DETAILED ACTION
In a communication received on 9 June 2026, applicants amended claims 1, 5, 10, 14, 19 and 23.
Claims 1-27 are pending.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Arguments
Applicant’s arguments with respect to claim(s) 1, 10, and 19 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1-3, 6-12, 15-21 and 24-27 is/are rejected under 35 U.S.C. 103 as being unpatentable over Chen et al. (US 2019/0130101 A1) in view of Khorrami et al. (US 2019/0340392 A1), Murali et al. (US 2020/0065645 A1), and Tolpin et al. (US 2017/0032120 A1), and further in view of Kounavis et al. (US 2019/0220605 A1).
With respect to claim 1, Chen discloses: a method for detecting unauthorized memory access cyberattacks (i.e., a processor-based method detects side-channel anomalies, including Spectre/Meltdown attacks that cross memory-isolation boundaries in Chen, ¶0097; ¶0002),
the method comprising:
receiving, by a processor, hardware event data (i.e., an HPC interface retrieves counter values and passes them to an organizer for later processing in Chen, ¶0024),
wherein the hardware event data is collected from hardware performance counter (HPC) circuitry of a targeted device during execution of an evasive program (i.e., timestamped HPC data are gathered while an attack executes, and one-class detection is designed to cover newly evolved attacks in Chen, ¶0039; ¶0015);
generating, by the processor, time-sequential hardware event data from the hardware event data (i.e., retrieved HPC values are timestamped and stored, thereby forming time-ordered hardware-event data in Chen, ¶0052),
generating, by the processor and using a classifier model, a set of one or more input-output pairs based at least in part on a set of one or more predictions, wherein a prediction of the set of one or more predictions comprises an incorrect classification of a normal program based at least in part on the time-sequential hardware event data (i.e., the model maps benign time-series input to a prediction and attack probability, and false-positive instances are retained for further training in Chen, ¶0062; ¶0049);
determining, by the processor and using the classifier model modified with the training data, whether an executing program comprises an unauthorized memory access cyberattack (i.e., the detector can retrain online from false positives and then apply the trained model to captured live HPC data in Chen, ¶0049; ¶0065).
Chen discloses the detector uses changes in timestamped HPC values to detect cache side-channel attacks (¶0017; ¶0052). Chen do(es) not explicitly disclose the following. Khorrami, in order to improves adaptability by exposing changes in code-execution behavior using successive-window temporal profiles (¶0044), discloses:
wherein the time-sequential hardware event data describes a plurality of relative differences in amount of a hardware event at a plurality of sequential timepoints (i.e., successive HPC measurements form time windows, and the feature vector expressly includes inter-sample changes in Khorrami, ¶0044; ¶0109),
wherein (i) the time-sequential hardware event data comprises a data feature value that corresponds to a relative change in an amount of a hardware event during a first timepoint of the plurality of sequential timepoints with respect to a second timepoint of the plurality of sequential timepoints (i.e., an HPC feature value is a mean of inter-sample changes within a time window in Khorrami, ¶0109)
and (ii) the second timepoint is prior to the first timepoint within the plurality of sequential timepoints (i.e., the measurements are accumulated between successive samples, so each inter-sample feature compares temporally ordered points in Khorrami, ¶0044; ¶0109).
Based on Chen in view of Khorrami, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Khorrami to improve upon those of Chen in order to improves adaptability by exposing changes in code-execution behavior using successive-window temporal profiles.
Chen discloses the primary recurrent classifier represents each HPC input xi at a specific sampling time (¶0056). Chen and Khorrami do(es) not explicitly disclose the following. Murali, in order to improve descriptive capability via interpretable factor contributions reveal how much each factor drives a prediction (¶0018), discloses:
providing, by the processor, the set of one or more input-output pairs to a distilled machine learning model to produce a contributing timepoint from the plurality of sequential timepoints based at least in part on a contribution of an input data feature to the prediction (i.e., a teacher/student knowledge-distillation model provides feature contributions for time-dependent inputs in Murali, ¶0039; ¶0037),
wherein the input data feature corresponds to the contributing timepoint (i.e., feature importance is extracted from contribution coefficients for time-dependent model inputs. in Murali, ¶0030; ¶0037).
Based on Chen in view of Khorrami, and further in view of Murali, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Murali to improve upon those of Chen in order to improve descriptive capability via interpretable factor contributions reveal how much each factor drives a prediction.
Chen discloses the primary detector retrains using information from false positives (¶0049). Chen, Khorrami, and Muralis do(es) not explicitly disclose the following. Tolpin, in order to improve resilience by mutating known malware predicts and protects against new variants (¶0012), discloses:
generating, by the processor, a synthetic evasive sample by (i) padding an original program sample with a set of one or more non-consequential blocks to produce a padded program sample, (ii) inserting an evasive portion of the evasive program corresponding to the contributing timepoint into the padded program sample, and (iii) permuting one or more function blocks of the padded program sample including the set of one or more non-consequential blocks and the evasive portion of the evasive program (i.e., code is combined with malicious or nonmalicious code, replicated or rearranged, while preserving functional equivalence. in Tolpin, ¶0046; ¶0067).
Based on Chen in view of Khorrami, and Murali, and further in view of Tolpin, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Tolpin to improve upon those of Chen in order to improve resilience by mutating known malware predicts and protects against new variants.
Chen discloses the primary classifier performs further training using false-positive information. (¶0049). Chen, Khorrami, Muralis, and Tolpin do(es) not explicitly disclose the following. Kounavis, in order to improve robustness and computational speed by targeted adversarial examples (¶0048), discloses:
providing, by the processor and to the classifier model, training data comprising the synthetic evasive sample to modify the classifier model (i.e., the original examples and generated adversarial examples are combined into an updated training set and supplied to train a later DNN in Kounavis, ¶0030).
Based on Chen in view of Khorrami, Murali, and Tolpin, and further in view of Kounavis, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Kounavis to improve upon those of Chen in order to improve robustness and computational speed by targeted adversarial examples.
With respect to claim 2, Chen discloses: the method of claim 1, wherein the classifier model comprises a long short-term memory (LSTM) that is configured to receive the time-sequential hardware event data as input (i.e., an LSTM may replace the stacked GRU that accepts time-series HPC values at specific sampling times in Chen, ¶0056; ¶0057).
With respect to claim 3, Chen discloses: the method of claim 1, wherein the classifier model (i.e., the side-channel model is trained on time-series HPC data and may be retrained online from false positives in Chen, ¶0042; ¶0049) is trained by:
providing the classifier model with a plurality of program samples (i.e., repeated benign workloads and attack executions produce a plurality of time-series program-execution samples in Chen, ¶0051)
comprising a plurality of corresponding labels that indicate whether the plurality of program samples include the unauthorized memory access cyberattack (i.e., stored HPC execution data are labeled as benign activity, attack activity, or another activity class in Chen, ¶0026).
Chen discloses the primary recurrent classifier represents each HPC input xi at a specific sampling time (¶0056). Chen and Khorrami do(es) not explicitly disclose the following. Murali, in order to improve descriptive capability via interpretable factor contributions reveal how much each factor drives a prediction (¶0018), discloses:
generating, using the plurality of program samples, the distilled machine learning model (i.e., a teacher/student knowledge-distillation process produces contribution features from model inputs and outcomes in Murali, ¶0039),
wherein the distilled machine learning model is configured to generate similar outputs to the classifier model (i.e., teacher/student knowledge distillation supplies a student model whose feature contributions explain the teacher behavior in Murali, ¶0039);
identifying, using the distilled machine learning model, one or more significant timepoints spanned by the time-sequential hardware event data that correspond to the plurality of program samples (i.e., coefficient-based feature importance identifies influential factors among time-dependent inputs in Murali, ¶0030; ¶0037).
Based on Chen in view of Khorrami, and further in view of Murali, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Murali to improve upon those of Chen in order to improve descriptive capability via interpretable factor contributions reveal how much each factor drives a prediction.
Chen discloses the primary classifier performs further training using false-positive information. (¶0049). Chen, Khorrami, Muralis, and Tolpin do(es) not explicitly disclose the following. Kounavis, in order to improve robustness and computational speed by targeted adversarial examples (¶0048), discloses:
generating a plurality of synthesized program samples using the one or more significant timepoints (i.e., a sliding window locates prediction-heavy bytecode and guides changed or injected code used to make adversarial examples in Kounavis, ¶0038); and
re-training the classifier model using the plurality of program samples and the plurality of synthesized program samples (i.e., an updated training set contains every original sample and every adversarial example, then trains a second DNN in Kounavis, ¶0030).
Based on Chen in view of Khorrami, Murali, and Tolpin, and further in view of Kounavis, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Kounavis to improve upon those of Chen in order to improve robustness and computational speed by targeted adversarial examples.
With respect to claim 6, Chen discloses the detector uses changes in timestamped HPC values to detect cache side-channel attacks (¶0017; ¶0052). Chen do(es) not explicitly disclose the following. Khorrami, in order to improves adaptability by exposing changes in code-execution behavior using successive-window temporal profiles (¶0044), discloses: the method of claim 3, wherein the classifier model is trained and re-trained using stochastic gradient descent and cross-entropy loss (i.e., an LSTM/RNN is trained end-to-end by backpropagating a likelihood-based sequence loss in Khorrami, ¶0134).
Based on Chen in view of Khorrami, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Khorrami to improve upon those of Chen in order to improves adaptability by exposing changes in code-execution behavior using successive-window temporal profiles.
With respect to claim 7, Chen discloses the primary classifier performs further training using false-positive information. (¶0049). Chen, Khorrami, Muralis, and Tolpin do(es) not explicitly disclose the following. Kounavis, in order to improve robustness and computational speed by targeted adversarial examples (¶0048), discloses: the method of claim 3,
wherein re-training the classifier model further comprises employing a machine learning model ensemble boosting framework (i.e., sequential DNN iterations are coordinated with adversarial-example generation and updated training sets in Kounavis, ¶0022; ¶0023),
wherein the machine learning model ensemble boosting framework comprises previous iterations of the classifier model (i.e., adversarial examples from a first DNN feed a second training set, and sequential DNN training repeats across iterations. in Kounavis, ¶0023; ¶0022).
Based on Chen in view of Khorrami, Murali, and Tolpin, and further in view of Kounavis, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Kounavis to improve upon those of Chen in order to improve robustness and computational speed by targeted adversarial examples.
With respect to claim 8, Chen discloses the primary recurrent classifier represents each HPC input xi at a specific sampling time (¶0056). Chen and Khorrami do(es) not explicitly disclose the following. Murali, in order to improve descriptive capability via interpretable factor contributions reveal how much each factor drives a prediction (¶0018), discloses: the method of claim 3,
wherein the distilled machine learning model is a linear regression model comprising a plurality of polynomial terms (i.e., knowledge-distillation can use a student model whose outputs are additive linear feature contributions in Murali, ¶0039; ¶0029),
the plurality of polynomial terms being used to identify the contributing timepoint (i.e., coefficients of a linear combination expose feature importance for time-dependent inputs in Murali, ¶0030; ¶0037).
Based on Chen in view of Khorrami, and further in view of Murali, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Murali to improve upon those of Chen in order to improve descriptive capability via interpretable factor contributions reveal how much each factor drives a prediction.
With respect to claim 9, Chen discloses: the method of claim 1,
wherein the hardware event data includes (i) branch mis-prediction rate (i.e., processor HPC registers count branch mis-predictions for the executing workload in Chen, ¶0018), and
(iii) a number of low-level cache misses (i.e., processor HPC registers count cache misses for the executing workload in Chen, ¶0018).
Chen discloses the detector uses changes in timestamped HPC values to detect cache side-channel attacks (¶0017; ¶0052). Chen do(es) not explicitly disclose the following. Khorrami, in order to improves adaptability by exposing changes in code-execution behavior using successive-window temporal profiles (¶0044), discloses:
(ii) a number of low-level cache references (i.e., HPCs expressly count L1 cache accesses and analogous L2/L3 cache accesses in Khorrami, ¶0042).
Based on Chen in view of Khorrami, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Khorrami to improve upon those of Chen in order to improves adaptability by exposing changes in code-execution behavior using successive-window temporal profiles.
With respect to claim 10, the limitation(s) of claim 10 are similar to those of claim(s) 1. Therefore, claim 10 is rejected with the same reasoning as claim(s) 1.
With respect to claim 11, the limitation(s) of claim 11 are similar to those of claim(s) 2. Therefore, claim 11 is rejected with the same reasoning as claim(s) 2.
With respect to claim 12, the limitation(s) of claim 12 are similar to those of claim(s) 3. Therefore, claim 12 is rejected with the same reasoning as claim(s) 3.
With respect to claim 15, the limitation(s) of claim 15 are similar to those of claim(s) 6. Therefore, claim 15 is rejected with the same reasoning as claim(s) 6.
With respect to claim 16, the limitation(s) of claim 16 are similar to those of claim(s) 7. Therefore, claim 16 is rejected with the same reasoning as claim(s) 7.
With respect to claim 17, the limitation(s) of claim 17 are similar to those of claim(s) 8. Therefore, claim 17 is rejected with the same reasoning as claim(s) 8.
With respect to claim 18, the limitation(s) of claim 18 are similar to those of claim(s) 9. Therefore, claim 18 is rejected with the same reasoning as claim(s) 9.
With respect to claim 19, the limitation(s) of claim 19 are similar to those of claim(s) 1. Therefore, claim 19 is rejected with the same reasoning as claim(s) 1.
With respect to claim 20, the limitation(s) of claim 20 are similar to those of claim(s) 2. Therefore, claim 20 is rejected with the same reasoning as claim(s) 2.
With respect to claim 21, the limitation(s) of claim 21 are similar to those of claim(s) 3. Therefore, claim 21 is rejected with the same reasoning as claim(s) 3.
With respect to claim 24, the limitation(s) of claim 24 are similar to those of claim(s) 6. Therefore, claim 24 is rejected with the same reasoning as claim(s) 6.
With respect to claim 25, the limitation(s) of claim 25 are similar to those of claim(s) 7. Therefore, claim 25 is rejected with the same reasoning as claim(s) 7.
With respect to claim 26, the limitation(s) of claim 26 are similar to those of claim(s) 8. Therefore, claim 26 is rejected with the same reasoning as claim(s) 8.
With respect to claim 27, the limitation(s) of claim 27 are similar to those of claim(s) 9. Therefore, claim 27 is rejected with the same reasoning as claim(s) 9.
Claim(s) 4, 5, 13, 14, 22, and 23 is/are rejected under 35 U.S.C. 103 as being unpatentable over Chen et al. (US 2019/0130101 A1) in view of Khorrami et al. (US 2019/0340392 A1), Murali et al. (US 2020/0065645 A1), Tolpin et al. (US 2017/0032120 A1), and Kounavis et al. (US 2019/0220605 A1), and further in view of Levy et al. (US 2019/0215329 A1).
With respect to claim 4, Chen discloses the primary classifier performs further training using false-positive information. (¶0049). Chen, Khorrami, Muralis, and Tolpin do(es) not explicitly disclose the following. Kounavis, in order to improve robustness and computational speed by targeted adversarial examples (¶0048), discloses: the method of claim 3, executing one or more data augmentation operations in a machine learning model ensemble boosting framework (i.e., sequential DNN iterations are coordinated with adversarial-example generation and updated training sets in Kounavis, ¶0022; ¶0023).
Based on Chen in view of Khorrami, Murali, and Tolpin, and further in view of Kounavis, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Kounavis to improve upon those of Chen in order to improve robustness and computational speed by targeted adversarial examples.
Chen discloses the primary classifier retrains from false-positive information. (¶0049). Chen, Khorrami, Muralis, Tolpin, Kounavis do(es) not explicitly disclose the following. Levy, in order to improves detection of novel malware through , synthetic code (¶0004), discloses:
wherein generating the plurality of synthesized program samples (i.e., a detection model is iteratively trained using synthetic malware samples generated from functional blocks in Levy, ¶0046) further comprises:
wherein the one or more data augmentation operations comprise manual data augmentation operations (i.e., functional blocks are manually or automatically extracted, then rule-based order and implementation variations generate synthetic code in Levy, ¶0050; ¶0041),
generative adversarial network (GAN) model-based data augmentation operations (i.e., competing generator and discriminator networks produce candidate malware that evades classification and improve by backpropagation in Levy, ¶0042), and
diffusion model-based data augmentation operations (i.e., the reference broadly permits other generative programming techniques for synthetic malware beyond its disclosed GAN in Levy, ¶0043).
Based on Chen in view of Khorrami, Murali, Tolpin, Kounavis, and further in view of Levy, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Levy to improve upon those of Chen in order to improves detection of novel malware through , synthetic code.
With respect to claim 5, Chen discloses: the method of claim 4,
wherein the one or more program samples are labelled to indicate (i) a presence of the unauthorized memory access cyberattack (i.e., execution-derived HPC samples are labeled to identify attack activity versus benign activity in Chen, ¶0026)
or (ii) a misclassification by the classifier model (i.e., false-positive instances are expressly identified and their identifying information is used for further training in Chen, ¶0049).
Chen discloses the primary detector retrains using information from false positives (¶0049). Chen, Khorrami, and Muralis do(es) not explicitly disclose the following. Tolpin, in order to improve resilience by mutating known malware predicts and protects against new variants (¶0012), discloses:
generating one or more sliced portions of one or more program samples (i.e., the system isolates a malware-relevant portion and can then combine, replicate, remove, or rearrange code in Tolpin, ¶0040; ¶0046),
and inserting the one or more sliced portions within the original program sample (i.e., an isolated malware portion can be combined with other code, including malicious or nonmalicious code, to form a mutated sample in Tolpin, ¶0040; ¶0046).
Based on Chen in view of Khorrami, and Murali, and further in view of Tolpin, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Tolpin to improve upon those of Chen in order to improve resilience by mutating known malware predicts and protects against new variants.
Chen, Khorrami, Muralis, Tolpin, Kounavis do(es) not explicitly disclose the following. Levy, in order to improves detection of novel malware through synthetic code (¶0004), discloses:
wherein performing the manual data augmentation operations comprises: (i.e., manual techniques extract functional blocks and behaviors into a form usable for synthetic-sample generation in Levy, ¶0050).
Based on Chen in view of Khorrami, Murali, Tolpin, Kounavis, and further in view of Levy, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Levy to improve upon those of Chen in order to improves detection of novel malware through synthetic code.
With respect to claim 13, the limitation(s) of claim 13 are similar to those of claim(s) 4. Therefore, claim 13 is rejected with the same reasoning as claim(s) 4.
With respect to claim 14, the limitation(s) of claim 14 are similar to those of claim(s) 5. Therefore, claim 14 is rejected with the same reasoning as claim(s) 5.
With respect to claim 22, the limitation(s) of claim 22 are similar to those of claim(s) 4. Therefore, claim 22 is rejected with the same reasoning as claim(s) 4.
With respect to claim 23, the limitation(s) of claim 23 are similar to those of claim(s) 5. Therefore, claim 23 is rejected with the same reasoning as claim(s) 5.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to SHERMAN L LIN whose telephone number is (571)270-7446. The examiner can normally be reached Monday through Friday 9:00 AM - 5:00 PM (Eastern).
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Joon Hwang can be reached on 571-272-4036. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
Sherman Lin
8/21/2026
/S. L./Examiner, Art Unit 2447
/JOON H HWANG/Supervisory Patent Examiner, Art Unit 2447