Prosecution Insights
Last updated: October 02, 2026
Application No. 18/647,885

MODEL POISONING DETECTION FOR ARTIFICIAL INTELLIGENCE MODELS

Non-Final OA §101§102§103§112
Filed
Apr 26, 2024
Examiner
MISIR, DAYWAYSHWAR D
Art Unit
Tech Center
Assignee
Lenovo (United States) Inc.
OA Round
1 (Non-Final)
84%
Grant Probability
Favorable
1-2
OA Rounds
4m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 84% — above average
84%
Career Allowance Rate
462 granted / 550 resolved
+24.0% vs TC avg
Strong +48% interview lift
Without
With
+48.5%
Interview Lift
resolved cases with interview
Typical timeline
2y 9m
Avg Prosecution
18 currently pending
Career history
558
Total Applications
across all art units

Statute-Specific Performance

§101
22.6%
-17.4% vs TC avg
§103
33.8%
-6.2% vs TC avg
§102
11.4%
-28.6% vs TC avg
§112
22.7%
-17.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 550 resolved cases

Office Action

§101 §102 §103 §112
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Prior to the issuing of this Office Action a discussion was held with applicant’s representative, David Morasch, to compactly prosecute this application, however, no agreement was received. Claim Objections Claim 9 is objected to because of the following informalities: In Claim 9, lines 5-6 and 8, “one or more third artificial intelligence models” was probably meant to be: the one or more third artificial intelligence models. Appropriate correction is required. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 1-13, 16, 18-19 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claim 1, line 11, recites the limitation “the first artificial intelligence model” which lacks antecedent basis. Dependent claims are subsequently rejected. The same rejection is made for Claim 19. Additionally, Claim 16, lines 3-4, recites the limitation “the one or more second artificial intelligence models” which lacks antecedent basis. The same rejection is made for Claim 18. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-13, 19 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. Step 1: All claims are directed towards either a method or an apparatus and thus satisfies Step 1 as falling into one of the statutory categories. Step 2A, Prong One: Independent Claim 1 recites (the same analysis applies to similar independent Claim 19): generate a first distance value based at least in part on a comparison of one or more first artificial intelligence models and one or more second artificial intelligence models; compare the first distance value to a distance value threshold; and generate one or more model poisoning scores based at least in part on comparison of the first artificial intelligence model and one or more third artificial intelligent models in training. These limitations, under their broadest reasonable interpretation, covers concepts that can be performed in the human mind and therefore would fall under the “Mental Processes” groupings of abstract ideas. That is finding distance values based on comparison between models, comparing them to a threshold, and finding poisoning scores based on comparisons are all activities that can be performed by the human mind using evaluation. Step 2A, Prong Two: Claim 1 recites the additional elements of (the same analysis applies to similar independent Claim 19): A first network equipment for wireless communication, generate a flag to initiate poisoning score detection based at least in part on whether the first distance value surpasses the distance value threshold; these limitations are considered as linking the use of the judicial exception to a particular technological environment or field of use – see MPEP 2106.05(h). The further additional element of a “processor” is recited at a high-level of generality such that it amounts to no more than mere instructions to apply the exception using a generic computer component. Accordingly, these additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea. The claims are therefore directed to an abstract idea. Step 2B: The claims do not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional elements are considered as linking the use of the judicial exception to a particular technological environment or field of use – see MPEP 2106.05(h). The further additional element of a “processor” amounts to no more than mere instructions to apply the exception using a generic computer component. Mere instructions to apply an exception using a generic computer component cannot provide an inventive concept. The claims are therefore not patent eligible. Dependent Claim 2 is considered as appending well-understood, routine, conventional activities previously known to the industry (accessing/storing models), specified at a high level of generality, to the judicial exception - see MPEP 2106.05(d). Dependent Claim 3 is also considered, under its broadest reasonable interpretation, to covers concepts that can be performed in the human mind and therefore would fall under the “Mental Processes” groupings of abstract ideas. That is finding features and distance values are all activities that can be performed by the human mind using evaluation. Dependent Claim 4 is also considered, under its broadest reasonable interpretation, to covers concepts that can be performed in the human mind and therefore would fall under the “Mental Processes” groupings of abstract ideas. That is generating text or image based descriptions for models and a distance value are all activities that can be performed by the human mind using observation and evaluation. Dependent Claim 5 is also considered, under its broadest reasonable interpretation, to covers concepts that can be performed in the human mind and therefore would fall under the “Mental Processes” groupings of abstract ideas. That is finding a numerical value or a percentage value for the model poisoning score are all activities that can be performed by the human mind using observation and evaluation. Dependent Claim 6 is considered as linking the use of the judicial exception to a particular technological environment or field of use – see MPEP 2106.05(h). Dependent Claim 7 is considered as appending well-understood, routine, conventional activities previously known to the industry (transmitting data), specified at a high level of generality, to the judicial exception - see MPEP 2106.05(d). Dependent Claim 8 is considered as linking the use of the judicial exception to a particular technological environment or field of use – see MPEP 2106.05(h). For Dependent Claim 9, the first and third limitations are considered, under their broadest reasonable interpretation, to covers concepts that can be performed in the human mind and therefore would fall under the “Mental Processes” groupings of abstract ideas. That is determining if a distance value exceed a threshold and finding a distance value based on comparison between models are all activities that can be performed by the human mind using evaluation. The second limitation is considered as appending well-understood, routine, conventional activities previously known to the industry (receiving data), specified at a high level of generality, to the judicial exception - see MPEP 2106.05(d). The last/fourth limitation is considered as linking the use of the judicial exception to a particular technological environment or field of use – see MPEP 2106.05(h). Dependent Claims 10-11 are considered as linking the use of the judicial exception to a particular technological environment or field of use – see MPEP 2106.05(h). Dependent Claims 12-13 are considered as appending well-understood, routine, conventional activities previously known to the industry (receiving and assigning data), specified at a high level of generality, to the judicial exception - see MPEP 2106.05(d). Claim Rejections - 35 USC § 102 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention. Claims 1-3, 5-6, 19 are rejected under 35 U.S.C. 102(a)(2) as being anticipated by Jyoti, WO 2024/160684 A1. Regarding Claim 1, Jyoti teaches: A first network equipment for wireless communication, comprising: at least one memory; and at least one processor coupled with the at least one memory and configured to cause the first network equipment to (paragraphs 10-11, 15): generate a first distance value based at least in part on a comparison of one or more first artificial intelligence models and one or more second artificial intelligence models (paragraph 25: “analyzing the calculated distances D1 ,D2,D3 by means of the processor (20) to detect poisoning in any of the plurality of Al Models (102). Analysis to detect poisoning further comprises computing a set ratios for mean of distances (D1 ,D2,D3) and comparing it to a pre-defined threshold. The step 203 is repeated multiple times for the each of the plurality of the Al models. We compare the distance between all 3 models”); compare the first distance value to a distance value threshold (paragraph 17: “The processor (20) computes a set ratios for mean of distances (D1 ,D2,D3) and compares it to a pre-defined threshold”); generate a flag to initiate poisoning score detection based at least in part on whether the first distance value surpasses the distance value threshold (paragraph 25: “analyzing the calculated distances D1 ,D2,D3 by means of the processor (20) to detect poisoning in any of the plurality of Al Models (102). Analysis to detect poisoning further comprises computing a set ratios for mean of distances (D1 ,D2,D3) and comparing it to a pre-defined threshold”); and generate one or more model poisoning scores based at least in part on comparison of the first artificial intelligence model and one or more third artificial intelligent models in training (paragraph 25: “analyzing the calculated distances D1 ,D2,D3 by means of the processor (20) to detect poisoning in any of the plurality of Al Models (102). Analysis to detect poisoning further comprises computing a set ratios for mean of distances (D1 ,D2,D3) and comparing it to a pre-defined threshold. The step 203 is repeated multiple times for the each of the plurality of the Al models. We compare the distance between all 3 models”). Regarding Claim 2, Jyoti further teaches: The first network equipment of claim 1, wherein the one or more first artificial intelligence models comprise one or more previously trained artificial intelligence models, the one or more second artificial intelligence models comprise one or more currently aggregated artificial intelligence models, and the one or more of third artificial intelligence models comprise one or more artificial intelligence models currently in training (paragraph 28: “This idea to develop a method of re-baselining a plurality of Al Models (102) and a system (10) thereof basically ensures that only non-poisoned models which are self-learning in the field (edge Al) are brought back and re-baselined. This regulates the quality of learning in the field/edge devices (12) ensuring accountability for the product manufactures. The core idea of the invention is poisoning detection before aggregation to prevent potential poisoning of the Global Model in a federated learning setup”. The poisoned models being part of the previously trained artificial intelligence models. Examiner’s note: see also Karame, US 2021/0051169 A1, for example paragraph 53). Regarding Claim 3, Jyoti further teaches: The first network equipment of claim 1, wherein to generate the first distance value, the at least one processor is configured to cause the first network equipment to: generate a first feature representation of the one or more first artificial intelligence models, and a second feature representation of the one or more second artificial intelligence models; and generate the first distance value based at least in part on a distance between the first feature representation and the second feature representation (paragraph 17: “While detecting poisoning the processor (20) is configured to feed a manipulated dataset to the plurality of Al Models (102) to get a plurality of first set of outputs comprising output from each layer of the plurality of self-learned Al models; feed the manipulated dataset to said at least two clean Al models (M1 , M2) to get a second set of outputs and a third set of outputs respectively for each layer of the said two clean Al models (M1 , M2); compute distance D1 between the first set of outputs and the second set of outputs using Lp norm; compute a distance D2 between the first set of outputs and the third set of outputs using Lp norm; compute a distance D3 between the second set of outputs and the third set of outputs using Lp norm; analyze the calculated distances D1 ,D2,D3 to detect poisoning in any of the self-learnt Al Models”. The Lp norms representative of the features representations). Regarding Claim 5, Jyoti further teaches: The first network equipment of claim 1, wherein the model poisoning score comprises one or more of a numerical value or a percentage likelihood value that the one or more third artificial intelligence models are in a poisoned state (paragraph 25: “analyzing the calculated distances D1 ,D2,D3 by means of the processor (20) to detect poisoning in any of the plurality of Al Models”. The distances representative of a numerical value). Regarding Claim 6, Jyoti further teaches: The first network equipment of claim 1, wherein the one or more third artificial intelligence models comprise one or more classes of artificial intelligence models, and wherein the at least one processor is configured to cause the first network equipment to generate a targeting indication comprising an indication of whether poisoning of the one or more third artificial intelligence models is targeted to at least one class of the one or more classes of artificial intelligence models (paragraph 13: “the Al models used in these edge devices (12) are involved in speech recognition, natural language processing, audio recognition, autonomous driving, etc. where they process data to generate required output based on certain rules/intelligence acquired through training. To process the inputs and give a desired output, the Al system (10)s use various models/algorithms which are trained using the training data. Once the Al system (10) is trained using the training data, the Al system (10)s are deployed along with self-learning mechanism. The deployed Al system (10)s use the self-learning mechanism within Al models to analyze the real time data and generate appropriate result. In this process they self-learn on the real time data. In accordance with the present disclosure each of the plurality of the plurality of edge devices (12) run a specified version of the Al model”). Claim 19 is similar to Claim 1 and is rejected under the same rationale as stated above for that claim. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 7-18, 20 are rejected under 35 U.S.C. 103 as being unpatentable over Jyoti, WO 2024/160684 A1, in of Yue, US 2025/0247776 A1. Regarding Claim 14, Jyoti teaches: a subscription request for poisoning detection for one or more third artificial intelligence models (paragraph 25: “analyzing the calculated distances D1 ,D2,D3 by means of the processor (20) to detect poisoning in any of the plurality of Al Models (102). Analysis to detect poisoning further comprises computing a set ratios for mean of distances (D1 ,D2,D3) and comparing it to a pre-defined threshold”); and receive, from the first network equipment, a poisoning detection result comprising a model poisoning score indicating a likelihood that at least one of the one or more third artificial intelligence models is in a poisoned state (paragraph 16: “detect poisoning in Al models amongst the plurality of Al Models”). Jyoti may not have taught the following, however, Yue shows: A second network equipment for wireless communication, comprising: at least one memory; and at least one processor coupled with the at least one memory and configured to cause the second network equipment to: transmit, to a first network equipment (Abstract; paragraph 221: “Systems and methods are disclosed that related to Distributed Machine Learning (DML) or Federated Learning (FL) in core network of a mobile or cellular communications system. In one embodiment, a method performed by a server Network Data Analytics Function (NWDAF) for selecting one or more client NWDAFs comprises transmitting, to each of a set of client NWDAFs, a preparation request for DML or FL and receiving, from each of at least some of the set of client NWDAFs, a response to the preparation request for DML or FL”). It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to use the teachings of Yue with that of Jyoti for having a second network equipment for wireless communication, comprising at least one memory and at least one processor coupled with the at least one memory and configured to cause the second network equipment to transmit, to a first network equipment. The ordinary artisan would have been motivated to modify Jyoti in the manner set forth above for the purposes of supporting distributed machine learning or federated learning in a core network of a mobile or cellular communications system [Yue: Abstract]. Regarding Claim 7, with Jyoti teaching those limitations of the claim as previously pointed out, Yue further teaches: The first network equipment of claim 1, wherein the at least one processor is configured to cause the first network equipment to transmit one or more of the model poisoning score, a client identifier, or a model identifier to a second network equipment (Abstract: “a server Network Data Analytics Function (NWDAF) for selecting one or more client NWDAFs comprises transmitting, to each of a set of client NWDAFs, a preparation request for DML or FL and receiving, from each of at least some of the set of client NWDAFs, a response to the preparation request for DML or FL”). Regarding Claim 8, Yue further teaches: The first network equipment of claim 7, wherein the first network equipment comprises an artificial intelligence network function and the second network equipment comprises a server network data analytics function (NWDAF) (Abstract: “a server Network Data Analytics Function (NWDAF) for selecting one or more client NWDAFs comprises transmitting, to each of a set of client NWDAFs, a preparation request for DML or FL and receiving, from each of at least some of the set of client NWDAFs, a response to the preparation request for DML or FL”). Regarding Claim 9, Jyoti further teaches: The first network equipment of claim 1, wherein the at least one processor is configured to cause the first network equipment to: determine that the first distance value exceeds the distance value threshold (paragraph 25: “Analysis to detect poisoning further comprises computing a set ratios for mean of distances (D1 ,D2,D3) and comparing it to a pre-defined threshold. The step 203 is repeated multiple times for the each of the plurality of the Al models. We compare the distance between all 3 models ( two clean and one from the plurality of self-learnt Al model) using a rule-based decision. The rationale behind comparing these distance is that the distance between the output of a poisoned model and the output of a clean model vis-a-vis the distance between outputs of two clean models when fed a manipulated dataset will show a remarkable difference”); generate a second distance value based at least in part on a comparison of the one or more first artificial intelligence models and one or more third artificial intelligence models (paragraph 17: “While detecting poisoning the processor (20) is configured to feed a manipulated dataset to the plurality of Al Models (102) to get a plurality of first set of outputs comprising output from each layer of the plurality of self-learned Al models; feed the manipulated dataset to said at least two clean Al models (M1 , M2) to get a second set of outputs and a third set of outputs respectively for each layer of the said two clean Al models (M1 , M2); compute distance D1 between the first set of outputs and the second set of outputs using Lp norm; compute a distance D2 between the first set of outputs and the third set of outputs using Lp norm; compute a distance D3 between the second set of outputs and the third set of outputs using Lp norm; analyze the calculated distances D1 ,D2,D3 to detect poisoning in any of the self-learnt Al Models”); and generate the flag to initiate the poisoning score detection further based at least in part on whether the second distance value exceeds the distance value threshold (paragraph 25: “analyzing the calculated distances D1 ,D2,D3 by means of the processor (20) to detect poisoning in any of the plurality of Al Models (102). Analysis to detect poisoning further comprises computing a set ratios for mean of distances (D1 ,D2,D3) and comparing it to a pre-defined threshold”). And Yue further teaches: receive, from one or more client network data analytics functions (NWDAFs) and based at least in part on the first distance value exceeding the distance value threshold, one or more third artificial intelligence models (paragraph 14: “multiple NWDAF will be deployed in a big PLMN, so maybe it is difficult for NWDAF to centralize all the raw data that are distributed in different Areas. However, it is desired or reasonable for the NWDAF distributed in an Area to share its model or data analytics with others NWDAFs”). Regarding Claim 10, with Jyoti teaching the poisoning of the models, Yue further teaches: The first network equipment of claim 9, wherein the model poisoning score comprises a likelihood that poisoning of the one or more third artificial intelligence models occurred via the one or more client NWDAFs (paragraph 55: “NWDAF service consumer discovers the NWDAF via NRF. NRF may return multiple NWDAF candidates matching the requested capabilities, area of interest, and supported Analytics ID(s). NWDAF service consumer selects an NWDAF (e.g. NWDAF 1) with analytics aggregation capability (i.e. aggregator NWDAF), based on its internal selection criteria, possibly considering registered NWDAF capabilities and information in NRF”. Capabilities representative of whether poisoning of the model is detected). Regarding Claim 11, Yue further teaches: The first network equipment of claim 1, wherein the first network equipment comprises a server network data analytics function (NWDAF) (paragraph 16: “The main idea of Federated Learning is to build machine-learning models based on data sets that are distributed in different network functions. A Client NWDAF (e.g. deployed in a domain or network function) locally trains the local ML model with its own data and share it to the server NWDAF. With local ML models from different Client NWDAFs, the Server NWDAF could aggregate them into a global or optimal ML model or ML model parameters and send them back to the Client NWDAFs for inference”). Regarding Claim 12, with Jyoti teaching the poisoning detection of the models, Yue further teaches: The first network equipment of claim 1, wherein the at least one processor is configured to cause the first network equipment to: receive, from a second network equipment, a subscription request for poisoning detection for the one or more third artificial intelligence models; and transmit, to the second network equipment, a poisoning detection result comprising the model poisoning score (Abstract; paragraph 221: “Systems and methods are disclosed that related to Distributed Machine Learning (DML) or Federated Learning (FL) in core network of a mobile or cellular communications system. In one embodiment, a method performed by a server Network Data Analytics Function (NWDAF) for selecting one or more client NWDAFs comprises transmitting, to each of a set of client NWDAFs, a preparation request for DML or FL and receiving, from each of at least some of the set of client NWDAFs, a response to the preparation request for DML or FL”). Regarding Claim 13, Jyoti further teaches: The first network equipment of claim 12, wherein the at least one processor is configured to cause the first network equipment to: receive, from the second network equipment, one or more identifiers for one or more third network equipment that participated in training the one or more third artificial intelligence models; and assign the model poisoning score to at least one of the one or more third network equipment (paragraph 25: “analyzing the calculated distances D1 ,D2,D3 by means of the processor (20) to detect poisoning in any of the plurality of Al Models (102). Analysis to detect poisoning further comprises computing a set ratios for mean of distances (D1 ,D2,D3) and comparing it to a pre-defined threshold”). Regarding Claim 15, Jyoti further teaches: The second network equipment of claim 14, wherein the poisoning detection result comprises an indication that at least one of the one or more third artificial intelligence models is likely in a poisoned state, and a targeting indication comprising an indication of whether poisoning of the at least one of the one or more third artificial intelligence models is targeted to at least one class of one or more classes of artificial intelligence models (paragraph 13: “the Al models used in these edge devices (12) are involved in speech recognition, natural language processing, audio recognition, autonomous driving, etc. where they process data to generate required output based on certain rules/intelligence acquired through training. To process the inputs and give a desired output, the Al system (10)s use various models/algorithms which are trained using the training data. Once the Al system (10) is trained using the training data, the Al system (10)s are deployed along with self-learning mechanism. The deployed Al system (10)s use the self-learning mechanism within Al models to analyze the real time data and generate appropriate result. In this process they self-learn on the real time data. In accordance with the present disclosure each of the plurality of the plurality of edge devices (12) run a specified version of the Al model”). Regarding Claim 16, Jyoti further teaches: The second network equipment of claim 14, wherein the at least one processor is configured to cause the second network equipment to transmit, to the first network equipment, one or more identifiers for one or more third network equipment that participated in training of the one or more second artificial intelligence models, wherein the poisoning detection result is associated with at least one of the one or more third network equipment (paragraph 25: “analyzing the calculated distances D1 ,D2,D3 by means of the processor (20) to detect poisoning in any of the plurality of Al Models (102). Analysis to detect poisoning further comprises computing a set ratios for mean of distances (D1 ,D2,D3) and comparing it to a pre-defined threshold”). Regarding Claim 17, Jyoti further teaches: The second network equipment of claim 14, wherein the at least one processor is configured to cause the second network equipment to: select one or more candidate artificial intelligence models from the one or more third artificial intelligence models based at least in part on the poisoning detection result indicating that the one or more candidate artificial intelligence models are likely not in a poisoned state; and utilize the one or more candidate artificial intelligence models for one or more of model training or data inference (Abstract: “The system (10) is designed to detect poisoning (method step 203) in Al models amongst the plurality of Al Models (102) and then select a group of non-poisoned Al models to perform federated learning on the selected group of non-poisoned Al models to get a re-baselined Model”). Regarding Claim 18, Jyoti further teaches: The second network equipment of claim 14, wherein the at least one processor is configured to cause the second network equipment to: determine, based at least in part on the poisoning detection result, that the one or more third artificial intelligence models are likely in a poisoned state; discard the one or more second artificial intelligence models; and exclude one or more poisoned clients associated with the one or more third artificial intelligence models likely in a poisoned state from taking part in one or more next rounds of federated learning model training (Abstract: “The system (10) is designed to detect poisoning (method step 203) in Al models amongst the plurality of Al Models (102) and then select a group of non-poisoned Al models to perform federated learning on the selected group of non-poisoned Al models to get a re-baselined Model”). Claim 20 is similar to Claim 14 and is rejected under the same rationale as stated above for that claim. Claim 4 is objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. Examiner's Note: The Examiner cites particular pages, sections, columns, line numbers, and/or paragraphs in the references as applied to the claims above for the convenience of the applicant. Although the specified citations are representative of the teachings in the art and are applied to the specific limitations within the individual claim, other passages and figures may apply as well. It is respectfully requested that, in preparing responses, the applicant fully consider the references in its entirety as potentially teaching all or part of the claimed invention, as well as the context of the passage as taught by the prior art or disclosed by the examiner and the additional related prior arts made of record that are considered pertinent to applicant's disclosure to further show the general state of the art. The Examiner's interpretations in parenthesis are provided with the cited references to assist the applicants to better understand how the examiner interprets the prior art to read on the claims. Such comments are entirely consistent with the intent and spirit of compact prosecution. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. See PTO-892 for the relevant prior art where for example Karame, US 2021/0051169 A1, teaches detecting model-poisoning attempts in a federated learning system. Any inquiry concerning this communication or earlier communications from the examiner should be directed to DAVE MISIR whose telephone number is (571)272-5243. The examiner can normally be reached M-R 8-5 pm, F some hours. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Abdullah Al Kawsar can be reached at 5712703169. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /DAVE MISIR/Primary Examiner, Art Unit 2127
Read full office action

Prosecution Timeline

Apr 26, 2024
Application Filed
Sep 10, 2026
Non-Final Rejection mailed — §101, §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12749012
DISTRIBUTED MACHINE LEARNING MODEL
3y 8m to grant Granted Sep 29, 2026
Patent 12748979
ARCHITECTURES, SYSTEMS AND METHODS HAVING SEGREGATED SECURE AND PUBLIC FUNCTIONS
2y 4m to grant Granted Sep 29, 2026
Patent 12749021
Automated Processing of Multiple Prediction Generation Including Model Tuning
2y 3m to grant Granted Sep 29, 2026
Patent 12737624
LEARNING APPARATUS, ANOMALY DETECTION APPARATUS, LEARNING METHOD, ANOMALY DETECTION METHOD, AND PROGRAM
3y 1m to grant Granted Sep 15, 2026
Patent 12718071
GENERATING PERSONALIZED CONTENT USING GENERATIVE ARTIFICIAL INTELLIGENCE
3y 0m to grant Granted Aug 25, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
84%
Grant Probability
99%
With Interview (+48.5%)
2y 9m (~4m remaining)
Median Time to Grant
Low
PTA Risk
Based on 550 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month