Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Amendments / Arguments
Applicant's arguments filed 06/11/2026, regarding the 35 U.S.C. 103 rejection have been fully considered and are persuasive. Therefore, the rejection has been withdrawn. However, upon further review the rejection is further maintained under Ward et al. (US 20190245878 A1, referred to as Ward) in view of Bairavasundaram et al. (US 20130086269 A1, referred to as Bairavasundaram).
However, it is noted that the amendments have raised a 112a issue which is discussed below.
DETAILED ACTION
This is a reply to the arguments filed on 06/11/2026, in which, claims 1-6, 8, 11-18 and 21-25 are pending. Claims 1, 11, and 16 are independent. Claims 7, 9-10 and 19-20 are cancelled.
When making claim amendments, the applicant is encouraged to consider the references in their entireties, including those portions that have not been cited by the examiner and their equivalents as they may most broadly and appropriately apply to any particular anticipated claim amendments.
Information Disclosure Statement
The information disclosure statements (IDS) submitted on 06/08/2026 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Claim Rejections - 35 USC § 112
The following is a quotation of the first paragraph of 35 U.S.C. 112(a):
(a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention.
The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112:
The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention.
Claims 1-6, 8, 11-18 and 21-25 rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention.
Claims 1, 11 and 16 recite that "the degree of the impact of the poisoned inference on the inference consumer is determined using information regarding the poisoned inference that is self-reported by the inference consumer... while the inference consumer is unaware that the poisoned inference is poisoned." This limitation requires that the inference consumer's awareness state be a specific condition existing at the time the reliance information is self-reported. That the consumer does not know the inference is poisoned. The specification fails to provide adequate written description support for this limitation. While the specification describes a self-reported inference reliance database in which the inference consumer records a degree of reliance on each inference and describes notifying the inference consumer of a poisoned inference as a remediation action, the specification is entirely silent regarding the awareness or unawareness of the inference consumer as to the poisoned status of any inference. The specification nowhere describes the consumer's knowledge state as a feature of the invention, nor ties the self-reporting of reliance information to the consumer being unaware of poisoning. The consumer's unawareness operates as a de facto assumption rather than a disclosed design choice or distinguishing characteristic.
Accordingly, claims 1, 11 and 16 lack adequate written description support for the limitation. The dependent claims are rejected under similar rationale.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-6, 8, 11-18 and 21-25 are rejected under 35 U.S.C. 103 as being unpatentable over Szeto et al. (US 20170124487 A1, referred to as Sezto) in view of Ward et al. (US 20190245878 A1, referred to as Ward) in further view of Bairavasundaram et al. (US 20130086269 A1, referred to as Bairavasundaram).
In reference to claim 1, A method for managing an artificial intelligence (AI) model hosted by at least one data processing system, comprising (Szeto: [0047], [0414] and Fig. 23-24 Provides for a method, executed by a hosted computing system with a processor and memory, directed to managing (training, versioning, deploying, rolling back) a machine learning model.)
Training a second instance of the AI model using ingest data (Szeto: [0209]-[0210] and [0417] Provides for training a later, updated instance of an already-existing model using newly ingested data.)
Providing, after the second instance of the AI model using the ingest data, the second instance of the AI model to an inference consumer (Szeto: [0241] and [0419]-[0423] Provides for post-training deployment of the newly trained variant to a production query interface where a consuming application obtains inferences.)
identifying after use of the second instance of the AI model has been provided to the inference consumer that the second instance of the AI model is a poisoned AI model (Szeto: [0211]-[0213] Provides for after the fact discovery, once the variant is already deployed and serving, that the model was corrupted.)
identifying a poisoned inference generated by the poisoned AI model using a snapshot of the poisoned AI model (Szeto: [0291]-[0296], [0351] and Fig. 19 Provides for pinpointing individual bad predictions attributable to a specific engine variant, using stored per-model metadata plus per-query records that tie each served inference back to the variant that generated it.)
wherein the snapshot comprises information that can be used to rebuild or restore the second instance of the AI model to a version of the second instance of the AI model that has not yet been trained using the ingest data (Szeto: [0221], [0255] and [0357] Provides for for stored per-model information to reproduce a historical model and effect a state rollback.)
the poisoned inference has already been provided to an inference consumer before the poisoned inference is identified using the snapshot (Szeto: [0290]-[0293] and [0324] Provides for a strict temporal sequence in which the prediction is served to the consuming application first, and only later aggregated, scored, filtered, and evaluated to identify poor predictions.)
Reverting, using the snapshot, the poisoned AI model to a non-poisoned version of the poisoned AI model (Szeto: [0175], [0216] and [0420]-[0425] Provides for reverting a model that was trained on unsuitable data back to an identified earlier clean variant, using the persisted per-model version record.)
Szeto doesn't explicitly teach making a first determination that the poisoned inference does not need to be remediated, In response to making the first determination Doing nothing about the poisoned inference already provided to the inference consumer, Letting the inference consumer continue to use the poisoned inference without ever generating and transmitting a replacement for the poisoned inference to the inference consumer using the non-poisoned version of the poisoned AI model even after the poisoned AI model is reverted the non-poisoned version of the poisoned AI model, The first determination being made as part of determining whether limited computing resources of the at least one data processing system can be saved by now having to remediate an impact of the poisoned inference of the inference consumer, The first determination is based on a degree of the impact of the poisoned inference on the inference consumer, The degree of the impact of the poisoned inference on the inference consumer is determined using information regarding the poisoned inference that is self-reported by the inference consumer after the inference consumer has used the poisoned inference, and while the inference consumer is unaware that the poisoned inference is poisoned. However, Ward teaches:
making a first determination that the poisoned inference does not need to be remediated (Ward: [0008] and [0048] Provides for detecting a defect as acceptable and affirmatively electing not to remediate it.)
In response to making the first determination Doing nothing about the poisoned inference already provided to the inference consumer (Ward: [0049]-[0051] Provides for affirmative inaction as the response to an acceptability determination, suppressing the remediation plan, the consequence action, and the reporting alike.)
Letting the inference consumer continue to use the poisoned inference without ever generating and transmitting a replacement for the poisoned inference to the inference consumer using the non-poisoned version of the poisoned AI model even after the poisoned AI model is reverted the non-poisoned version of the poisoned AI model (Ward: [0043]-[0049] Provides for the consumer continuing to operate with the known defect and for nothing corrective being transmitted to them.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Szeto, which provides a method for managing AI models including training, deployment, poisoning detection through snapshots, and reverting poisoned models to clean versions, with the teachings of Ward, which introduces affirmatively determining that a detected defect does not require remediation and taking no corrective action while allowing the consumer to continue using the affected output. One of ordinary skill in the art would recognize the ability to incorporate Ward's acceptability-based inaction decision into Szeto's poisoned inference management system to provide a more resource-efficient remediation framework. One of ordinary skill in the art would be motivated to make this modification in order to conserve computing resources by avoiding unnecessary remediation efforts when the impact of a poisoned inference is determined to be acceptable.
Szeto in view of Ward doesn’t explicitly teach the first determination being made as part of determining whether limited computing resources of the at least one data processing system can be saved by now having to remediate an impact of the poisoned inference of the inference consumer, the first determination is based on a degree of the impact of the poisoned inference on the inference consumer, the degree of the impact of the poisoned inference on the inference consumer is determined using information regarding the poisoned inference that is self-reported by the inference consumer after the inference consumer has used the poisoned inference and while the inference consumer is unaware that the poisoned inference is poisoned. However, Bairavasundaram teaches:
The first determination being made as part of determining whether limited computing resources of the at least one data processing system can be saved by now having to remediate an impact of the poisoned inference of the inference consumer (Bairavasundaram: [0005]-[0006], [0017] and [0033] Provides for deciding whether corrective action is worth taking.)
The first determination is based on a degree of the impact of the poisoned inference on the inference consumer (Bairavasundaram: [0028]-[0036] Provides for gating the remediation decision on the measured severity of the violation and its effect on the served workload.)
The degree of the impact of the poisoned inference on the inference consumer is determined using information regarding the poisoned inference that is self-reported by the inference consumer after the inference consumer has used the poisoned inference (Bairavasundaram: [0022]-[0024] and [0044] Provides for the consuming entity itself reporting usage and impact information upward.)
while the inference consumer is unaware that the poisoned inference is poisoned (Bairavasundaram: [0006] and [0028] Provides for reporting entities that supply information without knowledge of the violation assessment being performed above them.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Szeto in view of Ward, which together provide a method for managing poisoned AI models with snapshot-based detection, model reversion, and acceptability-based decisions to forgo remediation, with the teachings of Bairavasundaram, which introduces resource-aware remediation decisions based on measured impact severity using self-reported information from consuming entities who are unaware of the violation assessment being performed. One of ordinary skill in the art would recognize the ability to incorporate Bairavasundaram's impact-severity gating and consumer-reported feedback mechanisms into the combined poisoned inference management system to enable more informed and resource-conscious remediation decisions. One of ordinary skill in the art would be motivated to make this modification in order to optimize computing resource allocation by quantifying the actual impact of poisoned inferences before committing to remediation.
In reference to claim 2, The method of claim 1, further comprising: prior to making the first determination: obtaining a third instance of the AI model, the third instance of the AI model not being poisoned and being intended to generate future inferences to be provided to the inference consumer (Szeto: [0175], [0216], [0293] and [0366] Provides for obtaining and placing into production a distinct, non-poisoned model instance.)
In reference to claim 3, The method of claim 2, wherein obtaining the third instance of the AI model comprises: identifying a second portion of a training data set as poisoned training data, the second portion of the training data set being used to train the poisoned AI model (Szeto: [0212]-[0221] and [0422] Provides for identifying the particular portion of the training that was used to train the badly-performing model and that is the reason it performs poorly.)
Purging the poisoned training data from a training data repository (Szeto: [0052], [0135], [0254], and [0386] Provides for removing a data source from the platform's managed repository by explicit command, and for a cleansing component that filters and discards unwanted data before it reaches the algorithms.)
In reference to claim 4, The method of claim 3, wherein obtaining the third instance of the AI model further comprises: obtaining a first instance of the AI model, the first instance of the AI model not being poisoned (Szeto: [0175]. [0214]-[0216] and [0357] Provides for retrieving an identified earlier, unaffected model variant as the clean baseline, expressly because the later variant was trained on the problematic data.)
Obtaining a third portion of the training data set, the third portion of the training data set not including the poisoned training data (Szeto: [0131]-[0134], [0051], [0209] and [0254] Provides for selecting and registering a specific, differently-bounded subset or range of training data for a retraining run.)
Obtaining the third instance of the AI model using the third portion of the training data and the first instance of the AI model (Szeto: [0209]-[0210], [0228], [0238] and [0266] Provides for generating an updated model instance by applying newly selected training data to a persisted, re-usable prior model, with the result swapped in for the existing one.)
In reference to claim 5, The method of claim 4, wherein identifying the poisoned inference comprises: obtaining a second snapshot of the AI model from a snapshot database, the second snapshot of the AI model being the snapshot of the poisoned AI model (Szeto: [0085], [0179]-[0185], [0221] and [0255] Provides for a dedicated persistent database storing a uniquely-identified record for every generated model variant.)
Obtaining information associated with the snapshot of the poisoned AI model (Szeto: [0080], [0176], [0221] and [0255] Provides for retrieving a defined body of metadata bound to each stored model record.)
Identifying the poisoned inference using the information (Szeto: [0291], [0324] and [0346]-[0351] Provides for using the model-identifying metadata as a filter key to retrieve the specific served predictions attributable to that variant, and then surfacing those individual query records with their prediction scores.)
In reference to claim 6, The method of claim 5, wherein obtaining information associated with the snapshot of the poisoned AI model comprises: obtaining metadata using the information, the metadata indicating (Szeto: [0080], [0221] and [0255] Provides for a stored metadata part, distinct from the model part, retrieved alongside the model record and version, application-mapping, and evaluation information.)
An association between the poisoned AI model and the poisoned inference (Szeto: [0285]-[0291] and [0346]-[0351] Provides for an explicit stored binding between a specific served prediction and the identified engine variant that produced it.)
An identifier for the ingest data used to generate the poisoned inference (Szeto: [0080], [0143]-[0156[ and [0221] Provides for named, uniquely-identified data sources that are recorded against each model and even embedded in the model ID string itself, so the data used is traceable from the stored record.)
An identifier for the inference consumer that has consumed the poisoned inference (Szeto: [0281]-[0290], [0307] and [0325] Provides for recording a user ID and user-device ID within the tracking tag bound to each served prediction.)
In reference to claim 8, The method of claim 1, wherein making the first determination comprises: accessing a self-reported inference reliance database that is updated by the inference consumer, wherein the self-reported inference reliance dataabase comprises: a series of inferences provided to the inference consumer, the series of inferences comprising the poisoned inference; and a degree of reliance of the inference consumer on each inference of the series of inferences, the degree of reliance being self-reported by the inference consumer into the self-reported by the inference consumer into the self-reported inference reliance database; obtaining the degree of reliance of the inference consumer on the poisoned inference using the poisoned inference and the self-reported inference reliance database (Szeto: [0060], [0281]-[0292], [0328] and [0351] Provides for recording a user ID and user-device ID within the tracking tag bound to each served prediction.)
Making a second determination regarding that the degree of reliance of the inference consumer on the poisoned inference exceeds a reliance threshold; and in response to making the second determination electing, not to remediate the poisoned inference (Szeto: [0269]-[0278] and [0304]-[0305] Provides for comparing a computed score against a predefined threshold or baseline and, on the basis of that comparison, conditionally electing to take no action,)
In reference to claim 11, A non-transitory machine-readable medium having instructions stored therein, which when executed by a processor of a data processing system, cause the processor to perform operations for managing an artificial intelligence (AI) model hosted by at least the data processing system, the operations comprising: identifying after use of the second instance of the AI model has been provided to the inference consumer that the second instance of the AI model is a poisoned AI model; (Liu: [0011]-[0012] and [0025] Provides for data poisoning and provides a comprehensive definition of how a model can be poisoned. The method of identifying a poisoned model is desc
In reference to claim 11, A non-transitory machine-readable medium having instructions stored therein, which when executed by a processor of a data processing system, cause the processor to perform operations for managing an artificial intelligence (AI) model hosted by at least the data processing system, the operations comprising: (Szeto: [0047], [0414] and Fig. 23-24 Provides for a method, executed by a hosted computing system with a processor and memory, directed to managing (training, versioning, deploying, rolling back) a machine learning model.)
Training a second instance of the AI model using ingest data (Szeto: [0209]-[0210] and [0417] Provides for training a later, updated instance of an already-existing model using newly ingested data.)
Providing, after the second instance of the AI model using the ingest data, the second instance of the AI model to an inference consumer (Szeto: [0241] and [0419]-[0423] Provides for post-training deployment of the newly trained variant to a production query interface where a consuming application obtains inferences.)
identifying after use of the second instance of the AI model has been provided to the inference consumer that the second instance of the AI model is a poisoned AI model (Szeto: [0211]-[0213] Provides for after the fact discovery, once the variant is already deployed and serving, that the model was corrupted.)
identifying a poisoned inference generated by the poisoned AI model using a snapshot of the poisoned AI model (Szeto: [0291]-[0296], [0351] and Fig. 19 Provides for pinpointing individual bad predictions attributable to a specific engine variant, using stored per-model metadata plus per-query records that tie each served inference back to the variant that generated it.)
wherein the snapshot comprises information that can be used to rebuild or restore the second instance of the AI model to a version of the second instance of the AI model that has not yet been trained using the ingest data (Szeto: [0221], [0255] and [0357] Provides for for stored per-model information to reproduce a historical model and effect a state rollback.)
the poisoned inference has already been provided to an inference consumer before the poisoned inference is identified using the snapshot (Szeto: [0290]-[0293] and [0324] Provides for a strict temporal sequence in which the prediction is served to the consuming application first, and only later aggregated, scored, filtered, and evaluated to identify poor predictions.)
Reverting, using the snapshot, the poisoned AI model to a non-poisoned version of the poisoned AI model (Szeto: [0175], [0216] and [0420]-[0425] Provides for reverting a model that was trained on unsuitable data back to an identified earlier clean variant, using the persisted per-model version record.)
Szeto doesn't explicitly teach making a first determination that the poisoned inference does not need to be remediated, In response to making the first determination Doing nothing about the poisoned inference already provided to the inference consumer, Letting the inference consumer continue to use the poisoned inference without ever generating and transmitting a replacement for the poisoned inference to the inference consumer using the non-poisoned version of the poisoned AI model even after the poisoned AI model is reverted the non-poisoned version of the poisoned AI model, The first determination being made as part of determining whether limited computing resources of the at least one data processing system can be saved by now having to remediate an impact of the poisoned inference of the inference consumer, The first determination is based on a degree of the impact of the poisoned inference on the inference consumer, The degree of the impact of the poisoned inference on the inference consumer is determined using information regarding the poisoned inference that is self-reported by the inference consumer after the inference consumer has used the poisoned inference, and while the inference consumer is unaware that the poisoned inference is poisoned. However, Ward teaches:
making a first determination that the poisoned inference does not need to be remediated (Ward: [0008] and [0048] Provides for detecting a defect as acceptable and affirmatively electing not to remediate it.)
In response to making the first determination Doing nothing about the poisoned inference already provided to the inference consumer (Ward: [0049]-[0051] Provides for affirmative inaction as the response to an acceptability determination, suppressing the remediation plan, the consequence action, and the reporting alike.)
Letting the inference consumer continue to use the poisoned inference without ever generating and transmitting a replacement for the poisoned inference to the inference consumer using the non-poisoned version of the poisoned AI model even after the poisoned AI model is reverted the non-poisoned version of the poisoned AI model (Ward: [0043]-[0049] Provides for the consumer continuing to operate with the known defect and for nothing corrective being transmitted to them.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Szeto, which provides a method for managing AI models including training, deployment, poisoning detection through snapshots, and reverting poisoned models to clean versions, with the teachings of Ward, which introduces affirmatively determining that a detected defect does not require remediation and taking no corrective action while allowing the consumer to continue using the affected output. One of ordinary skill in the art would recognize the ability to incorporate Ward's acceptability-based inaction decision into Szeto's poisoned inference management system to provide a more resource-efficient remediation framework. One of ordinary skill in the art would be motivated to make this modification in order to conserve computing resources by avoiding unnecessary remediation efforts when the impact of a poisoned inference is determined to be acceptable.
Szeto in view of Ward doesn’t explicitly teach the first determination being made as part of determining whether limited computing resources of the at least one data processing system can be saved by now having to remediate an impact of the poisoned inference of the inference consumer, the first determination is based on a degree of the impact of the poisoned inference on the inference consumer, the degree of the impact of the poisoned inference on the inference consumer is determined using information regarding the poisoned inference that is self-reported by the inference consumer after the inference consumer has used the poisoned inference and while the inference consumer is unaware that the poisoned inference is poisoned. However, Bairavasundaram teaches:
The first determination being made as part of determining whether limited computing resources of the at least one data processing system can be saved by now having to remediate an impact of the poisoned inference of the inference consumer (Bairavasundaram: [0005]-[0006], [0017] and [0033] Provides for deciding whether corrective action is worth taking.)
The first determination is based on a degree of the impact of the poisoned inference on the inference consumer (Bairavasundaram: [0028]-[0036] Provides for gating the remediation decision on the measured severity of the violation and its effect on the served workload.)
The degree of the impact of the poisoned inference on the inference consumer is determined using information regarding the poisoned inference that is self-reported by the inference consumer after the inference consumer has used the poisoned inference (Bairavasundaram: [0022]-[0024] and [0044] Provides for the consuming entity itself reporting usage and impact information upward.)
while the inference consumer is unaware that the poisoned inference is poisoned (Bairavasundaram: [0006] and [0028] Provides for reporting entities that supply information without knowledge of the violation assessment being performed above them.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Szeto in view of Ward, which together provide a method for managing poisoned AI models with snapshot-based detection, model reversion, and acceptability-based decisions to forgo remediation, with the teachings of Bairavasundaram, which introduces resource-aware remediation decisions based on measured impact severity using self-reported information from consuming entities who are unaware of the violation assessment being performed. One of ordinary skill in the art would recognize the ability to incorporate Bairavasundaram's impact-severity gating and consumer-reported feedback mechanisms into the combined poisoned inference management system to enable more informed and resource-conscious remediation decisions. One of ordinary skill in the art would be motivated to make this modification in order to optimize computing resource allocation by quantifying the actual impact of poisoned inferences before committing to remediation.
In reference to claim 12, The non-transitory machine-readable medium of claim 11, further comprising: prior to making the first determination: obtaining a third instance of the AI model, the third instance of the AI model not being poisoned and being intended to generate future inferences to be provided to the inference consumer (Szeto: [0175], [0216], [0293] and [0366] Provides for obtaining and placing into production a distinct, non-poisoned model instance.)
In reference to claim 13, The non-transitory machine-readable medium of claim 12, wherein obtaining the third instance of the AI model comprises: identifying a second portion of a training data set as poisoned training data, the second portion of the training data set being used to train the poisoned AI model (Szeto: [0212]-[0221] and [0422] Provides for identifying the particular portion of the training that was used to train the badly-performing model and that is the reason it performs poorly.)
Purging the poisoned training data from a training data repository (Szeto: [0052], [0135], [0254], and [0386] Provides for removing a data source from the platform's managed repository by explicit command, and for a cleansing component that filters and discards unwanted data before it reaches the algorithms.)
In reference to claim 14, The non-transitory machine-readable medium of claim 13, wherein obtaining the third instance of the AI model further comprises: obtaining a first instance of the AI model, the first instance of the AI model not being poisoned (Szeto: [0175]. [0214]-[0216] and [0357] Provides for retrieving an identified earlier, unaffected model variant as the clean baseline, expressly because the later variant was trained on the problematic data.)
Obtaining a third portion of the training data set, the third portion of the training data set not including the poisoned training data (Szeto: [0131]-[0134], [0051], [0209] and [0254] Provides for selecting and registering a specific, differently-bounded subset or range of training data for a retraining run.)
Obtaining the third instance of the AI model using the third portion of the training data and the first instance of the AI model (Szeto: [0209]-[0210], [0228], [0238] and [0266] Provides for generating an updated model instance by applying newly selected training data to a persisted, re-usable prior model, with the result swapped in for the existing one.)
In reference to claim 15, The non-transitory machine-readable medium of claim 11, wherein identifying the poisoned inference comprises: obtaining a second snapshot of the AI model from a snapshot database, the second snapshot of the AI model being the snapshot of the poisoned AI model (Szeto: [0085], [0179]-[0185], [0221] and [0255] Provides for a dedicated persistent database storing a uniquely-identified record for every generated model variant.)
Obtaining information associated with the snapshot of the poisoned AI model (Szeto: [0080], [0176], [0221] and [0255] Provides for retrieving a defined body of metadata bound to each stored model record.)
Identifying the poisoned inference using the information (Szeto: [0291], [0324] and [0346]-[0351] Provides for using the model-identifying metadata as a filter key to retrieve the specific served predictions attributable to that variant, and then surfacing those individual query records with their prediction scores.)
In reference to claim 16, data processing system, comprising: a processor; and a memory coupled to the processor to store instructions, which when executed by the processor, cause the processor to perform operations for managing an artificial intelligence (AI) model hosted by at least the data processing system, the operations comprising: (Szeto: [0047], [0414] and Fig. 23-24 Provides for a method, executed by a hosted computing system with a processor and memory, directed to managing (training, versioning, deploying, rolling back) a machine learning model.)
Training a second instance of the AI model using ingest data (Szeto: [0209]-[0210] and [0417] Provides for training a later, updated instance of an already-existing model using newly ingested data.)
Providing, after the second instance of the AI model using the ingest data, the second instance of the AI model to an inference consumer (Szeto: [0241] and [0419]-[0423] Provides for post-training deployment of the newly trained variant to a production query interface where a consuming application obtains inferences.)
identifying after use of the second instance of the AI model has been provided to the inference consumer that the second instance of the AI model is a poisoned AI model (Szeto: [0211]-[0213] Provides for after the fact discovery, once the variant is already deployed and serving, that the model was corrupted.)
identifying a poisoned inference generated by the poisoned AI model using a snapshot of the poisoned AI model (Szeto: [0291]-[0296], [0351] and Fig. 19 Provides for pinpointing individual bad predictions attributable to a specific engine variant, using stored per-model metadata plus per-query records that tie each served inference back to the variant that generated it.)
wherein the snapshot comprises information that can be used to rebuild or restore the second instance of the AI model to a version of the second instance of the AI model that has not yet been trained using the ingest data (Szeto: [0221], [0255] and [0357] Provides for for stored per-model information to reproduce a historical model and effect a state rollback.)
the poisoned inference has already been provided to an inference consumer before the poisoned inference is identified using the snapshot (Szeto: [0290]-[0293] and [0324] Provides for a strict temporal sequence in which the prediction is served to the consuming application first, and only later aggregated, scored, filtered, and evaluated to identify poor predictions.)
Reverting, using the snapshot, the poisoned AI model to a non-poisoned version of the poisoned AI model (Szeto: [0175], [0216] and [0420]-[0425] Provides for reverting a model that was trained on unsuitable data back to an identified earlier clean variant, using the persisted per-model version record.)
Szeto doesn't explicitly teach making a first determination that the poisoned inference does not need to be remediated, In response to making the first determination Doing nothing about the poisoned inference already provided to the inference consumer, Letting the inference consumer continue to use the poisoned inference without ever generating and transmitting a replacement for the poisoned inference to the inference consumer using the non-poisoned version of the poisoned AI model even after the poisoned AI model is reverted the non-poisoned version of the poisoned AI model, The first determination being made as part of determining whether limited computing resources of the at least one data processing system can be saved by now having to remediate an impact of the poisoned inference of the inference consumer, The first determination is based on a degree of the impact of the poisoned inference on the inference consumer, The degree of the impact of the poisoned inference on the inference consumer is determined using information regarding the poisoned inference that is self-reported by the inference consumer after the inference consumer has used the poisoned inference, and while the inference consumer is unaware that the poisoned inference is poisoned. However, Ward teaches:
making a first determination that the poisoned inference does not need to be remediated (Ward: [0008] and [0048] Provides for detecting a defect as acceptable and affirmatively electing not to remediate it.)
In response to making the first determination Doing nothing about the poisoned inference already provided to the inference consumer (Ward: [0049]-[0051] Provides for affirmative inaction as the response to an acceptability determination, suppressing the remediation plan, the consequence action, and the reporting alike.)
Letting the inference consumer continue to use the poisoned inference without ever generating and transmitting a replacement for the poisoned inference to the inference consumer using the non-poisoned version of the poisoned AI model even after the poisoned AI model is reverted the non-poisoned version of the poisoned AI model (Ward: [0043]-[0049] Provides for the consumer continuing to operate with the known defect and for nothing corrective being transmitted to them.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Szeto, which provides a method for managing AI models including training, deployment, poisoning detection through snapshots, and reverting poisoned models to clean versions, with the teachings of Ward, which introduces affirmatively determining that a detected defect does not require remediation and taking no corrective action while allowing the consumer to continue using the affected output. One of ordinary skill in the art would recognize the ability to incorporate Ward's acceptability-based inaction decision into Szeto's poisoned inference management system to provide a more resource-efficient remediation framework. One of ordinary skill in the art would be motivated to make this modification in order to conserve computing resources by avoiding unnecessary remediation efforts when the impact of a poisoned inference is determined to be acceptable.
Szeto in view of Ward doesn’t explicitly teach the first determination being made as part of determining whether limited computing resources of the at least one data processing system can be saved by now having to remediate an impact of the poisoned inference of the inference consumer, the first determination is based on a degree of the impact of the poisoned inference on the inference consumer, the degree of the impact of the poisoned inference on the inference consumer is determined using information regarding the poisoned inference that is self-reported by the inference consumer after the inference consumer has used the poisoned inference and while the inference consumer is unaware that the poisoned inference is poisoned. However, Bairavasundaram teaches:
The first determination being made as part of determining whether limited computing resources of the at least one data processing system can be saved by now having to remediate an impact of the poisoned inference of the inference consumer (Bairavasundaram: [0005]-[0006], [0017] and [0033] Provides for deciding whether corrective action is worth taking.)
The first determination is based on a degree of the impact of the poisoned inference on the inference consumer (Bairavasundaram: [0028]-[0036] Provides for gating the remediation decision on the measured severity of the violation and its effect on the served workload.)
The degree of the impact of the poisoned inference on the inference consumer is determined using information regarding the poisoned inference that is self-reported by the inference consumer after the inference consumer has used the poisoned inference (Bairavasundaram: [0022]-[0024] and [0044] Provides for the consuming entity itself reporting usage and impact information upward.)
while the inference consumer is unaware that the poisoned inference is poisoned (Bairavasundaram: [0006] and [0028] Provides for reporting entities that supply information without knowledge of the violation assessment being performed above them.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Szeto in view of Ward, which together provide a method for managing poisoned AI models with snapshot-based detection, model reversion, and acceptability-based decisions to forgo remediation, with the teachings of Bairavasundaram, which introduces resource-aware remediation decisions based on measured impact severity using self-reported information from consuming entities who are unaware of the violation assessment being performed. One of ordinary skill in the art would recognize the ability to incorporate Bairavasundaram's impact-severity gating and consumer-reported feedback mechanisms into the combined poisoned inference management system to enable more informed and resource-conscious remediation decisions. One of ordinary skill in the art would be motivated to make this modification in order to optimize computing resource allocation by quantifying the actual impact of poisoned inferences before committing to remediation.
In reference to claim 17, The data processing system of claim 16, further comprising: prior to making the first determination: obtaining a third instance of the AI model, the third instance of the AI model not being poisoned and being intended to generate future inferences to be provided to the inference consumer (Szeto: [0175], [0216], [0293] and [0366] Provides for obtaining and placing into production a distinct, non-poisoned model instance.)
In reference to claim 18, The data processing system of claim 17, wherein obtaining the third instance of the AI model comprises: identifying a second portion of a training data set as poisoned training data, the second portion of the training data set being used to train the poisoned AI model (Szeto: [0212]-[0221] and [0422] Provides for identifying the particular portion of the training that was used to train the badly-performing model and that is the reason it performs poorly.)
Purging the poisoned training data from a training data repository (Szeto: [0052], [0135], [0254], and [0386] Provides for removing a data source from the platform's managed repository by explicit command, and for a cleansing component that filters and discards unwanted data before it reaches the algorithms.)
In reference to claim 21, The method of claim 1, further comprising and prior to training the second instance of the AI model using the ingest data: generating a snapshot database; generating the snapshot of the poisoned AI model; and storing the snapshot of the second instance of the AI model in the snapshot database (Szeto: [0085], [0179], [0214]-[0221] and [0255] Provides for establishing a dedicated persistent model-tracking database and, on every training event, creating and storing a versioned record of the resulting model variant so earlier variants can be unambiguously referenced and redeployed.)
In reference to claim 22, The method of claim 21, wherein the snapshot database comprises other snapshots of the poisoned AI model generated before the snapshot of the poisoned AI model is generated, the snapshots and the other snapshots being generated at different points in time throughout an existence of the second instance of the AI model to preserve AI model structure information of the second instance of the AI model at each of the different points in time (Szeto: [0080], [0179]-[0185], [0214]-[0221] and [0255] Provides for a database accumulating a temporally-ordered series of versioned model records each capturing the model's configuration and parameters at that moment so any point in the history can be referenced and redeployed.
In reference to claim 23, The method of claim 1, wherein identifying the poisoned inference generated by the poisoned AI model using the snapshot of the poisoned AI model comprises: using the information contained in the snapshot to identify an identifier of the ingest data that was used to train the second instance of the AI model; and identifying, in metadata of the poisoned inference, the identifier of the ingest data (Szeto: [0146], [0154]-[0156], [0221], [0291] and [0324] Provides for reading a stored model record to recover the identifier of the data source used to train that variant and for query records that carry variant-identifying metadata, permitting served predictions to be located by that key
In reference to claim 24, The method of claim 8, wherein the self-reported inference reliance database comprises a lookup table in which a first degree of reliance of the inference consumer on the poisoned inference is stored with an identifier associated with the poisoned inference (Szeto: [0281], [0328] and [0351]-[0353] Provides for a tabular record structure in which each served prediction is stored alongside a unique replay ID and a graduated numeric score derived from what the consumer did after receiving it.)
In reference to claim 25, The data processing system of claim 18, The data processing system of claim 18, wherein obtaining the third instance of the AI model further comprises: obtaining a first instance of the AI model, the first instance of the AI model not being poisoned; obtaining a third portion of the training data set, the third portion of the training data set not including the poisoned training data; and obtaining the third instance of the AI model using the third portion of the training data and the first instance of the AI model (Szeto: [0133]-[0134], [0209]-[0228], [0238] and [0459] Provides for processor-and-memory machine learning platform with a versioning system, predictive engine generator, and deployment platform that together retrieve an identified prior clean variant, register a differently-scoped training data selection, and generate an updated model instance from a persisted prior model.)
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. See PTO-892.
Applicant’s amendment necessitated the new ground(s) of rejection presented in this office action. Accordingly, THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to AIDAN EDWARD SHAUGHNESSY whose telephone number is (703)756-1423. The examiner can normally be reached on Monday-Friday from 7:30am to 5pm.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey Nickerson, can be reached at telephone number (469) 295-9235. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from Patent Center and the Private Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from Patent Center or Private PAIR. Status information for unpublished applications is available through Patent Center and Private PAIR for authorized users only. Should you have questions about access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free).
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) Form at https://www.uspto.gov/patents/usptoautomated-interview-request-air-form.
/A.E.S./Examiner, Art Unit 2432
/Jeffrey Nickerson/Supervisory Patent Examiner, Art Unit 2432