Prosecution Insights
Last updated: October 02, 2026
Application No. 18/330,606

SYSTEMS AND METHODS FOR FRAUD DETECTION

Final Rejection §103
Filed
Jun 07, 2023
Examiner
KING, DAVIDA LEE
Art Unit
3699
Tech Center
3600 — Transportation & Electronic Commerce
Assignee
Capital One Services LLC
OA Round
4 (Final)
36%
Grant Probability
At Risk
5-6
OA Rounds
0m
Est. Remaining
72%
With Interview

Examiner Intelligence

Grants only 36% of cases
36%
Career Allowance Rate
16 granted / 45 resolved
-16.4% vs TC avg
Strong +36% interview lift
Without
With
+36.4%
Interview Lift
resolved cases with interview
Typical timeline
3y 3m
Avg Prosecution
18 currently pending
Career history
82
Total Applications
across all art units

Statute-Specific Performance

§101
20.3%
-19.7% vs TC avg
§103
61.0%
+21.0% vs TC avg
§102
9.2%
-30.8% vs TC avg
§112
5.0%
-35.0% vs TC avg
Black line = Tech Center average estimate • Based on career data from 45 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Arguments Applicant's arguments filed 05/26/2026 with respect to the rejection(s) of claim(s) 1-8,10-12,14-16,18-19 and 21-24 have been fully considered and are persuasive. Therefore, the rejection has been withdrawn. However, upon further consideration, a new ground(s) of rejection is made. See remarks on page 14-17. The rejection of pending claims 1-8,10-12,14-16,18-19 and 21-24 under 35 U.S.C. 101 as directed to an abstract idea without significantly more, is withdrawn in view of MPEP 2106.04(d). See remarks on page 10- 13. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claims 1-8, 10-12, 14-16, 19, 21 and 22 are rejected under 35 U.S.C. 103 as being unpatentable over Yavilevich et al. (US 10063645), in view of Bercich et. al (US 12045716 B2), in view of Adjaoute et al. (US 10019744 B2), in view of Kramme et. al (US 20230088436 A1), and further in view of Moreton et al. (US 20240070646 A1). Regarding claim 1, Yavilevich discloses a system comprising: one or more processors; and a memory in communication with the one or more processors and storing instructions that, when executed by the one or more processors, are configured to cause the system to: identify, using a web browser extension, that a user has navigated to a webpage on a user device, (Column 4/line 17, The client device 101 may be, but is not limited to, a smart phone, a tablet computer, a personal computer, a laptop computer, a netbook computer, an electronic reader, and the like. The browser 102 may be any web browser, such as Safari®, Firefox®, Internet Explorer®, Chrome®, and the like. The processor of the client device 101 runs an operating system that may include iOS®, Android®, Unix®, Windows®, and the like. The mobile application 103 may be any application that is executable over the client device 101 and/or an extension of the browser 102. The mobile application 103 is typically downloaded from a central repository 140 which may, e.g., AppStore® by Apple Computers®, Google® Play®, and the like.) receive, via the webpage, data associated with a transaction; (Column 4/line 51, A user of the client device 101 can visit a web site that includes one or more web pages. While a web page is displayed in the browser 102, the user can perform various activities that are monitored by the tracking code. The interaction of a user within one web page is referred to as a “pageview session.”.; and Column 12/line 54, Examples of behaviors that may be detected as indicative of money laundering activity include, but are not limited to, frequent changes of financial advisers or institutions; selection of financial advisers or institutions that are geographically distant from the entity or the location of the transaction; requests for increased speed in processing a transaction or making funds available; failure to disclose a real party to a transaction; a prior conviction for an acquisitive crime; a significant amount of private funding from a person who is associated with, or an entity that is, a cash-intensive business; a third party private funder without an apparent connection to the entity's business; a disproportionate amount of private funding or cash which is inconsistent with the socio-economic profile of the persons involved; finance provided by a lender, other than a financial institution, with no logical explanation or economic justification; business transactions in countries where there is a high risk of money laundering and/or terrorism funding; false documentation in support of transactions; an activity level that is inconsistent with the client's business or legitimate income level; and/or an overly complicated ownership structure for the entity.) responsive to receiving the data: retrieve search history data corresponding to a searching session associated with the data, (Column 3/line 55, The tracking server 130 may include an interface (not shown in FIG. 1) to receive user activity information representative of activities performed by the user during a visit to a web page, and to receive web page content information representative of the web page content displayed to the user during the visit. The information received through the interface may be compressed. The tracking server 130 also includes a processor (not shown in FIG. 1) configured to perform at least the tasks of decompressing the received data and generating at least the exposure maps and other analytic reports with regard to users' activity. The processes performed by the tracking server 130 are described in greater detail below.; and Column 5/line 30,The pan/zoom data set includes the size of the web page downloaded to the user device; the size of a visible area on the client device 101 at any given moment (hereinafter “viewport”); the position of each viewport (e.g., position of scroll bars); a time period for which each viewport was active; and a layout in which the browser 102 attempted to render the web page.) a likelihood of fraud associated with the data by dynamically (i) determining a relevant time period from the search history data, (ii) selecting a relevant portion of the search history data based on the relevant time period, (Column 5/line 30, The pan/zoom data set includes the size of the web page downloaded to the user device; the size of a visible area on the client device 101 at any given moment (hereinafter “viewport”); the position of each viewport (e.g., position of scroll bars); a time period for which each viewport was active; and a layout in which the browser 102 attempted to render the web page.; and Column 5/line 50, Each event is associated with multiple properties or attributes. These properties can be recorded together with the event. For example, mouse events are transmitted with x, y coordinates of the cursor and the state of the mouse buttons; keyboard events are transmitted with the key that was pressed; scroll events are transmitted with the position of the scroll bars; resize events are transmitted with the new window size; click events are transmitted with the type and URL of the object or link that was clicked on, the orientation of the client device, and so on. In one embodiment, each event is transmitted with the time that it occurred. The time can be absolute or relative to a known previously transferred time, such as load time. The element data set includes position information about one or more elements in the web page. For example, the tracking code may collect position information about a subset of elements that are in the center of a web page or center of a viewport. The element position information is collected as the user interacts with the web page. An element can be, for example, a paragraph of text, a link, an image, a button, or any document object module (DOM) element of the web page. The position information of an element includes at least one of: identification of the element (DOM) path, identification (ID), and so on, the bounding rectangle of the element, and optional identification information of the children's elements. For example, if the element is a “form” type its children may be “submit button” and “select control.” It should be noted that for each pageview (i.e., a visit of a web page) information related to a plurality of viewports is collected. A viewport changes during the pageview, thus multiple viewports can be rendered for each pageview, typically in response to a pan or zoom operation. Each viewport being rendered in a pageview is referred to as a “viewport instance” and starts a viewport instance. The width/height of the viewport instance determines the “zoom” level of the viewport instance. The zoom level determines at which level a given area was viewed. In one embodiment, the collected and recorded information may be assembled per pageview.) Under broad reasonable interpretation, the examiner interprets “a likelihood of fraud associated with the data by dynamically (i) determining a relevant time period from the search history data, (ii) selecting a relevant portion of the search history data based on the relevant time period” as “The pan/zoom data set includes the size of the web page downloaded to the user device…a time period for which each viewport was active; and a layout in which the browser 102 attempted to render the web page… mouse events are transmitted with x, y coordinates of the cursor and the state of the mouse buttons; keyboard events are transmitted with the key that was pressed… resize events are transmitted with the new window size; click events are transmitted with the type and URL of the object or link that was clicked on… each event is transmitted with the time that it occurred…such as load time. The element data set includes position information about one or more elements in the web page.” in the cited prior art. Yavilevich does not explicitly disclose determine, using a machine learning model (MLM). However, Bercich teaches determine, using a machine learning model (MLM), (Column 9/line 59, The one or more processors 102 mays also be programmed by the computer-executable instructions to prepare an input vector for the entities in the population; process said input vector with the neural network to provide an encoded output vector at the output node for each of the entities; and store the encoded output vectors in the memory 104 for subsequent use in identifying a common characteristic between two or more of the entities. The one or more processors 102 may also be programmed by the computer-executable instructions to compare the encoded output vectors to identify the two or more entities with the common characteristic. FIG. 5 shows a federated learning system 500 for use by, for example, four independent entities A, B, C, and D, which are also indicated, respectively, by reference numbers 502, 504, 506 and 508.; and Column 4/line 17, use autoencoder-based data anonymization systems and methods to encrypt their data at the outset before attempting to detect particular behaviors. FIGS. 1A to 4 disclose such systems and methods. More particularly, ctn autoencoder system can maintain anonymity and preserve the relational content between and among PII data while still encoding it in a safe manner. Therefore, the data can still be used for network analysis, deduplication efforts and can generally serve as an input into machine-learning models to detect complex patterns whose accuracy and veracity is enhanced by the inclusion of this encoded PII data in the analysis. Business and research areas alike should be able to utilize this encoded data for analysis, without having to have access to the original data. This is especially applicable in (but not restricted to) the financial sector for the purposes of fraud detection and anti-money laundering efforts, and in the healthcare sectors, allowing third party providers and researchers to work with a more complete dataset than ever before without revealing any actual PII data). One of ordinary skill in the art would have recognized that applying the known technique of Bercich to the known invention of Yavilevich would have been recognized that the application of the technique would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate such fraud prevention into a similar invention. Further, it would have been recognized by those of ordinary skill in the art that modifying the system to include determine, using a machine learning model (MLM) results in an improved invention because applying said technique ensures that there is automatic detection of patterns using the user’s transaction history to allow the system to recognize and conduct more fraud prevention actions, thus improving the overall security of the invention. Yavilevich does not explicitly disclose wherein the MLM autonomously learns its own operation parameters to achieve higher accuracy and fewer errors in predicting the likelihood of fraud;determine whether the likelihood exceeds a predetermined threshold. However, Bercich teaches wherein the MLM autonomously learns its own operation parameters to achieve higher accuracy and fewer errors in predicting the likelihood of fraud; determine whether the likelihood exceeds a predetermined threshold, (Column 8/line 6, The one or more processors 102 can also be programmed to set a threshold for a total number of training cycles and to stop the training of the neural network at step 408 in response to the number of training cycles exceeding the threshold. The one or more processors 102 can also be programmed to set a threshold as a function of a loss plane of the output vector reconstruction error and stop the training of the neural network at step 410 in response to the output vector reconstruction error being less than the threshold.; and Column 4/line 17, As a matter of security, some entities might prefer to use autoencoder-based data anonymization systems and methods to encrypt their data at the outset before attempting to detect particular behaviors. FIGS. 1A to 4 disclose such systems and methods…autoencoder system can maintain anonymity and preserve the relational content between and among PII data while still encoding it in a safe manner. Therefore, the data can still be used for network analysis, deduplication efforts and can generally serve as an input into machine-learning models to detect complex patterns whose accuracy and veracity is enhanced by the inclusion of this encoded PII data in the analysis. Business and research areas alike should be able to utilize this encoded data for analysis, without having to have access to the original data. This is especially applicable in (but not restricted to) the financial sector for the purposes of fraud detection and anti-money laundering efforts, and in the healthcare sectors, allowing third party providers and researchers to work with a more complete dataset than ever before without revealing any actual PII data.) One of ordinary skill in the art would have recognized that applying the known technique of Bercich to the known invention of Yavilevich would have been recognized that the application of the technique would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate such fraud prevention into a similar invention. Further, it would have been recognized by those of ordinary skill in the art that modifying the system to include wherein the MLM autonomously learns its own operation parameters to achieve higher accuracy and fewer errors in predicting the likelihood of fraud; determine whether the likelihood exceeds a predetermined threshold results in an improved invention because applying said technique allows the system to identify fraud quickly and take action to prevent fraud from actually occurring, thus improving the overall security of the invention. Yavilevich as modified does not explicitly disclose identify a searching session path corresponding to the transaction, the searching session path comprising an order of webpages visited or links clicked to navigate to the webpage, webpage, or URLs typed in a navigation path of an internet browser. However, Adjaoute teaches identify a searching session path corresponding to the transaction, the searching session path comprising an order of webpages visited or links clicked to navigate to the webpage, webpage, or URLs typed in a navigation path of an internet browser, (Claim 1. catalog a sequence of webpage clickstream behaviors of a user computing device then being employed to browse through a webpage and a website maintained by a consumer website server; collect and maintain a database of comprehensive dossiers of user device ID's obtained from many user-device visits to many webpages maintained by many websites over a period of time; match a user device currently visiting a website by identifying characteristics obtainable through a user device browser, and forwarding these over a network to a dossier file already maintained in said database, if possible; and Claim 7, extract a clickstream behavior related to the particular paths and order of webpages an individual user follows with a sequence of user clicks… track session activity and pattern-match said clickstream behavior to normal-suspect-abnormal-malware patterns; and Para. 0047, Each such website 106-108 sends activity reports 114-116 to the centralized server 102 in real-time over the network as many independent and unrelated users visit and click through webpages 110-112.) One of ordinary skill in the art would have recognized that applying the known technique of Adjaoute to the known invention of Yavilevich as modified would have been recognized that the application of the technique would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate such fraud prevention into a similar invention. Further, it would have been recognized by those of ordinary skill in the art that modifying the system to include identify a searching session path corresponding to the transaction, the searching session path comprising an order of webpages visited or links clicked to navigate to the webpage, webpage, or URLs typed in a navigation path of an internet browser results in an improved invention because applying said technique ensures that there is automatic detection of patterns using the user’s transaction history and behaviors to allow the system to improve fraud detection, thus improving the overall security of the invention. Yavilevich as modified does not explicitly disclose and based on the search history data and the searching session path, a likelihood of fraud associated with the data by dynamically (iii) predicting the likelihood of the fraud by drawing patterns from the relevant portion of the search history data and the searching session path. However, Adjaoute teaches and based on the search history data and the searching session path, a likelihood of fraud associated with the data by dynamically (iii) predicting the likelihood of the fraud by drawing patterns from the relevant portion of the search history data and the searching session path, (Para. 0007, Indirectly, users can be authenticated and the risks of fraud can be reduced by inspecting the personal trusted devices they use and the ways real users behave when navigating webpages. This wasn't possible when phone orders were placed using wireline telephones before Caller ID was mandated. Now, highly distinctive personal trusted user devices, like smartphones and laptops, are being used to place retail orders.; and Para. 0026, The collection of comprehensive dossiers of user devices are organized by their identifying behavior and device-ID information, and both are used to calculate a fraud score in real-time. Each corresponding website is thereby assisted in deciding whether to allow a proposed transaction to be concluded with the particular user and their device.; and Para. 0024, For example, using a set of rules and/or probabilities and or neural networks and or fuzzy logic to provide a score between [0, 1] to identify the device.; and Claim 1. calculate a fraud score in real-time based on results obtained in the steps of analyzing and collecting; and configuring the calculation as a signal output useful to assist each consumer website server in determining whether to allow a proposed transaction to be concluded by a particular user computing device.; and Claim 2. the step to calculate said fraud score is principally determined according to results obtainable from analyzing said sequence of webpage clickstream behaviors.; and Claim 7. record said clickstream behavior and comparing it to previously determined patterns of normal, suspicious, and fraudulent activity; track session activity and pattern-match said clickstream behavior to normal-suspect-abnormal-malware patterns; monitor and analyze online transactions according to pre-determined business rules and statistical models, and to update profiles of users and accounts; correlate alerts and activities; and search for relationships amongst users and channels; wherein, a consumer website can be warned with a signal over the network of high risk users in real-time.) One of ordinary skill in the art would have recognized that applying the known technique of Adjaoute to the known invention of Yavilevich as modified would have been recognized that the application of the technique would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate such fraud prevention into a similar invention. Further, it would have been recognized by those of ordinary skill in the art that modifying the system to include based on the search history data and the searching session path, a likelihood of fraud associated with the data by dynamically (iii) predicting the likelihood of the fraud by drawing patterns from the relevant portion of the search history data and the searching session path results in an improved invention because applying said technique ensures that there is automatic detection of patterns using the user’s transaction history to allow the system to recognize and conduct more fraud prevention actions, thus improving the overall security of the invention. Yavilevich as modified does not explicitly disclose wherein the system is configured to dynamically adjust the predetermined threshold based on confirmed fraud outcomes to more accurately predict fraud associated with a specific user or transaction. However, Kramme teaches wherein the system is configured to dynamically adjust the predetermined threshold based on confirmed fraud outcomes to more accurately predict fraud associated with a specific user or transaction, (Claim 1. retrieving, by a processor, historical account data associated with a plurality of financial accounts, wherein the historical account data includes labels indicating different types of fraud; generating, by the processor, fraud classification rules by training a machine learning program, based on the historical account data, to identify factors that are predictive of the different types of fraud indicated by the labels; predicting, with the processor, and by applying the fraud classification rules to account data associated with a particular financial account, a fraud classification corresponding to a transaction associated with the particular financial account; and updating, with the processor, the fraud classification rules by re-training the machine leaning program based on the fraud classification.; and Claim 3. further comprising: receiving, by the processor, a final fraud determination associated with the fraud classification, wherein: the final fraud determination confirms or contradicts the fraud classification predicted by applying the fraud classification rules, and the machine leaning program is re-trained based part on the final fraud determination.; and Claim 8. further comprising: determining, by the processor, that the score exceeds a threshold score associated with the particular type of fraud, wherein the fraud classification indicates the particular type of fraud, based on the score exceeding the threshold score.; and Claim 14. wherein: the operations further comprise receiving a final fraud determination, associated with the fraud classification, that confirms or contradicts the fraud classification, and the machine leaning program is re-trained based on the final fraud determination.) One of ordinary skill in the art would have recognized that applying the known technique of Kramme to the known invention of Yavilevich as modified would have been recognized that the application of the technique would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate such fraud prevention into a similar invention. Further, it would have been recognized by those of ordinary skill in the art that modifying the system to include wherein the system is configured to dynamically adjust the predetermined threshold based on confirmed fraud outcomes to more accurately predict fraud associated with a specific user or transaction results in an improved invention because applying said technique ensures that there is automatic detection of patterns using the user’s transaction history to allow the system to recognize and conduct more fraud prevention actions, thus improving the overall security of the invention. Yavilevich as modified does not explicitly disclose and responsive to determining the likelihood exceeds the predetermined threshold, conduct one or more fraud prevention actions comprising at least one of: automatically generating a new virtual card number (VCN) for the user to use for completing the transaction, or modifying a GUI of the webpage by changing a size, a number, or a placement of one or more user input objects to prevent automated fraudulent actions within the GUI. However, Moreton teaches and responsive to determining the likelihood exceeds the predetermined threshold, conduct one or more fraud prevention actions comprising at least one of: automatically generating a new virtual card number (VCN) for the user to use for completing the transaction, or modifying a GUI of the webpage by changing a size, a number, or a placement of one or more user input objects to prevent automated fraudulent actions within the GUI, (Para. 0011, One overarching approach to spur adoption is to automatically create, track, and apply VCNs on behalf of a customer. This approach may employ a browser extension or other suitable programmatic construct to monitor a customer's behavior online. When the customer reaches a checkout page having a credit card number, CVV, and expiration date, the browser extension may generate a VCN (or retrieve an existing VCN) and populate the checkout form with the VCN. This obviates the need for the customer to manage their own VCNs. While potentially spurring wider adoption of VCNs, this approach itself gives rise to several additional technical problems that require technical solutions.; and Para. 0008] Importantly, when a transaction occurs using a VCN, the PAN is not exposed, which provides an added layer of security that protects the PAN during the transaction. Moreover, if the third-party stores the VCN and a data breach occurs at the third-party, the PAN is not compromised. In such a scenario, only the merchant-bound VCN is compromised, and the provider may generate a new VCN to cure the issue. The PAN is preserved, re-issuance is avoided, and the customer avoids a tremendous hassle.) One of ordinary skill in the art would have recognized that applying the known technique of Moreton to the known invention of Yavilevich as modified would have been recognized that the application of the technique would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate such fraud prevention into a similar invention. Further, it would have been recognized by those of ordinary skill in the art that modifying the system to include and responsive to determining the likelihood exceeds the predetermined threshold, conduct one or more fraud prevention actions comprising at least one of: automatically generating a new virtual card number (VCN) for the user to use for completing the transaction, or modifying a GUI of the webpage by changing a size, a number, or a placement of one or more user input objects to prevent automated fraudulent actions within the GUI results in an improved invention because applying said technique ensures that there is automatic detection of patterns using the user’s transaction history to allow the system to recognize and conduct more fraud prevention actions, thus improving the overall security of the invention. 5. Regarding claims 2 and 3, Yavilevich discloses one or more processors; and a memory in communication with the one or more processors and storing instructions that, when executed by the one or more processors, are configured to cause the system to: receive data associated with a transaction being conducted by a user on a webpage via a user device; (As seen in FIG. 1B, the plurality of characteristics may comprise data stored in the memory 104 which data is associated with any three or more of the following: a piece of personally identifiable information, a name, an age, a residential address, a business address, an address of a family relative, an address of a business associate, an educational history, an employment history, an address of any associate, a data from a social media site, a bank account number, a plurality of data providing banking information, a banking location, a purchase history, a purchase location, an invoice, a transaction date, a financial history, a credit history, a criminal record, a criminal history, a drug use history, a medical history, a hospital record, a police report, or a tracking history.; and Column 4/line 17, The client device 101 may be, but is not limited to, a smart phone, a tablet computer, a personal computer, a laptop computer, a netbook computer, an electronic reader, and the like. The browser 102 may be any web browser, such as Safari®, Firefox®, Internet Explorer®, Chrome®, and the like. The processor of the client device 101 runs an operating system that may include iOS®, Android®, Unix®, Windows®, and the like. The mobile application 103 may be any application that is executable over the client device 101 and/or an extension of the browser 102. The mobile application 103 is typically downloaded from a central repository 140 which may, e.g., AppStore® by Apple Computers®, Google® Play®, and the like.) responsive to receiving the data: retrieve search history data corresponding to a searching session associated with the data, (Column 4/line 51, A user of the client device 101 can visit a web site that includes one or more web pages. While a web page is displayed in the browser 102, the user can perform various activities that are monitored by the tracking code. The interaction of a user within one web page is referred to as a “pageview session.”.; and Column 12/line 54, Examples of behaviors that may be detected as indicative of money laundering activity include, but are not limited to, frequent changes of financial advisers or institutions; selection of financial advisers or institutions that are geographically distant from the entity or the location of the transaction; requests for increased speed in processing a transaction or making funds available; failure to disclose a real party to a transaction; a prior conviction for an acquisitive crime; a significant amount of private funding from a person who is associated with, or an entity that is, a cash-intensive business; a third party private funder without an apparent connection to the entity's business; a disproportionate amount of private funding or cash which is inconsistent with the socio-economic profile of the persons involved; finance provided by a lender, other than a financial institution, with no logical explanation or economic justification; business transactions in countries where there is a high risk of money laundering and/or terrorism funding; false documentation in support of transactions; an activity level that is inconsistent with the client's business or legitimate income level; and/or an overly complicated ownership structure for the entity.) identify a searching session path corresponding to the transaction, the searching session path comprising an order of webpages visited or links clicked to navigate to the webpage, (Column 1/line 48, Another technique for collecting web site analytics is by means of a client side script being embedded in web pages to monitor traffic. Such a script can collect information and submit it to a central server where the information is analyzed and stored. The script runs on a client device that typically collects URLs that a user visits, mouse movement, scrolling of web pages, resizing of browser windows, click events, keyboard use etc. (“per-action” data), the sequence of the visited URLs, and so on. The collected information is typically assembled and sent, “per-page” together with the identification of the client (e.g., an IP address) to the central server.; and Column 5/line 20, According to one embodiment, during the recording of the pageview session, the tracking code listens to events generated by the browser 102 and determines for each event if the event should be collected or if it should trigger the collection of data.; and Column 5/line 57, click events are transmitted with the type and URL of the object or link that was clicked on, the orientation of the client device, and so on. In one embodiment, each event is transmitted with the time that it occurred. The time can be absolute or relative to a known previously transferred time, such as load time. The element data set includes position information about one or more elements in the web page.) Under broad reasonable interpretation, the examiner interprets “identify a searching session path corresponding to the transaction, the searching session path comprising an order of webpages visited or links clicked to navigate to the webpage” as “collecting web site analytics is by means of a client side script being embedded in web pages …collect information and submit it to a central server where the information is analyzed and stored. The script runs on a client device that typically collects URLs that a user visits, mouse movement, scrolling of web pages, resizing of browser windows, click events, keyboard use etc. (“per-action” data), the sequence of the visited URLs… and during the recording of the pageview session, the tracking code listens to events generated by the browser 102 and determines for each event if the event should be collected or if it should trigger the collection of data” in the cited prior art. Yavilevich does not explicitly disclose determine, using a machine learning model (MLM) and based on the search history data and the searching session path. However, Bercich teaches determine, using a machine learning model (MLM) and based on the search history data and the searching session path, (Column 9/line 59, The one or more processors 102 mays also be programmed by the computer-executable instructions to prepare an input vector for the entities in the population; process said input vector with the neural network to provide an encoded output vector at the output node for each of the entities; and store the encoded output vectors in the memory 104 for subsequent use in identifying a common characteristic between two or more of the entities. The one or more processors 102 may also be programmed by the computer-executable instructions to compare the encoded output vectors to identify the two or more entities with the common characteristic. FIG. 5 shows a federated learning system 500 for use by, for example, four independent entities A, B, C, and D, which are also indicated, respectively, by reference numbers 502, 504, 506 and 508.; and Column 4/line 17, use autoencoder-based data anonymization systems and methods to encrypt their data at the outset before attempting to detect particular behaviors. FIGS. 1A to 4 disclose such systems and methods. More particularly, ctn autoencoder system can maintain anonymity and preserve the relational content between and among PII data while still encoding it in a safe manner. Therefore, the data can still be used for network analysis, deduplication efforts and can generally serve as an input into machine-learning models to detect complex patterns whose accuracy and veracity is enhanced by the inclusion of this encoded PII data in the analysis. Business and research areas alike should be able to utilize this encoded data for analysis, without having to have access to the original data. This is especially applicable in (but not restricted to) the financial sector for the purposes of fraud detection and anti-money laundering efforts, and in the healthcare sectors, allowing third party providers and researchers to work with a more complete dataset than ever before without revealing any actual PII data). One of ordinary skill in the art would have recognized that applying the known technique of Bercich to the known invention of Yavilevich would have been recognized that the application of the technique would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate such fraud prevention into a similar invention. Further, it would have been recognized by those of ordinary skill in the art that modifying the system to include determine, using a machine learning model (MLM) and based on the search history data and the searching session path results in an improved invention because applying said technique ensures that there is automatic detection of patterns using the user’s transaction history to allow the system to recognize and conduct more fraud prevention actions, thus improving the overall security of the invention. Yavilevich does not explicitly disclose first likelihood of fraud associated with the data by dynamically determining correlations in a selected relevant portion of the search history data based on a determined relevant time period and based on card uses in the transaction data. However, Bercich teaches first likelihood of fraud associated with the data by dynamically determining correlations in a selected relevant portion of the search history data based on a determined relevant time period and based on card uses in the transaction data, (Column 3/line 5, deep learning detection models are first developed and trained for each individual entity. Every single entity possesses properties that make it unique such as the composition of their customers, the entity location, and usage and frequency of specific financial products, which entails that each entity has a certain kind of specificity that sets it apart from others. Each entity is assigned a model for individual behaviors (e.g. for money laundering) so that complex nuances and differences across entities can be learned by the model, thus optimizing the model's suitability for detection in that entity. This also ensures that model accuracy is not eroded by cross training which would result in the generalization of inference such that the important structural differences between entities would be disregarded. Models for a specific behavior have the same architectural properties across all entities and are re-trained using the specific entity's data and feedback.; and Column 1/line 34, The invention relates to the field of “federated learning” and its use in conjunction with machine learning models to detect illicit financial crime behaviors including but not limited to money laundering. In particular, the invention relates to the use of “federated learning” in the process of model training and inference and the use of machine learning more generally.; and Column 2/line 66, The present system provides a cloud-based solution that uses federated learning to achieve the goat of a unified, holistic and accurate detection and analysis of money laundering (or other type of financial crime) behavior for financial entities devoid of the need to cross share client data between entities themselves.) Under broad reasonable interpretation, the examiner interprets “a likelihood of fraud associated with the data by dynamically (iii) predicting the likelihood of the fraud by drawing patterns from the relevant portion of the search history data and the searching session path” as “deep learning detection models are first developed and trained for each individual entity… Models for a specific behavior have the same architectural properties across all entities and are re-trained using the specific entity's data and feedback … The invention relates to the field of “federated learning” and its use in conjunction with machine learning models to detect illicit financial crime behaviors including but not limited to money laundering. In particular, the invention relates to the use of “federated learning” in the process of model training and inference and the use of machine learning more generally” in the cited prior art. One of ordinary skill in the art would have recognized that applying the known technique of Bercich to the known invention of Yavilevich would have been recognized that the application of the technique would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate such fraud prevention into a similar invention. Further, it would have been recognized by those of ordinary skill in the art that modifying the system to include first likelihood of fraud associated with the data by dynamically determining correlations in a selected relevant portion of the search history data based on a determined relevant time period and based on card uses in the transaction data results in an improved invention because applying said technique ensures that there is automatic detection of patterns using the user’s transaction history to allow the system to recognize and conduct more fraud prevention actions, thus improving the overall security of the invention. Yavilevich does not explicitly disclose determine whether the likelihood exceeds a predetermined threshold. However, Bercich teaches determine whether the likelihood exceeds a predetermined threshold, (Column 8/line 6, The one or more processors 102 can also be programmed to set a threshold for a total number of training cycles and to stop the training of the neural network at step 408 in response to the number of training cycles exceeding the threshold. The one or more processors 102 can also be programmed to set a threshold as a function of a loss plane of the output vector reconstruction error and stop the training of the neural network at step 410 in response to the output vector reconstruction error being less than the threshold.; and Column 4/line 17, As a matter of security, some entities might prefer to use autoencoder-based data anonymization systems and methods to encrypt their data at the outset before attempting to detect particular behaviors. FIGS. 1A to 4 disclose such systems and methods…autoencoder system can maintain anonymity and preserve the relational content between and among PII data while still encoding it in a safe manner. Therefore, the data can still be used for network analysis, deduplication efforts and can generally serve as an input into machine-learning models to detect complex patterns whose accuracy and veracity is enhanced by the inclusion of this encoded PII data in the analysis. Business and research areas alike should be able to utilize this encoded data for analysis, without having to have access to the original data. This is especially applicable in (but not restricted to) the financial sector for the purposes of fraud detection and anti-money laundering efforts, and in the healthcare sectors, allowing third party providers and researchers to work with a more complete dataset than ever before without revealing any actual PII data.) One of ordinary skill in the art would have recognized that applying the known technique of Bercich to the known invention of Yavilevich would have been recognized that the application of the technique would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate such fraud prevention into a similar invention. Further, it would have been recognized by those of ordinary skill in the art that modifying the system to include determine whether the likelihood exceeds a predetermined threshold results in an improved invention because applying said technique allows the system to identify fraud quickly and take action to prevent fraud from actually occurring, thus improving the overall security of the invention. Yavilevich as modified does not explicitly disclose wherein the system is configured to dynamically adjust the predetermined threshold based on confirmed fraud outcomes to more accurately predict fraud associated with a specific user or transaction. However, Kramme teaches wherein the system is configured to dynamically adjust the predetermined threshold based on confirmed fraud outcomes to more accurately predict fraud associated with a specific user or transaction, (Claim 1. retrieving, by a processor, historical account data associated with a plurality of financial accounts, wherein the historical account data includes labels indicating different types of fraud; generating, by the processor, fraud classification rules by training a machine learning program, based on the historical account data, to identify factors that are predictive of the different types of fraud indicated by the labels; predicting, with the processor, and by applying the fraud classification rules to account data associated with a particular financial account, a fraud classification corresponding to a transaction associated with the particular financial account; and updating, with the processor, the fraud classification rules by re-training the machine leaning program based on the fraud classification.; and Claim 3. further comprising: receiving, by the processor, a final fraud determination associated with the fraud classification, wherein: the final fraud determination confirms or contradicts the fraud classification predicted by applying the fraud classification rules, and the machine leaning program is re-trained based part on the final fraud determination.; and Claim 8. further comprising: determining, by the processor, that the score exceeds a threshold score associated with the particular type of fraud, wherein the fraud classification indicates the particular type of fraud, based on the score exceeding the threshold score.; and Claim 14. wherein: the operations further comprise receiving a final fraud determination, associated with the fraud classification, that confirms or contradicts the fraud classification, and the machine leaning program is re-trained based on the final fraud determination.) One of ordinary skill in the art would have recognized that applying the known technique of Kramme to the known invention of Yavilevich as modified would have been recognized that the application of the technique would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate such fraud prevention into a similar invention. Further, it would have been recognized by those of ordinary skill in the art that modifying the system to include wherein the system is configured to dynamically adjust the predetermined threshold based on confirmed fraud outcomes to more accurately predict fraud associated with a specific user or transaction results in an improved invention because applying said technique ensures that there is automatic detection of patterns using the user’s transaction history to allow the system to recognize and conduct more fraud prevention actions, thus improving the overall security of the invention. Yavilevich as modified does not explicitly disclose and responsive to determining the likelihood exceeds the predetermined threshold, conduct one or more fraud prevention actions comprising at least one of: automatically generating a new virtual card number (VCN) for the user to use for completing the transaction, or modifying a GUI of the webpage by changing a size, a number, or a placement of one or more user input objects to prevent automated fraudulent actions within the GUI. However, Moreton teaches and responsive to determining the likelihood exceeds the predetermined threshold, conduct one or more fraud prevention actions comprising at least one of: automatically generating a new virtual card number (VCN) for the user to use for completing the transaction, or modifying a GUI of the webpage by changing a size, a number, or a placement of one or more user input objects to prevent automated fraudulent actions within the GUI, (Para. 0011, One overarching approach to spur adoption is to automatically create, track, and apply VCNs on behalf of a customer. This approach may employ a browser extension or other suitable programmatic construct to monitor a customer's behavior online. When the customer reaches a checkout page having a credit card number, CVV, and expiration date, the browser extension may generate a VCN (or retrieve an existing VCN) and populate the checkout form with the VCN. This obviates the need for the customer to manage their own VCNs. While potentially spurring wider adoption of VCNs, this approach itself gives rise to several additional technical problems that require technical solutions.; and Para. 0008] Importantly, when a transaction occurs using a VCN, the PAN is not exposed, which provides an added layer of security that protects the PAN during the transaction. Moreover, if the third-party stores the VCN and a data breach occurs at the third-party, the PAN is not compromised. In such a scenario, only the merchant-bound VCN is compromised, and the provider may generate a new VCN to cure the issue. The PAN is preserved, re-issuance is avoided, and the customer avoids a tremendous hassle.) One of ordinary skill in the art would have recognized that applying the known technique of Moreton to the known invention of Yavilevich as modified would have been recognized that the application of the technique would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate such fraud prevention into a similar invention. Further, it would have been recognized by those of ordinary skill in the art that modifying the system to include and responsive to determining the likelihood exceeds the predetermined threshold, conduct one or more fraud prevention actions comprising at least one of: automatically generating a new virtual card number (VCN) for the user to use for completing the transaction, or modifying a GUI of the webpage by changing a size, a number, or a placement of one or more user input objects to prevent automated fraudulent actions within the GUI results in an improved invention because applying said technique ensures that there is automatic detection of patterns using the user’s transaction history to allow the system to recognize and conduct more fraud prevention actions, thus improving the overall security of the invention. 6. Regarding claim 4, Yavilevich discloses wherein the search history data comprises one or more of a name of a webpage, a type of webpage, an order of webpages, a total amount of search time, a time period between webpage searches, metadata associated with the user device, or combinations thereof, (and Column 5/line 30, The pan/zoom data set includes the size of the web page downloaded to the user device; the size of a visible area on the client device 101 at any given moment (hereinafter “viewport”); the position of each viewport (e.g., position of scroll bars); a time period for which each viewport was active; and a layout in which the browser 102 attempted to render the web page. Using the pan/zoom data set, a rectangular area that was visible on the client device 101 at every given moment can be determined. The position data can be represented using x, y coordinates of the viewport. To gather the pan/zoom data set, events including, for example, load, unload, scroll, resize, mousemove, mousedown, mouseup, click, keydown, keypress, keyup, paste, mouseleave, mouseenter, activate, deactivate, focus, blur, select, selectstart, submit, error, abort, and so on are monitored and recorded by the tracking code. In a preferred embodiment, when the tracking code is executed by a handled device having a touch screen display, events, such as orientationchange, touchstart, touchmove, and touchend are recorded and monitored.) 7. Regarding claims 5 and 19, Yavilevich discloses wherein the searching session is based on one or more of browsing time, number of clicks, number of webpages visited, or combinations thereof, (Column 2/line 41, a method for monitoring and tracking browsing activity of a user on a client device. The method comprises receiving, from the client device, browsing activity information of a user interacting with at least a page displayed over the client device, wherein the client device is at least a handheld device having a touch screen display; receiving, from the client device, page information identifying in part the page displayed over the client device; and generating based on the browsing activity information and the page information an exposure map at a page view level, wherein the exposure map indicates a salience of each area of a page-view respective of the page displayed over the client device and visited by the user.; and Column 1/line 40, Data is compiled, and reports are generated on demand or are delivered from time to time via email to display information about web server activity, such as the most popular page by number of visits, peak hours of website activity, most popular entry page, and so on. Alternatively data is logged on the web server that is being monitored and the logs are transferred to another computer, where they are compiled and analyzed.; and Column 5/line 30, The pan/zoom data set includes the size of the web page downloaded to the user device; the size of a visible area on the client device 101 at any given moment (hereinafter “viewport”); the position of each viewport (e.g., position of scroll bars); a time period for which each viewport was active; and a layout in which the browser 102 attempted to render the web page. Using the pan/zoom data set, a rectangular area that was visible on the client device 101 at every given moment can be determined. The position data can be represented using x, y coordinates of the viewport. To gather the pan/zoom data set, events including, for example, load, unload, scroll, resize, mousemove, mousedown, mouseup, click, keydown, keypress, keyup, paste, mouseleave, mouseenter, activate, deactivate, focus, blur, select, selectstart, submit, error, abort, and so on are monitored and recorded by the tracking code. In a preferred embodiment, when the tracking code is executed by a handled device having a touch screen display, events, such as orientationchange, touchstart, touchmove, and touchend are recorded and monitored.) 8. Regarding claim 6, Yavilevich discloses wherein the searching session path comprises one or more steps the user has taken to navigate to the webpage, (Column 5/line 1, the tracking code waits for user activities and in response to these activities compresses and buffers the collected user activity information, and selectively transmits the compressed user activity information. The compression and buffering reduces the bandwidth and overhead associated with the transmission of the user activity information over the network 110.…during the recording of the pageview session, the tracking code listens to events generated by the browser 102 and determines for each event if the event should be collected or if it should trigger the collection of data. Specifically, two sets of data are collected during a pageview session, (i.e., an interaction of a user within the web page): the pan/zoom data set and the element data set. The pan/zoom data set relates to pan/zoom operations and the element data set relates to elements of the web page. The pan/zoom data set includes the size of the web page downloaded to the user device; the size of a visible area on the client device 101 at any given moment (hereinafter “viewport”); the position of each viewport (e.g., position of scroll bars); a time period for which each viewport was active; and a layout in which the browser 102 attempted to render the web page. Using the pan/zoom data set, a rectangular area that was visible on the client device 101 at every given moment can be determined. The position data can be represented using x, y coordinates of the viewport. To gather the pan/zoom data set, events including, for example, load, unload, scroll, resize, mousemove, mousedown, mouseup, click, keydown, keypress, keyup, paste, mouseleave, mouseenter, activate, deactivate, focus, blur, select, selectstart, submit, error, abort, and so on are monitored and recorded by the tracking code. In a preferred embodiment, when the tracking code is executed by a handled device having a touch screen display, events, such as orientationchange, touchstart, touchmove, and touchend are recorded and monitored.) 9. Regarding claim 7, Yavilevich does not explicitly disclose wherein the data comprises a virtual card number (VCN). However, Moreton teaches wherein the data comprises a virtual card number (VCN), (Para. 0026, As discussed above, a need exists to generate a VCN with the last 4 digits (or other suitable trailing quantity of digits, in other embodiments) matching the last 4 digits of the PAN. This solves the problem of customers' confusion at checkout because the last 4 digits that display in the checkout form match the customers' expectations (by matching the last 4 digits of the PAN). The customer gets the best of both worlds—the security of using VCNs to prevent theft and the simultaneous, easy identification of their account. With this enhancement in place, a provider may design and deploy a browser extension or other programmatic construct that allow customers to use VCNs automatically, effortlessly, and seamlessly. This approach offers all the security of VCNs, but to the customer appears only to use the familiar PAN. While the foregoing describes a last 4 digits, other implementations expose less or more digits. The below disclosure may reference to the last X digits of a PAN or VCN as a trailing identifier having a trailing quantity of digits.) One of ordinary skill in the art would have recognized that applying the known technique of Moreton to the known invention of Yavilevich would have been recognized that the application of the technique would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate such fraud prevention into a similar invention. Further, it would have been recognized by those of ordinary skill in the art that modifying the system to include determine, using a machine learning model (MLM) and based on the search history data and the searching session path, a likelihood of fraud associated with the data results in an improved invention because applying said technique ensures that there is automatic detection of patterns using the user’s transaction history to allow the system to recognize and conduct more fraud prevention actions, thus improving the overall security of the invention. 10. Regarding claims 8, 12, and 16, Yavilevich does not explicitly disclose wherein the one or more fraud prevention actions comprise one or more of: causing the user device to display, via a graphical user interface (GUI), a first notification, transmitting a first prompt to the user device requesting the user enter a primary card number associated with the VCN, transmitting a second prompt to the user device requesting the user generate a new VCN, transmitting an authentication request to a secondary device associated with the user, modifying a spending limit associated with the VCN, or combinations thereof. However, Moreton teaches wherein the one or more fraud prevention actions comprise one or more of: causing the user device to display, via a graphical user interface (GUI), a first notification, transmitting a first prompt to the user device requesting the user enter a primary card number associated with the VCN, transmitting a second prompt to the user device requesting the user generate a new VCN, transmitting an authentication request to a secondary device associated with the user, modifying a spending limit associated with the VCN, or combinations thereof, (Para. 0060-0061, Generating agent 300A includes VCN 302, virtual card CVV 304, virtual card expiration date 306, linked PAN 308, and issuer 310. Generating agent 300A may be operate as part of browser extension 107,…VCN 302, generated by creation module 142 and displayed in generating agent 300A, takes the same form as PAN 202. In one embodiment, VCN 302 is a 16-digit number. In other embodiments, VCN 302 otherwise matches the length and format of PAN 202. Subsequently, a customer may provide VCN 302 to a merchant and incur an expense against credit card 104. In this fashion, VCN 302 provides a secure mechanism of transaction against an account without exposing PAN 202. VCN 302 may be created by user 102 using financial service provider system 110 or VCN 302 may be created by browser extension 107, which automatically recognizes that user 102 is on a webpage of merchant 108 having a credit card field. In some embodiments, user 102 may provide VCN 302 to merchant 108 in person, over the phone, or using any other suitable approach. FIG. 3A illustrates that the last 4 digits of VCN 302 match the last 4 digits of PAN 202; and Para. 0130-0132, In 802, VCN component 130 may allow user 102 to specify a merchant-specific control to with a VCN. The merchant-specific control may identify a limitation that restricts the use of the VCN. For example, a merchant-specific control may be a spending limit, and any transactions that exceed the spending limit may be rejected by financial service provider system without attempting to process the transaction. Other examples of merchant may be a limit on the number of charges, date/time limitations, and other suitable controls. In 804, VCN component 130 may associate the merchant-specific control with an existing VCN. VCN component 130 may store appropriate information in storage 138 for use in the later processing of transactions that use the VCN and the merchant-specific control entered in 802. In 806, VCN component 130 may apply merchant binding in response to a transaction using the VCN. Merchant-binding may verify that the transaction is being applied to the appropriate merchant. If a VCN is associated with “merchant A” and the transaction involves “merchant B,” the transaction may be denied. VCN component may also verify that the transaction is valid by examining the merchant-specific controls provided by user 102 in 802. For example, if a spending limit has been applied and the transaction has a price in excess of the spending limit, then the charge may be denied.) One of ordinary skill in the art would have recognized that applying the known technique of Moreton to the known invention of Yavilevich as modified would have been recognized that the application of the technique would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate such fraud prevention into a similar invention. Further, it would have been recognized by those of ordinary skill in the art that modifying the system to include determine, using a machine learning model (MLM) and based on the search history data and the searching session path, a likelihood of fraud associated with the data results in an improved invention because applying said technique ensures that there is automatic detection of patterns using the user’s transaction history to allow the system to recognize and conduct more fraud prevention actions, thus improving the overall security of the invention. 11. Regarding claim 10, Yavilevich does not explicitly disclose wherein the MLM is trained via federated learning. However, Bercich teaches wherein the MLM is trained via federated learning, (Column 1/line 34, The invention relates to the field of “federated learning” and its use in conjunction with machine learning models to detect illicit financial crime behaviors including but not limited to money laundering. In particular, the invention relates to the use of “federated learning” in the process of model training and inference and the use of machine learning more generally.) One of ordinary skill in the art would have recognized that applying the known technique of Bercich to the known invention of Yavilevich would have been recognized that the application of the technique would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate such fraud prevention into a similar invention. Further, it would have been recognized by those of ordinary skill in the art that modifying the system to include wherein the MLM is trained via federated learning results in an improved invention because applying said technique ensures that there is automatic detection of patterns using the user’s transaction history and behaviors to allow the system to improve fraud detection, thus improving the overall security of the invention 12. Regarding claim 11, Yavilevich does not explicitly disclose wherein the instructions are further configured to cause the system to: responsive to determining the likelihood does not exceed the predetermined threshold, authorize the transaction. However, Bercich teaches wherein the instructions are further configured to cause the system to: responsive to determining the likelihood does not exceed the predetermined threshold, authorize the transaction, (Column 8/line 6, The one or more processors 102 can also be programmed to set a threshold for a total number of training cycles and to stop the training of the neural network at step 408 in response to the number of training cycles exceeding the threshold. The one or more processors 102 can also be programmed to set a threshold as a function of a loss plane of the output vector reconstruction error and stop the training of the neural network at step 410 in response to the output vector reconstruction error being less than the threshold.). One of ordinary skill in the art would have recognized that applying the known technique of Bercich to the known invention of Yavilevich would have been recognized that the application of the technique would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate such fraud prevention into a similar invention. Further, it would have been recognized by those of ordinary skill in the art that modifying the system to include wherein the instructions are further configured to cause the system to: responsive to determining the likelihood does not exceed the predetermined threshold, authorize the transaction results in an improved invention because applying said technique allows the system to identify fraud quickly and take action to prevent fraud from actually occurring, thus improving the overall security of the invention. 13. Regarding claim 14, Yavilevich does not explicitly disclose wherein the MLM is trained to identify one or more correlations between the search history data, the searching session path, and/or the data to determine the likelihood of fraud. However, Bercich teaches wherein the MLM is trained to identify one or more correlations between the search history data, the searching session path, and/or the data to determine the likelihood of fraud, (Column 4/line 21, autoencoder system can maintain anonymity and preserve the relational content between and among PII data while still encoding it in a safe manner. Therefore, the data can still be used for network analysis, deduplication efforts and can generally serve as an input into machine-learning models to detect complex patterns whose accuracy and veracity is enhanced by the inclusion of this encoded PII data in the analysis. Business and research areas alike should be able to utilize this encoded data for analysis, without having to have access to the original data. This is especially applicable in (but not restricted to) the financial sector for the purposes of fraud detection and anti-money laundering efforts, and in the healthcare sectors, allowing third party providers and researchers to work with a more complete dataset than ever before without revealing any actual PII data.; and Column 15/line 42, The data utilized in the methods of the invention include, but are not limited to, data regarding identity… credit data (e.g., household income, credit history and/or credit score); financial data (e.g., income sources, income amounts, assets, tax records, loan information, loan history, loan repayments, banking history, banking transactions, financial institutions involved in such transactions, transaction locations, mortgage information, mortgage history, account balances, number of accounts, counterparty information, fraud activity, and/or fraud alerts); and insurance information (e.g. insurance claims, insurance policies, and/or insurance payments received)…analyzing data of entities in various sectors including, but not limited to, compliance for banks or other financial institutions, securities investigations, investigations of counterfeiting, illicit trade, or contraband, compliance regarding technology payments, regulatory investigations, healthcare, life sciences, pharmaceuticals, social networking, online or social media marketing, marketing analytics and agencies, urban planning, political campaigns, insurance analytics, real estate analytics, education, tax compliance and government analytics. One of ordinary skill in the art would have recognized that applying the known technique of Bercich to the known invention of Yavilevich would have been recognized that the application of the technique would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate such fraud prevention into a similar invention. Further, it would have wherein the MLM is trained to identify one or more correlations between the search history data, the searching session path, and/or the data to determine the likelihood of fraud results in an improved invention because applying said technique allows the system to identify fraud quickly and take action to prevent fraud from actually occurring, thus improving the overall security of the invention. 14. Regarding claim 15, Yavilevich discloses wherein the instructions are further configured to: identify, using a web browser extension, that the user has navigated to the webpage on the user device, wherein retrieving the search history data and identifying the searching session path are responsive to identifying that the user has navigated to the webpage, (Column 4/line 17, The client device 101 may be, but is not limited to, a smart phone, a tablet computer, a personal computer, a laptop computer, a netbook computer, an electronic reader, and the like. The browser 102 may be any web browser, such as Safari®, Firefox®, Internet Explorer®, Chrome®, and the like. The processor of the client device 101 runs an operating system that may include iOS®, Android®, Unix®, Windows®, and the like. The mobile application 103 may be any application that is executable over the client device 101 and/or an extension of the browser 102. The mobile application 103 is typically downloaded from a central repository 140 which may, e.g., AppStore® by Apple Computers®, Google® Play®, and the like…accordance with one embodiment, the user activity information is collected through a recording process performed by using a tracking code. The tracking code may be realized as a script, e.g., a Javascript embedded in a web page downloaded to the client device 101. The tracking code may also be embedded in a mobile application downloaded and installed in the client the device 101. It should be noted that the tracking code is seamlessly incorporated and executed in the client device 101. In one embodiment, the tracking code may start its execution automatically. Alternatively, the code may wait for an instruction from some other piece of script in the web page or the mobile application 103. The tracking code can decide whether to track activities of a user or not. Such a decision can be responsive to one or more predefined parameters, a result of a random process, or a combination thereof. The predefined parameters may include, for example, a page URL, a referring page URL, an IP address, a time zone, a browser type, whether the user is a returning user (to the web page and/or to the web site), a specific user action, and the like. A user of the client device 101 can visit a web site that includes one or more web pages. While a web page is displayed in the browser 102, the user can perform various activities that are monitored by the tracking code. The interaction of a user within one web page is referred to as a “pageview session.”) 15. Regarding claim 21, Yavilevich does not explicitly disclose wherein the MLM is a federated model configured to dynamically receive searching data of the user via the user device for retraining. However, Bercich teaches wherein the MLM is a federated model configured to dynamically receive searching data of the user via the user device for retraining, (Column 1/line 34, The invention relates to the field of “federated learning” and its use in conjunction with machine learning models to detect illicit financial crime behaviors including but not limited to money laundering. In particular, the invention relates to the use of “federated learning” in the process of model training and inference and the use of machine learning more generally.; and Column 3/line 11, Each entity is assigned a model for individual behaviors (e.g. for money laundering) so that complex nuances and differences across entities can be learned by the model, thus optimizing the model's suitability for detection in that entity. This also ensures that model accuracy is not eroded by cross training which would result in the generalization of inference such that the important structural differences between entities would be disregarded. Models for a specific behavior have the same architectural properties across all entities and are re-trained using the specific entity's data and feedback…The information that is extracted through this mathematically explains how the models' weights have changed alter being re-trained using their own feedback data. These scores, technically referred to as feature importance differential values, are then inputted into a supra deep learning neural network, which sits on top of all models concerning this behavior. The scores extracted from each entity are aggregated, as all entities will update their models based on insight learnt from the behavior of their clients. This aggregation of their differential scores is then combined with the weights of a single entity's neural network model, and then inputted into a supra neural network. This supra neural network is specifically trained offline to extract information from these differential scores which is then used to update the entity's neural weights, essentially shifting the entity's weights in a way that integrates both feedback learnt from their individual clients and information from the other entities' partial derivative scores, which implicitly impound information about those entities' feedback and contextual situation, whilst still preserving each entity's model specificity and without sharing any raw client data.) One of ordinary skill in the art would have recognized that applying the known technique of Bercich to the known invention of Yavilevich would have been recognized that the application of the technique would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate such fraud prevention into a similar invention. Further, it would have been recognized by those of ordinary skill in the art that modifying the system to include wherein the MLM is a federated model configured to dynamically receive searching data of the user via the user device for retraining results in an improved invention because applying said technique ensures that there is the model is continuously retrained on the user’s device, thus improving the overall performance of the invention. 16. Regarding claim 22, Yavilevich does not explicitly disclose wherein the MLM is a federated model such that users' personal browsing data is sent back to the MLM for training rather than to a central server to increase privacy and security of users' personal information. However, Bercich teaches wherein the MLM is a federated model such that users' personal browsing data is sent back to the MLM for training rather than to a central server to increase privacy and security of users' personal information, ((Column 8/line 6, The one or more processors 102 can also be programmed to set a threshold for a total number of training cycles and to stop the training of the neural network at step 408 in response to the number of training cycles exceeding the threshold. The one or more processors 102 can also be programmed to set a threshold as a function of a loss plane of the output vector reconstruction error and stop the training of the neural network at step 410 in response to the output vector reconstruction error being less than the threshold.; and Column 4/line 17, As a matter of security, some entities might prefer to use autoencoder-based data anonymization systems and methods to encrypt their data at the outset before attempting to detect particular behaviors. FIGS. 1A to 4 disclose such systems and methods…autoencoder system can maintain anonymity and preserve the relational content between and among PII data while still encoding it in a safe manner. Therefore, the data can still be used for network analysis, deduplication efforts and can generally serve as an input into machine-learning models to detect complex patterns whose accuracy and veracity is enhanced by the inclusion of this encoded PII data in the analysis. Business and research areas alike should be able to utilize this encoded data for analysis, without having to have access to the original data. This is especially applicable in (but not restricted to) the financial sector for the purposes of fraud detection and anti-money laundering efforts, and in the healthcare sectors, allowing third party providers and researchers to work with a more complete dataset than ever before without revealing any actual PII data.) One of ordinary skill in the art would have recognized that applying the known technique of Bercich to the known invention of Yavilevich would have been recognized that the application of the technique would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate such fraud prevention into a similar invention. Further, it would have been recognized by those of ordinary skill in the art that modifying the system to include wherein the MLM is a federated model such that users' personal browsing data is sent back to the MLM for training rather than to a central server to increase privacy and security of users' personal information results in an improved invention because applying said technique allows the system to identify fraud quickly and take action to prevent fraud from actually occurring, thus improving the overall security of the invention. Claims 23 and 24 are rejected under 35 U.S.C. 103 as being unpatentable over Yavilevich et al. (US 10063645), in view of Bercich et. al (US 12045716 B2), in view of Kramme et. al (US 20230088436 A1), and further in view of Moreton et al. (US 20240070646 A1), and further in view of Drake et al. (US 20170346851 A1). Regarding claim 23, Yavilevich as modified does not explicitly disclose wherein the one or more fraud prevention actions comprise redirecting the user to a new tab on the webpage to bypass a step in a pathway that the system has identified as potentially risky. However, Drake teaches wherein the one or more fraud prevention actions comprise redirecting the user to a new tab on the webpage to bypass a step in a pathway that the system has identified as potentially risky, (Para. 0327, In the case where the calling page needs to remain, for example, iOS8 when needing to maintain communication with a server like websocket or long-poll, first we create the new blank tab or window, then we wait until the new tab/window becomes visible (this being necessary because the calling page is sent to background and thus no longer generates visibility change events which we need to monitor), next we bind visibility events handlers to the newly created window document and initiate a countdown timer, and at this point we load attempt to load the app if already installed. If visibility change events are generated this indicates a successful app launch, and the countdown timer is cancelled, but if not, the timer generates a page redirection to the app store for the user to download the requisite app.; and Para. 0168, This shows an example display that a User might experience when permitting the release of personal data about themselves. Mobile device 1201 with biometrics sensors 1205 (face rec camera), 1208 (fingerprint), and 1209 (voice rec mic) is held by user 1202. They see instructions 1212 for an event 1263, and are shown a non-random photo 1262 which represents the facial portrait of the third party who is requesting their attributes. The user can approve 1261 or decline 1260 this data release. In this example, a patient would typically be in the presence of the doctor at a surgery or hospital, thus they can check that the photo on their screen is the correct one for the doctor they are permitting their information release to. Note that with an identity infrastructure and trust brokers in place, this provides strong protection against imposters and fraud.) One of ordinary skill in the art would have recognized that applying the known technique of Drake to the known invention of Yavilevich as modified would have been recognized that the application of the technique would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate such fraud prevention into a similar invention. Further, it would have been recognized by those of ordinary skill in the art that modifying the system to include wherein the one or more fraud prevention actions comprise redirecting the user to a new tab on the webpage to bypass a step in a pathway that the system has identified as potentially risky results in an improved invention because applying said technique ensures that there is automatic detection of patterns using the user’s transaction history to allow the system to recognize and conduct more fraud prevention actions, thus improving the overall security of the invention. 19. Regarding claim 24, Yavilevich as modified does not explicitly disclose wherein the one or more fraud prevention actions comprise transmitting an authentication request to a secondary device associated with the user such that the user must complete a multi-factor authentication process to proceed with the transaction. However, Drake teaches wherein the one or more fraud prevention actions comprise transmitting an authentication request to a secondary device associated with the user such that the user must complete a multi-factor authentication process to proceed with the transaction, (Para. 0341-0343, Another example of unwanted actions that present invention can protect against comes from bank Automatic Teller Machine (ATM) or Point-of-Sale (POS) credit/debit card skimming. These are attacks where Criminals obtain card details and possibly PIN numbers, such as for example using skimming hardware and hidden cameras to extract this information from magnetic stripes and ATM/POS keypads either electronically or by visual observation or recording. Card details stolen this way can be cloned onto plastic cards and subsequently used in ATMs to withdraw cash or POS to obtain goods, thus stealing from victim accounts. Coordinated attacks in 2003 obtained $45M cash this way in a single heist lasting a few hours. The present invention prevents unauthorized cash withdrawals or POS transactions because the banking payment switch or other internal bank software is programmed to seek the genuine user's permission for the withdrawal or sale by sending details of the proposed transaction to the user's smart token mobile device to request their approval. In the event of Criminals attempting to use stolen cards, unwanted transactions can be blocked, and the User can be alerted to the theft of their card, and can take further action to prevent subsequent loss, such as for example using the token mobile device to immediately cancel the card. Similar protection can also be afforded with this infrastructure, whereby all or selected customer card payments are blocked until such time as the customer makes use of the token app software to momentarily unlock their card for a transaction they intend to perform, optionally specifying an intended amount or approximation of it to help ensure the subsequent transaction is permitted. Common forms of card attack experienced by customers of illicit goods and service providers include transactions for amounts that are significantly higher than expected. For example, some illicit clubs in Europe operate modified POS terminals which display a sale amount to the customer which is 10 times lower than the amount the customer unknowingly approves at time of purchase. One of ordinary skill in the art would have recognized that applying the known technique of Drake to the known invention of Yavilevich as modified would have been recognized that the application of the technique would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate such fraud prevention into a similar invention. Further, it would have been recognized by those of ordinary skill in the art that modifying the system to include wherein the one or more fraud prevention actions comprise transmitting an authentication request to a secondary device associated with the user such that the user must complete a multi-factor authentication process to proceed with the transaction results in an improved invention because applying said technique ensures that there is automatic detection of patterns using the user’s transaction history to allow the system to recognize and conduct more fraud prevention actions, thus improving the overall security of the invention. Conclusion THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Systems and Methods for Using Browser History in Online Fraud Detection (US 20170169431 A1) teaches fraud detection computing device for using browser history to detect fraudulent online cardholder activity is provided. The fraud detection computing device includes one or more processors in communication with one or more memory devices. The fraud detection computing device is configured to receive, from an interchange network, an authorization request message, identify a device identifier associated with the cardholder computing device, authenticate that the device identifier is associated with the first cardholder account, retrieve a plurality of user browser history based on the device identifier, analyze the plurality of user browser history to determine a plurality of expected pending transactions, determine whether the payment card transaction is included within the plurality of expected pending transactions, and respond to the authorization request message based at least in part on whether the payment card transaction is included within the plurality of expected pending transactions. A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. In addition to the foregoing, other aspects are described in the claims, drawings, and text. Any inquiry concerning this communication or earlier communications from the examiner should be directed to Davida L. King whose telephone number is (571) 272-4724. The examiner can normally be reached M-F 8am-5pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Neha Patel can be reached on (571) 270-1492. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /D.L.K./Examiner, Art Unit 3699 /NEHA PATEL/Supervisory Patent Examiner, Art Unit 3699
Read full office action

Prosecution Timeline

Show 13 earlier events
Feb 11, 2026
Response after Non-Final Action
Feb 25, 2026
Non-Final Rejection mailed — §103
Mar 22, 2026
Interview Requested
Apr 17, 2026
Interview Requested
May 07, 2026
Examiner Interview (Telephonic)
May 11, 2026
Examiner Interview Summary
May 26, 2026
Response Filed
Aug 19, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12664540
COMPUTER-IMPLEMENTED SYSTEM AND METHOD FOR IMPLEMENTING ALIAS-BASED ADDRESSING FOR A DISTRIBUTED LEDGER
4y 8m to grant Granted Jun 23, 2026
Patent 12657601
METHOD OF REAL-TIME LOYALTY REWARDS REDEMPTION
3y 5m to grant Granted Jun 16, 2026
Patent 12639679
CONTROL CIRCUIT OF LARGE DATA PROCESSING DEVICE SYSTEM FOR VIRTUAL CURRENCY AND LARGE DATA PROCESSING DEVICE FOR VIRTUAL CURRENCY
3y 8m to grant Granted May 26, 2026
Patent 12632864
FEDERATED IDENTIFIERS FOR CROSS-PLATFORM INTEROPERABILITY
4y 6m to grant Granted May 19, 2026
Patent 12572930
ENABLING TRACEABLE TREES OF TRANSACTIONS
3y 5m to grant Granted Mar 10, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
36%
Grant Probability
72%
With Interview (+36.4%)
3y 3m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 45 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month