DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Information Disclosure Statement
The information disclosure statement(s) (IDS) submitted on 3/27/2024 is/are in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement(s) is/are being considered by the examiner.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claim 18 is rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Regarding Claim 18, the claim lacks antecedent basis for “the second trigger score” and “the third trigger score”. The claim appears to correspond to claims 5 and 12, which recite similar limitations. For purposes of examination, claim 18 will be construed as reciting “develop a second trigger score for a second initial input token and a third trigger score for a third initial input token” prior to the “calculate an average trigger score” limitation.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Step 1: Claims 1-7 are directed to a process. Claims 8-20 are directed to a machine or an article of manufacture.
With respect to claim(s) 1, 8, and 14:
2A Prong 1: The claim(s) recite(s) an abstract idea. Specifically:
developing/develop a trigger score for a particular initial input token of the initial input prompt based on the attention scores; (Mental process – A person can develop a trigger score for a token of an input based on attention scores via mind or by using pen and paper – see MPEP § 2106.04(a)(2)(III))
determining/determine that the trigger score meets a trigger flag condition; (Mental process – A person can determine that a score meets a trigger flag condition via mind – see MPEP § 2106.04(a)(2)(III))
creating/create, based on the determining, a sanitized input prompt, wherein the sanitized input prompt does not include the particular initial input token; (Mental process – A person can create a sanitized input prompt by removing the particular token via mind or by using pen and paper – see MPEP § 2106.04(a)(2)(III))
If claim limitations, under their broadest reasonable interpretation, cover performance of the limitations as a mental process, but for the recitation of generic computer components, then the claim limitations fall within the mathematical or mental process grouping of abstract ideas. Accordingly, the claim “recites” an abstract idea.
2A Prong 2: The additional elements recited in the claim(s) do not integrate the abstract idea into a practical application, individually or in combination.
Additional elements:
(Claim 1) A method of comprising: (Mere instructions to apply an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea – see MPEP 2106.05(f).)
(Claim 8) A system comprising: a processor; and a memory in communication with the processor, the memory containing program instructions that, when executed by the processor, are configured to cause the processor to perform a method, the method comprising: (Mere instructions to apply an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea – see MPEP 2106.05(f).)
(Claim 14) A computer program product, the computer program product comprising a computer readable storage medium having program instructions embodied therewith, the program instructions executable by a computer to cause the computer to: (Mere instructions to apply an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea – see MPEP 2106.05(f).)
(Claim 1) obtaining an initial output that was generated by a generative large language model (generative LLM) in response to processing an initial input prompt; (Mere instructions to apply an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea – see MPEP 2106.05(f).)
(Claims 8 and 14) obtaining/obtain an initial output that was generated by a generative large language model (generative LLM) in response to processing an initial input prompt; (Mere instructions to apply an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea – see MPEP 2106.05(f).)
extracting/extract, based on an attention layer of the generative LLM, attention scores for the initial input prompt; (Mere instructions to apply an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea – see MPEP 2106.05(f).)
prompting/prompt the generative large language model with the sanitized input prompt. (Mere instructions to apply an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea – see MPEP 2106.05(f).)
Since the claim as a whole, looking at the additional elements individually and in combination, does not contain any other additional elements that are indicative of integration into a practical application, the claim is directed to an abstract idea.
2B: The claim(s) do(es) not include additional elements that are sufficient to amount to significantly more than the judicial exception.
Additional elements:
(Claim 1) A method of comprising: (Mere instructions to apply an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea – see MPEP 2106.05(f).)
(Claim 8) A system comprising: a processor; and a memory in communication with the processor, the memory containing program instructions that, when executed by the processor, are configured to cause the processor to perform a method, the method comprising: (Mere instructions to apply an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea – see MPEP 2106.05(f).)
(Claim 14) A computer program product, the computer program product comprising a computer readable storage medium having program instructions embodied therewith, the program instructions executable by a computer to cause the computer to: (Mere instructions to apply an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea – see MPEP 2106.05(f).)
(Claim 1) obtaining an initial output that was generated by a generative large language model (generative LLM) in response to processing an initial input prompt; (Mere instructions to apply an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea – see MPEP 2106.05(f).)
(Claims 8 and 14) obtaining/obtain an initial output that was generated by a generative large language model (generative LLM) in response to processing an initial input prompt; (Mere instructions to apply an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea – see MPEP 2106.05(f).)
extracting/extract, based on an attention layer of the generative LLM, attention scores for the initial input prompt; (Mere instructions to apply an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea – see MPEP 2106.05(f).)
prompting/prompt the generative large language model with the sanitized input prompt. (Mere instructions to apply an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea – see MPEP 2106.05(f).)
Considering the additional elements individually and in combination, and the claim as a whole, the additional elements do not provide significantly more than the abstract idea. Therefore, the claim is not patent eligible.
With respect to claim(s) 2, 9, and 15:
2A Prong 2: The additional elements recited in the claim(s) do not integrate the abstract idea into a practical application, individually or in combination.
Additional elements:
wherein the extracting comprises extracting the attention scores for the particular initial input token with respect to all output tokens in the initial output. (Mere instructions to apply an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea – see MPEP 2106.05(f).)
2B: The claim(s) do(es) not include additional elements that are sufficient to amount to significantly more than the judicial exception.
Additional elements:
wherein the extracting comprises extracting the attention scores for the particular initial input token with respect to all output tokens in the initial output. (Mere instructions to apply an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea – see MPEP 2106.05(f).)
Since the claim does not recite additional elements that either integrate the judicial exception into a practical application, nor provide significantly more than the judicial exception, the claim is not patent eligible. Therefore, the claim is not patent eligible.
With respect to claim(s) 3, 10, and 16:
2A Prong 2: The additional elements recited in the claim(s) do not integrate the abstract idea into a practical application, individually or in combination.
Additional elements:
wherein the extracting comprises extracting the attention scores for an attention layer that corresponds to a last layer of the generative LLM. (Mere instructions to apply an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea – see MPEP 2106.05(f).)
2B: The claim(s) do(es) not include additional elements that are sufficient to amount to significantly more than the judicial exception.
Additional elements:
wherein the extracting comprises extracting the attention scores for an attention layer that corresponds to a last layer of the generative LLM. (Mere instructions to apply an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea – see MPEP 2106.05(f).)
Since the claim does not recite additional elements that either integrate the judicial exception into a practical application, nor provide significantly more than the judicial exception, the claim is not patent eligible. Therefore, the claim is not patent eligible.
With respect to claim(s) 4, 11, and 17:
2A Prong 1: The claim(s) recite(s) an abstract idea. Specifically:
wherein developing the trigger score for the particular initial input token comprises calculating the average of all attention scores for the particular initial input token. (Mathematical concepts – Calculating the average of scores involves mathematical calculations – see MPEP § 2106.04(a)(2)(I))
Additionally, the claim(s) do not recite any new additional elements that would amount to an integration of the abstract idea into a practical application (individually or in combination) or significantly more than the judicial exception.
Since the claim does not recite additional elements that either integrate the judicial exception into a practical application, nor provide significantly more than the judicial exception, the claim is not patent eligible. Therefore, the claim is not patent eligible.
With respect to claim(s) 5, 12, and 18:
2A Prong 1: The claim(s) recite(s) an abstract idea. Specifically:
developing a second trigger score for a second initial input token and a third trigger score for a third initial input token, (Mental process – A person can develop trigger scores for tokens of an input based on attention scores via mind or by using pen and paper – see MPEP § 2106.04(a)(2)(III))
[(Claims 5 and 12) wherein the determining comprises] calculating/calculate an average trigger score using the trigger score, the second trigger score, and the third trigger score; and (Mathematical concepts – Calculating the average of scores involves mathematical calculations – see MPEP § 2106.04(a)(2)(I))
determining/determine that the trigger score exceeds the average trigger score by above a pre-determined number of standard deviations. (Mental process – A person can determine that a score exceeds an average by above a pre-determined number of standard deviations via mind or using a pen and paper – see MPEP § 2106.04(a)(2)(III))
2A Prong 2: The additional elements recited in the claim(s) do not integrate the abstract idea into a practical application, individually or in combination.
Additional elements:
(Claim 18) wherein the program instructions are further executable by a computer to cause the computer to: (Mere instructions to apply an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea – see MPEP 2106.05(f).)
2B: The claim(s) do(es) not include additional elements that are sufficient to amount to significantly more than the judicial exception.
Additional elements:
(Claim 18) wherein the program instructions are further executable by a computer to cause the computer to: (Mere instructions to apply an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea – see MPEP 2106.05(f).)
Since the claim does not recite additional elements that either integrate the judicial exception into a practical application, nor provide significantly more than the judicial exception, the claim is not patent eligible. Therefore, the claim is not patent eligible.
With respect to claim(s) 6, 13, and 19:
2A Prong 2: The additional elements recited in the claim(s) do not integrate the abstract idea into a practical application, individually or in combination.
Additional elements:
(Claim 19) wherein the program instructions are further executable by a computer to cause the computer to: (Mere instructions to apply an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea – see MPEP 2106.05(f).)
obtaining a sanitized output that was generated by the generative LLM in response to processing the sanitized input prompt; and (Mere instructions to apply an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea – see MPEP 2106.05(f).)
providing the sanitized output to a user of the generative LLM. (Adding insignificant extra-solution activity to the judicial exception – see § MPEP2106.05(g).)
2B: The claim(s) do(es) not include additional elements that are sufficient to amount to significantly more than the judicial exception.
Additional elements:
(Claim 19) wherein the program instructions are further executable by a computer to cause the computer to: (Mere instructions to apply an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea – see MPEP 2106.05(f).)
obtaining a sanitized output that was generated by the generative LLM in response to processing the sanitized input prompt; and (Mere instructions to apply an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea – see MPEP 2106.05(f).)
providing the sanitized output to a user of the generative LLM. (Simply appending well-understood, routine, conventional activities previously known to the industry, specified at a high level of generality, to the judicial exception (WURC)- see MPEP § 2106.05(d)(ll)(i) - Receiving or transmitting data over a network, e.g., using the Internet to gather data, Symantec, 838 F.3d at 1321, 120 USPQ2d at 1362 (utilizing an intermediary computer to forward information).)
Since the claim does not recite additional elements that either integrate the judicial exception into a practical application, nor provide significantly more than the judicial exception, the claim is not patent eligible. Therefore, the claim is not patent eligible.
With respect to claim(s) 7 and 20:
2A Prong 1: The claim(s) recite(s) an abstract idea. Specifically:
concluding/conclude, after the determining, that the particular initial input token does not meet a commonality factor, (Mental process – A person can mentally conclude that a token does not meet a commonality factor – see MPEP § 2106.04(a)(2)(III))
wherein the creating the sanitized input prompt is in response to the concluding that the particular initial input token does not meet a commonality factor. (Mental process – A person can create a sanitized input via mind in response to concluding via mind that a token does not meet a commonality factor – see MPEP § 2106.04(a)(2)(III))
2A Prong 2: The additional elements recited in the claim(s) do not integrate the abstract idea into a practical application, individually or in combination.
Additional elements:
(Claim 20) wherein the program instructions are further executable by a computer to cause the computer to: (Mere instructions to apply an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea – see MPEP 2106.05(f).)
2B: The claim(s) do(es) not include additional elements that are sufficient to amount to significantly more than the judicial exception.
Additional elements:
(Claim 20) wherein the program instructions are further executable by a computer to cause the computer to: (Mere instructions to apply an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea – see MPEP 2106.05(f).)
Since the claim does not recite additional elements that either integrate the judicial exception into a practical application, nor provide significantly more than the judicial exception, the claim is not patent eligible. Therefore, the claim is not patent eligible.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1, 3, 8, 10, 14, and 16 are rejected under 35 U.S.C. 103 as being unpatentable over SUN ("Defending Against Backdoor Attacks in Natural Language Generation") in view of HE ("IMBERT: Making BERT Immune to Insertion-based Backdoor Attacks"), hereafter SUN and HE, respectively.
Regarding Claim 1:
SUN further teaches:
A method of comprising: obtaining an initial output that was generated by a generative large language model (generative LLM) in response to processing an initial input prompt; (SUN [page 4, section 5.1 Change in Target Semantics] teaches: “To be specific, given an input source sentence
x
, which we wish to decide whether it is poisoned, a pretrained NLG model
f
(
)
(i.e., a generative large language model) generates an output
y
given
x
:
y
=
f
(
x
)
.” SUN [page 5, Neural Machine Translation] teaches: “All NMT models are based on a standard Transformer-base backbone […].”)
developing a trigger score for a particular initial input token of the initial input prompt based on […]; (SUN [page 4, Trigger word based Methods] teaches: “Specifically, for a specific token
x
i
∈
x
(i.e., for a particular initial input token of the initial input prompt), let
x
'
=
x
\
x
i
denote the string of
x
with
x
i
removed. Here we define
S
c
o
r
e
(
x
i
)
(i.e., developing a trigger score), indicating the likelihood of
x
i
being a trigger word. A higher value of
S
c
o
r
e
(
x
i
)
indicates a higher likelihood of
x
i
being a trigger word.
S
c
o
r
e
x
=
D
i
s
f
x
,
f
x
\
x
i
3
"
Examiner’s note: SUN [page 4, Trigger word based Methods] determines the likelihood of an input token
x
i
being a trigger word based on the BERTScore exceeding a certain threshold value, thus implying that
x
is poisoned.)
determining that the trigger score meets a trigger flag condition; (SUN [page 4, Trigger word based Methods] teaches: “If
D
i
s
(
y
,
y
'
)
exceeds a certain threshold (i.e., determining that the trigger score meets a trigger flag condition), which is a hyperparameter to be tuned on the dev set, it means that the perturbation
x
→
x
'
leads to a significant semantic change in targets, implying that
x
is poisoned. […]
S
c
o
r
e
(
x
)
for the input sentence
x
is obtained by selecting its constituent token
x
i
with the largest value of
S
c
o
r
e
(
x
)
:
S
c
o
r
e
x
i
=
max
x
i
∈
x
D
i
s
f
x
,
f
x
\
x
i
4
"
)
prompting the generative large language model with the sanitized input prompt. (SUN [page 4, section 5.1 Change in Target Semantics] teaches: “Suppose that we perturb
x
to
x
'
, which can be replacing [or] deleting a word in
x
(i.e., the sanitized input prompt), or paraphrase
x
.
x
'
is fed to the pretrained NLG model (i.e., prompting the generative large language model with the sanitized prompt), which generates the output
y
'
=
f
(
x
'
)
.”)
SUN is not relied upon for teaching, but HE teaches: extracting, based on an attention layer of the […], attention scores for the initial input prompt; (HE [page 290, Attention-based Defence] teaches: “Given an input
x
(i.e., for the initial input prompt) with the length of
n
, for each head
h
(i.e., based on an attention layer of the […]), we can obtain a self-attention score matrix
A
h
∈
R
n
×
n
(i.e., extracting […] attention scores). In total we acquire
N
h
such matrices for each self-attention operation.”)
developing a trigger score […] based on the attention scores; (HE [page 290, Attention-based Defence] teaches: “As a second measure to salience, a token is considered a salient element, if it receives significant attention from all tokens per head (Kim et al., 2021; He et al., 2021). Hence, for each token
x
i
, we can compute its saliency score (i.e., developing a trigger score) via: […] Our preliminary experiments found that the saliency scores derived from the last layer of a Transformer are highly correlated to the model predictions. Thus, we use these scores for the sake of identifying suspicious tokens.” HE [page 289, section 3.2. Defence] teaches: “We consider its
l
2
norm
g
∈
R
x
as saliency scores. As we believe that the triggers dominate the final predictions, the tokens with the highest saliency scores are labelled as the suspicious tokens, which can be attained via
a
r
g
m
a
x
g
,
K
function as shown in line 5 of Algorithm 1, where
K
is a hyperparameter.” Examiner’s note: HE [page 290, Attention-based Defence] and [page 289, section 3.2. Defence] disclose computing a saliency score
s
(
x
i
)
from the self-attention score matrix
A
h
(i.e., based on the attention scores) for each input token. Then, Algorithm 1 removes the token from the input sentence
x
based on the tokens with the highest saliency scores, and thus teaches developing a trigger score […] based on the attention scores.)
creating, based on the determining, a sanitized input prompt, wherein the sanitized input prompt does not include the particular initial input token; and (HE [page 289, Token Deletion] teaches: “Once we identify the indices of mistrustful tokens (i.e., based on the determining), we can remove them from the input
x
;” HE [page 289, Algorithm 1] teaches removing the token(s) with highest saliency score from the input
x
and returning the input
x
'
without the suspicious token (i.e., a sanitized input prompt wherein the sanitized input prompt does not include the particular initial input token).)
Accordingly, it would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention, having the teachings of SUN and HE before them, to use HE’s saliency score computation as the trigger for deleting suspicious tokens from inputs in SUN’s method for defending against backdoor attacks in natural language generation. One would have been motivated to make such a combination in order to identify and remove triggers from inputs for defending against insertion-based backdoor attacks (HE [page 289, section 3 Methodology] and [pages 294-295, section 5 Conclusion]).
Regarding Claim 3:
SUN in view of HE teaches the elements of claim 1 as outlined above. SUN further teaches:
[…] the generative LLM. (SUN [page 4, section 5.1 Change in Target Semantics] teaches: “To be specific, given an input source sentence
x
, which we wish to decide whether it is poisoned, a pretrained NLG model
f
(
)
(i.e., the generative large language model) generates an output
y
given
x
:
y
=
f
(
x
)
.” SUN [page 5, Neural Machine Translation] teaches: “All NMT models are based on a standard Transformer-base backbone […].”)
HE further teaches: wherein the extracting comprises extracting the attention scores for an attention layer that corresponds to a last layer of the […]. (HE [page 290, Attention-based Defence] teaches: “Our preliminary experiments found that the saliency scores derived from the last layer of a Transformer (i.e., extracting the attention scores for an attention layer that corresponds to a last layer of the) are highly correlated to the model predictions. Thus, we use these scores for the sake of identifying suspicious tokens.”)
Regarding Claim 8:
The claim recites similar limitations as corresponding claim 1 and is rejected for similar reasons as claim 1 using similar teachings and rationale. SUN further teaches:
A system comprising: a processor; and a memory in communication with the processor, the memory containing program instructions that, when executed by the processor, are configured to cause the processor to perform a method, the method comprising: (SUN [page 5, section 6.1 Attacking Models] teaches that all NMT models used are the version implemented by FairSeq at https://github.com/pytorch/fairseq (see SUN [page 3, footer 1]). Therefore, one of ordinary skill in the art would recognize that a processor, memory in communication with a processor, and memory storing computer-executable program instructions are required to run FairSeq’s source code and to store the hate speech dictionary found in https://hatebase.org/, as shown in SUN [page 3, footer 2].)
Regarding Claim 10:
SUN in view of HE teaches the elements of claim 8 as outlined above. Additionally, the claim recites similar limitations as corresponding claim 3 and is rejected for similar reasons as claim 3 using similar teachings and rationale.
Regarding Claim 14:
The claim recites similar limitations as corresponding claims 1 and 8 and is rejected for similar reasons as claims 1 and 8 using similar teachings and rationale. SUN further teaches:
A computer program product, the computer program product comprising a computer readable storage medium having program instructions embodied therewith, the program instructions executable by a computer to cause the computer to: (SUN [page 5, section 6.1 Attacking Models] teaches that all NMT models used are the version implemented by FairSeq at https://github.com/pytorch/fairseq (see SUN [page 3, footer 1]). Therefore, one of ordinary skill in the art would recognize that a computer program product storing computer-executable program instructions is required to run FairSeq’s source code, as shown in SUN [page 3, footer 1].)
Regarding Claim 16:
SUN in view of HE teaches the elements of claim 14 as outlined above. Additionally, the claim recites similar limitations as corresponding claims 3 and 10 and is rejected for similar reasons as claims 3 and 10 using similar teachings and rationale.
Claims 2, 4, 6, 9, 11, 13, 15, 17, and 19 are rejected under 35 U.S.C. 103 as being unpatentable over SUN in view of HE, as applied respectively above to claims 1, 8, and 14, and further in view of EISENSTADT (US 20240386209 A1), hereafter EISENSTADT.
Regarding Claim 2:
SUN in view of HE teaches the elements of claim 1 as outlined above. SUN in view of HE is not relied upon for teaching, but EISENSTADT teaches:
wherein the extracting comprises extracting the attention scores for the particular initial input token with respect to all output tokens in the initial output. (EISENSTADT [0014] and [0065] teach obtaining attention values (i.e., extracting the attention scores) that define input-output token connections. EISENSTADT [0052] teaches that each attention head produces an
m
×
n
array containing an attention value for each input-output token pair (i.e., for the particular initial input token with respect to all output tokens in the initial output).)
Accordingly, it would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention, having the teachings of SUN, HE, and EISENSTADT before them, to include EISENSTADT’s obtaining of attention values for each input-output pair in SUN and HE’s method for defending against backdoor attacks in natural language generation. One would have been motivated to make such a combination in order to find the tokens with the highest attention values indicating the tokens are more distinct or interesting to look at with regard to interpreting a generative machine learning (ML) model output (EISENSTADT [0058] and [0042]).
Regarding Claim 4:
SUN in view of HE teaches the elements of claim 1 as outlined above. SUN further teaches:
wherein developing the trigger score for the particular initial input token (SUN [page 4, Trigger word based Methods] teaches: “Specifically, for a specific token
x
i
∈
x
(i.e., for a particular initial input token of the initial input prompt), let
x
'
=
x
\
x
i
denote the string of
x
with
x
i
removed. Here we define
S
c
o
r
e
(
x
i
)
(i.e., developing a trigger score), indicating the likelihood of
x
i
being a trigger word. A higher value of
S
c
o
r
e
(
x
i
)
indicates a higher likelihood of
x
i
being a trigger word.
S
c
o
r
e
x
=
D
i
s
f
x
,
f
x
\
x
i
3
"
)
SUN in view of HE is not relied upon for teaching, but EISENSTADT teaches: comprises calculating the average of all attention scores for the particular initial input token. (EISENSTADT [0053-0054] calculates a normalized value by aggregating all attention values related to the input token and at least one output token, and then dividing each aggregated sum by the number of output tokens.)
Accordingly, it would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention, having the teachings of SUN, HE, and EISENSTADT before them, to include EISENSTADT’s calculation of a normalized value from obtained attention values for each input-output pair in SUN and HE’s method for defending against backdoor attacks in natural language generation. One would have been motivated to make such a combination in order to find the tokens with the highest attention values indicating the tokens are more distinct or interesting to look at with regard to interpreting a generative machine learning (ML) model output (EISENSTADT [0058] and [0042]).
Regarding Claim 6:
SUN in view of HE teaches the elements of claim 1 as outlined above. SUN further teaches:
obtaining a sanitized output that was generated by the generative LLM in response to processing the sanitized input prompt; and (SUN [page 4, section 5.1 Change in Target Semantics] teaches generating an output by the NLG model
f
(
)
using sentence
x
'
, which had a word deleted or replaced (i.e., sanitized).)
[…] the sanitized output […] (SUN [page 4, section 5.1 Change in Target Semantics] teaches generating an output (i.e., the sanitized output) by the NLG model
f
(
)
using sentence
x
'
, which had a word deleted or replaced.)
SUN in view of HE is not relied upon for teaching, but EISENSTADT teaches: providing the […] output to a user of the generative LLM. (EISENSTADT [0035] and [0078] teach presenting the summary of the summarization model and visual cue overlays to the user via a user interface.)
Accordingly, it would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention, having the teachings of SUN, HE, and EISENSTADT before them, to include EISENSTADT’s screen display for displaying overlays or summary portions with visual cues in SUN and HE’s method for defending against backdoor attacks in natural language generation. One would have been motivated to make such a combination in order to generate a visual cue for the user highlighting words corresponding to the selected set of tokens for the attention head having the greatest semantic similarity with the selected portion of the summary (EISENSTADT [0078]).
Regarding Claim 9:
SUN in view of HE teaches the elements of claim 8 as outlined above. Additionally, the claim recites similar limitations as corresponding claim 2 and is rejected for similar reasons as claim 2 using similar teachings and rationale.
Regarding Claim 11:
SUN in view of HE teaches the elements of claim 8 as outlined above. Additionally, the claim recites similar limitations as corresponding claim 4 and is rejected for similar reasons as claim 4 using similar teachings and rationale.
Regarding Claim 13:
SUN in view of HE teaches the elements of claim 8 as outlined above. Additionally, the claim recites similar limitations as corresponding claim 6 and is rejected for similar reasons as claim 6 using similar teachings and rationale.
Regarding Claim 15:
SUN in view of HE teaches the elements of claim 14 as outlined above. Additionally, the claim recites similar limitations as corresponding claims 2 and 9 and is rejected for similar reasons as claims 2 and 9 using similar teachings and rationale.
Regarding Claim 17:
SUN in view of HE teaches the elements of claim 14 as outlined above. Additionally, the claim recites similar limitations as corresponding claims 4 and 11 and is rejected for similar reasons as claims 4 and 11 using similar teachings and rationale.
Regarding Claim 19:
SUN in view of HE teaches the elements of claim 14 as outlined above. Additionally, the claim recites similar limitations as corresponding claims 6 and 13 and is rejected for similar reasons as claims 6 and 13 using similar teachings and rationale.
Claims 5, 12, and 18 are rejected under 35 U.S.C. 103 as being unpatentable over SUN in view of HE, as applied respectively above to claims 1, 8, and 14, and further in view of WANG ("Generic Interpretable Reaction Condition Predictions with Open Reaction Condition Datasets and Unsupervised Learning of Reaction Center"), hereafter WANG.
Regarding Claim 5:
SUN in view of HE teaches the elements of claim 1 as outlined above. HE further teaches:
developing a second trigger score for a second initial input token and a third trigger score for a third initial input token, (HE [page 290, Attention-based Defence] computes a saliency score for each token
x
i
, and thus teaches computing trigger scores for
x
i
input tokens.)
SUN in view of HE is not relied upon for teaching, but WANG teaches: wherein the determining comprises: calculating an average trigger score using the trigger score, the second trigger score, and the third trigger score; and (WANG [pages 18-19, Analysis of the Parrot's understanding of reaction centers] calculates the average of the attention weights using all attention values (i.e., using the trigger score, the second trigger score, and the third trigger score) in the attention vector
A
t
t
n
C
for atom token, as shown in WANG’s equation (2).)
determining that the trigger score exceeds the average trigger score by above a pre-determined number of standard deviations. (WANG [pages 18-19, Analysis of the Parrot's understanding of reaction centers] calculates the standard deviation for the attention values in the attention vector
A
t
t
n
C
as shown in WANG’s equation (2), and selects an atom whose attention weights are greater than or equal to the threshold value determined
M
e
a
n
A
t
t
n
C
+
k
×
S
t
d
A
t
t
n
C
, where
k
is a constant and
S
t
d
is the standard deviation (i.e., by above a pre-determined number of standard deviations).)
Accordingly, it would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention, having the teachings of SUN, HE, and WANG before them, to include WANG’s average weight calculation and standard deviation threshold determination for an input token in SUN and HE’s method for defending against backdoor attacks in natural language generation. One would have been motivated to make such a combination in order to provide good interpretability using an attention mechanism to gain insight into the intrinsic relationship between the input tokens and their outputs (WANG [page 18, Discussion]).
Regarding Claim 12:
SUN in view of HE teaches the elements of claim 8 as outlined above. Additionally, the claim recites similar limitations as corresponding claim 5 and is rejected for similar reasons as claim 5 using similar teachings and rationale.
Regarding Claim 18:
SUN in view of HE teaches the elements of claim 14 as outlined above. Additionally, the claim recites similar limitations as corresponding claims 5 and 12 and is rejected for similar reasons as claims 5 and 12 using similar teachings and rationale.
Claims 7 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over SUN in view of HE, as applied respectively above to claims 1 and 14, and further in view of SABIR ("Interpretability and Transparency-Driven Detection and Transformation of Textual Adversarial Examples (IT-DT)"), hereafter SABIR.
Regarding Claim 7:
SUN in view of HE teaches the elements of claim 1 as outlined above. SUN further teaches:
[…] after the determining […] (SUN [page 4, Trigger word based Methods] teaches that if the likelihood of an input token
x
i
exceeds a threshold value, the input
x
may be poisoned (i.e., the determining).)
wherein the creating the sanitized input prompt […] (SUN [page 4, section 5.1 Change in Target Semantics] teaches generating an output by the NLG model
f
(
)
using sentence
x
'
, which had a word deleted or replaced (i.e., wherein the creating the sanitized input prompt).)
SUN in view of HE is not relied upon for teaching, but SABIR teaches: concluding […] that the particular initial input token does not meet a commonality factor, (SABIR [pages 16-17, Frequency-based Identification (FPI)] teaches detecting potential perturbed words by considering frequency (i.e., commonality factor) as a critical element, and further teaches that the FPI module selects words (i.e., the particular initial input token) whose frequency is less than a defined threshold (i.e., does not meet a commonality factor) to generate the set of potential perturbed candidates
P
c
a
n
d
.)
[…] is in response to the concluding that the particular initial input token does not meet a commonality factor. (SABIR [pages 16-17, Frequency-based Identification (FPI)] teaches detecting potential perturbed words by considering frequency (i.e., commonality factor) as a critical element, and further teaches that the FPI module selects words (i.e., the particular initial input token) whose frequency is less than a defined threshold (i.e., does not meet a commonality factor) to generate the set of potential perturbed candidates
P
c
a
n
d
. Then, SABIR [page 18, Algorithm 3] generates transformed examples
T
F
c
a
n
d
by replacing potential perturbed words from
P
c
a
n
d
.)
Accordingly, it would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention, having the teachings of SUN, HE, and SABIR before them, to include SABIR’s frequency-based identification (FPI) module for improved accuracy and reliability when detecting the likelihood of trigger words in SUN and HE’s method for defending against backdoor attacks in natural language generation. One would have been motivated to make such a combination in order to improve the accuracy and reliability of adversarial example detection methods because the frequency of perturbed words in an adversarial example is typically lower than the frequency of the original words in its non-perturbed counterpart (SABIR [pages 16-17, Frequency-based Identification (FPI)]).
Regarding Claim 20:
SUN in view of HE teaches the elements of claim 14 as outlined above. Additionally, the claim recites similar limitations as corresponding claim 7 and is rejected for similar reasons as claim 7 using similar teachings and rationale.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure:
QI (“ONION: A simple and Effective Defense Against Textual Backdoor Attacks”) is relevant to computing each word’s suspicion score from sentence perplexity reduction, removing words above a threshold, and feeding the result to the model.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to Alvaro S Laham Bauzo whose telephone number is (571)272-5650. The examiner can normally be reached Mon-Fri 7:30 AM - 11:00 AM | 1:00 PM - 5:30 PM ET.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Usmaan Saeed can be reached on (571) 272-4046. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/A.S.L./Examiner, Art Unit 2146 /DANIEL T PELLETT/ Primary Examiner, Art Unit 2121