Prosecution Insights
Last updated: August 17, 2026
Application No. 18/646,105

METHOD AND SYSTEM FOR WATERMARKING IMAGES, AND METHOD AND SYSTEM FOR DETECTING A WATERMARK IN AN IMAGE

Non-Final OA §103
Filed
Apr 25, 2024
Examiner
WELLS, HEATH E
Art Unit
2664
Tech Center
2600 — Communications
Assignee
City University of Hong Kong
OA Round
1 (Non-Final)
78%
Grant Probability
Favorable
1-2
OA Rounds
11m
Est. Remaining
87%
With Interview

Examiner Intelligence

Grants 78% — above average
78%
Career Allowance Rate
76 granted / 97 resolved
+16.4% vs TC avg
Moderate +9% lift
Without
With
+9.0%
Interview Lift
resolved cases with interview
Typical timeline
3y 2m
Avg Prosecution
28 currently pending
Career history
131
Total Applications
across all art units

Statute-Specific Performance

§101
14.7%
-25.3% vs TC avg
§103
71.0%
+31.0% vs TC avg
§102
2.3%
-37.7% vs TC avg
§112
9.8%
-30.2% vs TC avg
Black line = Tech Center average estimate • Based on career data from 97 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Election/Restrictions Claims 10-15 are withdrawn from further consideration pursuant to 37 CFR 1.142(b), as being drawn to a nonelected Group, there being no allowable generic or linking claim. Restriction to one of the following inventions was required under 35 U.S.C. 121: I. Claims 1-9, and 16-17, drawn to a method of watermarking images. II. Claims 10-15, drawn to a method of detecting watermarked images. The inventions are independent or distinct, each from the other because: Inventions Ι and ΙΙ are directed to related processes. The related inventions are distinct if: (1) the inventions as claimed are either not capable of use together or can have a materially different design, mode of operation, function, or effect; (2) the inventions do not overlap in scope, i.e., are mutually exclusive; and (3) the inventions as claimed are not obvious variants. See MPEP § 806.05(j). In the instant case, the inventions as claimed have different functions since invention Ι is using a method to watermark images, and invention ΙΙ is using a statistical method to detect watermarking. Furthermore, the inventions as claimed do not encompass overlapping subject matter and there is nothing of record to show them to be obvious variants. Restriction for examination purposes as indicated is proper because all the inventions listed in this action are independent or distinct for the reasons given above and there would be a serious search and/or examination burden if restriction were not required because one or more of the following reasons apply: The inventions have acquired a separate status in the art in view of their different classification. The inventions have acquired a separate status in the art due to their recognized divergent subject matter. The inventions require a different field of search (different classes / subclasses and different search queries). The prior art applicable to one invention would not likely be applicable to another invention. The inventions are likely to raise different non-prior art issues under 35 USC 101 and 35 USC 112(a). An election with traverse was made to Group 1, Claims 1-9 and 16-17 on 8 May 2026 in response to the above restriction requirement. The restriction requirement will be reviewed as required by MPEP 821.04 for rejoinder when all claims directed to the elected invention are in condition for allowance. Information Disclosure Statement The IDS dated 25 April 2024 has been considered and placed in the application file. Specification - Drawings The drawings are objected to because the blocks pertaining to elements shown in FIG. 3, 9 and 10 do not have descriptive labels in conformance with 37 CFR 1.84(n) and 1.84(o), or numbering that is further described in the specification. For example, a descriptive label what part of 3A is different than 3B should be inserted into FIG. 3 to describe the PDF process, and what each set of pictures shows in Fig. 9 and 10. Corrected drawing sheets in compliance with 37 CFR 1.121(d) are required in reply to the Office action to avoid abandonment of the application. Any amended replacement drawing sheet should include all of the figures appearing on the immediate prior version of the sheet, even if only one figure is being amended. The figure or figure number of an amended drawing should not be labeled as “amended.” If a drawing figure is to be canceled, the appropriate figure must be removed from the replacement sheet, and where necessary, the remaining figures must be renumbered and appropriate changes made to the brief description of the several views of the drawings for consistency. Additional replacement sheets may be necessary to show the renumbering of the remaining figures. Each drawing sheet submitted after the filing date of an application must be labeled in the top margin as either “Replacement Sheet” or “New Sheet” pursuant to 37 CFR 1.121(d). If the changes are not accepted by the examiner, the applicant will be notified and informed of any required corrective action in the next Office action. The objection to the drawings will not be held in abeyance. Acknowledgement is made of the color drawings submitted 25 April 2024 in this application. Applicants are reminded that, absent a successful petition, the black and white drawings submitted on 25 April 2024 will be used. No petition is currently on file. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention. Claims 1-6 and 16-17 (all claims not objected to or withdrawn) are rejected under 35 U.S.C. 103 as obvious over US Patent Publication 2024 0104681 A1, (Kishore et al.) in view of US Patent Publication 2023 0109964 A1, (Wang et al.). The references are listed in a PTO-892 from the Office Action in which they are first used. If a reference is not identifiable (e.g., due to a typo), it can be identified by searching for the quoted text. Claim 1 [AltContent: textbox (Kinshore et al. Fig. 1, showing using adversarial perturbations to create stenography images.)] PNG media_image1.png 494 686 media_image1.png Greyscale Regarding Claim 1, Kishore et al. teach a computer-implemented method for watermarking images ("Image steganography has been widely used in applications such as watermarking, copyright certification and private information storage," paragraph [0004]), comprising: providing a secret key network (SKN) ("The optimization procedure implemented in the encoder can be viewed as a recurrent neural network with a hidden state that iteratively optimizes the perturbation 8 with respect to the loss 1. At each iteration it obtains the previous estimate 8,_ 1 and the gradient off as input and produces a new δ. The hidden state allows LISO to learn what optimization method is best suited for this task," paragraph [0084] where the encoder is the secret key network and δ is the key, which is a normal distribution); applying an input image to the SKN ("In a manner similar to that previously described, the encoder 504 receives as inputs a secret message 510 and a cover image 511 and interacts with the decoder 506 to iteratively generate an output steganographic image 512," paragraph [0076]); generating a secret key signature (SKS) as a real vector ("Gradient descent or other techniques as described in more detail elsewhere herein can be used to alter the perturbed image over multiple iterations until the output of the decoder network 108 is the desired bit string of the input secret message 110," paragraph [0036] where the desired bit string is a real vector); and embedding a watermark in the input image by using an adversarial attack ("an example algorithm for image steganography utilizing adversarial perturbations is shown," paragraph [0055]) to modify the input image in a manner that aligns the SKN's output with the SKS ("the particular perturbed image 112 that corresponds to the decoded perturbed image that met the one or more specified criteria relative to the message is illustratively output by the steganographic encoder-decoder neural network 102 as a steganographic image containing the input secret message 110," paragraph [0034] where the one or more specified criteria are "aligns the secret key network with the secret key signature" and "Such an arrangement generates perturbed images using what are referred to herein as "adversarial attacks." Adversarial attacks generally involve making small, often imperceptible, perturbations to images in order to obtain a desired output when the image is used as input for a neural network. Adversarial perturbations have shown to be effective against standard image transformations ( e.g., different compression algorithms)" paragraph [0032]). Kishore et al. is not relied upon to explicitly teach all of standard multivariate normal (SMVN) distribution for a given input image distribution. [AltContent: textbox (Wang et al. Fig. 3B, showing using perturbations and gradients in stenography. )] PNG media_image2.png 507 664 media_image2.png Greyscale However, Wang et al. teach adapted to output a standard multivariate normal (SMVN) distribution for a given input image distribution ("In some example embodiments, the random seed noise is drawn from some specified distribution (such as standard multivariate normal distribution, uniform distribution, or the like), and 8 represents the parameters (such as, weights, biases, or the like) of the probabilistic neural network 106," paragraph [0069]) Therefore, taking the teachings of Kishore et al. and Wang et al. as a whole, it would have been obvious to a person having ordinary skill in the art before the time of the effective filing date of the claimed invention of the instant application to modify “Image Stenography Utilizing Adversarial Perturbations” as taught by Kishore et al. to use “Training a Neural Network for Generating Universal Adversarial Perturbations” as taught by Wang et al., showing that Kishore et al. and Wang et al. are analogous art because both are stenography using adversarial perturbations. The suggestion/motivation for combination is that, “there is a need to overcome the above-mentioned problem. More specifically, there is need to develop a method and system for generating universal adversarial perturbations, independent of a target ML/DNN model information.” as noted by the Wang et al. disclosure in paragraph [0004], which also motivates combination because the combination would predictably have a higher efficiency as there is a reasonable expectation that adversarial perturbations will need to be adjusted for various factors and in various ways; and/or because doing so merely combines prior art elements according to known methods to yield predictable results. Claim 2 Regarding claim 2, Kishore et al. teach the computer-implemented method of claim 1, as noted above. Kishore et al. is not relied upon to explicitly teach all of wherein the step of providing the SKN comprises training a deep neural network (DNN) to function as the SKN via a generation loss (Gen-Loss) which is designed to train the SKN's output to follow an SMVN distribution. However, Wang et al. teach wherein the step of providing the SKN comprises training a deep neural network (DNN) to function as the SKN via a generation loss (Gen-Loss) which is designed to train the SKN's output to follow an SMVN distribution ("Thus, the probabilistic neural network 106 that generates the universal adversarial perturbations 110 is used in robust machine learning to produce robust models, such as the robust model 308," paragraph [0070]). Kishore et al. and Wang et al. are combined as per claim 1. Claim 3 Regarding claim 3, Kishore et al. teach the computer-implemented method of claim 1, as noted above. Kishore et al. is not relied upon to explicitly teach all of wherein the SKN serves as a unique, non-linear mapping function. However, Wang et al. teach wherein the SKN serves as a unique, non-linear mapping function ("In some example embodiments, the trained probabilistic neural network 106 is used as a randomized mapping (i.e., a random channel) that processes the input data 406 and outputs the perturbed input data 406. To that end, in order to realize randomized behavior of the probabilistic neural network 106, the robust neural network model 408 receives random seed noise from the perturbed input data 406 as an auxiliary input," paragraph [0068] where randomized is both unique and non-linear). Kishore et al. and Wang et al. are combined as per claim 1. Claim 4 Regarding claim 4, Kishore et al. teach the computer-implemented method of claim 1, wherein the SKN is based on a modified ResNet18 architecture with linear activation in its final layer to map the input image to the real vector ("Numerous other types of system architectures can be used in other embodiments. Also, other types of neural networks can be used in other embodiments. Accordingly, illustrative embodiments herein are not limited to use with encoder-decoder neural networks, GANs or other particular types of neural networks," paragraph [0185] where Resnet is a commercially available network, and showing other networks teaches using commercially available networks). Claim 5 Regarding claim 5, Kishore et al. teach the computer-implemented method of claim 1, as noted above. Kishore et al. is not relied upon to explicitly teach all of wherein the SKS follows normal distribution properties and has a cosine value. However, Wang et al. teach wherein the SKS follows normal distribution properties and has a cosine value greater than 0 with an angle formed with an output vector of the input image ("the MIGE method estimates the gradient of the mutual information (i.e., the terms V 2 log Pe(Z) and Vlog Pe(ZIY=y)) using one or more score functions, such as a Stein Gradient Estimator, a Spectral Stein Gradient Estimator, a Kernel Exponential Family Estimator or the like," paragraph [0055] where a gradient teaches cosine values and angles). Kishore et al. and Wang et al. are combined as per claim 1. Claim 6 Regarding claim 6, Kishore et al. teach the computer-implemented method of claim 1, wherein in the step of embedding the watermark, the SKN's output is made in the same direction as the SKS, with a length extended such that it is unlikely to be a sample from the SMVN ("LISO embodiments can learn a descent direction that is better than the one found by conventional gradient-based optimization methods," paragraph [0107] where a descent direction teaches the same direction as the SKS and "The hidden message M is a bit-string of length m=HXWXB reshaped to match the cover image's size, i.e. M {0,l}" paragraph [0077]). Claim 16 Regarding claim 16, Kishore et al. teach a system for watermarking images ("Image steganography has been widely used in applications such as watermarking, copyright certification and private information storage," paragraph [0004]), comprising: one or more processors ("A given such processing platform is assumed to include at least one processing device comprising a processor coupled to a memory. Examples of such processing devices include computers, servers or other processing devices arranged to communicate over a network," paragraph [0160]); and a memory storing one or more programs configured to be executed by the one or more processors, the one or more programs including instructions for performing or facilitating performing of the computer-implemented method of claim 1 ("A given such memory that stores such program code for execution by a corresponding processor is an example of what is more generally referred to herein as a processor-readable storage medium having program code embodied therein, and may comprise, for example, electronic memory such as SRAM, DRAM or other types of random access memory," paragraph [0166]). Claim 17 Regarding claim 17, Kishore et al. teach a non-transitory computer readable medium having instructions stored thereon which, when executed by one or more processors, cause the one or more processors to execute the computer-implemented method of claim 1 ("A given such memory that stores such program code for execution by a corresponding processor is an example of what is more generally referred to herein as a processor-readable storage medium having program code embodied therein, and may comprise, for example, electronic memory such as SRAM, DRAM or other types of random access memory," paragraph [0166]). Allowable Subject Matter Claims 7-9 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. Reference Cited The prior art made of record and not relied upon is considered pertinent to applicant’s disclosure. US Patent Publication 2025 0298994 A1 to Zhang et al. discloses receiving an output text sequence from a trained large language model; converting the output text sequence into a token representation of the output text sequence; generating a dense watermarked text distribution over a token vocabulary of the output text sequence, the generating based on the token representation of the output text sequence and on a binary signature sequence; perturbing the dense watermarked text distribution to yield a perturbed distribution; and mapping the perturbed distribution to an encoded output text sequence. US Patent Publication 2024 0370535 A1 to Sheybani et al. discloses the model owner of the first machine learning model generates, based on the prover key, a proof of ownership of a second machine learning model by at least determining that the obfuscated watermark extractor extracts the watermark from the second machine learning model in response to the second machine learning model being provided as a public input to the obfuscated watermark extractor. Then, the proof of ownership is verified, based on the verifier key, to acknowledge that the second machine learning model matches the first machine learning model. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to HEATH E WELLS whose telephone number is (703)756-4696. The examiner can normally be reached Monday-Friday 8:00-4:00. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Ms. Jennifer Mehmood can be reached on 571-272-2976. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /Heath E. Wells/Examiner, Art Unit 2664 Date: 10 April 2026
Read full office action

Prosecution Timeline

Apr 25, 2024
Application Filed
Jul 22, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12694639
DETECTION OF PROHIBITED OBJECTS CONCEALED IN AN ITEM, USING A THREE-DIMENSIONAL IMAGE OF THE ITEM
3y 4m to grant Granted Jul 28, 2026
Patent 12694527
METHOD AND IMAGING SYSTEM FOR MATCHING IMAGES OF DISCRETE ENTITIES
3y 6m to grant Granted Jul 28, 2026
Patent 12688572
Using Deep Learning to Process Images of the Eye to Predict Visual Acuity
4y 5m to grant Granted Jul 21, 2026
Patent 12688697
RENDERING SYSTEM, DISPLAY SYSTEM, MOVING VEHICLE, RENDERING METHOD, AND NON-TRANSITORY STORAGE MEDIUM FOR CORRECTING A RENDERING LOCATION OF A MARKER
3y 11m to grant Granted Jul 21, 2026
Patent 12675869
METHOD FOR INSPECTING AN OBJECT
4y 12m to grant Granted Jul 07, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
78%
Grant Probability
87%
With Interview (+9.0%)
3y 2m (~11m remaining)
Median Time to Grant
Low
PTA Risk
Based on 97 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month