception The additional element adds insignificant extra-solution activity to the judicial exception and cannot provide an inventive concept. Storing and retrieving information in memory is directed to a well understood routine conventional activity of data transmission (MPEP 2106.05(d)(II)(iv)) Therefore, claim 33 is ineligible. With respect to claim 34: Step 2A Prong 1: claim 34, which incorporates the rejection of claim 33, recites an additional abstract idea: detecting the event from the concentrated information further comprises using a cosine difference to compare the different portions of the accumulated concentrated data. (This is an abstract idea of a "Mental Process." The "detecting" step under its broadest reasonable interpretation, covers concepts that can be practically performed in the human mind. The detection could be made manually by an individual.) Step 2a Prong 2: claim 34 does not recite any additional elements and thus cannot be integrated into a practical application. Step 2B: claim 34 does not recite an additional element. Therefore, claim 34 is ineligible. With respect to claim 35: Step 2A Prong 1: claim 35, which incorporates the rejection of claim 33, recites an additional abstract idea: using at least one event detected by comparing different portions of the accumulated concentrated data to generate a label for a training data set comprising concentrated information from the data stream; (This is an abstract idea of a "Mental Process." The "detecting" step under its broadest reasonable interpretation, covers concepts that can be practically performed in the human mind. The detection could be made manually by an individual.) Step 2a Prong 2: The judicial exception is not integrated into a practical application. using the training data set to train a Supervised Learning (SL) model; and (This amounts to no more than mere instructions to “apply” the exception using a generic computer component.) using the SL model to detect the event from the concentrated information. (This amounts to no more than mere instructions to “apply” the exception using a generic computer component.) Step 2B: the claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception The additional elements “using the training data…” and “using the SL model…” are recited in a generic level and they represent generic computer components to apply the abstract idea. Mere instructions to apply an exception cannot provide an inventive concept (MPEP 2106.05(f)). When considered in combination, these additional elements represent mere instructions to apply an expectation, which does not provide an inventive concept. Therefore, claim 35 is ineligible. With respect to claim 36: Step 2A Prong 1: claim 36, which incorporates the rejection of claim 27, recites an additional abstract idea: and evaluating the compatibility of the logical assertion with the contents of the knowledge base; (This is an abstract idea of a "Mental Process." The "evaluating" step under its broadest reasonable interpretation, covers concepts that can be practically performed in the human mind. The evaluation could be made manually by an individual.) Step 2a Prong 2: The judicial exception is not integrated into a practical application. converting parameter values corresponding to the detected event into a logical assertion; (this limitation amounts to adding insignificant extra-solution activity to the judicial exception). wherein the contents of the knowledge base comprises at least one of a rule or a fact. (this limitation amounts to adding insignificant extra-solution activity to the judicial exception). Step 2B: the claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception The additional elements “converting parameter…” and “wherein the contents…” adds insignificant extra-solution activity to the judicial exception and cannot provide an inventive concept. Storing and retrieving information in memory is directed to a well understood routine conventional activity of data transmission (MPEP 2106.05(d)(II)(iv)) When considered in combination, these additional elements represent insignificant extra-solution activity, which does not provide an inventive concept. Therefore, claim 36 is ineligible. With respect to claim 37: Step 2A Prong 1: claim 37, which incorporates the rejection of claim 36, recites an additional abstract idea: generating the evaluation of the detected event further comprises performing at least one of incrementing or decrementing an evaluation score for each logical conflict between the logical assertion and the fact or rule in the knowledge base. (This is an abstract idea of a "Mental Process." The "generating" step under its broadest reasonable interpretation, covers concepts that can be practically performed in the human mind. The generation could be made manually by an individual.) Step 2a Prong 2: claim 37 does not recite any additional elements and thus cannot be integrated into a practical application. Step 2B: claim 37 does not recite an additional element. Therefore, claim 37 is ineligible. With respect to claim 38: Step 2A Prong 1: claim 38, which incorporates the rejection of claim 27, does not recite an abstract idea. Step 2a Prong 2: The judicial exception is not integrated into a practical application. an operating environment of at least some of the plurality of devices; (This amounts to no more than mere instructions to “apply” the exception using a generic computer component.) an operating domain of at least some of the plurality of devices; (This amounts to no more than mere instructions to “apply” the exception using a generic computer component.) a service agreement applying to at least some of the plurality of devices; or (This amounts to no more than mere instructions to “apply” the exception using a generic computer component.) a deployment specification applying to at least some of the plurality of devices. (This amounts to no more than mere instructions to “apply” the exception using a generic computer component.) Step 2B: the claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception The additional elements are recited in a generic level and they represent generic computer components to apply the abstract idea. Mere instructions to apply an exception cannot provide an inventive concept (MPEP 2106.05(f)). When considered in combination, these additional elements represent mere instructions to apply an expectation, which does not provide an inventive concept. Therefore, claim 38 is ineligible. With respect to claim 39: Step 2A Prong 1: claim 39, which incorporates the rejection of claim 27, does not recite an abstract idea. Step 2a Prong 2: The judicial exception is not integrated into a practical application. updating the knowledge base to include a detected event that is logically compatible with the knowledge base. (this limitation amounts to adding insignificant extra-solution activity to the judicial exception). Step 2B: the claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception The additional element adds insignificant extra-solution activity to the judicial exception and cannot provide an inventive concept. Storing and retrieving information in memory is directed to a well understood routine conventional activity of data transmission (MPEP 2106.05(d)(II)(iv)) Therefore, claim 39 is ineligible. With respect to claim 40: Step 2A Prong 1: claim 40, which incorporates the rejection of claim 27, recites an additional abstract idea: generating the evaluation of the detected event further on the basis of an error value generated during at least one of concentration of information in the data stream or detection of an event from the concentrated information. (This is an abstract idea of a "Mental Process." The "generating" step under its broadest reasonable interpretation, covers concepts that can be practically performed in the human mind. The generation could be made manually by an individual.) Step 2a Prong 2: claim 40 does not recite any additional elements and thus cannot be integrated into a practical application. Step 2B: claim 40 does not recite an additional element. Therefore, claim 40 is ineligible. With respect to claim 41: Step 2A Prong 1: claim 41, which incorporates the rejection of claim 27, recites an additional abstract idea: using the RL algorithm to trial different values of the at least one hyperparameter and to determine a value of the at least one hyperparameter that is associated with a maximum value of the reward function. (This is an abstract idea of a "Mental Process." The "Reinforcement Learning (RL) algorithm" step under its broadest reasonable interpretation, covers concepts that can be practically performed in the human mind. An algorithm is considered multiple steps/calculation to be performed in a given order and given its broadest reasonable interpretation this could be performed by a human.) Step 2a Prong 2: claim 41 does not recite any additional elements and thus cannot be integrated into a practical application. Step 2B: claim 41 does not recite an additional element. Therefore, claim 41 is ineligible. With respect to claim 42: Step 2A Prong 1: claim 42, which incorporates the rejection of claim 27, recites an additional abstract idea: selecting an action to be performed on the machine learning algorithm as a function of the established state; (This is an abstract idea of a "Mental Process." The "selecting" step under its broadest reasonable interpretation, covers concepts that can be practically performed in the human mind. The selection could be made manually by an individual.) calculating a value of a reward function following performance of the selected action; (this is an abstract idea of a “mathematical concept”. The recited “calculating” represents mathematical operations that would fall under the “mathematical concepts” grouping.) Step 2a Prong 2: The judicial exception is not integrated into a practical application. establishing a state of the machine learning algorithm, wherein the state of the machine learning algorithm is represented by the value of the at least one hyperparameter; (This amounts to no more than mere instructions to “apply” the exception using a generic computer component.) causing the selected action to be performed on the machine learning algorithm; and (This amounts to no more than mere instructions to “apply” the exception using a generic computer component.) wherein selecting the action to be performed on the machine learning algorithm as a function of the established state comprises selecting the action from a set of actions comprising incrementation and decrementation of the value of the at least one hyperparameter. (This amounts to no more than mere instructions to “apply” the exception using a generic computer component.) Step 2B: the claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception The additional elements are recited in a generic level and they represent generic computer components to apply the abstract idea. Mere instructions to apply an exception cannot provide an inventive concept (MPEP 2106.05(f)). When considered in combination, these additional elements represent mere instructions to apply an expectation, which does not provide an inventive concept. Therefore, claim 42 is ineligible. With respect to claim 43: Step 2A Prong 1: claim 43, which incorporates the rejection of claim 27, does not recite an abstract idea. Step 2a Prong 2: The judicial exception is not integrated into a practical application. the plurality of devices connected by a communications network comprises a plurality of constrained devices. (This amounts to no more than mere instructions to “apply” the exception using a generic computer component.) Step 2B: the claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception The additional element is recited in a generic level and they represent generic computer components to apply the abstract idea. Mere instructions to apply an exception cannot provide an inventive concept (MPEP 2106.05(f)). Therefore, claim 43 is ineligible. With respect to claim 44: Step 2A Prong 1: The claim recites an abstract idea enumerated in the 2019 PEG. detect an event from the concentrated information; (This is an abstract idea of a "Mental Process." The "detect" step under its broadest reasonable interpretation, covers concepts that can be practically performed in the human mind. The detection could be made manually by an individual.) generate an evaluation of the detected event on the basis of logical compatibility between the detected event and a knowledge base; and (This is an abstract idea of a "Mental Process." The "generate" step under its broadest reasonable interpretation, covers concepts that can be practically performed in the human mind. The generation could be made manually by an individual.) use a Reinforcement Learning (RL) algorithm to refine the at least one hyperparameter of the machine learning algorithm, wherein a reward function of the RL algorithm is calculated on the basis of the generated evaluation. (This is an abstract idea of a "Mental Process." The "Reinforcement Learning (RL) algorithm" step under its broadest reasonable interpretation, covers concepts that can be practically performed in the human mind. An algorithm is considered multiple steps/calculation to be performed in a given order and given its broadest reasonable interpretation this could be performed by a human.) Step 2a Prong 2: The judicial exception is not integrated into a practical application. use a machine learning algorithm to concentrate information in the data stream, wherein the machine learning algorithm is configured according to at least one hyperparameter; (This amounts to no more than mere instructions to “apply” the exception using a generic computer component.) Step 2B: the claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception The additional element is recited in a generic level and they represent generic computer components to apply the abstract idea. Mere instructions to apply an exception cannot provide an inventive concept (MPEP 2106.05(f)). Therefore, claim 44 is ineligible. With respect to claim 45: Step 2A Prong 1: claim 45, which incorporates the rejection of claim 44, recites an additional abstract idea: a data processing function configured to use the machine learning algorithm to concentrate information in the data stream, wherein the machine learning algorithm is configured according to the at least one hyperparameter; (this is an abstract idea of a “mathematical concept”. The recited “function” represents a mathematical function that would fall under the “mathematical concepts” grouping.) an event detection function configured to detect the event from the concentrated information; (this is an abstract idea of a “mathematical concept”. The recited “function” represents a mathematical function that would fall under the “mathematical concepts” grouping.) an evaluation function configured to generate the evaluation of the detected event on the basis of logical compatibility between the detected event and the knowledge base; (this is an abstract idea of a “mathematical concept”. The recited “function” represents a mathematical function that would fall under the “mathematical concepts” grouping.) and a learning function configured to use the RL algorithm to refine the at least one hyperparameter of the machine learning algorithm, wherein the reward function of the RL algorithm is calculated on the basis of the generated evaluation. (this is an abstract idea of a “mathematical concept”. The recited “function” represents a mathematical function that would fall under the “mathematical concepts” grouping.) Step 2a Prong 2: claim 45 does not recite any additional elements and thus cannot be integrated into a practical application. Step 2B: claim 45 does not recite an additional element. Therefore, claim 45 is ineligible. With respect to claim 46: Step 2A Prong 1: claim 46, which incorporates the rejection of claim 45, does not recite an abstract idea. Step 2a Prong 2: The judicial exception is not integrated into a practical application. at least one of the functions comprises a virtualised function. (This amounts to no more than mere instructions to “apply” the exception using a generic computer component.) Step 2B: the claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception The additional element is recited in a generic level and they represent generic computer components to apply the abstract idea. Mere instructions to apply an exception cannot provide an inventive concept (MPEP 2106.05(f)). Therefore, claim 46 is ineligible. With respect to claim 47: Step 2A Prong 1: claim 47, which incorporates the rejection of claim 45, does not recite an abstract idea. Step 2a Prong 2: The judicial exception is not integrated into a practical application. the functions are distributed across different physical nodes. (This amounts to no more than mere instructions to “apply” the exception using a generic computer component.) Step 2B: the claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception The additional element is recited in a generic level and they represent generic computer components to apply the abstract idea. Mere instructions to apply an exception cannot provide an inventive concept (MPEP 2106.05(f)). Therefore, claim 47 is ineligible. With respect to claim 48: Step 2A Prong 1: claim 48, which incorporates the rejection of claim 45, recites an additional abstract idea: converting parameter values corresponding to the detected event into a logical assertion; (This is an abstract idea of a "Mental Process." The "converting" step under its broadest reasonable interpretation, covers concepts that can be practically performed in the human mind. The conversion could be done manually by an individual.) and evaluating the compatibility of the logical assertion with the contents of the knowledge base, wherein the contents of the knowledge base comprise at least one of a rule or a fact. (This is an abstract idea of a "Mental Process." The "evaluating" step under its broadest reasonable interpretation, covers concepts that can be practically performed in the human mind. The evaluation could be made manually by an individual.) Step 2a Prong 2: claim 48 does not recite any additional elements and thus cannot be integrated into a practical application. Step 2B: claim 48 does not recite an additional element. Therefore, claim 48 is ineligible. With respect to claim 49: Step 2A Prong 1: claim 49, which incorporates the rejection of claim 48, recites an additional abstract idea: the evaluation function is further configured to generate the evaluation of the detected event by performing at least one of incrementing or decrementing an evaluation score for each logical conflict between the logical assertion and the rule or the fact in the knowledge base. (This is an abstract idea of a "Mental Process." The "evaluation" step under its broadest reasonable interpretation, covers concepts that can be practically performed in the human mind. The evaluation could be made manually by an individual.) Step 2a Prong 2: claim 49 does not recite any additional elements and thus cannot be integrated into a practical application. Step 2B: claim 49 does not recite an additional element. Therefore, claim 49 is ineligible. With respect to claim 50: Step 2A Prong 1: The claim recites an abstract idea enumerated in the 2019 PEG. using a Reinforcement Learning (RL) algorithm to refine the at least one hyperparameter of the machine learning algorithm, wherein a reward function of the RL algorithm is calculated on the basis of the evaluation. (This is an abstract idea of a "Mental Process." The "Reinforcement Learning (RL) algorithm" step under its broadest reasonable interpretation, covers concepts that can be practically performed in the human mind. An algorithm is considered multiple steps/calculation to be performed in a given order and given its broadest reasonable interpretation this could be performed by a human.) Step 2a Prong 2: The judicial exception is not integrated into a practical application. receiving a notification of a detected event, wherein the event has been detected from information concentrated from the data stream using a machine learning algorithm that is configured according to at least one hyperparameter; (this limitation amounts to adding insignificant extra-solution activity to the judicial exception). receiving an evaluation of the detected event, wherein the evaluation has been generated on the basis of logical compatibility between the detected event and a knowledge base; and (this limitation amounts to adding insignificant extra-solution activity to the judicial exception). Step 2B: the claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception The additional elements add insignificant extra-solution activity to the judicial exception and cannot provide an inventive concept. Storing and retrieving information in memory is directed to a well understood routine conventional activity of data transmission (MPEP 2106.05(d)(II)(iv)) When considered in combination, these additional elements represent insignificant extra-solution activity, which does not provide an inventive concept. Therefore, claim 50 is ineligible. With respect to claim 51: The claim recites similar limitations as corresponding to claim 50. Therefore, the same subject matter analysis that was utilized for claim 50, as described above, is equally applicable to claim 51. Therefore, claim 51 is ineligible. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 27-51 are rejected under 35 U.S.C 103 as being unpatentable over Bhuyan (NPL ‘Network Anomaly Detection: Methods, Systems and Tools’ (2014)) in view of Thing (NPL ‘IEEE 802.11 Network Anomaly Detection and Attack Classification: A Deep Learning Approach’ (2013)) and Jomaa (NPL ‘Hyp-RL: Hyperparameter Optimization by Reinforcement learning’ (from applications IDS)). Regarding claim 27, Bhuyan teaches: A method for performing event detection on a data stream, the data stream comprising data from a plurality of devices connected by a communications network, the method comprising (Introduction “The term anomaly-based intrusion detection in networks refers to the problem of finding exceptional patterns in network traffic that do not conform to the expected normal behavior.”) detecting an event from the concentrated information; (Section B: The Problem of Anomaly Detection “Consequently, an event or an object is detected as anomalous if its degree of deviation with respect to the profile or behavior of the system, specified by the normality model, is high enough”) generating an evaluation of the detected event on the basis of logical compatibility between the detected event and a knowledge base; and (Section E: Knowledge-based methods and systems “The audit data preprocessor reformats the raw audit data to send as input to the inference engine. The inference engine monitors the state transitions extracted from the preprocessed audit data and then compares these states with the states available within the knowledge base. The decision engine monitors the improvement of the inference engine for matching accuracy of the state transitions. It also specifies the action(s) to be taken based on results of the inference engine and the decision table.”) Bhuyan does not teach: using a machine learning algorithm to concentrate information in the data stream, wherein the machine learning algorithm is configured according to at least one hyperparameter; using a Reinforcement Learning (RL) algorithm to refine the at least one hyperparameter of the machine learning algorithm, wherein a reward function of the RL algorithm is calculated on the basis of the generated evaluation. Thing does teach using a machine learning algorithm to concentrate information in the data stream, wherein the machine learning algorithm is configured according to at least one hyperparameter (IV. Proposed Deep Learning Approach “Consider a SAE with parameters W l , b l , denoting the parameters for the l th auto-encoder. The output of the l th layer with its input z l is the auto-encoder, a ( l ) . The encoding of the input feature vectors over the SAE is carried out by encoding each forward layer”) Bhuyan and Thing are considered analogous art to the claimed invention because they are in the same field of endeavor being event detection. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the event detection system of Bhuyan with the autoencoder of Thing. One would want to do this to encode the data. Neither Bhuyan nor Thing teach using a Reinforcement Learning (RL) algorithm to refine the at least one hyperparameter of the machine learning algorithm, wherein a reward function of the RL algorithm is calculated on the basis of the generated evaluation. Jomaa does teach this (Start of page 6 “The reward function is set as the hyperparameter response function, and depends on the data set D and the action selected, as shown below: [equation 9] considering that the agent's task is to maximize the reward. The observed reward depends solely on the data set and the hyperparameter configuration selected. Once an action is selected, a new hyperparameter configuration is evaluated.”) Bhuyan, Thing and Jomaa are considered analogous art to the claimed invention because they are in the same field of endeavor being neural network architectures. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the event detection system of Bhuyan with the autoencoder of Thing with the reinforcement learning of Jomaa. One would want to do this to enable adaptive tuning of model hyperparameters and improve event detection accuracy. Regarding claim 28, Bhuyan in view of Thing and Jomaa teaches claim 27 as outlined above. Jomaa further teaches: the machine learning algorithm is an autoencoder and wherein the method further comprises using an Unsupervised Learning (UL) algorithm to determine a number of layers in the autoencoder and a number of neurons in each layer of the autoencoder on the basis of at least one of: a parameter associated with the data stream; or the at least one hyperparameter. (End of page 8 and start of page 9 “Three different groups of hyper-parameters are investigated to generate the meta-data set: structure-based which can be summarized by the number of layers, number of neurons and activation function; optimization-based which include the type of optimizer and the number of epochs; and regularization-based which include dropout rate, regularization technique and the regularization constant.”). Regarding claim 29, Bhuyan in view of Thing and Jomaa teaches claim 28 as outlined above. Bhuyan further teaches: the parameter associated with the data stream comprises at least one of: a data transmission frequency associated with the data stream; or a dimensionality associated with the data stream. (Section B. Aspects of Network Anomaly Detection “the data covariance with d number of attributes, i.e., dimensions.”). Regarding claim 30, Bhuyan in view of Thing and Jomaa teaches claim 27 as outlined above. Bhuyan further teaches: the at least one hyperparameter comprises: a time interval associated with a window; a scaling factor; a layer number decreasing rate. (Section C. Clustering and Outlier-based methods and systems “The first step of MINDS is to extract important features that are used. Then, it summarizes the features based on time windows. After the feature construction step, the known attack detection module is used to detect network connections that correspond to attacks for which signatures are available, and to remove them from further analysis. Next, an outlier technique is activated to assign an anomaly score to each network connection.”) Regarding claim 31, Bhuyan in view of Thing and Jomaa teaches claim 27 as outlined above. Thing further teaches: the machine learning algorithm comprises a distributed, stacked autoencoder, and wherein using the distributed stacked autoencoder comprises: (IV. Proposed Deep Learning Approach “To achieve this, we utilized a Stacked Auto-encoder (SAE), which is a neural network built by stacking multiple layers of sparse auto-encoders”) dividing the data stream into one or more sub-streams of data; using a different autoencoder of the distributed stacked autoencoder to concentrate the information in each respective sub-stream; and providing the concentrated sub-streams to another autoencoder in another level of a hierarchy of the stacked autoencoder. (IV. Proposed Deep Learning Approach “The output of each layer forms the input to the successive layer. We proposed two frameworks, which are composed of two and three hidden layers, respectively. The first layer learns the first order features from the raw inputs, while the second layer learns the features corresponding to the patterns from the first order features. The third layer in the second framework learns the features corresponding to the patterns from the second order features”). Regarding claim 32, Bhuyan in view of Thing and Jomaa teaches claim 27 as outlined above. Bhuyan further teaches: accumulating data in the data stream; and dividing the accumulated data stream into a plurality of consecutive windows, each window corresponding to a different time interval; and wherein using the machine learning algorithm comprises concentrating the information in the windowed data (Section C. Clustering and Outlier-based methods and systems “The first step of MINDS is to extract important features that are used. Then, it summarizes the features based on time windows. After the feature construction step, the known attack detection module is used to detect network connections that correspond to attacks for which signatures are available, and to remove them from further analysis. Next, an outlier technique is activated to assign an anomaly score to each network connection.”) Regarding claim 33, Bhuyan in view of Thing and Jomaa teaches claim 27 as outlined above. Bhuyan further teaches: accumulating the concentrated information over time; and comparing different portions of the accumulated concentrated data. (Section E. Knowledge-based method and systems “The audit data preprocessor reformats the raw audit data to send as input to the inference engine. The inference engine monitors the state transitions extracted from the preprocessed audit data and then compares these states with the states available within the knowledge base”) Regarding claim 34, Bhuyan in view of Thing and Jomaa teaches claim 33 as outlined above. Bhuyan further teaches: detecting the event from the concentrated information further comprises using a cosine difference to compare the different portions of the accumulated concentrated data. (Table V shoes cosine difference is an option). Regarding claim 35, Bhuyan in view of Thing and Jomaa teaches claim 33 as outlined above. Bhuyan further teaches: using at least one event detected by comparing different portions of the accumulated concentrated data to generate a label for a training data set comprising concentrated information from the data stream; using the training data set to train a Supervised Learning (SL) model; and using the SL model to detect the event from the concentrated information. (Section B. Aspects of Network Anomaly Detection “In supervised mode, one assumes the availability of a training dataset which has labeled instances for the normal as well as the anomaly class. The typical approach in such cases is to build a predictive model for normal vs. anomaly classes. Any unseen data instance is compared against the model to determine which class it belongs to.”) Regarding claim 36, Bhuyan in view of Thing and Jomaa teaches claim 27 as outlined above. Bhuyan further teaches: converting parameter values corresponding to the detected event into a logical assertion; and evaluating the compatibility of the logical assertion with the contents of the knowledge base; wherein the contents of the knowledge base comprises at least one of a rule or a fact. (Section 2) Ontology and logic-based approaches: “It is possible to model attack signatures using expressive logic structure in real time by incorporating constraints and statistical properties.” And “Time-stamped security data is continuously monitored within the target mobile devices like smart phones and PDAs. Then it is processed by the knowledge-based temporal abstraction (KBTA) methodology”) Regarding claim 37, Bhuyan in view of Thing and Jomaa teaches claim 36 as outlined above. Bhuyan further teaches: generating the evaluation of the detected event further comprises performing at least one of incrementing or decrementing an evaluation score for each logical conflict between the logical assertion and the fact or rule in the knowledge base. (F. Combination learner methods and systems “Boosting builds an ensemble incrementally by training mis-classified instances obtained from the previous model.”). Regarding claim 38, Bhuyan in view of Thing and Jomaa teaches claim 27 as outlined above. Bhuyan further teaches: the knowledge base contains at least one of a rule or a fact, and wherein the at least one rule or fact is generated from at least one of: an operating environment of at least some of the plurality of devices; an operating domain of at least some of the plurality of devices; a service agreement applying to at least some of the plurality of devices; or a deployment specification applying to at least some of the plurality of devices. (E. Knowledge-based methods and systems “In knowledge-based methods, network or host events are checked against predefined rules or patterns of attack. The goal is to represent the known attacks in a generalized fashion so that handling of actual occurrences becomes easier”) Regarding claim 39, Bhuyan in view of Thing and Jomaa teaches claim 27 as outlined above. Bhuyan further teaches: updating the knowledge base to include a detected event that is logically compatible with the knowledge base. (E. Knowledge-based methods and systems “Dynamic updation of rule or knowledge base is a costly affair” this implies the knowledge base is updated). Regarding claim 40, Bhuyan in view of Thing and Jomaa teaches claim 27 as outlined above. Bhuyan further teaches: generating the evaluation of the detected event further on the basis of an error value generated during at least one of concentration of information in the data stream or detection of an event from the concentrated information. (F. Combination learner methods and systems “dLEARNIN [187] is an ensemble of classifiers that combines information from multiple sources. It is explicitly tuned to minimize the cost of errors.”). Regarding claim 41, Bhuyan in view of Thing and Jomaa teaches claim 27 as outlined above. Jomaa further teaches: using the RL algorithm to trial different values of the at least one hyperparameter and to determine a value of the at least one hyperparameter that is associated with a maximum value of the reward function. (Start of page 6 “The reward function is set as the hyperparameter response function, and depends on the data set D and the action selected, as shown below: [equation 9] considering that the agent's task is to maximize the reward. The observed reward depends solely on the data set and the hyperparameter configuration selected. Once an action is selected, a new hyperparameter configuration is evaluated.”) Regarding claim 42, Bhuyan in view of Thing and Jomaa teaches claim 27 as outlined above. Jomaa further teaches: establishing a state of the machine learning algorithm, wherein the state of the machine learning algorithm is represented by the value of the at least one hyperparameter; (Top of page 6 “Once an action is selected, a new hyperparameter configuration is evaluated. The transition function then generates a new state, s0, by appendinding the newly evaluated hyperparameter configuration, λ, and the corresponding reward r observed to the previous state s:”) selecting an action to be performed on the machine learning algorithm as a function of the established state; (top of page 6 “The reward function is set as the hyperparameter response function, and depends on the data set D and the action selected,”). causing the selected action to be performed on the machine learning algorithm; and (middle of page 6 “The agent reaches a terminal state in two cases, either the agent exceeds a pre-allocated budget T, for example running time, or the same action is selected twice in a row.”). calculating a value of a reward function following performance of the selected action (top of page 6 “The observed reward depends solely on the data set and the hyperparameter configuration selected.”). wherein selecting the action to be performed on the machine learning algorithm as a function of the established state comprises selecting the action from a set of actions comprising incrementation and decrementation of the value of the at least one hyperparameter. (Middle page 13 “From the very beginning, Hyp-RL selects hyperparameter configurations with better performance than the rest, which is indicative of the capability of the proposed policy to scale across data sets.”) Regarding claim 43, Bhuyan in view of Thing and Jomaa teaches claim 27 as outlined above. Bhuyan further teaches: the plurality of devices connected by a communications network comprises a plurality of constrained devices. (A. Prior Surveys on Network Anomaly Detection “we discuss sources, causes and aspects of network anomalies, and also include a detailed discussion of sources of packet and flow level feature datasets. In addition, we include a large collection of up-to-date anomaly detection methods under the categories of statistical, classification-based, knowledge-based, soft computing, clustering-based and combination learners, rather than restricting ourselves to only statistical approaches.”) Regarding claim 44, Bhuyan teaches: A system for performing event detection on a data stream, the data stream comprising data from a plurality of devices connected by a communications network, the system configured to: (Abstract) detecting an event from the concentrated information; (Section B: The Problem of Anomaly Detection “Consequently, an event or an object is detected as anomalous if its degree of deviation with respect to the profile or behavior of the system, specified by the normality model, is high enough”) generating an evaluation of the detected event on the basis of logical compatibility between the detected event and a knowledge base; and (Section E: Knowledge-based methods and systems “The audit data preprocessor reformats the raw audit data to send as input to the inference engine. The inference engine monitors the state transitions extracted from the preprocessed audit data and then compares these states with the states available within the knowledge base. The decision engine monitors the improvement of the inference engine for matching accuracy of the state transitions. It also specifies the action(s) to be taken based on results of the inference engine and the decision table.”) Bhuyan does not teach: using a machine learning algorithm to concentrate information in the data stream, wherein the machine learning algorithm is configured according to at least one hyperparameter; using a Reinforcement Learning (RL) algorithm to refine the at least one hyperparameter of the machine learning algorithm, wherein a reward function of the RL algorithm is calculated on the basis of the generated evaluation. Thing does teach using a machine learning algorithm to concentrate information in the data stream, wherein the machine learning algorithm is configured according to at least one hyperparameter (IV. Proposed Deep Learning Approach “Consider a SAE with parameters W l , b l , denoting the parameters for the l th auto-encoder. The output of the l th layer with its input z l is the auto-encoder, a ( l ) . The encoding of the input feature vectors over the SAE is carried out by encoding each forward layer”) Bhuyan and Thing are considered analogous art to the claimed invention because they are in the same field of endeavor being event detection. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the event detection system of Bhuyan with the autoencoder of Thing. One would want to do this to encode the data. Neither Bhuyan nor Thing teach using a Reinforcement Learning (RL) algorithm to refine the at least one hyperparameter of the machine learning algorithm, wherein a reward function of the RL algorithm is calculated on the basis of the generated evaluation. Jomaa does teach this (Start of page 6 “The reward function is set as the hyperparameter response function, and depends on the data set D and the action selected, as shown below: [equation 9] considering that the agent's task is to maximize the reward. The observed reward depends solely on the data set and the hyperparameter configuration selected. Once an action is selected, a new hyperparameter configuration is evaluated.”) Bhuyan, Thing and Jomaa are considered analogous art to the claimed invention because they are in the same field of endeavor being neural network architectures. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the event detection system of Bhuyan with the autoencoder of Thing with the reinforcement learning of Jomaa. One would want to do this to enable adaptive tuning of model hyperparameters and improve event detection accuracy. Regarding claim 45, Bhuyan in view of Thing and Jomaa teaches claim 44 as outlined above. Bhuyan further teaches: an event detection function configured to detect the event from the concentrated information; (Section B: The Problem of Anomaly Detection “Consequently, an event or an object is detected as anomalous if its degree of deviation with respect to the profile or behavior of the system, specified by the normality model, is high enough”) an evaluation function configured to generate the evaluation of the detected event on the basis of logical compatibility between the detected event and the knowledge base; (Section E: Knowledge-based methods and systems “The audit data preprocessor reformats the raw audit data to send as input to the inference engine. The inference engine monitors the state transitions extracted from the preprocessed audit data and then compares these states with the states available within the knowledge base. The decision engine monitors the improvement of the inference engine for matching accuracy of the state transitions. It also specifies the action(s) to be taken based on results of the inference engine and the decision table.”) Thing further teaches: a data processing function configured to use the machine learning algorithm to concentrate information in the data stream, wherein the machine learning algorithm is configured according to the at least one hyperparameter; (IV. Proposed Deep Learning Approach “Consider a SAE with parameters W l , b l , denoting the parameters for the l th auto-encoder. The output of the l th layer with its input z l is the auto-encoder, a ( l ) . The encoding of the input feature vectors over the SAE is carried out by encoding each forward layer”) Jomaa further teaches: and a learning function configured to use the RL algorithm to refine the at least one hyperparameter of the machine learning algorithm, wherein the reward function of the RL algorithm is calculated on the basis of the generated evaluation. (Start of page 6 “The reward function is set as the hyperparameter response function, and depends on the data set D and the action selected, as shown below: [equation 9] considering that the agent's task is to maximize the reward. The observed reward depends solely on the data set and the hyperparameter configuration selected. Once an action is selected, a new hyperparameter configuration is evaluated.”) Regarding claim 46, Bhuyan in view of Thing and Jomaa teaches claim 45 as outlined above. Jomaa further teaches: at least one of the functions comprises a virtualised function. (Page 7 Algorithm 1 Hyp-RL implies the function is virtualized.) Regarding claim 47, Bhuyan in view of Thing and Jomaa teaches claim 45 as outlined above. Bhuyan further teaches: the functions are distributed across different physical nodes. (C. Clustering and Outlier-based methods and systems “Their anomaly score function is based on a global model of the data that can be easily constructed by combining local models built independently at each node. They develop an efficient one-pass approximation algorithm for anomaly detection that works efficiently in distributed detection environments with very little loss of detection accuracy. Each node computes its own outliers and the inter-node communication needed to compute global outliers is not significant”) Regarding claim 48, Bhuyan in view of Thing and Jomaa teaches claim 45 as outlined above. Bhuyan further teaches: converting parameter values corresponding to the detected event into a logical assertion; and evaluating the compatibility of the logical assertion with the contents of the knowledge base, wherein the contents of the knowledge base comprise at least one of a rule or a fact.(Section 2) Ontology and logic-based approaches: “It is possible to model attack signatures using expressive logic structure in real time by incorporating constraints and statistical properties.” And “Time-stamped security data is continuously monitored within the target mobile devices like smart phones and PDAs. Then it is processed by the knowledge-based temporal abstraction (KBTA) methodology”) Regarding claim 49, Bhuyan in view of Thing and Jomaa teaches claim 48 as outlined above. Bhuyan further teaches: evaluation function is further configured to generate the evaluation of the detected event by performing at least one of incrementing or decrementing an evaluation score for each logical conflict between the logical assertion and the rule or the fact in the knowledge base. (F. Combination learner methods and systems “Boosting builds an ensemble incrementally by training mis-classified instances obtained from the previous model.”). Regarding claim 50, Bhuyan teaches: A method for managing an event detection process that is performed on a data stream, the data stream comprising data from a plurality of devices connected by a communications network, the method comprising: (Introduction “The term anomaly-based intrusion detection in networks refers to the problem of finding exceptional patterns in network traffic that do not conform to the expected normal behavior.”) receiving a notification of a detected event, (A. Statistical Methods and Systems “provide accurate notification or alarm generation of malicious activities occurring over long periods of time, subject to setting of appropriate thresholding or parameter tuning.” receiving an evaluation of the detected event, wherein the evaluation has been generated on the basis of logical compatibility between the detected event and a knowledge base; and (Section E: Knowledge-based methods and systems “The audit data preprocessor reformats the raw audit data to send as input to the inference engine. The inference engine monitors the state transitions extracted from the preprocessed audit data and then compares these states with the states available within the knowledge base. The decision engine monitors the improvement of the inference engine for matching accuracy of the state transitions. It also specifies the action(s) to be taken based on results of the inference engine and the decision table.”) Bhuyan does not teach wherein the event has been detected from information concentrated from the data stream using a machine learning algorithm that is configured according to at least one hyperparameter; and using a Reinforcement Learning (RL) algorithm to refine the at least one hyperparameter of the machine learning algorithm, wherein a reward function of the RL algorithm is calculated on the basis of the evaluation. Thing does teach wherein the event has been detected from information concentrated from the data stream using a machine learning algorithm that is configured according to at least one hyperparameter; (IV. Proposed Deep Learning Approach “Consider a SAE with parameters W l , b l , denoting the parameters for the l th auto-encoder. The output of the l th layer with its input z l is the auto-encoder, a ( l ) . The encoding of the input feature vectors over the SAE is carried out by encoding each forward layer”) Bhuyan and Thing are considered analogous art to the claimed invention because they are in the same field of endeavor being event detection. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the event detection system of Bhuyan with the autoencoder of Thing. One would want to do this to encode the data. Jomaa teaches using a Reinforcement Learning (RL) algorithm to refine the at least one hyperparameter of the machine learning algorithm, wherein a reward function of the RL algorithm is calculated on the basis of the evaluation. (Start of page 6 “The reward function is set as the hyperparameter response function, and depends on the data set D and the action selected, as shown below: [equation 9] considering that the agent's task is to maximize the reward. The observed reward depends solely on the data set and the hyperparameter configuration selected. Once an action is selected, a new hyperparameter configuration is evaluated.”) Bhuyan, Thing and Jomaa are considered analogous art to the claimed invention because they are in the same field of endeavor being neural network architectures. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the event detection system of Bhuyan with the autoencoder of Thing with the reinforcement learning of Jomaa. One would want to do this to enable adaptive tuning of model hyperparameters and improve event detection accuracy. Regarding claim 51, A node for managing an event detection process that is performed on a data stream, the data stream comprising data from a plurality of devices connected by a communications network, the node comprising processing circuitry and a memory containing instructions executable by the processing circuitry, whereby the node is operable to: (A. Statistical methods and systems “The system has a separate IDS server, i.e., a management console to aggregate alerts from the various sensors with a user interface, a middle-tier and a data management component.”) receiving a notification of a detected event, (A. Statistical Methods and Systems “provide accurate notification or alarm generation of malicious activities occurring over long periods of time, subject to setting of appropriate thresholding or parameter tuning.” receiving an evaluation of the detected event, wherein the evaluation has been generated on the basis of logical compatibility between the detected event and a knowledge base; and (Section E: Knowledge-based methods and systems “The audit data preprocessor reformats the raw audit data to send as input to the inference engine. The inference engine monitors the state transitions extracted from the preprocessed audit data and then compares these states with the states available within the knowledge base. The decision engine monitors the improvement of the inference engine for matching accuracy of the state transitions. It also specifies the action(s) to be taken based on results of the inference engine and the decision table.”) Bhuyan does not teach wherein the event has been detected from information concentrated from the data stream using a machine learning algorithm that is configured according to at least one hyperparameter; and using a Reinforcement Learning (RL) algorithm to refine the at least one hyperparameter of the machine learning algorithm, wherein a reward function of the RL algorithm is calculated on the basis of the evaluation. Thing does teach wherein the event has been detected from information concentrated from the data stream using a machine learning algorithm that is configured according to at least one hyperparameter; (IV. Proposed Deep Learning Approach “Consider a SAE with parameters W l , b l , denoting the parameters for the l th auto-encoder. The output of the l th layer with its input z l is the auto-encoder, a ( l ) . The encoding of the input feature vectors over the SAE is carried out by encoding each forward layer”) Bhuyan and Thing are considered analogous art to the claimed invention because they are in the same field of endeavor being event detection. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the event detection system of Bhuyan with the autoencoder of Thing. One would want to do this to encode the data. Jomaa teaches using a Reinforcement Learning (RL) algorithm to refine the at least one hyperparameter of the machine learning algorithm, wherein a reward function of the RL algorithm is calculated on the basis of the evaluation. (Start of page 6 “The reward function is set as the hyperparameter response function, and depends on the data set D and the action selected, as shown below: [equation 9] considering that the agent's task is to maximize the reward. The observed reward depends solely on the data set and the hyperparameter configuration selected. Once an action is selected, a new hyperparameter configuration is evaluated.”) Bhuyan, Thing and Jomaa are considered analogous art to the claimed invention because they are in the same field of endeavor being neural network architectures. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the event detection system of Bhuyan with the autoencoder of Thing with the reinforcement learning of Jomaa. One would want to do this to enable adaptive tuning of model hyperparameters and improve event detection accuracy. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to DANIEL P GRUSZKA whose telephone number is (571)272-5259. The examiner can normally be reached M-F 9:00 AM - 6:00 PM ET. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Li Zhen can be reached at (571) 272-3768. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /DANIEL GRUSZKA/Examiner, Art Unit 2121 /Li B. Zhen/Supervisory Patent Examiner, Art Unit 2121
Read full office action

Prosecution Timeline

Apr 07, 2022
Application Filed
Sep 24, 2025
Non-Final Rejection mailed — §101, §103
Dec 17, 2025
Response Filed
Apr 15, 2026
Non-Final Rejection mailed — §101, §103
Jul 13, 2026
Response Filed
Sep 28, 2026
Final Rejection mailed — §101, §103 (current)

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

4-5
Expected OA Rounds
40%
Grant Probability
99%
With Interview (+66.7%)
4y 4m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 5 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month