DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 02/05/2024 was filed. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Priority
Receipt is acknowledged of certified copies of papers required by 37 CFR 1.55.
Specification
The title of the invention is not descriptive. A new title is required that is clearly indicative of the invention to which the claims are directed.
Drawings
The drawings are objected to under 37 CFR 1.83(a) because they fail to show sensor circuitry 32 as described in the specification. Any structural detail that is essential for a proper understanding of the disclosed invention should be shown in the drawing. MPEP § 608.02(d). Corrected drawing sheets in compliance with 37 CFR 1.121(d) are required in reply to the Office action to avoid abandonment of the application. Any amended replacement drawing sheet should include all of the figures appearing on the immediate prior version of the sheet, even if only one figure is being amended. The figure or figure number of an amended drawing should not be labeled as “amended.” If a drawing figure is to be canceled, the appropriate figure must be removed from the replacement sheet, and where necessary, the remaining figures must be renumbered and appropriate changes made to the brief description of the several views of the drawings for consistency. Additional replacement sheets may be necessary to show the renumbering of the remaining figures. Each drawing sheet submitted after the filing date of an application must be labeled in the top margin as either “Replacement Sheet” or “New Sheet” pursuant to 37 CFR 1.121(d). If the changes are not accepted by the examiner, the applicant will be notified and informed of any required corrective action in the next Office action. The objection to the drawings will not be held in abeyance.
Claim Objections
Claim 11 objected to because of the following informalities:
grammatical error on “…as an input a different trained…” instead of grammatical error on “…as an input to a different trained…”
Appropriate correction is required.
Claim Rejections - 35 USC § 103
The following is a quotation of pre-AIA 35 U.S.C. 103(a) which forms the basis for all obviousness rejections set forth in this Office action:
(a) A patent may not be obtained though the invention is not identically disclosed or described as set forth in section 102, if the differences between the subject matter sought to be patented and the prior art are such that the subject matter as a whole would have been obvious at the time the invention was made to a person having ordinary skill in the art to which said subject matter pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under pre-AIA 35 U.S.C. 103(a) are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claim(s) 1, 6, 9, 10, 11, 16, 19 is/are rejected under 35 U.S.C. 103 as being unpatentable over Doshi et al. (US 2019/0044918, hereinafter "Doshi"), in view of Abadi et al. (US 2019/0171929 A1, hereinafter “Abadi”).
Regarding Claim 1
Doshi discloses: An apparatus comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to; ([Doshi, Fig. 8, 0067, 0069-0070] discloses an apparatus comprising of processors and memory storing instructions.)
provide a first secret and data ([Doshi, Fig. 4, 0042; 0036] discloses a transformation (i.e a first secret), which may includes rotations, scaling, noise, and additional false values, and sensor data (i.e data) to produce an output by an encoder 440 (i.e network))
send the output from the ([Doshi, Fig. 4, 0042] discloses the transformed data (i.e output) sent to a server 405.)
receive in reply from the server, an encoded label ([Doshi, Fig. 4, 0044] discloses client 410 (i.e apparatus) receive in reply from server 405, a transformed output data (i.e encoded label), wherein the transformed output data is further described in [0023] as encoded label: “The AI model is trained on camouflaged data by applying a particular transformation to camouflage the data at the client device before being transmitted. The AI model may provide camouflaged output data, with a reverse transformation applied to the output data to get back to a raw original result (such as, a classification or an inference) data useful to the client device.”)
and use a second secret to decode the encoded label to obtain a label for the data. ([Doshi, 0023, 0041, 0044] discloses using a transformation (i.e second secret) to decode the transformed output (i.e encoded label) to obtain raw output (i.e label) for the data.)
Doshi does not explicitly disclose: provide a first secret and data as inputs to a trained neural network to produce an output by inference; send the output from the trained neural network
Doshi and Abadi are both analogous art to the present invention because both are from the same field of endeavor directed to machine learning.
However, Abadi discloses: provide a first secret and data as inputs to a trained neural network to produce an output by inference ([Abadi, Fig. 4, 0051, 0078] discloses a neural network input key 414 (i.e first secret) and primary neural network input 410 (i.e data) as inputs to an encoder neural network 402 (i.e trained neural network) to produce encoded representation of primary neural network input 416 (i.e output by inference).)
send the output from the trained neural network ([Abadi, Fig. 4, 0051, 0078] discloses an encoded representation of primary neural network input 416 (i.e output) from to an encoder neural network 402 (i.e trained neural network) to a trusted decoder neural network 404).
It would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have combined the apparatus to transmit data to a server using secrets disclosed by Doshi with using a secret and data as inputs to the trained neural network to produce output by inference by Abadi. One of ordinary skill in the art would have been motivated to make this modification in order to encode the neural network input and prevent it from being reconstructed by another neural network. ([Abadi, 0004])
Regarding Claim 6:
Doshi in view of Abadi discloses: decode the encoded label using a decoding algorithm controlled by the server or decode the encoded label using a modulo function. ([Doshi, Fig. 4, 0044; 0023, 0038] discloses decoding the output data (i.e encoded label) using an application (i.e using the decoding algorithm), as seen in Fig. 4 containing the client decoder 445, being controlled by the service provider (i.e server): “For example, an application for a mobile device is provided by a service provider... The transformations are embedded within the application…Similarly, the output data received by the application on the mobile device from the model at the service provider may be transformed into usable data for the application and mobile device by the embedded transformation.")
Regarding Claim 9:
Doshi in view of Abadi discloses: wherein the data is input at a first layer of the trained neural network. ([Abadi, 0040, 0051] discloses the primary neural network input (i.e data) as input at the first full-connected layer (i.e first layer) of the encoder neural network (i.e trained neural network): “…includes a first fully-connected layer… The fully-connected layer can include m+n nodes, where each node provides an activation function that can produce an output to the first convolutional layer that is a linear combination of all the input data items from the primary neural network input 108 and the neural network input key 110.”)
Regarding Claim 10:
Doshi in view of Abadi discloses: wherein the first secret is at least one of the following: input at a layer after the first layer of the trained neural network or input at a layer after the second layer of the trained neural network or input at a layer before the last layer of the trained neural network. ([Abadi, 0040, 0051] discloses the neural network input key (i.e first secret) as input at the first full-connected layer before the last layer of the encoder neural network (i.e trained neural network))
Regarding Claim 11:
Doshi: A system configured for split inference, ([Doshi, Fig. 4, 0042] discloses a system of server 405 and client 410 configured for split inference)
comprising a server comprising at least one processor and at least one memory storing instructions; ([Doshi, Fig. 4, 0042; Fig. 8, 0067, 0069-0070] discloses a server 405 comprising of processors and memory storing instructions.)
an apparatus, comprising at least one processor and at least one memory storing instructions; wherein the instructions when executed by the at least one processor, further cause the server to; ([Doshi, Fig. 4, 0042; Fig. 8, 0067, 0069-0070] discloses a client device (i.e apparatus) comprising of processors and memory storing instructions.)
receive, from the apparatus, outputs from ([Doshi, Fig. 4, 0042-0043] discloses server 405 receiving the transformed data (i.e output) by an encoder (i.e network) from client 410 (i.e apparatus))
provide the received output as an input a different trained neural network to produce an encoded label; ([Doshi, Fig. 4, 0042-0043] discloses server 405 providing the the transformed data (i.e output) from an encoder as input to a camouflaged model 415 (i.e trained neural network) to produce a transformed output data (i.e encoded label), wherein the transformed output data is further described in [0023] as encoded label: “The AI model is trained on camouflaged data by applying a particular transformation to camouflage the data at the client device before being transmitted. The AI model may provide camouflaged output data, with a reverse transformation applied to the output data to get back to a raw original result (such as, a classification or an inference) data useful to the client device.”)
and send the encoded label to the apparatus. ([Doshi, Fig. 4, 0042-0043] discloses server 405 sending the transformed data (i.e encoded label) to the client 410 (i.e apparatus))
Doshi does not explicitly disclose: receive
Doshi and Abadi are both analogous art to the present invention because both are from the same field of endeavor directed to machine learning.
However, Abadi discloses: receive([Abadi, Fig. 4, 0051, 0078] discloses a trusted decoder neural network 404 receiving an encoded representation of primary neural network input 416 (i.e output) from to an encoder neural network 402 (i.e trained neural network)).
It would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have combined the system to transmit data between a server and apparatus disclosed by Doshi with receiving outputs from a trained neural network by Abadi. One of ordinary skill in the art would have been motivated to make this modification in order to use a trained neural network as an encoder to provide secure and private communications in the system of server and apparatus. ([Abadi, 0028])
Regarding Claim 16
Claim 16 is a method claim having similar limitations of apparatus of Claim 1, therefore it is rejected under the same rational as of Claim 1. Additionally, Claim 16 includes additional limitations below that rejected under Doshi.
Doshi teaches: A method of providing privacy without encryption in relation to split inference comprising: ([Doshi, Fig. 4, 0042, 0021-0025] discloses a method to providing privacy without encryption in relation to split inference.)
Regarding Claim 19:
(Claim 19 recites analogous limitations to Claim 6 and therefore is rejected on the same ground as Claim 6.)
Claim(s) 2, 3, 4, 17 is/are rejected under 35 U.S.C. 103 as being unpatentable over Doshi et al. (US 2019/0044918, hereinafter "Doshi"), in view of Abadi et al. (US 2019/0171929 A1, hereinafter “Abadi”) and Schiatti et al. (US 2021/0067339 A1, hereinafter “Schiatti”).
Regarding Claim 2:
Doshi in view of Abadi does not explicitly disclose: wherein the first secret and the second secret are same secret.
However, Schiatti discloses: wherein the first secret and the second secret are same secret. ([Schiatti, Fig. 12, 0106-0111] discloses the first secret and second secret as noise value Na used to encode model Ma and decode model MaNbMbNcMcNdMdNeMe: “Participant node A may add together a noise value Na with a trained model Ma… Participant node A may remove noise Na (1220). After the participant nodes A-E remove the noise Na, Nb, Nc, Nd, and Ne, may generate the aggregated model MaMbMcMdMe.”)
Doshi, Abadi, and Schiatti are analogous art to the present invention because they are from the same field of endeavor directed to machine learning.
It would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have combined the first secret and second secret disclosed by Doshi in view of Abadi with having the secrets the same by Schiatti. One of ordinary skill in the art would have been motivated to make this modification in order to mask private data when sending to other devices and to unmask output received from other devices using the same secret. ([Schiatti, 0093, 0106, 0110; Fig. 12, 0106-0111])
Regarding Claim 3:
Doshi in view of Abadi and Schiatti discloses: wherein the instructions when executed by the at least one processor, further cause the apparatus to randomly select the secret from a population of sample secrets. ([Doshi, 0050] discloses randomly select fake data (i.e secret) from a distribution (i.e population of sample secrets))
Regarding Claim 4:
Doshi in view of Abadi and Schiatti discloses: wherein the population of sample secrets is controlled by the server. ([Doshi, 0038, 0050] discloses the transformations, such as the fake data and its distribution, (i.e population of sample secrets) being controlled by the service provider (i.e server): “For example, an application for a mobile device is provided by a service provider... The transformations are embedded within the application.")
Regarding Claim 17:
(Claim 17 recites analogous limitations to Claim 2 and therefore is rejected on the same ground as Claim 2.)
Claim(s) 5, 18 is/are rejected under 35 U.S.C. 103 as being unpatentable over Doshi et al. (US 2019/0044918, hereinafter "Doshi"), in view of Abadi et al. (US 2019/0171929 A1, hereinafter “Abadi”) and Gao et al. (“Combinatorial Losses through Generalized Gradients of Integer Linear Programs”, hereinafter “Gao”).
Regarding Claim 5:
Doshi in view of Abadi discloses: wherein the encoded label is a permuted ([Doshi, 0023, 0041, 0043] discloses a transformed output from the server (i.e encoded label) as a permuted label by including permutations to the inputs and outputs for the transformation described in [0027-0028]: “The training may change the order of the inputs, such that each input is provided as a vector [c, y, a, b, x], and similarly the same may be applied to the output as vector [v, z, u]...”)
wherein the second secret recovers the unpermuted ([Doshi, 0023, 0041, 0043, 0027-0028] discloses using a transformation (i.e second secret) to recover raw output (i.e unpermuted label) by removing the transformation containing the permutation.)
Doshi in view of Abadi does not explicitly disclose: wherein the encoded label is a permuted one hot label, wherein the second secret recovers the unpermuted one hot label.
However, Gao discloses in the same field of endeavor: wherein the ([Gao, Section 3.1, Para 2] discloses a tuple of permuted labels Y (i.e encoded label) as a one-hot vectors, for some permutation σ (i.e permuted one-hot label))
wherein the second secret recovers the unpermuted one hot label. ([Gao, Section 3.1, Para 3 and 6] discloses using a permutation σ (i.e second secret) to recover the one-hot vectors (i.e one-hot label) by inversing σ (i.e unpermuted): “we can try to match feature vectors in the bag to the class labels using the information in the model’s probability distribution, that is, find the permutation ˆσ optimal… If the class conditional probabilities pj resulting from the model perfectly match the one-hot vectors, the optimal ˆσ will be the inverse of the permutation σ.”)
Doshi, Abadi, and Gao are analogous art to the present invention because they are from the same field of endeavor directed to machine learning.
It would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have combined the apparatus to transmit data to a server using permuted labels and a secret to recover unpermuted labels disclosed by Doshi in view of Abadi with one-hot labels disclosed by Gao. One of ordinary skill in the art would have been motivated to make this modification in order to represent data samples for training and testing models. ([Gao, Section 3.1, Para 1-5, Fig. 1, Fig. 2])
Regarding Claim 18:
(Claim 18 recites analogous limitations to Claim 5 and therefore is rejected on the same ground as Claim 5.)
Claim(s) 7, 8, 12, 13, 14, 15, 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Doshi et al. (US 2019/0044918, hereinafter "Doshi"), in view of Abadi et al. (US 2019/0171929 A1, hereinafter “Abadi”) and Gonzalez Sanchez et al. (US 2024/0119289 A1, hereinafter “Gonzalez”).
Regarding Claim 7:
Doshi in view of Abadi discloses: wherein the trained neural network is an encoder, that define one or more layers of artificial neurons(([Abadi, 0040, 0051] discloses an encoder neural network 402 (i.e trained neural network), containing convolution layers of nodes (i.e artificial neurons).)
Doshi in view of Abadi does not explicitly disclose: wherein the trained neural network is an encoder, that define one or more layers of artificial neurons, to be used as an input portion of a primary neural network that comprises the encoder and a predictor, that define one or more layers of artificial neurons, to be used as an output portion of the primary neural network.
However, Gonzalez discloses: wherein the trained neural network is an encoder, that define one or more layers of artificial neurons, ([Gonzalez, 0021, 0025; Fig. 3, 0044] discloses PP encoder containing layers of artificial neurons.)
to be used as an input portion of a primary neural network that comprises the encoder and a predictor, that define one or more layers of artificial neurons, to be used as an output portion of the primary neural network. ([Gonzalez, 0021, 0025; Fig. 3, 0044] discloses the PP encoder as an input portion of a trained neural network (i.e primary neural network) that comprises of the PP encoder and PP machine learning model (i.e predictor). The predictor has the output layers of the trained neural network and contains layers of artificial neurons)
Doshi, Abadi, and Gonzalez are analogous art to the present invention because they are from the same field of endeavor directed to machine learning.
It would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have combined the trained neural network as an encoder disclosed by Doshi in view of Abadi with using a primary neural network containing an encoder and predictor by Gonzalez. One of ordinary skill in the art would have been motivated to make this modification in order to privately send data across the network. ([Gonzalez, 0004])
Regarding Claim 8:
Doshi in view of Abadi and Gonzalez discloses: wherein the trained neural network, the encoder([Abadi, Fig. 4, 0051, 0078] discloses a neural network input key 414 (i.e first secret) and primary neural network input 410 (i.e data) as inputs to an encoder neural network 402 (i.e trained neural network).)
Doshi in view of Abadi does not explicitly discloses: wherein the trained neural network, the encoder, is received from a server, where the data
However, Gonzalez discloses: wherein the trained neural network, the encoder, is received from a server, ([Gonzalez, Fig. 9, 0105, 0021] discloses a server sending the PP encoder (i.e trained neural network))
where the data ([Gonzalez, Fig. 9, 0105, 0021] discloses raw data as inputs to the PP encoder (i.e trained neural network))
Doshi, Abadi, and Gonzalez are analogous art to the present invention because they are from the same field of endeavor directed to machine learning.
In view of motivation previously stated in claim 7, the claim is rejected.
Regarding Claim 12:
Doshi in view of Abadi discloses: wherein the trained neural network is an encoder, that define one or more layers of artificial neurons, (([Abadi, 0040, 0051] discloses an encoder neural network 402 (i.e trained neural network), containing convolution layers of nodes (i.e artificial neurons).)
Doshi in view of Abadi does not explicitly disclose: wherein the trained neural network is an encoder, that define one or more layers of artificial neurons, to be used as an input portion of a primary neural network that comprises the encoder and a predictor, that define one or more layers of artificial neurons, to be used as an output portion of the primary neural network.
However, Gonzalez discloses: wherein the trained neural network is an encoder, that define one or more layers of artificial neurons, ([Gonzalez, 0021, 0025; Fig. 3, 0044] discloses PP encoder containing layers of artificial neurons.)
to be used as an input portion of a primary neural network that comprises the encoder and a predictor, that define one or more layers of artificial neurons, to be used as an output portion of the primary neural network. ([Gonzalez, 0021, 0025; Fig. 3, 0044] discloses the PP encoder as an input portion of a trained neural network (i.e primary neural network) that comprises of the PP encoder and PP machine learning model (i.e predictor). The predictor has the output layers of the trained neural network and contains layers of artificial neurons)
Doshi, Abadi, and Gonzalez are analogous art to the present invention because they are from the same field of endeavor directed to machine learning.
It would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have combined the trained neural network as an encoder disclosed by Doshi in view of Abadi with using a primary neural network containing an encoder and predictor by Gonzalez. One of ordinary skill in the art would have been motivated to make this modification in order to privately send data across the network. ([Gonzalez, 0004])
Regarding Claim 13:
Doshi in view of Abadi and Gonzalez discloses: where the server is further caused to train the encoder and the predictor and to provide the encoder to the apparatus. ([Gonzalez, 0045] discloses training the encoder and the ML model (i.e predictor) and sending the encoder to the client (i.e apparatus))
Regarding Claim 14:
Doshi in view of Abadi and Gonzalez discloses: wherein the instructions when executed by the at least one processor, further cause the server ([Doshi, 0026-0028; Fig. 2, 0036-0037] discloses transformations using noise, fake outputs, and permutations to encode data to produce transformed data (i.e encoded label) using a client application 220 (i.e encoding algorithm) that is used to train camouflage model 255 (i.e neural network)).
Doshi does not explicitly disclose: further cause the server to, for each of a collection of different first secrets, use a first secret to encode data to produce an encoded label using an encoding algorithm that is used to train the
However, Abadi discloses: further cause the server to, for each of a collection of different first secrets, use a first secret to encode data to produce an encoded label using an encoding algorithm that is used to train the ([Abadi, 0075] discloses a training system (i.e server) for each of batch of neural network input keys (i.e a collection of different first secrets), use a key (i.e first secret) to encode data and produce the encoded representation of the primary neural network input (i.e encoded label) that is used to train the encoder neural network (i.e neural network))
Doshi and Abadi are analogous art to the present invention because they are from the same field of endeavor directed to machine learning.
It would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have combined training a neural network for encoding data disclosed by Doshi with using secrets to encode that data for training a neural network by Abadi. One of ordinary skill in the art would have been motivated to make this modification in order to train a neural network to encode data with a secret so that the encoded data cannot be easily decoded without a secret. ([Abadi, 0014])
However, Doshi in view of Abadi does not explicitly disclose: primary neural network that is then partitioned
However, Gonzalez discloses: primary neural network that is then partitioned ([Gonzalez, 0035] discloses a train neural network model partitioned.)
Doshi, Abadi, and Gonzalez are analogous art to the present invention because they are from the same field of endeavor directed to machine learning.
It would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have combined the system to train a neural network for encoding data using secrets disclosed by Doshi in view of Abadi with having a primary network partitioned by Gonzalez. One of ordinary skill in the art would have been motivated to make this modification in order to provide the partitioned parts of a trained neural network as an encoder to be sent to a client to preform private communications with a server. ([Gonzalez, 0020-0021])
Regarding Claim 15:
Doshi in view of Abadi and Gonzalez: wherein the instructions when executed by the at least one processor, further cause the server to provide the first secrets to the apparatus and to provide the encoder to the apparatus. ([Doshi, 0038] discloses providing the transformations (i.e first secrets) and the application that does the transforming (i.e encoder) to mobile device (i.e apparatus): “For example, an application for a mobile device is provided by a service provider... The transformations are embedded within the application. The application transforms the data...")
Regarding Claim 20:
(Claim 20 recites analogous limitations to Claim 7 and therefore is rejected on the same ground as Claim 7.)
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to Amanda D. Nguyen whose telephone number is (571)270-1854. The examiner can normally be reached M-F, 7:00am to 4:30 pm ET First Fridays off, 2nd Friday 7:00 am - 3:30 pm ET.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Abdullah Al Kawsar can be reached at (571)270-3169. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/AMANDA D NGUYEN/Examiner, Art Unit 2127
/ABDULLAH AL KAWSAR/Supervisory Patent Examiner, Art Unit 2127