FINAL REJECTION, SECOND DETAILED ACTION
Status of Prosecution
The present application, 18/561,104 filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
The application was filed in the Office on November 15, 2023 and is a section 371 national stage application of PCT/US2022/052814 filed on Dec. 14, 2022.
The Office mailed a non-final rejection, first detailed action on June 19, 2026.
Applicant’s representative Melanie Chernoff initiated an interview on Aug. 3, 2026. Amendments with accompanying remarks and arguments were filed on Aug. 11, 2026.
Claims 1-20 are pending and all are rejected. Claims 1, 12 and 20 are independent claims.
Status of Claims
Claims 1-2, 5-8, 12-13 and 16-20 are rejected under 35 USC. § 103 as being unpatentable over Luo et al. (“Luo”), United States Patent 10,853,696 published on Dec. 1, 2020 in view of non-patent literature Kim et al. (“Koo”), “Training with the Invisibles: Obfuscating Images to Share Safely for Learning Visual Recognition Models,” published Jan. 1, 2019.
Claims 3-4 and 14-15 are rejected under 35 USC. § 103 as being unpatentable over Luo in view of Kim in further view of non-patent literature in view of non-patent literature Yuan et al., (“Yuan”), Stealthy Porn: Understanding Real-World Adversarial Images for Illicit Online Promotion,” published in 2023 (Applicant-cited).
Claims 9-11 are rejected under 35 USC. § 103 as being unpatentable over Luo in view of Kim in further view of non-patent literature in view of Cao et al., (“Cao”), United States Patent Application 10,824,897 published in Nov. 3, 2020.
Response to Remarks and Arguments
Examiner thanks Applicant’s representative for the courtesies extended during the Aug. 3, 2026 interview.
First regarding the § 112 rejection, Examiner has considered the amendment and finding it sufficient to traverse, withdraws.
Second, regarding the § 101 subject matter rejection, Examiner has considered the arguments presented and finds them persuasive. Therefore, the rejection is withdrawn.
Finally, regarding the prior art rejections, Examiner has considered the amendments. Examiner has newly-rejected the claims with the application of non-patent literature Kim et al. (“Koo”), “Training with the Invisibles: Obfuscating Images to Share Safely for Learning Visual Recognition Models,” published Jan. 1, 2019 which teaches the newly amended language.
Examiner also notes in response to Remarks that Luo’s different classification and models are not as required by the claim as presented. Luo teaches that the embedding and the classification models may be one. (Luo: col. 20, lines to 14, “FIG. 5 shows the classification model 520 as a 10 separate model than the embedding model 510; however, in various embodiments, the classification model 520 comprises one or more layers included in the embedding model 510.”).
The claims stand rejected.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. § 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
A.
Claims 1-2, 5-8, 12-13 and 16-20 are rejected under 35 USC. § 103 as being unpatentable over Luo et al. (“Luo”), United States Patent 10,853,696 published on Dec. 1, 2020 in view of non-patent literature Kim et al. (“Koo”), “Training with the Invisibles: Obfuscating Images to Share Safely for Learning Visual Recognition Models,” published Jan. 1, 2019.
As to Claim 1, Luo teaches: A method, comprising:
receiving as input to a machine learning model, by one or more processors, training images (Luo: Fig. 4, col. 16, lines 11 to 32, the online system obtains a set of training images at step [410]);
associating, by the one or more processors, at least one label of a first set of labels to respective training images, wherein the first set of labels includes policy labels relating to a policy for approving content for publication(Luo: col. 16, lines 24 to 28, “Each training image of the set is labeled with a combination of a maintained policy that a training image of the set was determined to have violated and a source from which the training image was obtained by the online system”) ; and
training, by the one or more processors based on the training images and the associated at least one label of the first set of labels, the machine learning model (Luo: col. 17, lines 34 to 38, “to train a machine learning embedding model that generates an embedding describing evaluation of images against 35 one or more of the maintained policies, the online system applies the machine learning embedding model to each training image of the set”; Examiner also notes that the embedding and the classification models may be one as noted in col. 20, lines to 14, “FIG. 5 shows the classification model 520 as a 10 separate model than the embedding model 510; however, in various embodiments, the classification model 520 comprises one or more layers included in the embedding model 510.”), wherein:
the policy predictions include an indication of a violation or approval based on the respective policy labels (Luo: col. 18, lines 60 to 63, the violation is based on the respective policy label per the embedding training process).
PNG
media_image1.png
852
452
media_image1.png
Greyscale
Luo may not explicitly teach: wherein the training images includes at least one obfuscated training image, and
the machine learning model is trained to output policy predictions at least for obfuscated images without de-obfuscating the obfuscated images.
Kim is non-patent literature that teaches obfuscating the images so that humans are not able to recognize their detailed contents, while machines can still utilize them to train new models. (Kim: Abstract). Specifically, Kim teaches that obfuscated images are used as training images (Kim: Fig. 1, the Obfuscating Network (O) is used to feed into a new network of interest (F) with the obfuscated training set (X’, y)). Classification labels are also used to denote aspects of the image (Kim: Sec. 3.1, y is a classification label for each sample, per the classification task equation). The training takes place directly on the obfuscated images, therefore not de-obfuscating the obfuscated images.
PNG
media_image2.png
574
390
media_image2.png
Greyscale
It would have been obvious to a person having ordinary skill in the art at a time before the effective filing date of the invention to have modified the Luo apparatuses and processes and devices by utilizing obfuscated images as taught by Kim. Such a person would have been motivated to do so with a reasonable expectation of success to allow for “recognition-aware obfuscation,” allowing for the sharing of images so that people cannot recognize the image contents yet can still bused to train a model for a given recognition task (Kim: Sec. 3).
As to Claim 2, Luo and Kim teach the elements of claim 1.
Luo further teaches: wherein the policy labels indicate a policy violation or a policy approval (Luo: col. 18, lines 60 to 63, “where the classification model predicts a maintained policy violated by an image based on the embedding generated for the image”).
As to Claim 5, Luo and Kim teach the elements of claim 1.
Luo further teaches: executing the machine learning model to identify violative content, the executing comprising:
receiving one or more images as input into the machine learning model(Koo: col. 2, lines 62 to 66, the n discriminators are capable of determining a respective reference images to allow for the generation of obfuscation image scores); and
determining, using the machine learning model, a policy prediction for each of the one or more images (Luo: col. 18, lines 60 to 63, the violation is based on the respective policy label per the embedding training process).
As to Claim 6, Luo and Kim teach the elements of claim 5.
Luo further teaches: wherein the policy prediction for each of the one or more images includes an indication of a violation or approval (Luo: col. 18, lines 60 to 63, “where the classification model predicts a maintained policy violated by an image based on the embedding generated for the image”).
As to Claim 7, Luo and Kim teach the elements of claim 6.
Luo further teaches: wherein when the policy prediction includes the violation indication, the method further includes rejecting, by the one or more processors, the respective image such that the respective image is not provided for output (Luo: col. 16, lines 3 to 10, a policy may prevent presentation of images including “violent content … illegal content … [or] offensive test”).
As to Claim 8, Luo and Kim teach the elements of claim 6.
Luo and Kim may not explicitly teach: wherein when the policy prediction includes the approval indication, the method further includes providing for output, by the one or more processors, the respective image.
It would have been obvious to a person having ordinary skill in the art at a time before the effective filing date of the application to have further implemented the Luo- Kim disclosures and teachings by outputting for presentation the content that is not violative of a policy and therefore approved. Such a person would have been motivated to do so with a reasonable expectation of success to allow for non-violative content to be eligible for presentation for regular use cases.
As to Claim 12, it is rejected for similar reasons as claim 1.
As to Claim 13, it is rejected for similar reasons as claim 2.
As to Claim 16, it is rejected for similar reasons as claim 5.
As to Claim 17, it is rejected for similar reasons as claim 6.
As to Claim 18, it is rejected for similar reasons as claim 7.
As to Claim 19, it is rejected for similar reasons as claim 8.
As to Claim 20, it is rejected for similar reasons as claim 1 and 12.
B.
Claims 3-4 and 14-15 are rejected under 35 USC. § 103 as being unpatentable over Luo et al. (“Luo”), United States Patent 10,853,696 published on Dec. 1, 2020 in view of non-patent literature Kim et al. (“Koo”), “Training with the Invisibles: Obfuscating Images to Share Safely for Learning Visual Recognition Models,” published Jan. 1, 2019 in further view of non-patent literature in view of non-patent literature Yuan et al., (“Yuan”), Stealthy Porn: Understanding Real-World Adversarial Images for Illicit Online Promotion,” published in 2023.
As to Claim 3, Luo and Kim teach the elements of claim 1.
Luo and Koo further teaches: associating, by the one or more processors, at least one label of a second set of labels to the respective training images (Luo: col. 16, line 66 to col. 17, lines 5, the images labeled with a combination of a maintained policy violated by the image and source from which the training images were obtained; Koo, col. 5, lines 16 to 20, the images are labeled with information about the image regions).
Luo and Kim may not explicitly teach: wherein the second set of labels includes obfuscation labels.
Yuan is an academic paper that generally discusses the weaknesses of deep learning with respect o adversarial techniques involving cybercriminal and image-based detection schemes (Yuan: Abstract). Specifically, Yuan teaches that adversarial explicit content are in obfuscated images that are distributed for illicit online advertising, phishing and other insidious purposes (Yuan: p. 1). A model is proposed that is able to detect different types of obfuscation tricks or methodologies (Yuan: Sec. V.B, p. 8, the obfuscation techniques include color manipulation, rotation, noising, texturing, blurring, occlusion and transparentizing and overlay).
It would have been obvious to a person having ordinary skill in the art at a time before the effective filing date of the application to have modified the Luo- Kim disclosures and teachings by implementing the labels with obfuscation information labels as taught and suggested by Yuan. Such a person would have been motivated to do so with a reasonable expectation of success to better understand the different obfuscation techniques and sources of the images for the user and the model (Yuan: Sec. V.B, p. 8).
As to Claim 4, Luo, Kim and Yuan teach the elements of claim 3.
Yuan further teaches: wherein the obfuscation labels identify a type of obfuscation of a plurality of obfuscation types (Yuan: Sec. V.B, p. 8, the obfuscation techniques include color manipulation, rotation, noising, texturing, blurring, occlusion and transparentizing and overlay).
As to Claim 14, it is rejected for similar reasons as claim 3.
As to Claim 15, it is rejected for similar reasons as claim 4.
C.
Claims 9-11 are rejected under 35 USC. § 103 as being unpatentable over Luo et al. (“Luo”), United States Patent 10,853,696 published on Dec. 1, 2020 in view of non-patent literature Kim et al. (“Koo”), “Training with the Invisibles: Obfuscating Images to Share Safely for Learning Visual Recognition Models,” published Jan. 1, 2019 in further view of non-patent literature in view of Cao et al., (“Cao”), United States Patent Application 10,824,897 published in Nov. 3, 2020.
As to Claim 9, Luo and Kim teach the elements of claim 1.
Luo further teaches: further executing the machine learning model to identify violative content (Luo: col. 18, lines 60 to 63, the violation is based on the respective policy label per the embedding training process);
Luo may not explicitly teach: the executing comprising detecting that one or more images received as input are one or more obfuscated images.
Cao teaches in general concepts related to an online system receiving an image associated with a set of pixel values and providing the set of pixel values to a model. The model is used to determine whether a protected brand, possibly obfuscated, is detected (Cao: Abstract). Specifically, Cao teaches that obfuscated images are detected (Cao: Fig. 3, col. 9m lines 33 to 43, the detection module [245] detects obfuscated identity of the brand).
PNG
media_image3.png
938
645
media_image3.png
Greyscale
It would have been obvious to a person having ordinary skill in the art at a time before the effective filing date of the application to have modified the Luo- Kim disclosures and teachings by implementing the obfuscation detection as taught and suggested by Cao. Such a person would have been motivated to do so with a reasonable expectation of success to determine and accordingly label the region of interest in the image (Cao: col. 9, lines 55 to 60).
As to Claim 10, Luo, Kim and Cao teach the elements of claim 9.
Cao further teaches: further comprising detecting target concept of the one or more obfuscated images (Cao: col. 7, lines 14 to 18, the machine-learning module [230] may assign regions of interest within an image to one or more classes (i.e. a target concept).
As to Claim 11, Luo, Kim and Cao teach the elements of claim 10.
Cao further teaches: further comprising comparing the detected target concept to a target concept of a content host (Cao: Abstract, the online system compares each embedding to a database of embeddings) .
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Prior art made of the record:
Edwards et al. (“Edwards”), United States Patent Application Publication 2019/0188830 (June 20, 2019) (discussing adversarial training network to determine privacy protection layer for image obfuscation).
Any inquiry concerning this communication or earlier communications from the examiner should be directed to JAMES T TSAI whose telephone number is (571)270-3916. The examiner can normally be reached M-F 8-5 Eastern.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Viker Lamardo can be reached on 571-270-5871. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/JAMES T TSAI/Primary Examiner, Art Unit 2147