Prosecution Insights
Last updated: October 02, 2026
Application No. 18/535,868

FEDERATED LEARNING MODEL ATTACK PREVENTION

Final Rejection §103
Filed
Dec 11, 2023
Examiner
LEE, MICHAEL CHRISTOPHER
Art Unit
Tech Center
Assignee
Dell Products L.P.
OA Round
2 (Final)
62%
Grant Probability
Moderate
3-4
OA Rounds
6m
Est. Remaining
88%
With Interview

Examiner Intelligence

Grants 62% of resolved cases
62%
Career Allowance Rate
100 granted / 160 resolved
+2.5% vs TC avg
Strong +25% interview lift
Without
With
+25.1%
Interview Lift
resolved cases with interview
Typical timeline
3y 3m
Avg Prosecution
44 currently pending
Career history
199
Total Applications
across all art units

Statute-Specific Performance

§101
30.1%
-9.9% vs TC avg
§103
46.5%
+6.5% vs TC avg
§102
9.7%
-30.3% vs TC avg
§112
12.5%
-27.5% vs TC avg
Black line = Tech Center average estimate • Based on career data from 160 resolved cases

Office Action

§103
DETAILED ACTION Notice of AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Amendment Applicant’s amendment and remarks dated 8/14/2026 have been considered. Claims 4, 10, and 16 have been cancelled. Claims 1-3, 5-9, 11-15, and 17-18 are pending. Response to Arguments On pages 8-9 of Applicant’s 8/14/2026 Amendment and remarks, Applicant argues that the rejections under 35 U.S.C. 101 should be withdrawn because the only mental step identified in the independent claims has now been deleted, such that there are no mental steps remaining in the independent claims. The examiner finds this argument to be persuasive. All rejections under 35 U.S.C. 101 are hereby withdrawn. On pages 9-10 Applicant’s 8/14/2026 Amendment and remarks, with respect to the prior art rejections under 35 U.S.C. 103, Applicant argues that the amendments to the independent claims overcome the previous rejections. The examiner agrees. The previous rejections under 35 U.S.C. 103 are withdrawn. However, new rejections under 35 U.S.C. 103, which are necessitated by Applicant’s amendments to the claims, are set forth herein. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claims 1, 5, 7, 11, 13, and 17 are rejected under 35 U.S.C. 103 as being unpatentable over US 20190362072 A1, hereinafter referenced as KESARWANI, in view of US 20240330824 A1, hereinafter referenced as VEGI, in view of Tolpegin, Vale, et al. "Data poisoning attacks against federated learning systems." European symposium on research in computer security. Cham: Springer International Publishing, 2020, hereinafter referenced as TOLPEGIN, and further in view of US 20110202792 A1, hereinafter referenced as ATZMONY. Regarding Claim 1 KESARWANI teaches: An information handling system comprising: (KESARWANI, para. 0022: “Accordingly, the techniques and systems as described herein provide a system and technique for delaying the effect of malicious input on a machine learning model.”; Examiner’s Note: the broadest reasonable interpretation of “information handling system”, as set forth on page 9, lines 5-27 of the instant specification, includes any system that processes or handles any information, and KESARWANI discloses a system for handling malicious input with respect to a machine learning model) at least one processor; and (KESARWANI, para. 0044: “As shown in FIG. 4, computer system/server 12′ in computing node 10′ is shown in the form of a general-purpose computing device. The components of computer system/server 12′ may include, but are not limited to, at least one processor or processing unit 16′, a system memory 28′, and a bus 18′ that couples various system components including system memory 28′ to processor 16′.”) a memory, wherein the memory comprises a volatile memory and a non-volatile memory; (KESARWAI, para. 0045: “System memory 28′ can include computer system readable media in the form of volatile memory, such as random access memory (RAM) 30′ and/or cache memory 32′. Computer system/server 12′ may further include other removable/non-removable, volatile/non-volatile computer system storage media. By way of example only, storage system 34′ can be provided for reading from and writing to a non-removable, non-volatile magnetic media (not shown and typically called a “hard drive”).”) wherein the information handling system is configured to: (KESARWANI, para. 0022: “Accordingly, the techniques and systems as described herein provide a system and technique for delaying the effect of malicious input on a machine learning model.”; Examiner’s Note: the broadest reasonable interpretation of “information handling system”, as set forth on page 9, lines 5-27 of the instant specification, includes any system that processes or handles any information, and KESARWANI discloses a system configured to prevent malicious input with respect to a machine learning model) receive data ... , wherein the data is associated with … a machine learning model; (KESARWANI, para. 0030: “At 103 the system may receive input from one or more users. This input may include the feedback or reviews provided by users. In other words, this input may include training input that will be used to retrain the machine learning model. The input may include malicious input that would affect the results or responses of the machine learning model.”) prevent the particular data ... from being used to update the machine learning model. (KESARWANI, para. 0025: “Therefore, the systems and methods as described herein provide a technique for delaying infection of the machine learning model, either by detecting input is malicious and preventing incorporation of the malicious feedback into the training of the model or by using an ensemble machine learning model approach and also correcting any possible infection that has been introduced to the machine learning model, which is not possible using conventional techniques. Accordingly, the described systems and methods provide a technique for training machine learning models using user input that results in retrained machine learning models that are more resistant to malicious attacks than conventional systems.”; KESARWANI, para. 0032: “The system may use these previous versions to further assist in preventing malicious input from poisoning the machine learning models. For example, the system may randomly reset a selected subset of the machine learning models to a previous clean version. Thus, if one of the models included in the randomly selected subset was infected, it would be reset to a clean, uninfected version or state. This random resetting also ensures that the entire system will not be poisoned. In other words, even if all of the models that were reset were uninfected models, the fact that the models were reset ensures that the entire system cannot become infected. The ensemble machine learning model would therefore include not only the models that have been retrained and the models that were not retrained, but also the reset models. Additionally, the system may use the previously identified clean version of the model if a model is identified as being infected. For example, the system may correct the model by resetting the model to a previously marked clean state model.”) However, KESARWANI fails to explicitly teach: ... during each of a plurality of time windows ... … federated learning for … wherein data received during each time window of the plurality of time windows is retained in the volatile memory and is destaged from the volatile memory to the non-volatile memory only at the end of that time window in response to particular data from a particular time window being associated with a statistical anomaly prior to the end of the particular time window, prevent the particular data from the particular time window from being destaged from the volatile memory to the non-volatile memory such that the particular data is not used to update the machine learning model. However, in a related field of endeavor (determining anomalies in machine learning models, see para. 0012), VEGI teaches and makes obvious: receive data during each of a plurality of time windows, wherein the data is associated with a machine learning model; (VEGI, para. 0035: “Upon receipt of the money movement transaction information, the statistical analysis engine 202 segregates the data into a series of time windows, and performs statistical analysis on the time windows as further described with reference to FIG. 3. If there is a statistical difference between a given time window and a previous time window, then the anomaly detection engine 204 determines whether the statistical difference is an anomaly.”; Examiner’s Note: the KESARWANI-VEGI combination now modifies the machine learning models of KESARWANI to pertain to financial transactions as in VEGI, where the collected data used to train and re-train the machine learning model is segregated into time windows as in VEGI) in response to particular data from a particular time window being associated with a statistical anomaly prior to the end of the particular time window (VEGI, para. 0015: “If statistical differences exist between the given time window and the previous time window, the system performs anomaly detection to determine whether the statistical differences are anomalies.”; VEGI, para. 0035: “Upon receipt of the money movement transaction information, the statistical analysis engine 202 segregates the data into a series of time windows, and performs statistical analysis on the time windows as further described with reference to FIG. 3. If there is a statistical difference between a given time window and a previous time window, then the anomaly detection engine 204 determines whether the statistical difference is an anomaly.”; Examiner’s Note: the KESARWANI-VEGI combination now modifies the machine learning models of KESARWANI to pertain to financial transactions as in VEGI, where the collected data used to train and re-train the machine learning model is segregated into time windows as in VEGI, and further uses the anomaly detection engine 204 of VEGI to determine if there is a statistical difference that is an anomaly in a particular time window) prevent the particular data from the particular time window from being … used to update the machine learning model. (VEGI, para. 0015: “If statistical differences exist between the given time window and the previous time window, the system performs anomaly detection to determine whether the statistical differences are anomalies.”; VEGI, para. 0035: “Upon receipt of the money movement transaction information, the statistical analysis engine 202 segregates the data into a series of time windows, and performs statistical analysis on the time windows as further described with reference to FIG. 3. If there is a statistical difference between a given time window and a previous time window, then the anomaly detection engine 204 determines whether the statistical difference is an anomaly.”; Examiner’s Note: the KESARWANI-VEGI combination now modifies the machine learning models of KESARWANI to pertain to financial transactions as in VEGI, where the collected data used to train and re-train the machine learning model is segregated into time windows as in VEGI, and further uses the anomaly detection engine 204 of VEGI to determine if there is a statistical difference that is an anomaly in a particular time window, and if an anomaly is detected, the anomalous data is treated as malicious and is not used to train the model as disclosed by KESARWANI) Before the effective filing date of the present application, it would have been obvious to one of ordinary skill in the art to combine the teachings of KESARWANI with VEGI as explained above. As disclosed by VEGI, one of ordinary skill would have been motivated to do so in order “ to mitigate the impact of the anomaly on the business decision output data, or maintain transaction flow of an enterprise.” (para. 0016). Moreover, as disclosed by KESARWANI, one of ordinary skill would be motivated to do so in order to catch a malicious actor within a period of time, so that “the incorporation of malicious input is delayed to the entirety of the machine learning model, thereby allowing time for a person or other system to determine if malicious input has infected the machine learning model.” (para. 0024). However, KESARWANI and VEGI fail to explicitly teach: ... … federated learning for … wherein data received during each time window of the plurality of time windows is retained in the volatile memory and is destaged from the volatile memory to the non-volatile memory only at the end of that time window … destaged from the volatile memory to the non-volatile memory such that the particular data is not … However, in a related field of endeavor (machine learning model training, including federated learning, see p. 480, section 1), TOLPEGIN teaches and makes obvious: wherein the data is associated with federated learning for a machine learning model (TOLPEGIN, p. 481, section 1: “While FL systems allow participants to keep their raw data local, a significant vulnerability is introduced at the heart of question (2). Consider the scenario wherein a subset of participants are either malicious or have been compromised by some adversary. This can lead to these participants having mislabeled or poisonous samples in their local training data. With no central authority able to validate data, these malicious participants can consequently poison the trained global model.” TOLPEGIN, p. 493, section 4: “Given a highly effective adversary, how can a FL system defend against the label flipping attacks discussed thus far? To that end, we propose a defense which enables the aggregator to identify malicious participants. After identifying malicious participants, the aggregator may blacklist them or ignore their updates θr,i in future rounds.”; Examiner’s Note: TOLPEGIN discloses that poisoning attacks can be made on federated learning systems, and that a defense to such an attack is to identify malicious participants and blacklist them; the KESARWANI-VEGI-TOLPEGIN combination now modifies the machine learning models of KESARWANI to pertain to financial transactions as in VEGI and to be a federated learning model as in TOLPEGIN) Before the effective filing date of the present application, it would have been obvious to one of ordinary skill in the art to combine the teachings of KESARWANI with VEGI and TOLPEGIN as explained above. As disclosed by TOLPEGIN, one of ordinary skill would have been motivated to do so in order to determine a defense to such poisoning attacks in the federated learning context. (p. 493, section 4). However, KESARWANI, VEGI, and TOLPEGIN fail to explicitly teach: wherein data received during each time window of the plurality of time windows is retained in the volatile memory and is destaged from the volatile memory to the non-volatile memory only at the end of that time window destaged from the volatile memory to the non-volatile memory such that the particular data is not However, in a related field of endeavor (large data storage systems, see para. 0002), and also being a reference reasonably pertinent to the problem faced by the inventor of protecting against statistical anomalies in an enterprise situation, ATZMONY teaches and makes obvious: wherein data received during each time window of the plurality of time windows is retained in the volatile memory and is destaged from the volatile memory to the non-volatile memory only at the end of that time window (ATZMONY, para. 0056: “the pre-parity storage area is located in a volatile storage device.”; ATZMONY, para. 0062: “data is copied from the pre-parity storage to non-volatile storage according to a criterion whereby data which has not been accessed for a predetermined period of time is de-staged.”; ATZMONY, para. 0071: “incoming values are de-staged from the pre-parity storage area to non-volatile storage according to a criterion whereby incoming values which has not been accessed for a predetermined period of time are de-staged.”; Examiner’s Note: ATZMONY discloses destaging values from a volatile storage deice to a non-volatile storage device (which can be memory, see para. 0084), and further that such de-staging comes after a predetermined period of time (corresponding to recited “end of that time window”); the KESARWANI-VEGI-TOLPEGIN-ATZMONY combination now modifies the machine learning models of KESARWANI to pertain to financial transactions as in VEGI and to be a federated learning model as in TOLPEGIN, such that a volatile memory is only destaged to a non-volatile memory after a predetermined period of time as in ATZMONY) in response to particular data from a particular time window being associated with a statistical anomaly prior to the end of the particular time window, prevent the particular data from the particular time window from being destaged from the volatile memory to the non-volatile memory such that the particular data is not used to update the machine learning model. (ATZMONY, para. 0056: “the pre-parity storage area is located in a volatile storage device.”; ATZMONY, para. 0062: “data is copied from the pre-parity storage to non-volatile storage according to a criterion whereby data which has not been accessed for a predetermined period of time is de-staged.”; ATZMONY, para. 0071: “incoming values are de-staged from the pre-parity storage area to non-volatile storage according to a criterion whereby incoming values which has not been accessed for a predetermined period of time are de-staged.”; Examiner’s Note: ATZMONY discloses destaging values from a volatile storage device to a non-volatile storage device (which can be memory, see para. 0084), and further that such de-staging comes after a predetermined period of time (corresponding to recited “end of that time window”); the KESARWANI-VEGI-TOLPEGIN-ATZMONY combination now modifies the machine learning models of KESARWANI to pertain to financial transactions as in VEGI and to be a federated learning model as in TOLPEGIN, such that after determining data within a time window is associated with an anomaly (as in VEGI), flushing the volatile memory of ATZMONY prior to the predetermined period of time in order to defend against a poisoning attack as in TOLPEGIN) Before the effective filing date of the present application, it would have been obvious to one of ordinary skill in the art to combine the teachings of KESARWANI with VEGI, TOLPEGIN, and ATZMONY as explained above. As disclosed by ATZMONY, one of ordinary skill would have been motivated to do so in order to set the pre-parity storage area to only move to non-volatile memory “each time a set of incoming values has accumulated in the pre-parity storage area which answers to a predetermined criteria” for moving to the non-volatile memory.” (para. 0032). One of ordinary skill would further be motivated to do so to defend against attacks against RAID systems during pre-parity vs. post-parity computations. (para. 0016) Regarding Claim 5 KESARWANI, VEGI, TOLPEGIN, and ATZMONY teach the system of claim 1 as explained above. However, KESARWANI and VEGI fail to explicitly teach: wherein the preventing further comprises: preventing the particular data from being used to update a local model; and preventing the particular data from being sent to a cloud system that is configured to build a central model. However, in a related field of endeavor (machine learning model training, including federated learning, see p. 480, section 1), TOLPEGIN teaches and makes obvious: wherein the preventing further comprises: preventing the particular data from being used to update a local model; and (TOLPEGIN, pp. 480-481, section 1: “Federated learning (FL) allows data to remain at the edge with only model parameters being shared with a central server. Specifically, there is no centralized data curator who collects and verifies an aggregate dataset. Instead, each data holder (participant) is responsible for conducting training on their local data. In regular intervals participants are then send model parameter values to a central parameter server or aggregator where a global model is created through aggregation of the individual updates. A global model can thus be trained over all participants’ data without any individual participant needing to share their private raw data.”; Examiner’s Note: TOLPEGIN teaches that in federated learning, there are local models trained locally; the KESARWANI-VEGI-TOLPEGIN-ATZMONY combination now trains the machine learning models of KESARWANI using the federated learning techniques of TOLPEGIN, and the teachings of KESARWANI (see para. 0025) are used to prevent the local models of TOLPEGIN from being trained using malicious data) preventing the particular data from being sent to a cloud system that is configured to build a central model. (TOLPEGIN, pp. 480-481, section 1: “Federated learning (FL) allows data to remain at the edge with only model parameters being shared with a central server. Specifically, there is no centralized data curator who collects and verifies an aggregate dataset. Instead, each data holder (participant) is responsible for conducting training on their local data. In regular intervals participants are then send model parameter values to a central parameter server or aggregator where a global model is created through aggregation of the individual updates. A global model can thus be trained over all participants’ data without any individual participant needing to share their private raw data.”; Examiner’s Note: TOLPEGIN teaches that in federated learning, there are aggregated global models at a central server; the KESARWANI-VEGI-TOLPEGIN-ATZMONY combination now trains the machine learning models of KESARWANI using the federated learning techniques of TOLPEGIN, and the teachings of KESARWANI (see para. 0025) are used to prevent the local models of TOLPEGIN from uploading model updates to the central server if the data is malicious) Before the effective filing date of the present application, it would have been obvious to one of ordinary skill in the art to combine the teachings of KESARWANI with VEGI, TOLPEGIN, and ATZMONY as explained above. As disclosed by TOLPEGIN, one of ordinary skill would have been motivated to do so in order to determine a defense to such poisoning attacks in the federated learning context. (p. 493, section 4). Claim 7 recites a method that corresponds to the system of claim 1, and is therefore rejected for the same reasons explained above with respect to claim 1. Claim 11 depends from claim 7 and recites a method that corresponds to the system of claim 5, and is therefore rejected for the same reasons explained with respect to claims 5 and 7. Regarding Claim 13 KESARWANI teaches: An article of manufacture comprising a non-transitory, computer-readable medium having computer-executable instructions thereon that are executable by a processor ..: (KESARWANI, para. 0005: “Another aspect of the invention provides an apparatus for delaying the effect of malicious attacks on a machine learning model that is continuously retrained using input captured from a plurality of users, comprising: at least one processor; and a computer readable storage medium having computer readable program code embodied therewith and executable by the at least one processor, the computer readable program code comprising”) The remaining limitations of claim 13 correspond to the system of claim 1, and therefore claim 13 is rejected for the same reasons explained with respect to claim 1. Claim 17 depends from claim 13 and recites an article of manufacture that corresponds to the system of claim 5, and is therefore rejected for the same reasons explained with respect to claims 5 and 13. Claims 2-3, 8-9, and 14-15 are rejected under 35 U.S.C. 103 as being unpatentable over KESARWANI in view of VEGI, TOLGENPIN, and ATZMONY and further in view of US 20220317912 A1, hereinafter referenced as DARJI. Regarding Claim 2 KESARWANI, VEGI, TOLPEGIN, and ATZMONY teach the system of claim 1 as explained above. However, KESARWANI, VEGI, TOLPEGIN, and ATZMONY fail to explicitly teach: wherein the information handling system is a hyper-converged infrastructure (HCI) system. However, in a related field of endeavor (supporting machine learning and AI applications, see paras. 0154, 0156), DARJI teaches and makes obvious: wherein the information handling system is a hyper-converged infrastructure (HCI) system. (DARJI, para. 0153: “Readers will appreciate that the various components described above may be grouped into one or more optimized computing packages as converged infrastructures. Such converged infrastructures may include pools of computers, storage and networking resources that can be shared by multiple applications and managed in a collective manner using policy-driven processes. Such converged infrastructures may be implemented with a converged infrastructure reference architecture, with standalone appliances, with a software driven hyper-converged approach (e.g., hyper-converged infrastructures), or in other ways.” Examiner’s Note: the KESARWANI-VEGI-TOLPEGIN-ATZMONY-DARJI combination now implements the machine learning models of KESARWANI within a hyper-converged infrastructure approach as taught by DARJI). Before the effective filing date of the present application, it would have been obvious to one of ordinary skill in the art to combine the teachings of KESARWANI with VEGI, TOLPEGIN, ATZMONY, and DARJI as explained above. As disclosed by DARJI, one of ordinary skill would have been motivated to do so in order to utilize a single vendor to “ensure that a converged infrastructure that includes storage resources and on-premises cloud infrastructures (e.g., an Amazon Outpost) may be managed in a certain way. For example, the one or more converged system management services may guarantee that I/O operations that are directed to storage resources and were initiated by the GPU servers in the converged infrastructure described above will be prioritized over I/O operations initiated by devices that are external to the converged infrastructure.” (para. 0249). Regarding Claim 3 KESARWANI, VEGI, TOLPEGIN, ATZMONY, and DARJI teach the system of claim 2 as explained above. However, KESARWANI, VEGI, TOLPEGIN, and ATZMONY fail to explicitly teach: wherein the data is received from at least one edge node of the HCI system. However, in a related field of endeavor (supporting machine learning and AI applications, see paras. 0154, 0156), DARJI teaches and makes obvious: wherein the data is received from at least one edge node of the HCI system. (DARJI, para. 0277: “The example of FIG. 8 includes an edge device 802 that is configured to receive control messages from a cloud-based storage service 804 over a data communication link 806.”; Examiner’s Note: the KESARWANI-VEGI-TOLPEGIN-ATZMONY-DARJI combination now implements the machine learning models of KESARWANI within a hyper-converged infrastructure approach as taught by DARJI, where data can be received from edge devices as disclosed by DARJI). Before the effective filing date of the present application, it would have been obvious to one of ordinary skill in the art to combine the teachings of KESARWANI with VEGI, TOLPEGIN, ATZMONY, and DARJI as explained above. As disclosed by DARJI, one of ordinary skill would have been motivated to do so in order to utilize a single vendor to “ensure that a converged infrastructure that includes storage resources and on-premises cloud infrastructures (e.g., an Amazon Outpost) may be managed in a certain way. For example, the one or more converged system management services may guarantee that I/O operations that are directed to storage resources and were initiated by the GPU servers in the converged infrastructure described above will be prioritized over I/O operations initiated by devices that are external to the converged infrastructure.” (para. 0249). Claim 8 depends from claim 7 and recites a method that corresponds to the system of claim 2, and is therefore rejected for the same reasons explained with respect to claims 2 and 7. Claim 9 depends from claim 8 and recites a method that corresponds to the system of claim 3, and is therefore rejected for the same reasons explained with respect to claims 3 and 8. Claim 14 depends from claim 13 and recites an article of manufacture that corresponds to the system of claim 2, and is therefore rejected for the same reasons explained with respect to claims 2 and 13. Claim 15 depends from claim 14 and recites an article of manufacture that corresponds to the system of claim 3, and is therefore rejected for the same reasons explained with respect to claims 3 and 14. Claims 6, 12, and 18 are rejected under 35 U.S.C. 103 as being unpatentable over KESARWANI in view of VEGI, TOLPEGIN, and ATZMONY, and further in view of US 20180095857 A1, hereinafter referenced as SARIR. Regarding Claim 6 KESARWANI, VEGI, TOLPEGIN, and ATZMONY teach the system of claim 1 as explained above. However, KESARWANI, VEGI, TOLPEGIN, and ATZMONY fail to explicitly teach: wherein the statistical anomaly is associated with at least one of a write-after-read activity anomaly, a data size anomaly, and a compression ratio anomaly. However, in a related field of endeavor (anomaly detection, see para. 0002), SARIR teaches and makes obvious: wherein the statistical anomaly is associated with at least one of a write-after-read activity anomaly, a data size anomaly, and a compression ratio anomaly. (SARIR, para. 0039: “For example, according to some aspects, processing device 110 may analyze statistical variation(s) between historical retrieval request data 144 in respect of data retrieval parameter 128 according to at least one suitable statistical outlier detection test. ... For example, according to some aspects, data retrieval parameter 128 comprises a requested size of data to be retrieved from data source 150 (which is accessible to processing device 110) and processing device 110 determines, based on historical retrieval request data 144, that the requested data size is more than three times the mean value of the previously requested data sizes of at least one prior data retrieval request, such as prior data retrieval request 144, and that data retrieval request comprises a request anomaly at least in respect of requested data size.”; Examiner’s Note: SARIR teaches determining whether the data size of a request is a statistical outlier; the KESARWANI-VEGI-TOLPEGIN-ATZMONY-SARIR combination now trains the machine learning models of KESARWANI, as applied to financial transactions as in VEGI, to detect statistical outliers with respect to data size requests as in SARIR) Before the effective filing date of the present application, it would have been obvious to one of ordinary skill in the art to combine the teachings of KESARWANI with VEGI, TOLPEGIN, ATZMONY, and SARIR as explained above. As disclosed by SARIR, one of ordinary skill would have been motivated to do so in order to “avoid the performance of at least some unnecessary processing in respect of data retrieval requests that are ultimately denied .” (para. 0043). One of ordinary skill would further understand the benefit of detecting potentially malicious data requests using techniques such as outliers in data size, so as to deny access to the machine learning models to malicious actors. Claim 12 depends from claim 7 and recites a method that corresponds to the system of claim 6, and is therefore rejected for the same reasons explained with respect to claims 6 and 7. Claim 18 depends from claim 13 and recites an article of manufacture that corresponds to the system of claim 6, and is therefore rejected for the same reasons explained with respect to claims 6 and 18. Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. US 20210373788 A1 (Martin). “At a later point time, the write data may be destaged from the cache to the physical storage device, such as the non-volatile physical storage device (e.g., the PDs of 24) accessed by a DA.” (para. 0037). US 20220129152 A1 (Adams). “For example, during this window of time, the contents of the cache 28 may be de-staged to one or more physical storage devices.” (para. 0034). US 20210168119 A1 (Perraud). Paras. 0028-0036 describe deleting certain information from a time window in the event of an attack. Any inquiry concerning this communication or earlier communications from the examiner should be directed to MICHAEL C LEE whose telephone number is (571)272-4933. The examiner can normally be reached M-F 12:00 pm - 8:00 pm ET. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Omar Fernandez Rivas can be reached at 571-272-2589. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /MICHAEL C. LEE/Examiner, Art Unit 2128
Read full office action

Prosecution Timeline

Dec 11, 2023
Application Filed
May 15, 2026
Non-Final Rejection mailed — §103
Aug 04, 2026
Examiner Interview Summary
Aug 04, 2026
Applicant Interview (Telephonic)
Aug 14, 2026
Response Filed
Aug 28, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12748920
RULES-BASED TEMPLATE EXTRACTION
5y 3m to grant Granted Sep 29, 2026
Patent 12645972
Performing Property Estimation Using Quantum Gradient Operation on Quantum Computing System
3y 7m to grant Granted Jun 02, 2026
Patent 12603081
METHOD AND SERVER FOR A TEXT-TO-SPEECH PROCESSING
4y 7m to grant Granted Apr 14, 2026
Patent 12602605
QUANTUM COMPUTER ARCHITECTURE BASED ON MULTI-QUBIT GATES
3y 11m to grant Granted Apr 14, 2026
Patent 12591915
METHODS AND SYSTEMS FOR DETERMINING RECOMMENDATIONS BASED ON REAL-TIME OPTIMIZATION OF MACHINE LEARNING MODELS
5y 0m to grant Granted Mar 31, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
62%
Grant Probability
88%
With Interview (+25.1%)
3y 3m (~6m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 160 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month