Prosecution Insights
Last updated: August 17, 2026
Application No. 18/549,371

Systems and Methods for Non-Destructive Detection of Hardware Anomalies

Non-Final OA §103
Filed
Sep 07, 2023
Priority
Mar 12, 2021 — provisional 63/160,601 +1 more
Examiner
HAJIABBASI, AMIR MAHDI
Art Unit
2407
Tech Center
2400 — Computer Networks
Assignee
Battelle Memorial Institute
OA Round
3 (Non-Final)
86%
Grant Probability
Favorable
3-4
OA Rounds
0m
Est. Remaining
95%
With Interview

Examiner Intelligence

Grants 86% — above average
86%
Career Allowance Rate
24 granted / 28 resolved
+27.7% vs TC avg
Moderate +9% lift
Without
With
+8.9%
Interview Lift
resolved cases with interview
Typical timeline
2y 6m
Avg Prosecution
9 currently pending
Career history
39
Total Applications
across all art units

Statute-Specific Performance

§101
4.8%
-35.2% vs TC avg
§103
60.3%
+20.3% vs TC avg
§102
13.5%
-26.5% vs TC avg
§112
16.7%
-23.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 28 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claims 1, 10, and 20 are independent and amended. Claims 1-2, 4-26 are pending. No claims are new. Claim 3 is canceled. Amendments to the claims have been accepted. Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 03/06/2026 has been entered. Response to Arguments Applicant’s arguments, see pp. 8-11 (pp. 1-4 of Remarks), filed 03/06/2026, with respect to the rejection(s) of claim(s) 1-2, 4-6, 10-16, 20-23, and 26 under 35 U.S.C. § 103 over Prvulovic in view of Daniel have been fully considered and are persuasive. Therefore, the rejection has been withdrawn. However, upon further consideration, a new ground(s) of rejection is made in view of 35 U.S.C. § 103 over Prvulovic in view of Daniel and Xie. Claim Rejections - 35 USC § 103 The text of those sections of Title 35, U.S. Code not included in this action can be found in a prior Office action. Claim(s) 1, 2, 4-6, 10-16, 20-23, and 26 is/are rejected under 35 U.S.C. 103 as being unpatentable over Prvulovic (Prvulovic et al., US 20180012020 A1, cited in prior office action) in view of Daniel (Daniel et al., US 20190377870 A1, cited in a prior office action) and Xie (Xie et al., 'Hardware Trojans classification based on controllability and observability in gate-level netlist', 2017). Regarding Claim 1, Prvulovic teaches a computer-implemented method for providing hardware anomaly detection, the computer-implemented method comprising: receiving, by one or more computer processors, a Radio Frequency (RF) signal emitted by a target device (¶74, "The sensor 410 may detect signals from a monitored device (i.e., the monitored system 350) using, for example, a sophisticated purpose-designed antenna/probe array that can detect and amplify signals (i.e., side channel emissions)" ¶86, "Near-field antennas, such as magnetic probes, may be used for detecting frequencies up to 100 MHz because the antennas will be in the near field even when they are 10 feet away from the monitored device.", the signals that are picked up can be radio waves (Radio Frequency Signal)); decomposing, by the one or more computer processors, the received signal from the target device into a plurality of windows, wherein each window is a time slice (Fig. 4, Separator 424, ¶110, the signal(s) are turned into sequences of overlapping windows. ¶7, the window represents a portion of time); determining, by the one or more computer processors, at least one hardware anomaly condition for the target device based on a first hardware anomaly model and the plurality of windows (Fig. 4, Analyzer 430, Verifier 440, ¶110, 145, ¶146, the verifier collects statistical data related to the sequence of hardware interaction event and analyzes it to determine whether an anomaly has occurred. ¶124, the analyzer used for verification of detected anomalies is a hardware/software interactions model); and executing, by the one or more computer processors, at least one predetermined action based on the at least one hardware anomaly condition (Fig. 4, Anomaly Reporter 450, ¶79, anomalies are reported and used to perform actions such as sending notifications of the anomaly or shutting down devices with the anomaly). Prvulovic does not teach that the first hardware anomaly model is trained to detect one or more powered-on anomalies for a target device. In an analogous art, Daniel teaches an anomaly model that is trained to detect one or more powered-on anomalies for a target device (¶103, ¶104, ¶106, Fig. 7B, attacks on a device are simulated (powered-on anomalies) to create RF signal data regarding malicious attacks. ¶146, the data is used to train a model to detect attacks). One of ordinary skill in the art prior to the effective filing date of the claimed invention could modify Prvulovic using Daniel to train the hardware anomaly model to detect one or mor powered-on anomalies for the target device, as training models to detect anomalies using pre-existing signals based on sensed RF signals known to be indicative of an attack can be done no matter the type of attack as long as the attack alters the RF signals used to train the model (the altering of which both Prvulovic and Daniel teach). It would be obvious to one of ordinary skill prior to the effective filing date of the claimed invention to modify Prvulovic using Daniel to train the hardware anomaly model to detect one or more powered-on anomalies for a target device because having the model already be trained to perform the detection would mean that the model would be ready to be used when first deployed in a practical setting. Prvulovic in view of Daniel does not teach but, in an analogous art, Xie teaches an anomaly model that is trained to detect one or more powered-off anomalies (p.6, '2.4 SVM-based classifier training and hardware Trojan classification'; a SVM (anomaly model) is trained to detect hardware Trojans (anomalies). p.5, 2.2, '2.2 Testability feature extraction'; the data used as input for the models are SCOAP data. pp. 3-4, '2.1 Controllability and observability analysis', "To hide the activity of Hardware Trojans, the trigger might be connected to nets with low activity to create a rare triggering vector…"; the hardware Trojan anomalies are usually inactive (powered-off anomalies), and how active each circuit is can be measured by the SCOAP data.). One of ordinary skill in the art prior to the effective filing date of the claimed invention could modify Prvulovic in view of Daniel using Xie to further train the hardware anomaly model to detect one or more powered-off anomalies for the target device, as Prvulovic, Daniel, and Xie all regard the performance of simulation of hardware anomalies to obtain the training data for the machine learning models (Prvulovic, ¶7; Daniel, ¶103- ¶106, ¶146; Xie, p.3, '2 Proposed method'). It would be obvious for one of ordinary skill in the art prior to the effective filing date of the claimed invention to modify Prvulovic in view of Daniel using Xie to further train the hardware anomaly model to detect one or more powered-off anomalies for the target device because it would allow for the detection of hardware-anomalies that only rarely get activated under ordinary verification scenarios (Xie, p.2, '1 Introduction', "Dynamic detection techniques generally judge a circuit according to the activation of HT parts. However, HTs are often latent and rarely activated under ordinary functional verification constrains thus hard to discover. By contrast, static detection techniques do not require any test pattern generation and, hence, the consequences of detection get rid of the effects of simulation consequences.") Regarding Claim 10 and substantially claim 20, Prvulovic in view of Daniel and Xie teaches the limitations substantially similar to those of claim 1 as shown above. Prvulovic further teaches a system/apparatus for implementing the method substantially similar to that of claim 1, the system/apparatus comprising: a Radio Frequency (RF) front-end (Prvulovic, ¶74, ¶86, the signals that are picked up by the antenna (front-end) can be radio waves (Radio Frequency)); one or more computer processors; one or more computer readable storage media and program instructions stored on the one or more computer readable storage media for execution by at least one of the one or more computer processors (Prvulovic, ¶151). Regarding Claim 2, Prvulovic in view of Daniel and Xie teaches the computer-implemented method of claim 1, wherein the first hardware anomaly model uses artificial intelligence; and the artificial intelligence is selected from the group consisting of machine learning, neural networks, and combinations thereof (Prvulovic, ¶7, ¶136, ¶137, machine learning is used for the model for its determining of anomalies or not). Regarding claim 12, Prvulovic in view of Daniel and Xie teaches the system of claim 10, wherein the first hardware anomaly model uses artificial intelligence (Prvulovic, ¶7, ¶136, ¶137, machine learning is used for the model for its determining of anomalies or not). Regarding Claim 13, and substantially claim 22, Prvulovic in view of Daniel and Xie teaches the system of claim 12, wherein the artificial intelligence is selected from the group consisting of machine learning, neural networks, and combinations thereof (Prvulovic, ¶7, ¶136, ¶137, machine learning is used for the model for its determining of anomalies or not). Regarding Claim 4 and substantially claims 14 and 23, Prvulovic in view of Daniel and Xie teaches the computer-implemented method of claim 2, wherein the first hardware anomaly model is trained to detect at least one of a hardware failure caused by a mechanical failure, the hardware failure caused by overheating, the hardware failure caused by heating/cooling/heating cycles, a cache attack, a memory attack, other exploit attack, covert communication, and combinations thereof (Prvulovic, ¶5, "… thermal attacks rely on variations in system temperature when different operations are executed… Cache-based attacks use a malicious process running on the same machine to extract secrets by observing which memory blocks are accessed by the target application". ¶77, ¶124, cache misses are noted. ¶149, programs are monitored to detect various kinds of attacks (exploits). See also Xie, p.1, '1 Introduction', "HTs can transform IC functionality, reveal valuable information, reduce reliability, and even incapacitate a chip"). Regarding Claim 5 and substantially claim 15, Prvulovic in view of Daniel and Xie teaches the computer-implemented method of claim 1, wherein the at least one hardware anomaly condition for the target device comprises an unknown exploit occurring on the target device (Prvulovic, ¶5, ¶21, ¶35, ¶77, the patterns of cache activity are high unlikely, and are used to determine that an anomaly exists, but do not identify the attack itself other than being cache-related). Regarding Claim 6 and substantially claim 16, Prvulovic in view of Daniel and Xie teaches the computer-implemented method of claim 1, wherein the at least one predetermined action includes causing an alert to be displayed to a user (Prvulovic, ¶79, the anomaly is reported by the anomaly reporter by sending a notification. ¶68, received information is displayed to a user). Regarding Claim 11 and substantially claim 21, Prvulovic in view of Daniel and Xie teaches the system of claim 10, wherein the RF front-end further comprises: an antenna interface; and an antenna, wherein the antenna is electrically coupled to the antenna interface (Prvulovic, ¶62, "Example implementations of the computing device architecture 200 may include an antenna interface 210 that provides a communication interface to an antenna;"). Regarding Claim 26, Prvulovic in view of Daniel and Xie teaches the computer-implemented method of claim 1. Daniel further teaches that a target exploit type is simulated on the target device to generate a Radio Frequency (RF) signal with representations of one or more instructions to indicate the target exploit; and the generated RF signal is used for training and/or verification of the hardware anomaly model for the target exploit type (Daniel, ¶103, ¶104, ¶106, Fig. 7B, malicious software attacks (instructions that indicate a target exploit) on a device are simulated to create RF signal data regarding malicious attacks. ¶146, the data is used to train a model to detect attacks (anomaly conditions)) (see claim 1 for motivation to combine). Claim(s) 7 and 17 is/are rejected under 35 U.S.C. 103 as being unpatentable over Prvulovic in view of Daniel and Xie as applied to claims 1 and 10 above, and further in view of Bhatkar (Bhatkar et al., US 8555385 B1, cited in a prior office action). Regarding Claim 7 and substantially claim 17, Prvulovic in view of Daniel and Xie teaches the computer-implemented method of claim 1. Prvulovic teaches a predetermined exploit occurring on the target device (Prvulovic, ¶12, "The signal processing may include signal processing, responsive to identifying a potential anomaly and based on the software model and the HW/SW interaction model of the monitored device, the portions of the one or more signals having the identified potential anomaly", ¶149, known/named exploits are detected on the target device). Prvulovic in view of Daniel and Xie does not teach the rest of the claim. In an analogous art, Bhatkar teaches that the at least one hardware anomaly condition comprises a first detected hardware anomaly condition and a second detected hardware anomaly condition, and wherein the first detected hardware anomaly condition comprises a hardware failure condition ((Col:Lines) 5:57-63, "According to some embodiments, behavior based analysis module 154 may identify other patterns of behavior in addition to or instead of malware behavior patterns. For example, behavior based analysis module 154 may identify program bugs, hardware failures, network anomalies, and other patterns for which rules may be provided to match against a plurality of observable events") and the second detected hardware anomaly condition comprises a predetermined exploit occurring on the target device (9:42-47, "According to some embodiments, behavior based analysis module 154 may match one or more extracted high level behaviors against a plurality of signatures to identify and/or classify a malware sample. For example, a signature (e.g., a rule set identifying one or more high level behaviors) may be used to classify malware into a family of threats."; 9:12-16, “For example, a non-process threat may execute and inject code into an memory space of an existing process associated with a benign process. The non-process threat may then create a remote thread associated with the benign process to perform one or more malicious actions.”; the system detect behaviors involving a malicious exploit with the target device (predetermined exploit) 5:47-67, 6:1-10; both the hardware failures and the behavior failures are analyzed). It would be obvious to one of ordinary skill in the art prior to the effective filing date of the invention to modify Prvulovic in view of Daniel and Xie using Bhatkar to detect a hardware failure condition and a predetermined exploit occurring on a target device because hardware failures can have rules to match for analysis (Bhatkar, 5:57-63) and predetermined exploits, as known threats, can have security measures/remedies (Bhatkar, 9:47-49) Claim(s) 8, 18, and 24 is/are rejected under 35 U.S.C. 103 as being unpatentable over Prvulovic in view of Daniel and Xie as applied to claims 1, 10, and 20 above, and further in view of Reedman (Reedman et al., US 20200034529 A1, cited in a prior office action). Regarding Claim 8 and substantially claims 18 and 24, Prvulovic in view of Daniel and Xie teaches the computer-implemented method of claim 1. Prvulovic in view of Daniel and Xie does not teach the rest of the claim. In an analogous art, Reedman teaches that decomposing the received signal from the target device into the plurality of windows, wherein each window is the time slice further comprises: decomposing, by the one or more computer processors, the received signal into In-Phase/Quadrature (I/Q) data (¶10, " The processor may determine a product of the streams of measured time-stamped samples at identical times and convert the product into a real data stream and an imaginary data stream, using I/Q digital signal processing.", ¶46, "The term ‘I/Q digital signal processing’ may denote a signal representation that is much more precise than just using a series of samples of the momentary amplitude of the signal… one may look at it as a corkscrew (helix, spiral, coil spring) in three dimensions. Thus, the I/Q data sample represents the coordinates of a signal as seen down the time axis of the corkscrew. The amplitude modulated sinusoids are known as In-phase and Quadrature components"). It would be obvious to one of ordinary skill in the art prior to the effective filing date of the invention to modify Prvulovic in view of Daniel and Xie using Reedman to decompose, by the one or more computer processors, the received signal into In-Phase/Quadrature (I/Q) data because it solves issues regarding the determination of the frequency/amplitude of the received signal and is much more precise (Reedman, ¶46). Claim(s) 9, 19, and 25 is/are rejected under 35 U.S.C. 103 as being unpatentable over Prvulovic in view of Daniel and Xie as applied to claims 1, 10, and 20 above, and further in view of Kune (Kune et al., US 20180007074 A1, cited in a prior office action). Regarding Claim 9 and substantially claims 19 and 25, Prvulovic in view of Daniel and Xie teaches the computer-implemented method of claim 1. Prvulovic in view of Daniel and Xie does not teach the rest of the claim. In an analogous art, Kune teaches that determining the at least one hardware anomaly condition for the target device based on the first hardware anomaly model and the plurality of windows further comprises: determining, by the one or more computer processors, a power spectral density (¶28, the signal processing modules calculates features such as the power spectral density of a signal) of each window of the plurality of windows, wherein the power spectral density is determined using a discrete Fourier Transform (¶30, the features are calculated using discrete Fourier Transforms on time portions/windows of the signal); and determining, by the one or more computer processors, whether an instruction is being executed on the target device using a multi-variate Gaussian probability density function, wherein the multi-variate Gaussian probability density function is a statistical machine learning technique (¶34, an anomaly is detected using statistical techniques such as the usage of standard deviations and means from a multi-dimensional Gaussian probability density function on the machine learning module. ¶43, the anomalies on the target device are malware instructions). It would be obvious to one of ordinary skill in the art prior to the effective filing date of the invention to modify Prvulovic in view of Daniel and Xie using Kune to determine, by one or more computer processors, a power spectral density of each window of a plurality of windows, wherein the power spectral density is determined using a discrete Fourier Transform, and determine whether an instruction is being executed on the target device using a multi-variate Gaussian probability density function, wherein the multi-variate Gaussian probability density function is a statistical machine learning technique, because the determined features can be used by a machine learning module to detect anomalies (Kune, ¶33). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Meriac (MERIAC et al., US 20190391888 A1) teaches determining whether a hardware component was active (powered-on) or not (powered-off) during a hardware anomaly (¶31). Kels (KELS et al., US 20220201023 A1) teaches taking behavioral information from an inactive device and inputting the information into a trained machine-learning model to determine if there is an anomaly with the inactive device (¶22, ¶41). Amida ('Enabling Hardware Trojan Detection and Prevention through Emulation', 2018) teaches Trojan payloads that leak data by modulating a temperature hot spot (p. 1), as well as a hardware Trojans triggered by RF signals (p. 5, 'A. Hardware Emulation') prior to its activation (p. 7, "… to detect the difference in the side-channel statistics after a Trojan has been operated or activated or, if possible, after a Trojan has been included in the design, but before activation. ") and performing classification via a machine learning model (p. 8). Any inquiry concerning this communication or earlier communications from the examiner should be directed to AMIR MAHDI HAJIABBASI whose telephone number is (703)756-5511. The examiner can normally be reached M-F 7:30-5 EST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Catherine Thiaw can be reached at (571) 270-1138. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /A.M.H./ Amir Mahdi HajiabbasiExaminer, Art Unit 2407 /Catherine Thiaw/Supervisory Patent Examiner, Art Unit 2407 7/22/2026
Read full office action

Prosecution Timeline

Sep 07, 2023
Application Filed
Jun 25, 2025
Non-Final Rejection mailed — §103
Sep 05, 2025
Response Filed
Oct 29, 2025
Final Rejection mailed — §103
Mar 06, 2026
Request for Continued Examination
Mar 17, 2026
Response after Non-Final Action
Jul 24, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12705340
DETECTION OF MALICIOUS DIRECT MEMORY ACCESS DEVICE USED FOR DIRECT DEVICE ASSIGNMENT
2y 9m to grant Granted Aug 11, 2026
Patent 12682071
Software Security Defect Prediction Methods and Devices
2y 5m to grant Granted Jul 14, 2026
Patent 12682045
FAULT-ATTACK ANALYSIS DEVICE AND METHOD
2y 7m to grant Granted Jul 14, 2026
Patent 12670266
SECURE MULTI-PARTY COMPUTATION
2y 9m to grant Granted Jun 30, 2026
Patent 12664270
CONNECTED ASSET RISK MANAGEMENT
2y 3m to grant Granted Jun 23, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
86%
Grant Probability
95%
With Interview (+8.9%)
2y 6m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 28 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month