DETAILED ACTION
This action is in response to the claims filed 02/13/2024 for Application number 18/439,941. Claims 1-20 are currently pending.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Priority
Receipt is acknowledged of certified copies of papers required by 37 CFR 1.55.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 02/13/2024 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims 1, 4, 11, 14, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Sternby et al. ("US 20230145544 A1", hereinafter "Sternby") in view of Aramoon et al. ("Don't Forget To Sign The Gradients!", hereinafter "Aramoon").
Regarding claim 1, Sternby teaches A method comprising:
embedding a parameter component watermark into a first parameter of a neural network model to generate a second parameter of the neural network model (“The key sample may be used both for embedding the watermark (i.e. training the network with the key sample)” [¶0055; key sample corresponds to an embedded parameter watermark]);
embedding an input component watermark into a first input to the neural network model to generate a second input to the neural network model (“and for extracting the watermark (i.e. inputting the key sample to the neural network for receiving a specific output associated with the watermark).” [¶0055]);
and
training the neural network model based on the second parameter, the second input, and the second model gradient to generate a trained neural network model. (“In the training process the trainable parameters (e.g. the weights or the nodes associated with the weights) of the neural network are split into two sets and control is further put on which trainable parameters that will be updated during a round of the training process… For example, by using watermarking key samples with an unexpected class at training, it can be determined if a model that is suspected to be stolen has been trained with these key samples by inspecting the output/classification of the key samples for the examined model.” [¶0064])
However Sternby fails to explicitly teach embedding a gradient component watermark into a first model gradient of the neural network model to generate a second model gradient of the neural network model;
Aramoon teaches embedding a gradient component watermark into a first model gradient of the neural network model to generate a second model gradient of the neural network model; (“One of such techniques that recently has shown great promise is digital watermarking. However, current watermarking approaches can embed very limited amount of information and are vulnerable against watermark removal attacks. In this paper, we present GradSigns, a novel watermarking framework for deep neural networks (DNNs). GradSigns embeds the owner’s signature into the gradient of the cross-entropy cost function with respect to inputs to the model.” [Abstract])
It would have been obvious to one of ordinary skill in the art before the effective filing date to modify Sternby’s watermarking system by embedding a watermark into a gradient of a neural network as taught by Aramoon. One would have been motivated to make this modification to ensure reliable commercialization of deep learning models by developing techniques to protect model vendors. [Abstract, Aramoon]
Regarding claim 4, Sternby/Aramoon teaches The method according to claim 1, further comprising: Sternby teaches acquiring output data of a to-be-verified neural network model for input data. (“The controller is also configured to cause evaluation of an output from the neural network by causing performance of at least one of determination of that a confidence value associated with the output of the at least one key sample inputted to the neural network is above a confidence threshold” [¶0028])
Regarding claims 11, 14 and 20, they are substantially similar to claims 1 and 4 respectively, and are rejected in the same manner, the same art, and reasoning applying.
Claims 2, 3, 12, and 13 are rejected under 35 U.S.C. 103 as being unpatentable over Sternby in view of Aramoon and further in view of Pan et al. ("Device-Bind Key-Storageless Hardware AI Model IP Protection: Joint PUF and Permute-Diffusion Encryption-Enabled Approach", hereinafter "Pan").
Regarding claim 2, Sternby/Aramoon teaches The method according to claim 1, further comprising:
However fails to explicitly teach determining a random seed based on a physical unclonable function response in a device where the neural network model is located, wherein the random seed is used for generating the parameter component watermark, the input component watermark, and the gradient component watermark.
Pan teaches determining a random seed based on a physical unclonable function response (“Since the chaos random sequence generated in (8) has related to initial states λ and s0 (“random seed”) merely, the PUF-based secret key kp is applied to determine these initial states as follows:…” [pg. 7, left col, §B, ¶3]) in a device where the neural network model is located (“To preserve user privacy, well-trained intelligent models are usually deployed on local devices rather than the remote cloud server” [pg. 3, top right col]), wherein the random seed is used for generating the parameter component watermark, the input component watermark, and the gradient component watermark. (“After that, s is sorted in ascending/descending order, and the sorted random sequence ˜s is obtained. Next, the converted weight w(j) is permuted based on position exchange between s and ˜s.” [pg. 7, left col, bottom para; note: the random seed/sequence of Pan are used in the modification of neural network weights/parameters therefore when combined with Sternby/Aramoon would teach the recited limitation])
It would have been obvious to one of ordinary skill in the art before the effective filing date to modify Sternby’s/Aramoon’s teachings in order to implement the PUF response as taught by Pan. One would have been motivated to make this modification to solve the security issues of MLaaS during model transmission and deployment. [Abstract, Introduction (right col), Pan]
Regarding claim 3, Sternby/Aramoon/Pan teaches The method according to claim 2, further comprising:
generating the parameter component watermark based on the first parameter of the neural network model and the random seed; (Sternby, ¶0055)
generating the input component watermark based on the first input to the neural network model and the random seed; (Sternby, ¶0055) and
generating the gradient component watermark based on the first model gradient of the neural network model and the random seed. (Aramoon, Abstract)
Note: As cited in claim 2, Pan teaches the generation/modification of NN parameters with a random seed/sequence thus when combined with the teachings of Sternby/Aramoon would teach the claim as recited
Same motivation to combine the teachings of Sternby/Aramoon/Pan as claim 2.
Regarding claims 12 and 13, they are substantially similar to claims 2 and 3 respectively, and are rejected in the same manner, the same art, and reasoning applying.
Allowable Subject Matter
Claims 5-10 and 15-19 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim any intervening claims. None of the prior art, either alone or in combination, fairly discloses limitations of claims 5 and 15 in particular:
wherein the to-be-verified neural network model comprises a to-be-verified network parameter, and the method further comprises: inputting the output data, the to-be-verified network parameter, and an attack indicator to an adaptive controller to determine a verification mode based on an output from the adaptive controller, wherein the verification mode is used for verifying the to-be-verified neural network model.
No prior art was uncovered which fairly discloses using an adaptive controller to determine a verification mode based on an output from the adaptive controller.
The closest prior art of record is Sternby et al. (“US 20230145544 A1”) which discloses a neural network watermarking method to prove ownership of the model, however the reference does not explicitly teach using an adaptive controller to determine a verification mode based on an output from the adaptive controller.
Aramoon et al. (“Don’t Forget To Sign The Gradients”) and Pan et al. (“Device-Bind Key-Storageless Hardware AI Model IP Protection: Joint PUF and Permute-Diffusion Encryption-Enabled Approach”) both discloses various aspects of digital watermarking and PUF response however the references do not explicitly disclose using an adaptive controller to determine a verification mode based on an output from the adaptive controller.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Mahbub et al. ("US 20250226978 A1") discloses jointly embedding watermarked weights and outputs.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to MICHAEL H HOANG whose telephone number is (571)272-8491. The examiner can normally be reached Mon-Fri 8:30AM-4:30PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Kakali Chaki can be reached at (571) 272-3719. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/MICHAEL H HOANG/ PRIMARY EXAMINER, Art Unit 2122