DETAILED ACTION
This action is in response to the filing on 04/22/2026. Claims 1, 3-6, 8-9, 11-14, 16-17, and 19-25, are pending and have been considered below.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1, 3-6, 8-9, 11-14, 16-17, 19-21, and 24 are rejected under 35 U.S.C. 103 as being unpatentable over Suzuki (US 2021/0352190 A1), hereinafter Suzuki, in view of Kapoor et al. (US 2007/0185922 A1), hereinafter Kapoor, and further in view of Manley et al. (US 2023/0185674 A1), hereinafter Manley, and further in view of Kochar et al. (US 2021/0357297 A1), hereinafter Kochar.
Regarding claim 1, Suzuki teaches a method for managing inference models, the method comprising: (An information processing apparatus and a method of controlling the information processing apparatus are provided. The information processing apparatus stores a plurality of learned models, determines whether the stored plurality of learned models include confidential information, and presents, to a user, learned models of the plurality of learned models determined to include the confidential information. [see Suzuki, Abstract]):
identifying an inference model of the inference models that is compromised (Suzuki discloses determining if the learned models include confidential information [see Suzuki, Abstract], and that models with confidential information are at risk of leaking the confidential information [see Suzuki, para. 5]);
presenting, to a user, a graphical user interface (Suzuki discloses a GUI presented to the user to confirm whether all displayed models can be cleared [see Suzuki, para. 81 and FIG. 13B]);
obtaining a reversion plan for the inference model using the graphical user interface by obtaining, from the user and to define the reversion plan, user input indicating a selection (Suzuki discloses a GUI presented to the user to confirm whether all displayed models can be cleared [see Suzuki, para. 81 and FIG. 13B]);
performing the reversion plan to obtain an updated inference model (Suzuki discloses a GUI presented to the user to confirm whether all displayed models can be cleared, and clearing the models upon confirmation [see Suzuki, para. 81 and FIG. 13B]);
using the updated inference model to provide computer implemented services (Suzuki discloses using the learned model for estimation processing [see Suzuki, para. 51] and notifying the user before using the model that it may contain confidential information to be extracted [see para. 29 and FIG. 15B]. Thus, the cleared model can be used for the estimation processing).
However, Suzuki fails to teach identifying a first resource cost for reverting the inference model to an uncompromised state and a second resource cost for reverting the inference model to a partially compromised state; presenting, to a user, a graphical user interface based at least in part on the first resource cost and the second resource cost, the graphical user interface comprising: a range bar; a model indicator positioned with the range bar; a compromise indicator positioned with the range bar, the compromise indicator being based on a first portion of poisoned training data and a second portion of the poisoned training data; a first recovery point positioned with the range bar and that does not overlap any portion of the compromise indicator; and a second recovery point positioned with the range bar and that overlaps at least a portion of the compromise indicator; and obtaining a reversion plan for the inference model using the graphical user interface by obtaining, from the user and to define the reversion plan, user input indicating a selection of the first recovery point or the second recovery point.
In the same field of endeavor, Kapoor teaches:
identifying a first point for reverting a database to a fully restored state and second point for reverting a database to a partially restored state (Kapoor discloses a plurality of database states in which the database can be restored to, including the last backup operation, and any of states 316-320 which occur after one or more transactions after the backup operation [see Kapoor, para. 37-38 and FIG. 3A]. Kapoor further discloses how the database can be restored to the last backup operation, or any of the points in between the backup operation and the restore operation [see Kapoor, para. 39-40 and FIG. 3A]);
presenting, to a user, a graphical user interface based at least in part on the first point and the second point, the graphical user interface comprising: a first recovery point and a second recovery point (Kapoor discloses a plurality of database states in which the database can be restored to, including the last backup operation, and any of states 316-320 which occur after one or more transactions after the backup operation [see Kapoor, para. 37-38 and FIG. 3A]. Kapoor further discloses how the database can be restored to the last backup operation, or any of the points in between the backup operation and the restore operation [see Kapoor, para. 39-40 and FIG. 3A]. Kapoor further discloses GUIs which the user can interact with to obtain the restore plan for the database [see Kapoor, para. 46 and FIGS. 4A-4C]);
obtaining a reversion plan for the database using the graphical user interface by obtaining, from the user and to define the reversion plan, user input indicating a selection of the first recovery point or the second recovery point (Kapoor discloses a plurality of database states in which the database can be restored to, including the last backup operation, and any of states 316-320 which occur after one or more transactions after the backup operation [see Kapoor, para. 37-38 and FIG. 3A]. Kapoor further discloses how the database can be restored to the last backup operation, or any of the points in between the backup operation and the restore operation [see Kapoor, para. 39-40 and FIG. 3A]. Kapoor further discloses GUIs which the user can interact with to obtain the restore plan for the database [see Kapoor, para. 46 and FIGS. 4A-4C]);
It would have been obvious to one of ordinary skill, in the art at the time before the effective filing date of the invention to incorporate identifying a first point for reverting a database to a fully restored state and second point for reverting a database to a partially restored state as suggested in Kapoor into Suzuki to teach identifying a first point for reverting the inference model to an uncompromised state and second point for reverting the inference model to a partially compromised state because the database backup and restore methodology of Kapoor could be incorporated into the method of resetting learned models described in Suzuki such that the backup and restore methodology can be applied to learned models. Thus, the combination of Suzuki and Kapoor would identify for a learning model [see Suzuki, Abstract], a plurality of points in which the learned model can be restored to, including the last backup operation, and any of one or more intermediate states between the last backup operation and the restore operation [see Kapoor, para. 37-40 and FIG. 3A]. Further, when transactions between the backup operation and the restore operation [see Kapoor, para. 37-40 and FIG. 3A] contain confidential information that can be extracted [see Suzuki, para. 75 and FIG. 11], the learned model can be restored to the last backup operation such that it contains no confidential information that can be extracted, or restored to a point between the backup operation and the restore operation that contains a portion of the confidential information that can be extracted.
It would have been further obvious to one of ordinary skill, in the art at the time before the effective filing date of the invention to incorporate presenting, to a user, a graphical user interface based at least in part on the first point and the second point, the graphical user interface comprising: a first recovery point and a second recovery point as suggested in Kapoor into Suzuki to teach presenting, to a user, a graphical user interface based at least in part on the first point and the second point, the graphical user interface comprising: a first recovery point and a second recovery point and to incorporate obtaining a reversion plan for the database using the graphical user interface by obtaining, from the user and to define the reversion plan, user input indicating a selection of the first recovery point or the second recovery point to teach obtaining a reversion plan for the inference model using the graphical user interface by obtaining, from the user and to define the reversion plan, user input indicating a selection of the first recovery point or the second recovery point because the database backup and restore methodology of Kapoor could be incorporated into the method of resetting learned models described in Suzuki such that the backup and restore methodology can be applied to learned models. Thus, the restore GUI obtained disclosed by Kapoor [see Kapoor, para. 37-40, 46, and FIGS. 3A-4C] could be used to restore the inference model of Suzuki based on the plurality of points.
It would have been obvious to one of ordinary skill, in the art at the time before the effective filing date of the invention to incorporate the teachings of Kapoor into Suzuki because both methods control information processing systems (see Suzuki, Abstract; see Kapoor, Abstract). Incorporating the teaching of Kapoor into Suzuki would provide the functionality to store data of various types and contain data of every file type [see Kapoor, para. 24] and automatically formulate the command set necessary to restore to the state that existed at the specified point in time without any effort on the part of the user to determine which backup versions need to be restored [see Kapoor, para. 76].
However, the combination of Suzuki and Kapoor fails to teach identifying a first resource cost for reverting the inference model to an uncompromised state and a second resource cost for reverting the inference model to a partially compromised state; presenting, to a user, a graphical user interface based at least in part on the first resource cost and the second resource cost, the graphical user interface comprising: a range bar; a model indicator positioned with the range bar; a compromise indicator positioned with the range bar, the compromise indicator being based on a first portion of poisoned training data and a second portion of the poisoned training data; a first recovery point positioned with the range bar and that does not overlap any portion of the compromise indicator; and a second recovery point positioned with the range bar and that overlaps at least a portion of the compromise indicator.
In the same field of endeavor, Manley teaches:
identifying a resource cost for reverting the data (Manley discloses a time estimator configured to estimate the time taken to restore backup data to a restore location [see Manley, Abstract]);
presenting, to a user, a graphical user interface based at least in part on the resource cost (Manley discloses presenting the estimated time for restoring the backup data to the user [see Manley, para. 53] and generating an optimal schedule for restoring data using the time estimation [see Manley, para. 54]).
It would have been obvious to one of ordinary skill, in the art at the time before the effective filing date of the invention to incorporate identifying a resource cost for reverting the data as suggested in Manley into the combination of Suzuki and Kapoor to teach identifying a first resource cost for reverting the inference model to an uncompromised state and a second resource cost for reverting the inference model to a partially compromised state because it would have been obvious to further combine the combination of Suzuki and Kapoor as indicated above, with the time estimation of Manley to estimate the time taken to restore for each of the plurality of points in the backup/restore methodology of Kapoor on the inference model of Suzuki.
It would have been further obvious to one of ordinary skill, in the art at the time before the effective filing date of the invention to incorporate presenting, to a user, a graphical user interface based at least in part on the resource cost as suggested in Manley into the combination of Suzuki and Kapoor to teach presenting, to a user, a graphical user interface based at least in part on the first resource cost and the second resource cost because it would have been obvious to one of ordinary skill in the art before the effective filing date to further combine the combination of Suzuki and Kapoor as indicated above, with the time estimation of Manley to estimate the time taken to restore for each of the plurality of points in the backup/restore methodology of Kapoor on the inference model of Suzuki. Further, the combination could present the time estimation of restoring the backup to a point [see Manley, para. 53] for each point between the backup operation and the restore operation including the backup point itself [see Kapoor, para. 37-40, 46, and FIGS. 3A-4C], for obtaining the restoration plan.
It would have been obvious to one of ordinary skill, in the art at the time before the effective filing date of the invention to incorporate the teachings of Manley into the combination of Suzuki and Kapoor because both systems are directed to data backups and restore operations (see Kapoor, Abstract; see Manley, Abstract). Incorporating the teaching of Manley into the combination of Suzuki and Kapoor would optimize scheduling of a data backup and/or restore of a backup data in a data backup and/or restore environment (see Manley, para. 5).
However, the combination of Suzuki, Kapoor, and Manley fails to teach the graphical user interface comprising: a range bar; a model indicator positioned with the range bar; a compromise indicator positioned with the range bar, the compromise indicator being based on a first portion of poisoned training data and a second portion of the poisoned training data; a first recovery point positioned with the range bar and that does not overlap any portion of the compromise indicator; and a second recovery point positioned with the range bar and that overlaps at least a portion of the compromise indicator.
In the same field of endeavor, Kochar teaches a graphical user interface comprising:
a range bar (Kochar discloses a timeline presenting recoverable ranges on the UI [see Kochar, para. 17, and timeline 200A of FIG. 5]);
a compromise indicator positioned with the range bar, the compromise indicator being based on a first portion of data and a second portion of the data (Kochar discloses that there is no log backup when data was skipped, deleted, corrupted, etc. [see Kochar, para. 31], and coloring the region of the timeline with backups available in green and no backup available on the timeline as red [see Kochar, para. 36]);
a first recovery point positioned with the range bar and that does not overlap any portion of the compromise indicator (Kochar discloses the UI having a plurality of points in time that correspond with the state of the database at that point in time [see Kochar, para. 28 and FIG. 2], and the UI having a timeline indicating restoration availability [see Kochar, para. 36 and FIG. 5]. Thus, a state that can be restored in the green would not overlap the compromise indicator in the red);
a second recovery point positioned with the range bar (Kochar discloses the UI having a plurality of points in time that correspond with the state of the database at that point in time [see Kochar, para. 28 and FIG. 2], and the UI having a timeline indicating restoration availability [see Kochar, para. 36 and FIG. 5]);
It would have been obvious to one of ordinary skill, in the art at the time before the effective filing date of the invention to incorporate a range bar as suggested in Kochar into the combination of Suzuki, Kapoor, and Manley to teach a model indicator positioned with the range bar (It would have been obvious to one of ordinary skill in the art before the effective filing date that when viewing the timeline disclosed by Kochar [see Kochar, para. 28 and 36, and FIG. 5], it could range from the most recent backup operation to the current restore operation as disclosed for the timeline in Kapoor [see Kapoor, para. 37 and FIG. 3A], the restore operation indicating where the model currently is in the timeline.) and to further incorporate a first recovery point positioned with the range bar and that does not overlap any portion of the compromise indicator, and a second recovery point positioned with the range bar as suggested in Kochar into the combination of Suzuki, Kapoor, and Manley.
It would have been further obvious to one of ordinary skill in the art before the effective filing date to incorporate a compromise indicator positioned with the range bar, the compromise indicator being based on a first portion of data and a second portion of the data as suggested In Kochar into the combination of Suzuki, Kapoor, and Manley to teach a compromise indicator positioned with the range bar, the compromise indicator being based on a first portion of poisoned training data and a second portion of the poisoned training data because the teachings of indicators for backup availability in a database backup GUI [see Kochar, para. 31 and 36] could be used to present the status of training data of the machine learning model, the training data being either compromised or uncompromised, such that the combination of Suzuki, Kapoor, Manley, and Kochar would present a GUI presenting a range bar with recoverable points and indicators displaying whether the points are in a range of uncompromised data or compromised data.
It would have been further obvious to one of ordinary skill in the art before the effective filing date to incorporate a second recovery point positioned with the range bar as suggested in Kochar into the combination of Suzuki, Kapoor, and Manley to teach a second recovery point positioned with the range bar and that overlaps at least a portion of the compromise indicator because the GUI presenting a range bar with recoverable points and indicators displaying whether the points are in a range of uncompromised data or compromised data would have at least a second point at least partially overlapping the range of compromised data indicated by the compromise indicator.
It would have been obvious to incorporate the teachings of Kochar into the combination of Suzuki, Kapoor, and Manley because both methods provide GUIs for performing restore operations (see Kapoor, Abstract; see Kochar, Abstract). Incorporating the teachings of Kochar into the combination of Suzuki, Kapoor, and Manley would provide ease of use for users derived from having a visual representation of recoverability (see Kochar, para. 14).
Regarding claim 3, the combination of Suzuki, Kapoor, Manley, and Kochar as applied in claim 1 above teaches all the limitations of claim 1 and further teaches:
wherein the first recovery point is based on a first previous version of the inference model in the uncompromised state, and the second recovery point is based on a second previous version of the inference model in the partially compromised state (The combination of Suzuki and Kapoor would identify for a learning model [see Suzuki, Abstract], a plurality of points in which the learned model can be restored to, including the last backup operation, and any of one or more inbetween states between the last backup operation and the restore operation [see Kapoor, para. 37-40 and FIG. 3A]. Further, when transactions between the backup operation and the restore operation [see Kapoor, para. 37-40 and FIG. 3A] contain confidential information that can be extracted [see Suzuki, para. 75 and FIG. 11], the learned model can be restored to the last backup operation such that it contains no confidential information that can be extracted, or restored to a point between the backup operation and the restore operation that contains a portion of the confidential information that can be extracted. Further, when combined with the timeline UI including the recovery points of Kochar [see Kochar para. 28 and 36, and FIGS. 2 and 5], would include recovery points corresponding to versions of the inference model corresponding to states including no confidential information and states including confidential information).
Regarding claim 4, the combination of Suzuki, Kapoor, Manley, and Kochar as applied in claim 3 above teaches all the limitations of claim 3 and further teaches:
wherein the first recovery point and the second recovery point are positioned with the range bar based on a temporal ordering of the first previous version of the inference model, the second previous version of the inference model, and the inference model (Kochar discloses the timeline presenting a plurality of recovery points corresponding to versions at that point in time, with Version 2 at a point in time subsequent to Version 1 [see Kochar, para. 28 and FIG. 2]. Thus, the combination of Suzuki and Kochar would present point in time points temporally ordered for the inference models of Suzuki).
Regarding claim 5, the combination of Suzuki, Kapoor, Manley, and Kochar as applied in claim 4 above teaches all the limitations of claim 4 and further teaches:
wherein the second previous version of the inference model is a further trained version of the first previous version of the inference model based on the first portion of the poisoned training data (Kapoor discloses a plurality of states that can be restored to, including the last backup operation, and any of states 316-320 which occur after one or more transactions after the backup operation [see Kapoor, para. 37-38 and FIG. 3A]. Kapoor further discloses how they can restore to the last backup operation, or any of the points in between the backup operation and the restore operation [see Kapoor, para. 39-40 and FIG. 3A]. Thus, when combined with the inference model of Suzuki, the states would be successive states of the inference model when new data is introduced).
Regarding claim 6, the combination of Suzuki, Kapoor, Manley, and Kochar as applied in claim 5 above teaches all the limitations of claim 5 and further teaches:
wherein the inference model is a further trained version of the second previous version of the inference model based on the second portion of the poisoned training data ([Kapoor discloses a plurality of states that can be restored to, including the last backup operation, and any of states 316-320 which occur after one or more transactions after the backup operation [see Kapoor, para. 37-38 and FIG. 3A]. Kapoor further discloses how they can restore to the last backup operation, or any of the points in between the backup operation and the restore operation [see Kapoor, para. 39-40 and FIG. 3A]. Thus, when combined with the inference model of Suzuki, the states would be successive states of the inference model when new data is introduced. Further, if there is more than one confidential data within a backup cycle, there would be two separate states of the model such that there is a first version with first confidential data and a second version with the first confidential data and a second confidential data]).
Regarding claim 8, the combination of Suzuki, Kapoor, Manley, and Kochar as applied in claim 6 above teaches all the limitations of claim 6 and further teaches wherein the graphical user interface further comprises:
a reversion cost estimate indicator that indicates a computing resource cost for reverting the inference model to previous versions of the inference model based on the user input (Manley discloses estimating resources and cost to restore to a backup using a recommended schedule [see Manley, para. 44], and presenting the recommended schedule to a user along with other details such as a recommended date and time [see Manley, para. 55]. It would have been obvious to one of ordinary skill in the art to also present the estimated resource and cost for the recommended schedule with the recommended schedule and other details);
a reversion time estimate indicator that indicates a duration of time for reverting the inference model to the previous versions of the inference model based on the user input (Manley discloses using a time estimator to estimate the amount of time to restore to a backup and that the estimated time can be presented to a user [see Manley, para. 53]).
Regarding claim 9, claim 9 contains substantially similar limitations to those found in claim 1. Therefore, it is rejected for the same reason as claim 1 above. Additionally, the combination of Suzuki, Kapoor, Manley, and Kochar further teaches:
A non-transitory machine-readable medium having instructions stored therein, which when executed by a processor, cause the processor to perform operations for managing for managing inference models, the operations comprising (Suzuki discloses that the present invention can be realized by instructions on a non-transitory computer-readable storage medium [see Suzuki, para. 96]).
Regarding claim 17, claim 17 contains substantially similar limitations to those found in claim 1. Therefore, it is rejected for the same reason as claim 1 above. Additionally, the combination of Suzuki, Kapoor, Manley, and Kochar further teaches:
A data processing system, comprising: a processor; and a memory coupled to the processor to store instructions, which when executed by the processor, cause the processor to perform operations for managing data collection for managed devices and unmanaged devices, the operations comprising (Suzuki discloses that the present invention can be realized by instructions on a non-transitory computer-readable storage medium [see Suzuki, para. 96]).
Regarding claims 11 and 19, claims 11 and 19 contains substantially similar limitations to those found in claim 3 above. Consequently, claims 11 and 19 are rejected for the same reasons.
Regarding claims 12 and 20, claims 12 and 20 contains substantially similar limitations to those found in claim 4 above. Consequently, claims 12 and 20 are rejected for the same reasons.
Regarding claim 13, claim 13 contains substantially similar limitations to those found in claim 5 above. Consequently, claim 13 is rejected for the same reasons.
Regarding claim 14, claim 14 contains substantially similar limitations to those found in claim 6 above. Consequently, claim 14 is rejected for the same reasons.
Regarding claim 16, claim 16 contains substantially similar limitations to those found in claim 8 above. Consequently, claim 16 is rejected for the same reasons.
Regarding claim 21, the combination of Suzuki, Kapoor, Manley, and Kochar as applied in claim 1 above teaches all the limitations of claim 1 and further teaches:
wherein the compromise indicator comprises a filled area shape positioned along range bar (Kochar discloses using colored areas in green, red, and orange to indicate status of backup status along a range bar [see Kochar, para. 36 and FIG. 5]).
Regarding claim 24, the combination of Suzuki, Kapoor, Manley, and Kochar as applied in claim 1 above teaches all the limitations of claim 8 and further teaches:
wherein the graphical user interface further comprises a reversion control element, and the reversion cost estimate indicator and the reversion time estimate indicator are dynamically updated as the reversion control element is moved to different positions along the range bar (It would have been obvious to one of ordinary skill in the art before the effective filing date that the timeline as disclosed by Kochar [see Kochar, para. 17 and FIG. 5] as modified to include the backup states disclosed by Kapoor [see Kapoor, para. 37-40 and FIG. 3A], could select a point and dynamically update the cost and time estimates as calculated and presented in Manley [see Manley, para. 44, 53, and 55] corresponding to the selected point, such that different states along the timeline correspond to different cost and time estimates).
Claims 22-23 are rejected under 35 U.S.C. 103 as being unpatentable over Suzuki (US 2021/0352190 A1), hereinafter Suzuki, in view of Kapoor et al. (US 2007/0185922 A1), hereinafter Kapoor, and further in view of Manley et al. (US 2023/0185674 A1), hereinafter Manley, and further in view of Kochar et al. (US 2021/0357297 A1), hereinafter Kochar, as applied in claim 1 above, and further in view of Patrick et al. (US 8,665,275 B1), hereinafter Patrick.
Regarding claim 22, the combination of Suzuki, Kapoor, Manley, and Kochar as applied in claim 1 above teaches all the limitations of claim 21.
However, the combination of Suzuki, Kapoor, Manley, and Kochar fails to teach wherein a dimension of the filled area shape projecting away from a position on the range bar represents a quantity of the poisoned training data used to update the inference model at a point in time corresponding the position on the range bar.
In the same field of endeavor, Patrick teaches:
wherein a dimension of the filled area shape projecting away from a position on the range bar represents a quantity of the data used at a point in time corresponding the position on the range bar (Patrick discloses a range bar with indicators presenting the time taken for data backups as well as the amount of data used for each backup [see Patrick, Col. 9, ln 4-26 and FIG. 3C]).
It would have been obvious to one of ordinary skill, in the art at the time before the effective filing date of the invention to incorporate wherein a dimension of the filled area shape projecting away from a position on the range bar represents a quantity of the data used at a point in time corresponding the position on the range bar as suggested in Patrick into the combination of Suzuki, Kapoor, Manley, and Kochar to teach wherein a dimension of the filled area shape projecting away from a position on the range bar represents a quantity of the poisoned training data used to update the inference model at a point in time corresponding the position on the range bar because indicating a quantity of data used at a specific backup state at a point in time would be additional status data of that point in time that could be used in combination with the status indicator of Kochar [see Kochar, para. 36 and FIG. 5] to represent the quantity of compromised training data as identified by Suzuki. It would have been obvious to incorporate the teaching of Patrick into the combination of Suzuki, Kapoor, Manley, and Kochar because both methods provide GUIs for restoring backups (see Kapoor, Abstract; see Patrick, Abstract). Incorporating the teaching of Patrick into the combination of Suzuki, Kapoor, Manley, and Kochar would present the history of image backup files created from a source storage during a backup job, as well as certain timing and other statistics related to each image backup file aiding the difficulty to grasp timing and other statistics of the image backup files of the backup job in order to ascertain the current state of the backup job [see Patrick, Col. 2, lines 12-21].
Regarding claim 23, the combination of Suzuki, Kapoor, Manley, Kochar, and Patrick as applied in claim 22 above teaches all the limitations of claim 22 and further teaches:
wherein a portion of the range bar not indicated by the compromise indicator indicates a previous version of the inference model that is not influenced by the poisoned training data (Kochar discloses the UI having a plurality of points in time that correspond with the state of the data at that point in time [see Kochar, para. 28 and FIG. 2], and the UI having a timeline indicating restoration availability [see Kochar, para. 36 and FIG. 5]. Thus, a state that can be restored in the green would indicate a previous version not influenced by the compromised data).
Claim 25 is rejected under 35 U.S.C. 103 as being unpatentable over Suzuki (US 2021/0352190 A1), hereinafter Suzuki, in view of Kapoor et al. (US 2007/0185922 A1), hereinafter Kapoor, and further in view of Manley et al. (US 2023/0185674 A1), hereinafter Manley, and further in view of Kochar et al. (US 2021/0357297 A1), hereinafter Kochar, as applied in claim 1 above, and further in view of Warnecke, A., et al. ("Machine unlearning of features and labels. arXiv:2108.11577v3, 2022), hereinafter Warnecke.
Regarding claim 25, the combination of Suzuki, Kapoor, Manley, and Kochar as applied in claim 1 above teaches all the limitations of claim 1.
However, the combination of Suzuki, Kapoor, Manley, and Kochar fails to teach wherein performing the reversion plan to obtain the updated inference model comprises untraining the inference model using a selected portion of the poisoned training data corresponding to the user input.
In the same field of endeavor, Warnecke teaches:
wherein performing the reversion plan to obtain the updated inference model comprises untraining the inference model using a selected portion of the poisoned training data (Warnecke discloses untraining a machine learning model to remove influence of data leaks and privacy concerns for data that is compromised with sensitive information [see Warnecke, Abstract]).
It would have been obvious to one of ordinary skill, in the art at the time before the effective filing date of the invention to incorporate wherein performing the reversion plan to obtain the updated inference model comprises untraining the inference model using a selected portion of the poisoned training data as suggested in Warnecke into the combination of Suzuki, Kapoor, Manley, and Kochar to teach wherein performing the reversion plan to obtain the updated inference model comprises untraining the inference model using a selected portion of the poisoned training data corresponding to the user input because the unlearning method of Warnecke could be used to unlearn the compromised data selected from the graphical user interface through the combination of Suzuki, Kapoor, Kochar and Patrick, such that the data is untrained from the model. It would have been obvious to incorporate the teaching of Warnecke into the combination of Suzuki, Kapoor, Manley, and Kochar because both methods are directed to removing compromised training data from machine learning models [see Suzuki, Abstract, para. 81, and FIG. 13B; see Warnecke, Abstract]. Incorporating the teaching of Warnecke into the combination of Suzuki, Kapoor, Manley, and Kochar would adapt the influence of training data on a learning model retrospectively, thereby correcting data leaks and privacy issues.
Response to Amendment
Applicant’s amendment, filed 04/22/2026, to the specification have been fully considered and are accepted, the objection to the specification is respectfully withdrawn.
Applicant’s amendment, filed 04/22/2026, to the claims have been fully considered and are accepted, the objections to the claims are respectfully withdrawn.
Response to Arguments
Applicant’s arguments, filed 04/22/2026, traversing the rejection of claims 1, 9, and 17 under 35 U.S.C. 171 have been fully considered and are persuasive, the rejection of claims 1, 9, and 17 under 35 U.S.C. 171 are respectfully withdrawn.
Applicant’s arguments, filed 04/22/2026, traversing the rejection of claims 1-20 under 35 U.S.C. 101 have been fully considered and are persuasive, the rejection of claims 1-20 under 35 U.S.C. 101 are respectfully withdrawn.
Applicant’s arguments, filed 04/22/2026, traversing the rejection of claims 1-20 under 35 U.S.C. 103 have been fully considered and are not persuasive. Applicant argues that Suzuki, Kapoor, Manley, and Kochar separately or in combination fail to disclose or suggest the first and second recovery points configured relative to a compromise indicator, Examiner respectfully disagrees.
With respect to the compromise indicator, as indicated above in the 35 U.S.C. 103 section, the claim limitation is rendered obvious in view of the combination of Suzuki, Kapoor, Manley and Kochar. Specifically, Kochar discloses a compromise indicator positioned with the range bar, the compromise indicator being based on a first portion of data and a second portion of the data in para. 31 and 36, and FIG. 5, that in combination with Suzuki, Kapoor, and Kochar would render obvious a compromise indicator positioned with the range bar, the compromise indicator being based on a first portion of poisoned training data and a second portion of the poisoned training data because the compromise indicator presented in Kochar could similarly be used to show the status of training data used in training a machine learning model being either compromised or uncompromised on a GUI presenting backup states in the same manner that Kochar presents an indicator showing the status of backup states in the GUI. Further, with respect to the first and second recovery points, Kapoor and Kochar both show a plurality of recovery points in their respective GUIs, thus, in combination of Suzuki, Kapoor, Manley and Kochar, would render obvious a compromise indicator as previously described, a recovery point on the range bar not overlapping the compromise indicator, and a recovery point on the range at least partially overlapping the compromise indicator. Specifically, if the range bar has two areas, one area being uncompromised, and one area being compromised, and a plurality of data points spanning the range, there is reasonably at least one recovery point within each area.
For at least the aforementioned reasons, the claims are rendered obvious in view of the prior art, and the rejection of claims 1, 3-6, 8-9, 11-14, 16-17, and 19-25 is respectfully maintained.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
L. Bourtoule et al., ("Machine Unlearning," 2021 IEEE Symposium on Security and Privacy (SP), San Francisco, CA, USA, 2021, pp. 141-159, doi: 10.1109/SP40001.2021.00019.) discloses a method of unlearning specific training data in machine learning models applicable to any learning model, and showing the largest improvements in stateful algorithms.
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to JAKE BREEN whose telephone number is (571)272-0456. The examiner can normally be reached Monday - Friday, 7:00 AM - 3:00 PM EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jennifer Welch can be reached at (571) 272-7212. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/J.T.B./Examiner, Art Unit 2143
/JENNIFER N WELCH/Supervisory Patent Examiner, Art Unit 2143