Prosecution Insights
Last updated: October 02, 2026
Application No. 18/122,897

SYSTEM AND METHODS FOR ANOMALY AND MALWARE DETECTION IN MEDICAL IMAGING DATA

Non-Final OA §103
Filed
Mar 17, 2023
Examiner
FARAMARZI, GITA
Art Unit
2496
Tech Center
2400 — Computer Networks
Assignee
Optum Inc.
OA Round
3 (Non-Final)
51%
Grant Probability
Moderate
3-4
OA Rounds
0m
Est. Remaining
70%
With Interview

Examiner Intelligence

Grants 51% of resolved cases
51%
Career Allowance Rate
41 granted / 80 resolved
-6.7% vs TC avg
Strong +19% interview lift
Without
With
+18.9%
Interview Lift
resolved cases with interview
Typical timeline
3y 7m
Avg Prosecution
24 currently pending
Career history
122
Total Applications
across all art units

Statute-Specific Performance

§101
8.3%
-31.7% vs TC avg
§103
57.4%
+17.4% vs TC avg
§102
4.9%
-35.1% vs TC avg
§112
28.4%
-11.6% vs TC avg
Black line = Tech Center average estimate • Based on career data from 80 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on May 04, 2026 has been entered. Status of Claims The following is a Final Office Action in response to applicant’s filing on 05/04/2026. Claims 1-5, 11, and 20 were amended. Claims 13-15 were canceled. Claims 21-23 were newly added. Claims 1-12 and 16-23 are pending, of which claims 1, 11, and 20 are in independent form. Response to Amendment The amendment filed 05/04/2026 has been entered. Amendments to the claims 1, 11, and 20 have overcome the previous 35 USC § 112(a) rejection and 35 USC § 112(b) rejection. Response to Arguments In view of the remarks submitted on 05/04/2026, applicant’s arguments have been carefully and respectfully considered but they are not persuasive. Claim Rejections - 35 USC § 103 On Pages 8-12 of remarks, Applicant argues that neither Goswami nor Briliauskas, alone or in combination, teaches the limitation "based at least in part on determining that the first score meets or exceeds a first threshold, modifying the medical imaging file by using a content disarm and reconstruction technique to remove the suspected anomalous or malicious data from the medical imaging file" as recited in the amended independent claim 1”. The examiner is relying on Prosky to teach said limitation. Proskey teaches the claimed modification because Prosky receives a DICOM medical imaging file, identifies selected content within the file, removes or replaces that content, and generates a reconstructed, de-identified medical imaging file that retains the remaining the valid content. In particular, Prosky identifies patient identifiers in the DICOM file and generates a de-identified medical scan that no longer includes the identified information, see paragraph [0186]; replaces identified header fields with anonymized fields, see paragraph [0238], and identifies patient information within regions of the image data, substitutes other obfuscated content for those regions, and replaces the original image data with the resulting de-identified image data see paragraphs [0233], [0243] and [0247]. Those operations functionally constitute content disarm and reconstruction because the medical imaging file is parsed, selected undesirable content is removed and the remaining permitted content is used to produce a modified, usable medical imaging file. Therefore, Prosky discloses the limitation “modifying the medical imaging file by using a content disarm and reconstruction technique to remove the suspected anomalous or malicious data from the medical imaging file” of claim 1. The same reasons apply to independent claims 11 and 20, and the dependent claims at least virtue of their dependencies. Therefore, the examiner maintains the rejection under 35 USC § 103. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claims 1, 6-9, 11, and 16-23 are rejected under 35 U.S.C. 103 as being unpatentable over Goswami et al. (US 2021/0056404 A1), hereinafter Goswami in view of Prosky et al. (US 2020/0160978 A1), hereafter Prosky. In regards to claim 1, Goswami discloses a system comprising: one or more processors (Goswami, Para. 0148, a data processing system suitable for storing and/or executing program code will include at least one processor coupled directly or indirectly to memory elements through a communication bus, such as a system bus); and one or more memories storing processor-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform operations (Goswami, Para. 0148, the memory elements can include local memory employed during actual execution of the program code, bulk storage, and cache memories which provide temporary storage of at least some program code in order to reduce the number of times code must be retrieved from bulk storage during execution): obtaining a medical imaging file comprising a header and a data set, wherein the header includes metadata associated with the medical imaging file (Goswami, Para. 0083, a training dataset 210 is provided that comprises training image data 212 and image metadata 214. The image metadata 214 comprises metadata indicating a correct classification for the corresponding image data 212. Thus, for each image in the training dataset 210, there is a set of image data 212 and a corresponding image metadata 214) and the data set includes one or more images captured by a medical imaging device (Goswami, Para. 0093, the input data set may represent a medical image, such as an x-ray image, CT scan image, MRI image, or the like, that is to have portions of the image, or the image as a whole, classified into one or more predefined classifications); evaluating the medical imaging file using a classification model to: i) generate a first score representative of a likelihood that the medical imaging file contains anomalous or malicious data (Goswami, Paras. 0071-0072, thus, the term “classification” or “class” in the context of the output generated by the machine learning model may refer to either a vector output with probability values or scores associated with different predefined categories (or classifications), or a one-hot or binary output indicating a classification of the input. For purposes of the present description of an example embodiment, the classification or class will be considered to be a vector output comprising probability values or scores indicating the likelihood that a corresponding class is a correct classification for the input to the machine learning model) see also paras 0093-0094 and 0071-0072). Goswami does not explicitly disclose ii) identify suspected anomalous or malicious data within the medical imaging file; based at least in part on determining that the first score meets or exceeds a first threshold, modifying the medical imaging file by using a content disarm and reconstruction technique to remove the suspected anomalous or malicious data from the medical imaging file. However, Prosky teaches ii) identify suspected anomalous or malicious data within the medical imaging file (Prosky, Para. 0063, the image quality score can be based on a detected corruption, and/or detected external factor that determined to negatively affect the quality of the image data during the capturing of the medical scan and/or subsequent to the capturing of the medical scan) and (Prosky, Para. 0168, a first DICOM image for storage in the first memory, designated for PHI, where the first DICOM image includes at least one patient identifier. Step 2704 includes performing, via at least one first processor coupled to the first memory and designated for PHI), (para. 0232) and (Para.0243); based at least in part on determining that the first score meets or exceeds a first threshold (Prosky, Para. 0064, the medical scan image analysis system can automatically filter training sets based on selecting only medical scans with image quality scores that compare favorably to the image quality threshold. As another example, one or more subsystems can flag a particular imaging machine and/or hospital or other medical entity that have produced at least a threshold number and/or percentage of medical scan with image quality scores that compare unfavorably to the image quality threshold), modifying the medical imaging file by using a content disarm and reconstruction technique to remove the suspected anomalous or malicious data from the medical imaging file (Prosky, Para. 0186, Step 2704 includes performing, via at least one first processor coupled to the first memory and designated for PHI, a de-identification function on the first DICOM image to identify the at least one patient identifier and generate a first de-identified medical scan that does not include the at least one patient identifier), (Prosky, Para. 0233, the image obfuscation function can include a facial structure obfuscation function performed on the medical scan to generate de-identified image data that does not include identifying facial structure. For example, the facial structure obfuscation function can mask, scramble, replace with a fiducial, or otherwise obfuscate the pixels of the region identified by the facial detection function) and (Prosky, Para. 0247). Goswami and Prosky are both considered to be analogous to the claim invention because they are in the same field of detecting anomalies and/or malware in imaging files. Therefore, it would have been obvious to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Goswami to incorporate the teachings of Prosky to include ii) identify suspected anomalous or malicious data within the medical imaging file (Prosky, Para. 0063) and (Prosky, Para. 0168), (para. 0232) and (Para.0243); based at least in part on determining that the first score meets or exceeds a first threshold (Prosky, Para. 0064), modifying the medical imaging file by using a content disarm and reconstruction technique to remove the suspected anomalous or malicious data from the medical imaging file (Prosky, Para. 0186), (Prosky, Para. 0233) and (Prosky, Para. 0247)). Doing so would aid the model parameters to update over time to improve existing inference functions and/or to add new inference functions, for example corresponding to new scan categories. In particular, the some or all of the de-identified medical scans generated by the de-identification system 2608 can be transmitted back to the central server system, and the central server system 2640 can train on this data to improve existing models by producing updated model parameters of an existing inference function and/or to generate new models, for example, corresponding to new scan categories, by producing new model parameters for new inference functions (Prosky, Para. 0167). In regards to claim 6, the combination of Goswami and Prosky teaches the system of claim 1, wherein the one or more processors and the one or more memories are components of an edge server of a picture archiving and communication system (PACS), and wherein the medical imaging file is received by the edge server from the medical imaging device (Prosky, Para. 0259, in various embodiments, the medical picture archive system is a Picture Archive and Communication System (PACS) server, and the first DICOM image is received in response to a query sent to the medical picture archive system by the transmitter in accordance with a DICOM communication protocol). Therefore, it would have been obvious to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Goswami to incorporate the teachings of Prosky to include wherein the processor and the memory are components of an edge server of a picture archiving and communication system (PACS), and wherein the medical imaging file is received by the edge server from the medical imaging device (Prosky, Para. 0259). Doing so would aid the model parameters to update over time to improve existing inference functions and/or to add new inference functions, for example corresponding to new scan categories. In particular, the some or all of the de-identified medical scans generated by the de-identification system 2608 can be transmitted back to the central server system, and the central server system 2640 can train on this data to improve existing models by producing updated model parameters of an existing inference function and/or to generate new models, for example, corresponding to new scan categories, by producing new model parameters for new inference functions (Prosky, Para. 0167). In regards to claim 7, the combination of Goswami and Prosky teaches the system of claim 1, the operations further comprising converting the images in the data set of the medical imaging file to greyscale prior to evaluating the medical imaging file using the classification model (Prosky, Para. 0259, contrasting parameters and/or density windowing may have already been applied and/or the image data may have been undergone other pre-processing to convert density values to greyscale values) and (Para. 0260, the input can correspond to density values of raw sensor data, and the output can correspond to greyscale values of a JPEG). Therefore, it would have been obvious to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Goswami to incorporate the teachings of Prosky to include the instructions further causing the system to convert the images in the data set of the medical imaging file to greyscale prior to evaluating the medical imaging file using the classification model (Prosky, Para. 0259). Doing so would aid the model parameters to update over time to improve existing inference functions and/or to add new inference functions, for example corresponding to new scan categories. In particular, the some or all of the de-identified medical scans generated by the de-identification system 2608 can be transmitted back to the central server system, and the central server system 2640 can train on this data to improve existing models by producing updated model parameters of an existing inference function and/or to generate new models, for example, corresponding to new scan categories, by producing new model parameters for new inference functions (Prosky, Para. 0167). In regards to claim 8, the combination of Goswami and Prosky teaches the system of claim 1, wherein the medical imaging file is a digital imaging and communications in medicine DICOM file (Prosky, Para. 0150, the receiver can receive DICOM images from the medical picture archive system 2620. The transmitter 2604 can send annotated DICOM files to the medical picture archive system 2620). Therefore, it would have been obvious to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Goswami to incorporate the teachings of Prosky to include teaches the system of claim 1, wherein the medical imaging file is a DICOM file (Prosky, Para. 0150). Doing so would aid the model parameters to update over time to improve existing inference functions and/or to add new inference functions, for example corresponding to new scan categories. In particular, the some or all of the de-identified medical scans generated by the de-identification system 2608 can be transmitted back to the central server system, and the central server system 2640 can train on this data to improve existing models by producing updated model parameters of an existing inference function and/or to generate new models, for example, corresponding to new scan categories, by producing new model parameters for new inference functions (Prosky, Para. 0167). In regards to claim 9, the combination of Goswami and Prosky teaches the system of claim 1, wherein the classification model is one of a multi-layer perceptron (MLP) model, a support vector machine (SVM) model, random forest model, or a convolutional neural network (CNN) (Goswami, Para. 0085, for purposes of the present description, it is again assumed that the computer model 104 is a CNN that is trained to perform an image classification operation on input data that represents one or more images, and thus the computer model is identified as a target ML classifier 104). In regards to claim 11, the method of claim 11 is similarly analyzed and rejected as the system claim 1. In regards to claim 16, the method of claim 16 is similarly analyzed and rejected as the system claim 6. In regards to claim 17, the method of claim 17 is similarly analyzed and rejected as the system claim 7. In regards to claim 18, the method of claim 18 is similarly analyzed and rejected as the system claim 8. In regards to claim 19, the method of claim 19 is similarly analyzed and rejected as the system claim 9. In regards to claim 20, the non-transitory, computer-readable medium of claim 20 is similarly analyzed and rejected as the system claim 1 and method claim 11. In regards to claim 21, the combination of Goswami and Prosky teaches the one or more non-transitory computer readable media of claim 20, wherein the medical imaging file is obtained by an edge server of a picture archiving and communication system (PACS) and from the medical imaging device (Prosky, Para. 0259, in various embodiments, the medical picture archive system is a Picture Archive and Communication System (PACS) server, and the first DICOM image is received in response to a query sent to the medical picture archive system by the transmitter in accordance with a DICOM communication protocol). Therefore, it would have been obvious to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Goswami to incorporate the teachings of Prosky to include wherein the medical imaging file is obtained by an edge server of a picture archiving and communication system (PACS) and from the medical imaging device (Prosky, Para. 0259). Doing so would aid the model parameters to update over time to improve existing inference functions and/or to add new inference functions, for example corresponding to new scan categories. In particular, the some or all of the de-identified medical scans generated by the de-identification system 2608 can be transmitted back to the central server system, and the central server system 2640 can train on this data to improve existing models by producing updated model parameters of an existing inference function and/or to generate new models, for example, corresponding to new scan categories, by producing new model parameters for new inference functions (Prosky, Para. 0167). In regards to claim 22, the combination of Goswami and Prosky teaches the one or more non-transitory computer readable media of claim 20, wherein the operations further comprise converting the images in the data set of the medical imaging file to greyscale prior to evaluating the medical imaging file using the classification model (Prosky, Para. 0259, contrasting parameters and/or density windowing may have already been applied and/or the image data may have been undergone other pre-processing to convert density values to greyscale values) and (Para. 0260, the input can correspond to density values of raw sensor data, and the output can correspond to greyscale values of a JPEG). Therefore, it would have been obvious to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Goswami to incorporate the teachings of Prosky to include the one or more non-transitory computer readable media of claim 20, wherein the operations further comprise converting the images in the data set of the medical imaging file to greyscale prior to evaluating the medical imaging file using the classification model (Prosky, Para. 0259). Doing so would aid the model parameters to update over time to improve existing inference functions and/or to add new inference functions, for example corresponding to new scan categories. In particular, the some or all of the de-identified medical scans generated by the de-identification system 2608 can be transmitted back to the central server system, and the central server system 2640 can train on this data to improve existing models by producing updated model parameters of an existing inference function and/or to generate new models, for example, corresponding to new scan categories, by producing new model parameters for new inference functions (Prosky, Para. 0167). In regards to claim 23, the combination of Goswami and Prosky teaches the one or more non-transitory computer readable media of claim 20, wherein the medical imaging file is a digital imaging and communications in medicine (DICOM) file (Prosky, Para. 0150, the receiver can receive DICOM images from the medical picture archive system 2620. The transmitter 2604 can send annotated DICOM files to the medical picture archive system 2620). Therefore, it would have been obvious to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Goswami to incorporate the teachings of Prosky to include teaches wherein the medical imaging file is a digital imaging and communications in medicine (DICOM) file (Prosky, Para. 0150). Doing so would aid the model parameters to update over time to improve existing inference functions and/or to add new inference functions, for example corresponding to new scan categories. In particular, the some or all of the de-identified medical scans generated by the de-identification system 2608 can be transmitted back to the central server system, and the central server system 2640 can train on this data to improve existing models by producing updated model parameters of an existing inference function and/or to generate new models, for example, corresponding to new scan categories, by producing new model parameters for new inference functions (Prosky, Para. 0167). . Claims 2-5 and 12 are rejected under 35 U.S.C. 103 as being unpatentable over Goswami et al. (US 2021/0056404 A1), hereinafter Goswami in view of Prosky et al. (US 2020/0160978 A1), hereafter Prosky and further in view of Briliauskas et al. (US 11,693,965 B1), hereinafter Briliauskas. In regards to claim 2, the combination of Goswami and Prosky does not explicitly teach the system of claim 1, the operations further comprising: evaluating the modified medical imaging file using the classification model to generate a second score representative of a likelihood that the modified medical imaging file contains anomalous or malicious data; and based at least in part on determining that the second score meets or exceeds the first threshold, quarantining the medical imaging file or flagging the medical imaging file for additional review. However, Briliauskas teaches the operations further comprising: evaluating the modified medical imaging file using the classification model to generate a second score representative of a likelihood that the modified medical imaging file contains anomalous or malicious data; and based at least in part on determining that the second score meets or exceeds the first threshold, quarantining the medical imaging file or flagging the medical imaging file for additional review (Briliauskas, Col. 12, Lines 15-26, once a file is labeled (e.g., “clean” or “malicious”), the file is stored with its label in the training data set on the client device 300. Additionally, or alternatively, malicious files may be quarantined, deleted, etc., and/or an alert may be presented to a user recommending that the malicious file be removed. If, however, a match in the malware properties database is not identified for a local file and the maliciousness of the file cannot be accurately predicted, the file may be flagged for additional evaluation, quarantined, discarded, and/or removed from the training data). Goswami, Prosky and Briliauskas are considered to be analogous to the claim invention because they are in the same field of detecting anomalies and/or malware in imaging files. Therefore, it would have been obvious to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Goswami and Prosky to incorporate the teachings of Briliauskas to include the instructions further causing the system to: evaluate the modified medical imaging file using the classification model to generate a second score representative of a likelihood that the modified medical imaging file contains anomalous or malicious data; and if the second score meets or exceeds the first threshold, quarantine the medical imaging file or flagging the medical imaging file for additional review (Briliauskas, Col. 12, Lines 15-26). Doing so would aid the federate learning methods described herein leverage the unique files stored on each client device, which can result in a more robust and accurate model that reflects client preferences (Briliauskas, Col. 10, Lines 1-3). In regards to claim 3, the combination of Goswami and Prosky does not explicitly teach the system of claim 1, wherein the one or more processors are configured to store the medical imaging file is stored without modification if the first score is less than the second threshold, the second threshold being lower than the first threshold. However, Briliauskas teaches wherein the one or more processors are configured to store the medical imaging file is stored without modification if the first score is less than the second threshold, the second threshold being lower than the first threshold (Briliauskas, Col. 12, Lines 13-18, a file is only labeled as clean if the maliciousness score, generated by the model, is below a first threshold (e.g., 0.5) or if a confidence score of the prediction is above a second threshold (e.g., above 0.8). Once a file is labeled (e.g., “clean” or “malicious”), the file is stored with its label in the training data set on the client device 300). Goswami, Prosky and Briliauskas are both considered to be analogous to the claim invention because they are in the same field of detecting anomalies and/or malware in imaging files. Therefore, it would have been obvious to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Goswami and Prosky to incorporate the teachings of Briliauskas to include wherein the medical imaging file is stored without modification if the first score is less than a second threshold, wherein the second threshold is lower than the first threshold (Briliauskas, Col. 12, Lines 13-18). Doing so would aid the federate learning methods described herein leverage the unique files stored on each client device, which can result in a more robust and accurate model that reflects client preferences (Briliauskas, Col. 10, Lines 1-3). In regards to claim 4, the combination of Goswami and Prosky does not explicitly teach the system of claim 1, wherein the one or more processors are configured to use the medical imaging file to retrain the classification model if the first score is between the first threshold and a second threshold, wherein the second threshold is lower than the first threshold. However, Briliauskas teaches wherein the one or more processors are configured to use the medical imaging file to retrain the classification model if the first score is between the first threshold and a second threshold, wherein the second threshold is lower than the first threshold (Briliauskas, Col. 10, Lines 65-68d Col. 11, Lines1-8, the output of the model is a malicious “score” (e.g., a fraction from 0-1) which indicates a predicted likelihood that the file is malicious. For example, a file with a maliciousness score of 0.86 or 86% is highly likely to be malicious. In some embodiments, the model outputs both a classification for the file (e.g., malicious or not malicious) and a confidence score, which indicates a confidence level of the prediction. For example, an output with a low confidence score (e.g., less than 0.5 or 50%) indicates that the classification for the file may be inaccurate). Goswami, Prosky and Briliauskas are considered to be analogous to the claim invention because they are in the same field of detecting anomalies and/or malware in imaging files. Therefore, it would have been obvious to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Goswami tand Prosky o incorporate the teachings of Briliauskas to include wherein the one or more processors are configured to use the medical imaging file to retrain the classification model if the first score is between the first threshold and a second threshold, wherein the second threshold is lower than the first threshold (Briliauskas, Col. 10, Lines 65-68 and Col. 11, Lines1-8). Doing so would aid the federate learning methods described herein leverage the unique files stored on each client device, which can result in a more robust and accurate model that reflects client preferences (Briliauskas, Col. 10, Lines 1-3). In regards to claim 5, the combination of Goswami and Prosky does not explicitly teach the system of claim 1, wherein the one or more processors are configured to store the medical imaging file without said modification if the first score is less than the first threshold. However, Briliauskas teaches wherein the one or more processors are configured to store the medical imaging file without said modification if the first score is less than the first threshold (Briliauskas, Col. 26, Lines 9-14, for example, a file may only be labeled as malicious if the confidence score exceeds 0.7 or 70%. If the confidence score is below 0.7, then the file may be labeled as clean. In some embodiments, a second threshold may be set for labeling a file as "clean), (Briliauskas, Col. 12, Lines 17-19, once a file is labeled (e.g., "clean" or "malicious"), the file is stored with its label in the training data set on the client device 300). Goswami and Briliauskas are both considered to be analogous to the claim invention because they are in the same field of detecting anomalies and/or malware in imaging files. Therefore, it would have been obvious to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Goswami to incorporate the teachings of Briliauskas to include wherein the one or more processors are configured to store the medical imaging file without said modification if the first score is less than the first threshold (Briliauskas, Col. 26, Lines 9-14), (Briliauskas, Col. 12, Lines 17-19). Doing so would aid the federate learning methods described herein leverage the unique files stored on each client device, which can result in a more robust and accurate model that reflects client preferences (Briliauskas, Col. 10, Lines 1-3). In regards to claim 10, the combination of Goswami and Prosky does not explicitly teach the system of claim 1, wherein the classification model is a first classification model and the first score is representative of a likelihood that the medical imaging file contains an anomaly, the operations further comprising evaluating the medical imaging file using a second classification model that generates a second score representative of a likelihood that the medical imaging file contains malware. However, Briliauskas teaches the system of claim 1, wherein the classification model is a first classification model and the first score is representative of a likelihood that the medical imaging file contains an anomaly (Briliauskas, Col. 8, Lines 38-42, predicting whether the file is malicious includes generating, by the first malware detection model, a maliciousness score for the file, where the is labeled as malicious if the maliciousness score meets or exceeds a threshold), the operations further comprising evaluating the medical imaging file using a second classification model that generates a second score representative of a likelihood that the medical imaging file contains malware (Briliauskas, Col. 6, Lines 18-20, the operations further include predicting a maliciousness of at least one additional local file using the second malware detection model). Goswami and Briliauskas are both considered to be analogous to the claim invention because they are in the same field of detecting anomalies and/or malware in imaging files. Therefore, it would have been obvious to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Goswami to incorporate the teachings of Briliauskas to include wherein the medical imaging file is used to retrain the classification model if the first score is between the first threshold and a second threshold, wherein the second threshold is lower than the first threshold (Briliauskas, Col. 10, Lines 65-68d Col. 11, Lines1-8). Doing so would aid the federate learning methods described herein leverage the unique files stored on each client device, which can result in a more robust and accurate model that reflects client preferences (Briliauskas, Col. 10, Lines 1-3). In regards to claim 12, the method of claim 12 is similarly analyzed and rejected as the system claim 2. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. See PTO-892. Any inquiry concerning this communication or earlier communications from the examiner should be directed to GITA FARAMARZI whose telephone number is (571)272-0248. The examiner can normally be reached Monday- Friday 9:00 am- 6:00 pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jorge L. Ortiz-Criado can be reached at (571)272-7624. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /GITA FARAMARZI/Examiner, Art Unit 2496
Read full office action

Prosecution Timeline

Show 3 earlier events
Oct 02, 2025
Interview Requested
Oct 09, 2025
Applicant Interview (Telephonic)
Oct 09, 2025
Examiner Interview Summary
Oct 30, 2025
Response Filed
Feb 05, 2026
Final Rejection mailed — §103
May 04, 2026
Request for Continued Examination
May 11, 2026
Response after Non-Final Action
Aug 12, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12627633
SYSTEM AND METHOD FOR APPLICATION TRAFFIC AND RUNTIME BEHAVIOR LEARNING AND ENFORCEMENT
5y 9m to grant Granted May 12, 2026
Patent 12339997
ENTITY FOCUSED NATURAL LANGUAGE GENERATION
2y 1m to grant Granted Jun 24, 2025
Patent 12316648
Data value classifier
5y 10m to grant Granted May 27, 2025
Patent 12301564
VIRTUAL SESSION ACCESS MANAGEMENT
4y 3m to grant Granted May 13, 2025
Patent 12256022
BLOCKCHAIN TRANSACTION COMPRISING RUNNABLE CODE FOR HASH-BASED VERIFICATION
3y 3m to grant Granted Mar 18, 2025
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
51%
Grant Probability
70%
With Interview (+18.9%)
3y 7m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 80 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month