Prosecution Insights
Last updated: August 08, 2026
Application No. 18/447,771

MODEL TRAINING USING DIFFERENTIAL PRIVACY AND KNOWLEDGE TRANSFER

Non-Final OA §103
Filed
Aug 10, 2023
Examiner
SHELTON, SETH CAPRIANO-UMA
Art Unit
2141
Tech Center
2100 — Computer Architecture & Software
Assignee
SAP SE
OA Round
1 (Non-Final)
Grant Probability
Favorable
1-2
OA Rounds

Examiner Intelligence

Grants only 0% of cases
0%
Career Allowance Rate
0 granted / 0 resolved
-55.0% vs TC avg
Minimal +0% lift
Without
With
+0.0%
Interview Lift
resolved cases with interview
Typical timeline
Avg Prosecution
6 currently pending
Career history
5
Total Applications
across all art units

Statute-Specific Performance

§101
11.1%
-28.9% vs TC avg
§103
50.0%
+10.0% vs TC avg
§102
16.7%
-23.3% vs TC avg
§112
22.2%
-17.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 0 resolved cases

Office Action

§103
CTNF 18/447,771 CTNF 101995 Notice of Pre-AIA or AIA Status 07-03-aia AIA 15-10-aia The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA. Claim Rejections - 35 USC § 103 07-20-aia AIA The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 07-21-aia AIA Claim (s) 1, 2-4, 6, 8-10, 13-16, and 18 is/are rejected under 35 U.S.C. 103 as being unpatentable over Bhowmick et al, U.S. Patent No. 11989634, published November 30, 2018 in view of Hegde et al, U.S. PG Pub 2020/0356858, published May 10, 2019 . With regard to independent claim 1, Bhowmick teaches, “A system comprising: a memory storing processor-executable program code;” (Col.1, lines: 55-57; EN: This denotes both a memory to store instructions and a processor to execute instructions ). “and at least one processing unit to execute the processor-executable program code to cause the system to:” (Col.1, lines: 55-57; EN: This denotes a processor to execute instructions ). “acquire training data comprising a plurality of target variable categories” (Col.5, lines: 49-65; EN: This denotes that the training data used comes from local data stored on local client devices and can incorporate different types of data depending on the model and what data type that model needs ). “train a first classification model based on the training data;” (Col.5, lines:49-54, Fig. 1; EN: This denotes training a local model based on local data stored on a client device ). “train a second classification model using differential privacy” (Col. 5 lines 66-67, Col. 6 lines: 1-14; EN: This denotes updating models utilizing differential privacy ). “and a first loss function including a weight loss term” (Col. 8, lines: 6-13; EN: This denotes the loss function and weights associated with each layer in a model ). “comparing the determined node weights of the trained first classification model to node weights of the second classification model” (Col. 7, lines: 30-53; EN: This denotes determining the difference in parameters between multiple models ). However, Bhowmick fails to explicitly disclose “determine node weights of the trained first classification model;”. Hedge teaches, “determine node weights of the trained first classification model;” (Paragraph 0085, Fig. 1; EN: This denotes the weight values used for node weights ). Bhowmick and Hedge are considered to be analogous art to the claimed invention due to the fact that they both disclose model classification, training, and using differential privacy on various models. It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to modify the multiple classification models using differential privacy of Bhowmick with the trained classification models of Hedge. One would be motivated to do so to improve the performance of models utilizing differential privacy and enhance the privacy of data used by the trained models. With regard to dependent claim 2 , Bhowmick teaches the limitation “and the weight loss term determines a distance between the determined node weights of the trained first classification model and the node weights of the second classification model” (Col. 5, line: 19-23; EN: This denotes updating model weights based on aggregated model updates and model updates sent from client devices ). However, Bhowmick fails to explicitly disclose “A system according to Claim 1, wherein the first classification model is trained based on a second loss function including a predictive loss term” and “the first loss function comprises the predictive loss term” (Paragraph 0027, Fig. 1; EN: This denotes the use of a predictive loss term ). Hedge teaches the limitation “A system according to Claim 1, wherein the first classification model is trained based on a second loss function including a predictive loss term” (Paragraph 0095, Fig. 1; EN: This denotes training a model on different graphs to generate prediction outputs ). “the first loss function comprises the predictive loss term” (Paragraph 0027, Fig. 1; EN: This denotes the use of a predictive loss term ). With regard to dependent claim 3 , Bhowmick teaches the limitation “A system according to Claim 2, wherein the second classification model is trained based on the training data” (Col.5, line: 51-65; EN: This denotes training a model using local data stored on a client device ). With regard to dependent claim 4 , Bhowmick teaches the limitation “A system according to Claim 2, wherein training of the second classification model comprises: for each of a first plurality of a plurality of instances of the training data” (Col.5, line: 51-65; EN: This denotes training a model on local data stored on a client device. The type of data used depends on the model, such as an image processor model, natural language model, or a voice classification model ). “determine a gradient of the first loss function with respect to the node weights of the second classification model;” (Col. 10, line 31-39; EN: This denotes the use of a gradient when privatizing model updates ). “determine a composite gradient of the first loss function with respect to the node weights of the second classification model based on the gradient of the first loss function determined for each of the first plurality of the plurality of instances;” (Col. 8, line 13-40; EN: This denotes using the update rule which includes gradient descent ). “and update the node weights of the second classification model based on the composite gradient” (Col. 11, lines 13-22; EN: This denotes updating the weight vectors of an updated model ). With regard to dependent claim 6 , This claim is similar in scope to claim 4 and is rejected under a similar rationale. With regard to independent claim 8 , This claim is similar in scope to claim 1 and is rejected under a similar rationale. With regard to dependent claim 9 , This claim is similar in scope to claim 2 and is rejected under a similar rationale. With regard to dependent claim 10 , This claim is similar in scope to claim 3 and is rejected under a similar rationale. With regard to independent claim 13 , This claim is similar in scope to claim 1 and is rejected under a similar rationale. With regard to dependent claim 14 , This claim is similar in scope to claim 2 and is rejected under a similar rationale. With regard to dependent claim 15 , This claim is similar in scope to claim 3 and is rejected under a similar rationale. With regard to dependent claim 16 , This claim is similar in scope to claim 4 and is rejected under a similar rationale. With regard to dependent claim 18 , This claim is similar in scope to claim 4 and is rejected under a similar rationale . 07-22-aia AIA Claim (s) 5, 7, 11, 12, 17, and 19 is/are rejected under 35 U.S.C. 103 as being unpatentable over Bhowmick et al, U.S. Patent No. 11989634, published November 30, 2018 and Hegde et al, U.S. PG Pub 2020/0356858, published May 10, 2019 as applied to claim s 1, 2-4, 6, 8-10, 13-16, and 18 above, and further in view of Qian et al, U.S. Patent No. 12373729, published May 28, 2020 and Alban et al, U.S. PG Pub 2024/0078433, published May 5, 2017 . With regard to dependent claim 5 , Bhowmick and Hedge fail to explicitly disclose “A system according to Claim 4, wherein determination of the gradient of the first loss function for each of the first plurality of instances comprises limiting of a magnitude of each gradient based on a threshold” and “and wherein determination of the composite gradient comprises determination of an average gradient of the gradients and addition of noise to the average gradient.” Alben teaches the limitation “A system according to Claim 4, wherein determination of the gradient of the first loss function for each of the first plurality of instances comprises limiting of a magnitude of each gradient based on a threshold” (Paragraph 0122; EN: This denotes the use of a gradient clipping threshold in regards to adjusting weight gradients ). Bhowmick, Hedge, and Alben considered to be analogous art to the claimed invention due to the fact that they all disclose training models with regards to loss functions and weight updates. It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to modify the use of differential privacy on multiple classification models of Bhowmick and the trained classification models of Hedge with the gradient magnitude limiting function of Alben. One would be motivated to do so to improve the performance of models utilizing differential privacy and enhance the privacy of data used by the trained models. However, Bhowmick, Hedge, and Alben fail to explicitly disclose “and wherein determination of the composite gradient comprises determination of an average gradient of the gradients and addition of noise to the average gradient.” Qian teaches the limitation “and wherein determination of the composite gradient comprises determination of an average gradient of the gradients and addition of noise to the average gradient” (Col. 4 lines 48-67, Col. 5 lines 1-28; EN: This denotes averaging gradients from a client system and adding noise through the use of a gradient/data-perturbation model ). Bhowmick, Hedge, Alben, and Qian are considered to be analogous art to the claimed invention due to the fact that they all disclose training models with regards to loss functions and weight updates. It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to modify the use of differential privacy on multiple classification models of Bhowmick, the trained classification models of Hedge, the gradient magnitude limiting function of Alben with the improvement to the efficiency of deep neural network learning of Qian. One would be motivated to do so to improve the performance of models utilizing differential privacy and enhance the privacy of data used by the trained models. With regard to dependent claim 7 , This claim is similar in scope to claim 5 and is rejected under a similar rationale. With regard to dependent claim 11 , This claim is similar in scope to claim 5 and is rejected under a similar rationale. With regard to dependent claim 12 , This claim is similar in scope to claim 5 and is rejected under a similar rationale. With regard to dependent claim 17 , This claim is similar in scope to claim 5 and is rejected under a similar rationale. With regard to dependent claim 19 , This claim is similar in scope to claim 5 and is rejected under a similar rationale. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to SETH CAPRIANO-UMARI SHELTON whose telephone number is (571)270-0213. The examiner can normally be reached 8am-5pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Matthew Ell can be reached at (571) 270-3264. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /SETH CAPRIANO-UMARI SHELTON/ Examiner, Art Unit 2141 /MATTHEW ELL/ Supervisory Patent Examiner, Art Unit 2141 Application/Control Number: 18/447,771 Page 2 Art Unit: 2141 Application/Control Number: 18/447,771 Page 3 Art Unit: 2141 Application/Control Number: 18/447,771 Page 4 Art Unit: 2141 Application/Control Number: 18/447,771 Page 5 Art Unit: 2141 Application/Control Number: 18/447,771 Page 6 Art Unit: 2141
Read full office action

Prosecution Timeline

Aug 10, 2023
Application Filed
May 15, 2026
Non-Final Rejection mailed — §103
Jul 27, 2026
Applicant Interview (Telephonic)
Jul 27, 2026
Examiner Interview Summary

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
Grant Probability
Low
PTA Risk
Based on 0 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month