Prosecution Insights
Last updated: October 02, 2026
Application No. 18/524,852

PRIVACY PRESERVING JOINT TRAINING OF MACHINE LEARNING MODELS

Non-Final OA §103§112
Filed
Nov 30, 2023
Priority
Mar 18, 2021 — provisional 63/162,591 +1 more
Examiner
SMITH, BRIAN M
Art Unit
Tech Center
Assignee
NEC Corporation
OA Round
1 (Non-Final)
52%
Grant Probability
Moderate
1-2
OA Rounds
1y 5m
Est. Remaining
89%
With Interview

Examiner Intelligence

Grants 52% of resolved cases
52%
Career Allowance Rate
138 granted / 263 resolved
-7.5% vs TC avg
Strong +37% interview lift
Without
With
+36.9%
Interview Lift
resolved cases with interview
Typical timeline
4y 3m
Avg Prosecution
32 currently pending
Career history
289
Total Applications
across all art units

Statute-Specific Performance

§101
23.9%
-16.1% vs TC avg
§103
37.2%
-2.8% vs TC avg
§102
12.9%
-27.1% vs TC avg
§112
19.9%
-20.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 263 resolved cases

Office Action

§103 §112
CTNF 18/524,852 CTNF 92919 Notice of Pre-AIA or AIA Status 07-03-aia AIA 15-10-aia The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA. 07-30-03-h AIA Claim Interpretation The following is a quotation of 35 U.S.C. 112(f): (f) Element in Claim for a Combination. – An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof. 07-30-05 The claims in this application are given their broadest reasonable interpretation using the plain meaning of the claim language in light of the specification as it would be understood by one of ordinary skill in the art. The broadest reasonable interpretation of a claim element (also commonly referred to as a claim limitation) is limited by the description in the specification when 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is invoked. As explained in MPEP § 2181, subsection I, claim limitations that meet the following three-prong test will be interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph: (A) the claim limitation uses the term “means” or “step” or a term used as a substitute for “means” that is a generic placeholder (also called a nonce term or a non-structural term having no specific structural meaning) for performing the claimed function; (B) the term “means” or “step” or the generic placeholder is modified by functional language, typically, but not always linked by the transition word “for” (e.g., “means for”) or another linking word or phrase, such as “configured to” or “so that”; and (C) the term “means” or “step” or the generic placeholder is not modified by sufficient structure, material, or acts for performing the claimed function. Use of the word “means” (or “step”) in a claim with functional language creates a rebuttable presumption that the claim limitation is to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites sufficient structure, material, or acts to entirely perform the recited function. Absence of the word “means” (or “step”) in a claim creates a rebuttable presumption that the claim limitation is not to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is not interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites function without reciting sufficient structure, material or acts to entirely perform the recited function. Claim limitations in this application that use the word “means” (or “step”) are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action. Conversely, claim limitations in this application that do not use the word “means” (or “step”) are not being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action. 07-30-06 This application includes one or more claim limitations that do not use the word “means,” but are nonetheless being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, because the claim limitation(s) uses a generic placeholder that is coupled with functional language without reciting sufficient structure to perform the recited function and the generic placeholder is not preceded by a structural modifier. Such claim limitations are: privacy preserving generator configured to learn; classifier configured to measure accuracy; reconstructor configured to recover; discriminator configured to ensure; and attack simulator configured to ensure in both Claims 9 and 14. Because this/these claim limitation(s) is/are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, it/they is/are being interpreted to cover the corresponding structure described in the specification as performing the claimed function, and equivalents thereof. If applicant does not intend to have this/these limitation(s) interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, applicant may: (1) amend the claim limitation(s) to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph (e.g., by reciting sufficient structure to perform the claimed function); or (2) present a sufficient showing that the claim limitation(s) recite(s) sufficient structure to perform the claimed function so as to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. Claim Rejections - 35 USC § 112 07-30-02 AIA The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. 07-34-01 Claims 5 , 9 , 10 , and 14 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claim limitations privacy preserving generator, classifier, reconstructor, discriminator , and attack simulator in Claims 9 and 14 invoke 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. However, the written description fails to disclose the corresponding structure, material, or acts for performing the entire claimed functions and to clearly link the structure, material, or acts to the functions. Paragraphs [0050, 0053] ( generator ); [0050] ( classifier ); [0050-0051] ( reconstructor ); [0051] ( discriminator ); and [0052] ( attack simulator ) only describe the functions that the limitations are to accomplish, but fail to disclose any structure nor sufficient algorithms by which to accomplish the respective functions. 07-34-23 Therefore, the claim is indefinite and is rejected under 35 U.S.C. 112(b) or pre-AIA 35 U.S.C. 112, second paragraph. Applicant may: (a) Amend the claim so that the claim limitation will no longer be interpreted as a limitation under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph; (b) Amend the written description of the specification such that it expressly recites what structure, material, or acts perform the entire claimed function, without introducing any new matter (35 U.S.C. 132(a)); or (c) Amend the written description of the specification such that it clearly links the structure, material, or acts disclosed therein to the function recited in the claim, without introducing any new matter (35 U.S.C. 132(a)). If applicant is of the opinion that the written description of the specification already implicitly or inherently discloses the corresponding structure, material, or acts and clearly links them to the function so that one of ordinary skill in the art would recognize what structure, material, or acts perform the claimed function, applicant should clarify the record by either: (a) Amending the written description of the specification such that it expressly recites the corresponding structure, material, or acts for performing the claimed function and clearly links or associates the structure, material, or acts to the claimed function, without introducing any new matter (35 U.S.C. 132(a)); or (b) Stating on the record what the corresponding structure, material, or acts, which are implicitly or inherently set forth in the written description of the specification, perform the claimed function. For more information, see 37 CFR 1.75(d) and MPEP §§ 608.01(o) and 2181. For the purpose of examination, an invention which uses a processor to perform the recited functions will be considered to be within the scope of the claims. Further, the term similar in Claims 9 and 14 is a relative term which renders the claim indefinite. The term similar is not defined by the claim, the specification does not provide a standard for ascertaining the requisite degree, and one of ordinary skill in the art would not be reasonably apprised of the scope of the invention. Therefore, the uncertainty as to which data representations are similar to facsimile data renders the claim scope indefinite. The term complex in Claims 5 and 10 is a relative term which renders the claim indefinite. The term complex is not defined by the claim, the specification does not provide a standard for ascertaining the requisite degree, and one of ordinary skill in the art would not be reasonably apprised of the scope of the invention. Therefore, the uncertainty as to which representation learning algorithms are complex renders the claim scope indefinite. Claim Rejections - 35 USC § 103 07-06 AIA 15-10-15 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. 07-20-aia AIA The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 07-23-aia AIA The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. 07-20-02-aia AIA This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention. 07-21-aia AIA Claim s 1-8 , 10-13 , and 15 are rejected under 35 U.S.C. 103 as being unpatentable over Pascale, US PG Pub 2020/0082290, in view of Bradshaw, US PG Pub 2021/0056405 . Regarding Claim 1 , Pascale teaches a method of training a shared machine learning (ML) model (Pascale, Fig. 5, elements 514, “Learning Engine” denoting training & 516, “Inference Engine” shared between elements 504, “Server” & 502, “Client Device”) , the method comprising steps of: generating, by a cloud infrastructure provider, a data transformation function; sharing, by the cloud infrastructure provider, the data transformation function with one or more hosted services (Pascale, Fig. 5, the server shares via 532 the “Anonymization Strategy”/ transformation function 512 with the “Anonymization Engine” 506 hosted on the “Client Device” 502; where the server generates the strategy, see Fig. 8, “Updated Anonymization Strategy” 814 & Abstract, “the statistical learning component modifies the anonymization strategy to generate an updated anonymization strategy”) ; receiving one or more private datasets, by the cloud infrastructure provider, from the one or more hosted services, from the one or more hosted services, each private dataset having been created by applying the data transformation function to a dataset of the one or more hosted services (Pascale, Fig, 5, the client device applies the anonymization strategy to the data and sends element 528, “Intermediate Anonymized Data” to the server ) ; training a machine learning (ML) model … to produce a trained ML model (Pascale, [0046], “the statistical learning component 106 can train the machine learning process based on training data received from an electronic device”). While Pascale teaches training the ML model with received data, Pascale is silent regarding training the model with data which has been anonymized according to any anonymization function (i.e. with the received transformed data). However, Bradshaw teaches training a machine learning (ML) model using one or more private datasets , wherein the private datasets were received and having been created by applying [a] data transformation function to a dataset of one or more hosted services (Bradshaw, Fig. 1, “Obfuscation” 124a is applied to “User data” 120 to create private dataset / “Obfuscated User Data” 120a to train “ANN” 110 via “Machine Learning” 112 , see Abstract, “a processor that trains the master version based on the received obfuscated user data using machine learning”). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Pascale to train their machine learning model using obfuscated/anonymized data (of the method of Pascale), received from clients, as Bradshaw trains their machine learning model. The motivation to do so is so that “the user data without obfuscation is not sent to the cloud to protect the privacy of the user” (Bradshaw, [0021]), i.e. so that sources of training data for the machine learning model can retain the privacy of their data. Regarding Claim 2 , the Pascale/Bradshaw combination of Claim 1 teaches the method of Claim 1 (and thus the rejection of Claim 1 is incorporated). The combination has already been shown to teach wherein the training is performed by the cloud infrastructure provider (Pascale, Fig. 5, training occurs on the server & [0046], “the statistical learning component 106 can train the machine learning process based on training data received from an electronic device”). Regarding Claim 3 , the Pascale/Bradshaw combination of Claim 1 teaches the method of Claim 1 (and thus the rejection of Claim 1 is incorporated). Pascale further teaches wherein when applied to the dataset, the data transformation function creates the one or more private datasets including a numeric vector representation of raw data in the dataset, without any original values of the raw data in the dataset (Pascale, [0058], “the data transformer 508 can encode the data 526 into a vector” & [0059], “the anonymization strategy can be a differential privacy technique that adds randomized noise data to the data” denotes that the raw values are all changed ). Regarding Claim 4 , the Pascale/Bradshaw combination of Claim 1 teaches the method of Claim 1 (and thus the rejection of Claim 1 is incorporated). Pascale further teaches wherein the step of generating a data transformation function includes training the data transformation function using data (Pascale, [0066], “the anonymization strategy can be an updated anonymization strategy generated based on a machine learning process associated with probabilistic model that represents the data”). Regarding Claim 5 , the Pascale/Bradshaw combination of Claim 1 teaches the method of Claim 1 (and thus the rejection of Claim 1 is incorporated). Pascale further teaches wherein the data transformation function includes one of … a noise addition algorithm (Pascale, [0066], “the anonymization strategy can be an updated anonymization strategy generated based on a machine learning process associated with probabilistic model that represents the data”). Regarding Claim 6 , the Pascale/Bradshaw combination of Claim 1 teaches the method of Claim 1 (and thus the rejection of Claim 1 is incorporated). Pascale further teaches querying the trained model using a private dataset (Pascale, [0046], “the machine learning process can be a process that determines classifications, correlations, inferences, and/or expression associated with the anonymized data”). Regarding Claim 7 , the Pascale/Bradshaw combination of Claim 6 teaches the method of Claim 6 (and thus the rejection of Claim 6 is incorporated). Pascale further teaches wherein the querying includes: creating a first private dataset, by one of the hosted services, by applying the data transformation function to a first dataset of the one of the one or more hosted services; and querying the trained ML model using the first private dataset (Pascale, Fig. 5, “Intermediate Anonymized Data” 528 to “Inference Engine” 516). Regarding Claim 8 , the Pascale/Bradshaw combination of Claim 7 teaches the method of Claim 7 (and thus the rejection of Claim 7 is incorporated). Pascale further teaches receiving a result from the trained ML model in response to the querying (Pascale, [0046], “the machine learning process can be a process that determines classifications, correlations, inferences, and/or expression associated with the anonymized data”). Claims 10-13 recite a system comprising one or more processors configured to provide for execution of the methods of Claims 1, 3, 5, and 7, respectively. As Pascale executes their method on a distributed computer system (Pascale, Fig. 5, server and client & [0090]), Claims 10-13 are rejected for reasons set forth in the rejections of Claims 1, 3, 5, and 7, respectively. Similarly, Claim 15 recites a tangible, non-transitory computer-readable medium having instructions thereon to perform the method of Claim 1. As Pascale executes their method on a distributed computer system, in which a computer readable medium is inherent (Pascale, [0090], “computer readable storage medium”), Claim 15 is rejected for reasons set forth in the rejection of Claim 1 . 07-21-aia AIA Claim s 9 and 14 are rejected under 35 U.S.C. 103 as being unpatentable over Pascale, US PG Pub 2020/0082290, in view of Bradshaw, US PG Pub 2021/0056405, and further in view of Wang, US PG Pub 2014/0281572 . Regarding Claim 9 , the Pascale/Bradshaw combination of Claim 1 teaches the method of Claim 1 (and thus the rejection of Claim 1 is incorporated). Pascale further teaches optimizing the data transformation function by inputting raw data of a dataset into an optimization system including: a privacy preserving generator configured to learn data representations of the raw data (Pascale, [0040], “infer one or more properties of raw data (e.g. domain, correlations, tec.) via a statistical learning process” with [00435], “generate an updated anonymization strategy for the data 112 based on a machine learning process associated with a probabilistic model that represents the data”) ; a classifier configured to measure accuracy of a ML task (Pascale, [0040], “Accuracy and/or efficiency of a machine learning model associated with data anonymization can also be provided”) … a discriminator configured to ensure the data representations are similar to facsimile data (Pascale, [0075], “a measure of accuracy of the data can be performed where similarity of aggregate statistics on the data is determined before and after the anonymization strategy is applied to the data”); and an attack simulator configured to ensure an external entity is unable to recover the raw data (Pascale, [0061], “The anonymization engine can be updated … while also maintain a certain degree of differential privacy. For example, one or more differential privacy parameters (e.g. epsilon, delta, etc.) can remain unchanged through a data anonymization process to ensure that a certain degree of differential privacy is maintained” denotes to ensure an external entity is unable to recover the raw data ). Pascale is silent regarding a reconstructor configured to recover the raw data , but Wang teaches this limitation (Wang, [0027], “so that the processor can perform decryption as necessary”). It would have been obvious to one of ordinary skill in the art to, in addition to data anonymization, include encryption and decryption in the of obfuscation of Pascale/Bradshaw. The motivation to do so is that Bradshaw already says the private data can be encrypted (Bradshaw, [0042], “The obfuscation of the extracted plurality of features can also include using data encryption”). Claim 14 recites a system comprising one or more processors configured to provide for execution of the method of Claim 9. As Pascale executes their method on a distributed computer system (Pascale, Fig. 5, server and client & [0090]), Claim 14 is rejected for reasons set forth in the rejection of Claim 9. Conclusion Hao et al., “Efficient and privacy-enhanced federated learning for industrial artificial intelligence,” as cited by the applicant and cited in rejection in the parent application, is also relevant to the instant application. Any inquiry concerning this communication or earlier communications from the examiner should be directed to BRIAN M SMITH whose telephone number is (469)295-9104. The examiner can normally be reached Monday - Friday, 8:00am - 4pm Pacific. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Kakali Chaki can be reached at (571) 272-3719. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /BRIAN M SMITH/Primary Examiner, Art Unit 2122 Application/Control Number: 18/524,852 Page 2 Art Unit: 2122 Application/Control Number: 18/524,852 Page 3 Art Unit: 2122 Application/Control Number: 18/524,852 Page 4 Art Unit: 2122 Application/Control Number: 18/524,852 Page 5 Art Unit: 2122 Application/Control Number: 18/524,852 Page 6 Art Unit: 2122 Application/Control Number: 18/524,852 Page 7 Art Unit: 2122 Application/Control Number: 18/524,852 Page 8 Art Unit: 2122 Application/Control Number: 18/524,852 Page 9 Art Unit: 2122 Application/Control Number: 18/524,852 Page 10 Art Unit: 2122 Application/Control Number: 18/524,852 Page 11 Art Unit: 2122 Application/Control Number: 18/524,852 Page 13 Art Unit: 2122 Application/Control Number: 18/524,852 Page 14 Art Unit: 2122
Read full office action

Prosecution Timeline

Nov 30, 2023
Application Filed
Jun 01, 2026
Non-Final Rejection mailed — §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12737594
Improved Processing of Sequential Data via Machine Learning Models Featuring Temporal Residual Connections
3y 4m to grant Granted Sep 15, 2026
Patent 12731050
CONTENT DELIVERY OPTIMIZATION
3y 9m to grant Granted Sep 08, 2026
Patent 12731005
PROCESSING LABELED DATA IN A MACHINE LEARNING OPERATION
3y 3m to grant Granted Sep 08, 2026
Patent 12718101
COMPRESSION OF MACHINE LEARNING MODELS
6y 11m to grant Granted Aug 25, 2026
Patent 12718139
SYSTEMS AND METHODS FOR IDENTIFYING MANUFACTURING DEFECTS
5y 3m to grant Granted Aug 25, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
52%
Grant Probability
89%
With Interview (+36.9%)
4y 3m (~1y 5m remaining)
Median Time to Grant
Low
PTA Risk
Based on 263 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month