Prosecution Insights
Last updated: October 02, 2026
Application No. 18/417,534

Hyper-customized customer defined machine learning models

Final Rejection §103
Filed
Jan 19, 2024
Examiner
CHANG, TOM Y
Art Unit
2455
Tech Center
2400 — Computer Networks
Assignee
Zscaler Inc.
OA Round
2 (Final)
53%
Grant Probability
Moderate
3-4
OA Rounds
1y 5m
Est. Remaining
73%
With Interview

Examiner Intelligence

Grants 53% of resolved cases
53%
Career Allowance Rate
243 granted / 455 resolved
-4.6% vs TC avg
Strong +20% interview lift
Without
With
+20.0%
Interview Lift
resolved cases with interview
Typical timeline
4y 1m
Avg Prosecution
22 currently pending
Career history
481
Total Applications
across all art units

Statute-Specific Performance

§101
11.4%
-28.6% vs TC avg
§103
48.9%
+8.9% vs TC avg
§102
17.3%
-22.7% vs TC avg
§112
13.8%
-26.2% vs TC avg
Black line = Tech Center average estimate • Based on career data from 455 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This action is responsive to communication received on 05/16/26. Claims 1-2,4,6-12,14 and 16-24 are pending of which claims 1 and 11 are amended and 21-24 new. The Examiner recommends filing a written authorization for Internet communication in response to the present action. Doing so permits the USPTO to communicate with Applicant using Internet email to schedule interviews or discuss other aspects of the application. Without a written authorization in place, the USPTO cannot respond to Internet correspondence received from Applicant. The preferred method of providing authorization is by filing form PTO/SB/439, available at: https://www.uspto.gov/patent/forms/forms. See MPEP § 502.03 for other methods of providing written authorization. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1, 2, 7, 11, 12, 17, 22 and 24 are rejected under 35 U.S.C. 103 as being unpatentable over Singhal US 2022/0398500, further in view of Choudhury US 2024/0394407 and Lee US 2024/0080245. Regarding claims 1 and 11, Singhal teaches a method and non-transitory CRM executed by processor to perform the method comprising steps of: providing a first set of data obtained based on monitoring a plurality of endpoints by a service provider, wherein the plurality of endpoints are associated with a customer(global training system (I e service provider) maintains a database of global parameters aggregated from multiple computing device(i.e. endpoints), ¶41) [0041] The local training systems of the user devices obtain the current values 112 of the set of global model parameters 110 from the global training system 102 and generate parameter value updates 114 to the set of global model parameters 110 using local training data generated on the user devices. The local training systems transmit the parameter value updates 114 to the global training system 102 for use in updating the set of global model parameters 110 of the machine learning model 108. and wherein the first set of data includes is indexed by an index(global parameter stored in database that is indexed, ¶113) [0113] In this specification, the term “database” is used broadly to refer to any collection of data: the data does not need to be structured in any particular way, or structured at all, and it can be stored on storage devices in one or more locations. Thus, for example, the index database can include multiple collections of data, each of which may be organized and accessed differently. responsive toa request from the customer wanting to create a user-defined machine learning model, receiving a second set of data that maps to a subset of the first set of data based on the index, wherein the second set of data is maintained private from the service provider(updating of local parameters via querying the global parameter database that is indexed, ¶s 9,13) [0009] Determining the updated values of the set of local parameters of the machine learning model may comprise: providing the query dataset, data defining the current values of the set of local parameters, and the data defining the current values of the set of global parameters as input to an update algorithm. [0013] Another innovative aspect of the subject matter described in this specification can be embodied in methods performed by a server computing device that is in data communication with a plurality of client computing devices over a data communication network that include the actions of selecting a subset of client computing devices from the plurality of client computing devices; transmitting, to each client computing device in the subset and over the data communication network, data defining current values of a set of global parameters of a machine learning model, wherein the machine learning model has the set of global parameters maintained at the server computing device and a plurality of sets of local parameters maintained at the plurality of the client computing devices; receiving, from each client computing device in the subset and over the data communication network, respective parameter update data defining an update to the set of global parameters of the machine learning model; and updating the current values of the set of global parameters of the machine learning model based on the respective parameter update data. receiving a metric from the customer for accepting criteria of the user-defined machine learning model; and(objective function used to evaluate performance of the model, ¶s81,82) [0081]…where g.sup.(t) denotes the current values of the global model parameters, and l.sub.i.sup.(t,k.sup.r.sup.−1) denotes the values of the set of local model parameters as of the current step, with l.sub.i.sup.(t,0) denoting the randomly initialized values of the set of local model parameters. f.sub.i(x)=[AltContent: rect].sub.ξ∈D.sub.i[(f.sub.i(x,ξ)] is an objective function used by the system to evaluate a measure of performance of the machine learning model on the particular task, where x is the combination (e.g., concatenation ∥) of the global model parameters g and set of the local model parameters l, and ξ is a training example generated from the support dataset. Specifically, for a given training example, the system can evaluate the objective function to measure a difference between (i) a training output generated by processing the training input using the machine learning model in accordance with current values of the global and local model parameters and (ii) the target output. [0082] For example, the objective function can be a cross-entropy objective function or a squared-error objective function, and different systems running at different client computing devices can use different objective functions. Optionally, in order to incentivize the set of local model parameters trained in this way to not diverge too far from the corresponding set of global parameters, an additional regularization term that penalizes any difference between local and global parameter values may be added to the objective function. determining the user-defined machine learning model based on the first set of data, the second set of data, and the metric(local training is performed with to achieve a target output where target output is based on measure of performance, ¶s 65, 77, 81) [0065] The local training systems 106A-N are each configured to maintain a set of local model parameters 105A-N, e.g., in a logical data storage area or physical data storage device. At each of multiple training iterations, the local training system receives data defining the current values 112 of the set of global model parameters 110 and then uses received data to obtain a reconstruction of the values of its own local model parameters 105 of the machine learning model. The local training system then uses the local parameter values to determine parameter value updates 114 to its copy of the set of global model parameters 110. [0077] In some implementations, the system continually generates training examples for training the machine learning model based on the local data, i.e., based on either support dataset or query dataset, and both before and after receiving the current global model parameter values of the machine learning model. Each training example generated by the system can include a machine learning model training input and a target output that should be generated by the machine learning model to perform a particular machine learning task by processing the training input. [0081]…where g.sup.(t) denotes the current values of the global model parameters, and l.sub.i.sup.(t,k.sup.r.sup.−1) denotes the values of the set of local model parameters as of the current step, with l.sub.i.sup.(t,0) denoting the randomly initialized values of the set of local model parameters. f.sub.i(x)=[AltContent: rect].sub.ξ∈D.sub.i[(f.sub.i(x,ξ)] is an objective function used by the system to evaluate a measure of performance of the machine learning model on the particular task, where x is the combination (e.g., concatenation ∥) of the global model parameters g and set of the local model parameters l, and ξ is a training example generated from the support dataset. Specifically, for a given training example, the system can evaluate the objective function to measure a difference between (i) a training output generated by processing the training input using the machine learning model in accordance with current values of the global and local model parameters and (ii) the target output. Singhal does not teach wherein the first set of data includes is indexed by an index that uniquely identifies entries of the first set of data receiving, from the customer, a second set of data that maps to a subset of the first set of data based on the index, the second set of data being indexed by the index, the second set of data thereby mapping to a subset of the first set of data via matching values of the index between the first set of data and the second set of data wherein the user-defined machine learning model is defined by the customer and the user-defined machine learning model is maintained private from the service provider. Choudhury in the same field of endeavor as the invention teaches a system for a collaborative machine learning framework. Choudhury teaches wherein the first set of data includes is indexed by an index that uniquely identifies entries of the first set of data(central training dataset includes an index with unique column value that maps across datasets from different organization providing training data) ; [0036] As mentioned above, the secure distributed data collaboration system utilizes a central generative model to generate a synthetic dataset. As used herein, the term “central generative model” refers to generative model within a centralized server. For example, the secure distributed data collaboration system receives the combined feature map and utilizes the central generative model to generate a synthetic dataset. In particular, the central generative model stores and processes information (e.g., the combined feature map) at a single server. For instance, the secure distributed data collaboration system utilizes the central generative model to receive the intermediate feature maps from different local nodes to generate the synthetic dataset. However, raw information of datasets from the local nodes are not exposed to the central generative model, only representations of the dataset (e.g., the intermediate feature maps). [0084] Additionally, FIG. 3B shows an act 336 of randomly sampling from a list given by mat [discrete column d][category c2]. For example, the secure distributed data collaboration system 102 passes the random sampling from list mat [discrete column d][category c2] to pass to dataset B. In particular, the value passed to dataset B is val. Moreover, FIG. 3B shows an act 338 of randomly selecting a discrete column from dataset B. In particular, the local node for dataset B receives the index value val which indicates data row data [val]. For the act 338, the secure distributed data collaboration system 102 randomly selects one of the discrete columns from dataset B {d1, d2, d6, d7.}. For instance, the act 338 selects d6 which results in a mask vector for dataset B of [0,0,1,0]. Similar to above, the secure distributed data collaboration system 102 selects a category based on whichever data [val] row has an entry in the d6 column. For instance, if the category in the d6 column of data [val] row is c1, then the secure distributed data collaboration system 102 utilizes c1 as the condition vector for passing through local generator (corresponding to dataset B). [0113] FIG. 9 shows ablation study results. For example, a first ablation study 900 shows experimenters testing the secure distributed data collaboration system 102 with mixing layers and without mixing layers. In particular, the first ablation study 900 shows that the secure distributed data collaboration system 102 performs better with mixing layers in terms of KL divergence and model efficacy. Accordingly, the mixing layers assist the secure distributed data collaboration system 102 in learning better correlation between unique columns of different local sites. receiving, from the customer, a second set of data that maps to a subset of the first set of data based on the index, the second set of data being indexed by the index, the second set of data thereby mapping to a subset of the first set of data via matching values of the index between the first set of data and the second set of data(based on a first feature map from the client device and a second feature map from a second node collected at the central server, synthetic data set is created as a combination from both dataset based on indexing column, ¶47,59, 85,125, 126) [0047] In one or more embodiments, the secure distributed data collaboration system utilizes conditional vector sampling. As used herein, the term “conditional vector sampling” refers to the secure distributed data collaboration system accounting for datasets with skewed category frequencies during training. For example, condition vector sampling refers to generating a sample vector from a dataset (e.g., a probability distribution) while conditioning on the value of other vectors. In particular, the condition vector sampling accounts for additional information such as imbalanced datasets. Moreover, during both training and inference, the secure distributed data collaboration system utilizes conditional vector sampling to generate synthetic datasets. [0059] As also discussed, the secure distributed data collaboration system 102 generates the synthetic dataset 206 and provides the synthetic dataset 206 to a client device 208. For example, as already discussed, the client device 208 corresponds with a request sent from the secure distributed data collaboration system 102 to perform a data collaboration with one or more local nodes. In response to the request, the secure distributed data collaboration system 102 sends the synthetic dataset 206 to the client device 208, which is able to make additional analytical insight based on the provided synthetic dataset 206. Additional details regarding the client device 208 sending data collaboration requests, configuration of data collaboration requests, and the secure distributed data collaboration system 102 providing the synthetic dataset 206 is provided below in the description of FIGS. 5A-5C. [0085] FIG. 4A illustrates details of the secure distributed data collaboration system 102 passing synthetic rows of a generated synthetic dataset to local discriminators of the local nodes in accordance with one or more embodiments. Further, as discussed, the secure distributed data collaboration system 102 utilizes a central generative model 412 to process a combined feature map to generate a synthetic dataset. [0125] The series of acts 1100 includes an act 1102 of sending a request to perform a data collaboration with a first dataset from a first local node and a second dataset from a second local node, an act 1104 of receiving a first intermediate feature map without personally identifiable information, an act 1106 of receiving a second intermediate feature map without personally identifiable information, an act 1108 of generating a combined feature map, and an act 1110 of generating, utilizing a central generative model, a synthetic dataset from the combined feature map. [0126] In particular, the act 1102 can include sending a request to perform a data collaboration with a first dataset from a first local node and a second dataset from a second local node, wherein the first dataset and the second dataset comprises personally identifiable information, the act 1104 can include receiving a first intermediate feature map corresponding with the first dataset from the first local node without personally identifiable information, the act 1106 can include receiving a second intermediate feature map corresponding with the second dataset from the second local node without personally identifiable information, the act 1108 can include generating a combined feature map from the first intermediate feature map and the second intermediate feature map, and the act 1110 can include generating, utilizing a central generative model, a synthetic dataset from the combined feature map, wherein the synthetic dataset is statistically representative of the first dataset and the second dataset. wherein the user-defined machine learning model is defined by the customer and the user-defined machine learning model is maintained private from the service provider(collaboration request combines the organization’s dataset and second dataset from central server(from other organizations), the synthetic dataset is given to local node that allows the synthetic dataset to be used to train a model at the local node, without exposing personal identifiable data, thus the model is maintained private from the other organizations, ¶s37,125). [0037] As mentioned above, the secure distributed data collaboration system utilizes local generators at the local nodes. As used herein, the term “local generator” refers to a model trained on data to generate new samples of data that are similar/representative of the initial samples of data. In contrast to the central generative model, the secure distributed data collaboration system trains the local generators locally on each local node without transferring raw data to the central generative model. [0137] Moreover, in one or more embodiments, the series of acts 1100 includes generating the first intermediate feature map from a first local generator of the first local node, generating the second intermediate feature map from a second local generator of the second local node, determining a first discriminator loss for a first local discriminator of the first local node, and determining a second discriminator loss for a second local discriminator of the second local node. Further, in one or more embodiments, the series of acts 1100 includes updating parameters of the central generative model by determining a first local generator loss to update parameters of the first local generator, determining a second local generator loss to update parameters of the second local generator, determining a combined measure of loss based on the first local generator loss, the second local generator loss and the synthetic dataset, and back-propagating the combined measure of loss to the central generative model. It would have been obvious to a person of ordinary skill in the art before the effective filing of the invention to modify Singhal with the method of generating a dataset that samples and combines two datasets. The reason for this modification would be to provide a method to share and map training data from other organizations that a requesting organization can use to train models The combination of Singhal/Choudhary teaches a request from a customer to generate a model(Choudhary ¶125) but does not teach the request include performance metrics. Thus Singhal/Choudhary do not teach receiving, from the customer, a metric from the customer for defining accepting criteria for performance of the user-defined machine learning model. Lee in the same field of endeavor as the invention teaches a system for federated machine learning. Lee teaches receiving, from the customer, a metric from the customer for defining accepting criteria for performance of the user-defined machine learning model. [0197] In operation 805, a consumer (e.g., an NWDAF including an AnLF or an NWDAF including an MTLF) may transmit a subscription request to an NWDAF including an MTLF to retrieve or train an ML model. For the subscription request, the consumer may use an Nnwdaf_MLModelProvision service (e.g., when the consumer is an NWDAF including an AnLF) including an analytics ID and an ML model metric or an Nnwdaf_MLModelTraining_Subscribe service (e.g., when the consumer is an NWDAF including an MTLF) or an Nnwdaf_MLModelTrainingInfo_Request (e.g., when the consumer is an NWDAF including an MTLF). The ML model metric may include ML model accuracy/precision/recall, an accuracy reporting interval, and/or a predetermined status (e.g., an ML model accuracy threshold, a total training time). The ML model accuracy threshold may be used to indicate the target ML model accuracy of a training process, and the FL server NWDAF may stop the training process when reaching the ML model accuracy threshold during the training process. It would have been obvious to a person of ordinary skill in the art before the effective filing of the invention to modify Singhal/Choudhary with a request for model training that include accuracy metric. The reason for this modification would be to allow control over the performance/accuracy of a model to requested. Regarding claims 2 and 12, Singhal teaches wherein the steps further include: hosting the user-defined machine learning model by the service provider to analyze production data to make a prediction based thereon, wherein the hosting and the prediction are maintained private from the service provider( trained model deployed to perform task such as prediction tasks for example patient health predictions, ¶s55,56,120). [0055] As another example, the task can be a health prediction task, where the input is electronic health record data for a patient and the output is a prediction that is relevant to the future health of the patient, e.g., a predicted treatment that should be prescribed to the patient, the likelihood that an adverse health event will occur to the patient, or a predicted diagnosis for the patient. [0056] In the example health prediction task, the machine learning model can also be emotion recognition model which is configured to detect or recognize emotional information of a patient from passive sensor data about the patient's physical state. The passive sensor data can include, e.g., electroencephalogram (EEG) data or electrocardiogram (ECG) data. [0120] Machine learning models can be implemented and deployed using a machine learning framework, e.g., a TensorFlow framework, a Microsoft Cognitive Toolkit framework, an Apache Singa framework, or an Apache MXNet framework. Regarding claims 7 and 17, Singhal teaches wherein the hosting, the second set of data, and the prediction are maintained private from the service provider(federated framework allow local data to and global data to be maintained separately and with privacy protections, ¶s30,35). [0030] To determine updated (e.g., trained) values of the model parameters including the set of global parameters and the multiple sets of local parameters in a manner that respects user privacy, the global training system, together with the local training systems, can train the machine learning model within the context of a federated learning framework while providing additional privacy protection during the training to prevent information that is sensitive, user-specific, or both from being easily recoverable or otherwise derivable outside of the client computing system on which it is stored. [0035] The systems and methods according to example aspects of the present specification can allow for additional privacy protection to be provided to such users by maintaining, at a local training system implemented on a user computing device, a set of local parameters of the machine learning model, such as sensitive, user-specific parameters as in the collaborative filtering setting, and updating the values of this set of local parameters entirely within the client computing device during training. Regarding claims 22 and 24 Lee teaches wherein the determining the user-defined machine learning model comprises one of:(i) outputting the user-defined machine learning model to the customer when the user- defined machine learning model satisfies the accepting criteria of the metric(successful return code, ¶s168), [0168] When the NWDAF including the MTLF completes ML model training based on the ML model provided by the service consumer, the NWDAF including the MTLF may obtain successful return code of the ML model and the ML model information as the information on ML model training. and(ii) outputting to the customer an indication that no viable model is found when no model satisfies the accepting criteria of the metric(return notification that unable to train model, ¶155,209). [0155] Delay event notification: This parameter indicates that an NWDAF fails to complete training of an interim local ML model within the maximum response time provided by a consumer, together with cause code (e.g., fails to train a local ML model, requires more time to train the local ML model, and the like). [0209] (Conditional) In operation 861, in response to the consumer request of operation 805, the FL server NWDAF may transmit an Nnwdaf_MLModelProvision_Notify message or an Nnwdaf_MLModelTraining_Notify service or Nnwdaf_MLModelTrainingInfo_Response to the consumer periodically (e.g., the number of predetermined training rounds or every 10 minutes) or when reaching a predetermined status (e.g., reaching the ML model accuracy threshold or expiration of training time) to dynamically update the global model metric. Claims 4, 6, 8, 14, 16 and 18 are rejected under 35 U.S.C. 103 as being unpatentable over Singhal/Choudhary/Lee as applied to claim 2 and 12 above, and further in view of Jaiswal US 2014/0304197. Regarding claims 4 and 14 Singhal a system for training a machine learning model and where the trained model is used for performing predictions. Singhal does not teach a trained machine learning model for cybersecurity analysis. Thus, Singhal/Choudhary/Lee do not teach wherein the monitoring the plurality of endpoints is for cybersecurity, and wherein the prediction relates to whether or not an endpoint of the plurality of endpoints will violate a cybersecurity or data protection policy. Jaiswal in the same field of endeavor of training and using machine learning models for data loss detection and prevention. Jaiswal teaches wherein the monitoring the plurality of endpoints is for cybersecurity, and wherein the prediction relates to whether or not an endpoint of the plurality of endpoints will violate a cybersecurity or data protection policy(determine violation of data loss protection policy, ¶31). [0031] Each endpoint device 102A-102C includes a DLP agent 106 that monitors data loss vectors to ensure that sensitive (e.g., confidential) information does not leave the endpoint device for illegitimate purposes. The DLP agent 106 may scan data as it moves through a data loss vector and/or when a request to send the data through a data loss vector is received. When DLP agent 106 detects data moving through a data loss vector or a request to move the data through the data loss vector, the DLP agent 106 implements a DLP policy 110 to determine whether the data is sensitive data (includes sensitive information). The DLP policy 110 may specify a type of content to be monitored (e.g., messages, displayed data, stored documents, etc.), how to identify sensitive data, and/or an action to be performed when sensitive data is detected. In one embodiment, the DLP policy 110 includes a MLD profile 112. The DLP agent 106 includes a machine learning (ML) module 108 that processes the data using the MLD profile 112. By processing the data using the MLD profile 112, the ML module 108 determines whether the data is sensitive data. It would have been obvious to a person of ordinary skill in the art at the time of the effective filing of the instant application to modify Singhal/Choudhary/Lee method’s of training detection models with a data loss detection and prevention system of Jaiswal. The reason for this modification would be to implement a known method(federation) for training a detection model to prevent sensitive data loss. Regarding claims 6 and 16, Singhal a system for training a machine learning model and where the trained model is used for performing predictions. Singhal/Choudhary/Lee do not teach a trained machine learning model for cybersecurity analysis. Thus, Singhal does not teach one or more of blocking a transaction, allowing the transaction, and notifying the customer of the transaction, based on the prediction. Jaiswal in the same field of endeavor of training and using machine learning models for data loss detection and prevention. Jaiswal teaches one or more of blocking a transaction, allowing the transaction, and notifying the customer of the transaction, based on the prediction(action takes such as preventing exit of sensitive date, ¶42). [0042] Policy violation responder 220 applies one or more DLP response rules 245 when a DLP policy violation is detected. Each DLP response rule 245 may be associated with one or more DLP policies 250. Each DLP response rule 245 includes one or more actions for policy violation responder 220 to take in response to violation of an associated DLP policy 250. Once a violation of a DLP policy 250 is discovered, policy violation responder 220 may determine which DLP response rules are associated with the violated DLP policy 250. One or more actions included in the response rule 245 can then be performed. Examples of performed actions include sending a notification to an administrator, preventing the data from exiting an endpoint device through a data loss vector, locking down the computer so that no data can be moved off of the endpoint device through any data loss vector, encrypting data as it is moved off the endpoint device, and so on. It would have been obvious to a person of ordinary skill in the art at the time of the effective filing of the instant application to modify Singhal/Choudhary/Lee’s method of training detection models with a data loss detection and prevention system of Jaiswal. The reason for this modification would be to implement a known method(federation) for training a detection model to prevent sensitive data loss Regarding claims 8 and 18, Singhal a system for training a machine learning model and where the trained model is used for performing predictions. Singhal/Choudhary/Lee do not teach wherein the monitoring the plurality of endpoints is for cybersecurity, and wherein the service provider is configured to perform monitoring for a plurality of customers. Jaiswal in the same field of endeavor of training and using machine learning models for data loss detection and prevention. Jaiswal teaches wherein the monitoring the plurality of endpoints is for cybersecurity, and wherein the service provider is configured to perform monitoring for a plurality of customers(DLP(data loss prevention) agent with model deployed on multiple endpoints of customer network ¶s 4,31). [0004] To more accurately protect sensitive unstructured data, some DLP systems are exploring the use of vector machine learning (VML) technology. However, VML is very complex to implement. Accordingly, current DLP systems that use VML require an expert in VML to design machine learning-based detection (MLD) profiles for customers. The DLP system that is shipped to the customer then has a predefined MLD profile that the customer is unable to modify. Such DLP systems do not provide any tools (e.g., user interface or workflow) to enable users to generate their own MLD profiles [0031] Each endpoint device 102A-102C includes a DLP agent 106 that monitors data loss vectors to ensure that sensitive (e.g., confidential) information does not leave the endpoint device for illegitimate purposes. The DLP agent 106 may scan data as it moves through a data loss vector and/or when a request to send the data through a data loss vector is received. When DLP agent 106 detects data moving through a data loss vector or a request to move the data through the data loss vector, the DLP agent 106 implements a DLP policy 110 to determine whether the data is sensitive data (includes sensitive information). The DLP policy 110 may specify a type of content to be monitored (e.g., messages, displayed data, stored documents, etc.), how to identify sensitive data, and/or an action to be performed when sensitive data is detected. In one embodiment, the DLP policy 110 includes a MLD profile 112. The DLP agent 106 includes a machine learning (ML) module 108 that processes the data using the MLD profile 112. By processing the data using the MLD profile 112, the ML module 108 determines whether the data is sensitive data. It would have been obvious to a person of ordinary skill in the art at the time of the effective filing of the instant application to modify Singhal/Choudhary/Lee’s method of training detection models with a data loss detection and prevention system of Jaiswal. The reason for this modification would be to implement a known method(federation) for training a detection model to prevent sensitive data loss Claims 9-10 and 19-20 are rejected under 35 U.S.C. 103 as being unpatentable over Singhal/Choudhary/Lee as applied to claims 1 and 11 above, and further in view of Singh US 2025/0008346. Regarding claims 9 and 19, Singhal teaches the first set of data input(global) and second set of data inputs(local) but does not teaches specific number of inputs/features and thus does not teach wherein the first set of data includes features or inputs X1, X2, ..., Xm for N transactions and with the index, where M is an integer > 1, wherein the second set of data includes features or inputs Z1, Ze, ..., Zp for N’ transactions and with the index, where P is an integer > 1 and M and P do not have to be the same value, N’ << N. Singh in the same field of endeavor teaches a system for machine learning training. Singh teaches wherein the first set of data includes features or inputs X1, X2, ..., Xm for N transactions and with the index, where M is an integer > 1,(first parameter with integer M greater than 3, ¶76,78) wherein the second set of data includes features or inputs Z1, Ze, ..., Zp for N’ transactions and with the index, where P is an integer > 1 and M and P do not have to be the same value, N’ << N,(second parameter with integer N greater than 3, ¶s76,78,268) [0076] FIG. 5 shows an exemplary illustration of cell data (e.g. cell data 404) stored in a memory (e.g. the memory 402). As illustrated herein, the cell data may include cell-specific parameters of a plurality of cells (501-1, 501-2, 501-3, . . . , 501-N). Each cell is associated with a network access node providing network access service for the cell. The cell data may include cell specific parameters for each cell. For example, the cell data, for a first cell 501-1, may include cell-specific parameters of the first cell. The cell-specific parameters, for the first cell 501-1, may include a first attribute 511-1 (e.g. a mobility parameter) represented by a first parameter X(1,1) (e.g. a parameter representing user movement patterns in the first cell 501-1), a second attribute 511-2 (e.g. geolocation) represented by a second parameter X(1,2) (e.g. a parameter representing the location of the first cell 501-1), a third attribute 511-3 (e.g. topography) represented by a third parameter X(1,3) (e.g. a parameter representing the terrain of the first cell 501-1), and such, up to an M-th attribute represented by an M-th parameter X(1,M). Similarly, the cell data includes cell-specific parameters of a second cell 501-2, a third cell 501-3, and such, up to an N-th cell. M and N are integers greater than 3. [0078] FIG. 6 shows an exemplary illustration of RAN-related data (e.g. RAN data 405) stored in a memory (e.g. the memory 402). As illustrated herein, the RAN data may include RAN-related data of a plurality of cells (601-1, 601-2, 601-3, . . . , 601-N). Each cell is associated with a network access node providing network access service for the cell. The RAN data may include RAN-related data for each cell. For example, the RAN data, for a first cell 601-1, may include RAN-related data of the first cell. The RAN-related data, for the first cell 601-1, may include a first attribute 611-1 (e.g. a network performance metric) represented by a first parameter Y(1,1) (e.g. a data throughput metric of the first cell 601-1), a second attribute 611-2 (e.g. another network performance metric) represented by a second parameter Y(1,2) (e.g. a latency metric of the first cell 601-1), a third attribute 611-3 (e.g. data traffic) represented by a third parameter Y(1,3) (e.g. data representing types and volumes of data traffic of the first cell 601-1), and such, up to a Q-th attribute represented by a Q-th parameter X(1,Q). Similarly, the RAN data includes RAN-related data of a second cell 601-2, a third cell 601-3, and such, up to a P-th cell. P and Q are integers greater than 3. [0268] Unless explicitly specified, the term “transmit” encompasses both direct (point-to-point) and indirect transmission (via one or more intermediary points). Similarly, the term “receive” encompasses both direct and indirect reception. Furthermore, the terms “transmit,” “receive,” “communicate,” and other similar terms encompass both physical transmission (e.g., the transmission of radio signals) and logical transmission (e.g., the transmission of digital data over a logical software-level connection). For example, a processor or controller may transmit or receive data over a software-level connection with another processor or controller in the form of radio signals, where the physical transmission and reception is handled by radio-layer components such as RF transceivers and antennas, and the logical transmission and reception over the software-level connection is performed by the processors or controllers. The term “communicate” encompasses one or both of transmitting and receiving, i.e., unidirectional or bidirectional communication in one or both of the incoming and outgoing directions. The term “calculate” encompasses both ‘direct’ calculations via a mathematical expression/formula/relationship and ‘indirect’ calculations via lookup or hash tables and other array indexing or searching operations. It would have been obvious to a person of ordinary skill in the art at the time of the effective filing of the instant application to modify Singhal/Choudhary/Lee with training of local model with global and local data with organized as input vectors of N(i.e. M as claimed) and M(i.e. P as claimed) number of values. The reason for this modification would be to provide a method of organizing the inputs that combines local and global data to train a machine learning model. Regarding claims 10 and 20, Singhal teaches the first set of data input(global) and second set of data inputs(local) but does not teaches specific number of inputs/features and thus does not teach wherein the determining finds the user-defined machine learning model with inputs Xi, X2, ..., Xm, Z1, Z2, ..., Zp to achieve outputs Y for the N’ transactions matching the accepting criteria. Singh in the same field of endeavor teaches a system for machine learning training. Singh teaches wherein the determining finds the user-defined machine learning model with inputs Xi, X2, ..., Xm, Z1, Z2, ..., Zp to achieve outputs Y for the N’ transactions matching the accepting criteria(calculate and output based on inputs ¶34,76,78). [0034] It is to be noted that the terms “AI model” and “machine learning model” are often used interchangeably in the literature, but there may also be some subtle differences between the two. An AI (Artificial Intelligence) model refers to a computational system that aims to perform tasks that would typically require human intelligence, such as problem-solving, pattern recognition, classification, and perception. AI models can be developed using various techniques, which may or may not include machine learning. AI models may include rule-based and rely on pre-defined logic, while they may also include the use of machine learning algorithms to adapt and improve over time. A machine learning model is considered a particular type of AI model that may learn from data. Machine learning models can be supervised (learning from labeled data), unsupervised (learning from unlabeled data), or reinforcement learning (learning from interactions with an environment). AI models that do not use machine learning techniques may typically include rule-based systems or systems that rely on pre-defined logic and knowledge representation. These models are designed and built by human experts who encode the rules and knowledge directly into the system. In this sense, they are not “trained” like machine learning models, which learn from data. However, rule-based AI models may also be updated and improved by refining the rules or adding new ones, which may require human intervention or may be provided via a particular training module that may change parameters associated with the defined rules. These updates can be considered a form of “training”. The term used in this disclosure, namely AI/ML, encompasses in particular machine learning models, but it may also include AIs that do not involve a machine learning model particularly, but which may be trained. The term “model” used herein may be understood as any kind of algorithm, which provides output data based on input data provided to the model (e.g., any kind of algorithm generating or calculating output data based on input data). [0076] FIG. 5 shows an exemplary illustration of cell data (e.g. cell data 404) stored in a memory (e.g. the memory 402). As illustrated herein, the cell data may include cell-specific parameters of a plurality of cells (501-1, 501-2, 501-3, . . . , 501-N). Each cell is associated with a network access node providing network access service for the cell. The cell data may include cell specific parameters for each cell. For example, the cell data, for a first cell 501-1, may include cell-specific parameters of the first cell. The cell-specific parameters, for the first cell 501-1, may include a first attribute 511-1 (e.g. a mobility parameter) represented by a first parameter X(1,1) (e.g. a parameter representing user movement patterns in the first cell 501-1), a second attribute 511-2 (e.g. geolocation) represented by a second parameter X(1,2) (e.g. a parameter representing the location of the first cell 501-1), a third attribute 511-3 (e.g. topography) represented by a third parameter X(1,3) (e.g. a parameter representing the terrain of the first cell 501-1), and such, up to an M-th attribute represented by an M-th parameter X(1,M). Similarly, the cell data includes cell-specific parameters of a second cell 501-2, a third cell 501-3, and such, up to an N-th cell. M and N are integers greater than 3. [0078] FIG. 6 shows an exemplary illustration of RAN-related data (e.g. RAN data 405) stored in a memory (e.g. the memory 402). As illustrated herein, the RAN data may include RAN-related data of a plurality of cells (601-1, 601-2, 601-3, . . . , 601-N). Each cell is associated with a network access node providing network access service for the cell. The RAN data may include RAN-related data for each cell. For example, the RAN data, for a first cell 601-1, may include RAN-related data of the first cell. The RAN-related data, for the first cell 601-1, may include a first attribute 611-1 (e.g. a network performance metric) represented by a first parameter Y(1,1) (e.g. a data throughput metric of the first cell 601-1), a second attribute 611-2 (e.g. another network performance metric) represented by a second parameter Y(1,2) (e.g. a latency metric of the first cell 601-1), a third attribute 611-3 (e.g. data traffic) represented by a third parameter Y(1,3) (e.g. data representing types and volumes of data traffic of the first cell 601-1), and such, up to a Q-th attribute represented by a Q-th parameter X(1,Q). Similarly, the RAN data includes RAN-related data of a second cell 601-2, a third cell 601-3, and such, up to a P-th cell. P and Q are integers greater than 3. It would have been obvious to a person of ordinary skill in the art at the time of the effective filing of the instant application to modify Singhal/Choudhary/Lee with training of local model with global and local data with organized as input vectors of N(i.e. M as claimed) and M(i.e. P as claimed) number of values. The reason for this modification would be to provide a method of organizing the inputs that combines local and global data to train a machine learning model to output predictions Claims 21 and 23 are rejected under 35 U.S.C. 103 as being unpatentable over Singhal/Choudhary/Lee as applied to claims 1 and 11 above, and further in view of Ghosh US 11,620,541. Regarding claims 21 and 23, Singhal/Choudhary/Lee do not teach wherein the first set of data comprises feature embeddings computed by the service provider from log data obtained based on the monitoring of the plurality of endpoints, and wherein the feature embeddings are exposed to the customer via a feature store for use in determining the user- defined machine learning model. Ghosh in the same field of endeavor as the invention teaches a system for custom analytics include model training. Ghosh teaches wherein the first set of data comprises feature embeddings computed by the service provider from log data obtained based on the monitoring of the plurality of endpoints, and wherein the feature embeddings are exposed to the customer via a feature store for use in determining the user- defined machine learning model. [(53) Examples of components which may generate machine data from which events can be derived include, but are not limited to, web servers, application servers, databases, firewalls, routers, operating systems, and software applications that execute on computer systems, mobile devices, sensors, Internet of Things (IoT) devices, etc. The machine data generated by such data sources can include, for example and without limitation, server log files, activity log files, configuration files, messages, network packet data, performance measurements, sensor measurements, etc. Col 6 Lines 20-27] [(67) In the illustrated embodiment, one or more of host applications 114 may generate various types of performance data during operation, including event logs, network data, sensor data, and other types of machine data. For example, a host application 114 comprising a web server may generate one or more web server logs in which details of interactions between the web server and any number of client devices 102 is recorded. As another example, a host device 106 comprising a router may generate one or more router logs that record information related to network traffic managed by the router. As yet another example, a host application 114 comprising a database server may generate one or more logs that record information related to requests sent from other host applications 114 (e.g., web servers or application servers) for data managed by the database server. Col 8 Line 57- Col 9 Line4] It would have been obvious to a person of ordinary skill in the art before the effective filing of the invention to modify Singhal/Choudhary/Lee with generating training data from various network logs as taught by Ghosh. The reason for this modification would be to provide training datasets from network event/metric logs that can generate model to detect network events/anomalies/security issues. Applicant Remarks Applicant’s arguments with respect to claims 1-2,4,6-12,14 and 16-24 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to Tom Y. Chang whose telephone number is 571-270-5938. The examiner can normally be reached on Monday-Friday from 9am to 5pm. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Emmanuel Moise, can be reached on (571)272-3865. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from Patent Center. Status information for published applications may be obtained from Patent Center. Status information for unpublished applications is available through Patent Center for authorized users only. Should you have questions about access to Patent Center, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) Form at https://www.uspto.gov/patents/uspto-automated- interview-request-air-form. /TOM Y CHANG/ Primary Examiner, Art Unit 2455
Read full office action

Prosecution Timeline

Jan 19, 2024
Application Filed
Feb 19, 2026
Non-Final Rejection mailed — §103
May 18, 2026
Response Filed
Aug 26, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12712918
SYSTEMS AND METHODS FOR EVALUATING AN ELECTRONIC COMMUNICATION
2y 3m to grant Granted Aug 18, 2026
Patent 12699597
SYSTEMS AND METHODS FOR IMPLEMENTING TRANS-CLOUD APPLICATION TEMPLATES
4y 10m to grant Granted Aug 04, 2026
Patent 12627665
ADMITTING AN ENTITY COMPUTING DEVICE TO A NETWORK BASED ON A SIGNAL STRENGTH AND NETWORK CONDITIONS
2y 9m to grant Granted May 12, 2026
Patent 12547828
TRAFFIC-BASED GPU LOAD ROUTING WITHIN LLM CLUSTERS
2y 0m to grant Granted Feb 10, 2026
Patent 12542838
METHODS, DEVICES, AND SYSTEMS FOR DETERMINING A SUBSET FOR AUTONOMOUS SHARING OF DIGITAL MEDIA
1y 11m to grant Granted Feb 03, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
53%
Grant Probability
73%
With Interview (+20.0%)
4y 1m (~1y 5m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 455 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month