Prosecution Insights
Last updated: October 02, 2026
Application No. 18/678,524

SYSTEM AND METHOD FOR ADJUSTING OR CREATING AI MODELS BASED ON MODEL BREACH ALERTS

Final Rejection §102§103
Filed
May 30, 2024
Priority
Jun 02, 2023 — provisional 63/470,571 +1 more
Examiner
BAZNA, JUDY
Art Unit
2495
Tech Center
2400 — Computer Networks
Assignee
Darktrace Holdings Limited
OA Round
2 (Final)
69%
Grant Probability
Favorable
3-4
OA Rounds
9m
Est. Remaining
94%
With Interview

Examiner Intelligence

Grants 69% — above average
69%
Career Allowance Rate
20 granted / 29 resolved
+11.0% vs TC avg
Strong +24% interview lift
Without
With
+24.5%
Interview Lift
resolved cases with interview
Typical timeline
3y 1m
Avg Prosecution
11 currently pending
Career history
50
Total Applications
across all art units

Statute-Specific Performance

§101
3.9%
-36.1% vs TC avg
§103
77.7%
+37.7% vs TC avg
§102
12.3%
-27.7% vs TC avg
§112
4.5%
-35.5% vs TC avg
Black line = Tech Center average estimate • Based on career data from 29 resolved cases

Office Action

§102 §103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Arguments Applicants’ arguments regarding 112(b) rejection, see Remarks pages 1-11, filed on 04/06/2026, have been fully considered and are persuasive. The 112(b) rejection of claim 10-13 has been withdrawn. Regarding applicant argument: “Applicant notes that Poliakov is silent in at least these respects. Specifically, amended Claim 1 teaches that the model breach alert is triggered by an internal, operational evaluation where the Al model itself processes a series of live events to determine if its own specific threshold has been violated. In contrast, the Office Action asserts that the "trigger event" of Poliakov anticipates this limitation. However, Poliakov defines its trigger event explicitly as an external notification, such as a new Al application becoming available or a new security concern being identified by a vulnerability database. Poliakov relies on external database updates to signal that a new adversarial attack vector exists in the wild, which is wholly different from amended Claim 1. (See [0043] of Poliakov stating that the trigger event is based on "a new Al application becoming available or a new security concern 113 being identified by the vulnerability database 112"). Indeed, Poliakov is entirely silent regarding an Al model actively receiving and evaluating a series of events to determine if an internal threshold has been breached. Because Poliakov fails to teach or suggest an Al model internally evaluating events to trigger a model breach alert, it cannot anticipate amended Claim 1.” In response to applicants’ argument that the references fail to show certain features of the invention, it is noted that the features upon which applicant relies (i.e., the model breach alert is triggered by an internal) are not recited in the rejected claim(s). Although the claims are interpreted in light of the specification, limitations from the specification are not read into the claims. See In re Van Geuns, 988 F.2d 1181, 26 USPQ2d 1057 (Fed. Cir. 1993). In addition, Examiner respectfully disagrees. Poliakov in Para [0039]. Para [0043]. [0183] teaches an external input triggers a state change, and the AI then processes the event internally without outside control. This model describes a closed-loop or autonomous response phase where the system handles the workflow by itself. Claim Rejections - 35 USC § 102 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention. Claims 1, 3, 4, 7, 8, 10, 1, 13, 14- 17, 20 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Poliakov (US 20200082097 A1). Regarding claim 1, Poliakov teaches a non-transitory storage medium including software configured, when executed by one or more processors, to adjust content within an Artificial Intelligence (AI) model or create a new AI model, the software comprising: a model health analysis component configured, when executed by the one or more processors, to analyze content associated with a model breach alert, the model breach alert corresponds to a determination in which a set of conditions has been met to denote that an event or a series of events received and evaluated by the Al model violates a threshold associated with the Al model (Para [0039]. Para [0043]. [0183]: the protection engine 103 identifies parameters of an AI application 109 running on a computing device 110, upon a trigger event (e.g., a new AI application becoming available or a new security concern 113 being identified by the vulnerability database 112). At block 506, the protection engine 103 determines a target configuration of an AI model to protect the AI application, based on the assessed vulnerability of the AI application. In various embodiments, the target configuration can be based on the goal of the AI model, metrics provided by the metric submodule 216 of FIG. 2, and/or defense category.); and a model refinement component configured, when executed by one or more processors, to receive analytic results from the model health analysis component and at least one of i) determine adjustments to the threshold associated with the AI model (Para [0132]. Para [0185]-[0186]: the enhanced AI model is used to protect the AI application. Upon determining that a new attack and/or defense is available, the method updated to include the new attack and/or defense. The new attacks and/or defenses thereof, including example code of each, can be harvested from various sources, such as the databases discussed herein and other public sources. In this way, an infrastructure of continuously improved and computationally efficient protection of the AI application is provided.) or ii) generate a new AI model in substitution of the AI model in order to avoid an over-breaching condition or improve cyber threat detection. Regarding claim 3, Poliakov teaches the non-transitory storage medium of claim 2, wherein the model health analysis component is further configured to access a misconfiguration data store including contextual information associated with a plurality of potential misconfigurations of the AI model and determine whether one of the plurality of potential misconfigurations appears to have occurred based on the set of conditions met to cause the model breach alert (Para [0043]-[0046]: The defense database 114 represents one or more databases that provide solutions, sometimes referred to herein as defenses 115, to different AI security vulnerabilities. Stated differently, the defense database 114 is a source of different solutions that may be applied to one or more AI application security attacks. To that end, the protection engine 103 identifies parameters of an AI application 109 running on a computing device 110, at predetermined intervals or upon a trigger event (e.g., a new AI application becoming available or a new security concern 113 being identified by the vulnerability database 112). In one embodiment, there is a rules database 118 that is operative to provide the goal (e.g., purpose) of an AI application to the protection engine 103 by way of a data packet 119 sent over the network 106.). Regarding claim 4, Poliakov teaches the non-transitory storage medium of claim 1, wherein the model refinement component is configured to determine the adjustments to the threshold associated with the AI model including at least one or more exceptions to increase a model breath threshold associated with at least one type of model breach alert to address the over-breaching condition corresponding to a condition where a number or a frequency of detections of model breach alerts corresponding to the model breach alert is greater than a prescribed number or a prescribed frequency that causes an administrator to ignore a notification of the model breach alert (Para [0179]: the protection engine 200 suggests metrics for the remaining 45 combinations of defense that are left (that were not previously selected). Finally, the protection engine 200 chooses the combination of defenses and dataset and having the best metric and this combination will be the universal defense suitable for our AI application. Then we check it and see if this potential metric value equals to the metric value calculated by manual tests of this combination of attacks and defenses. For example, the assessment module 220 is run and attacks are executed on the AI solution with the selected defenses and dataset. If the results are within a predetermined threshold tolerance, the protection engine 103 concludes that the AI model for the subject AI application to be the appropriate one. Upon determining that the metric is not within a predetermined threshold tolerance, the protection engine 200 select additional (e.g., three) combinations from the dataset and runs the model once again. This process continues iteratively until a determination is made that the metric is within a predetermined threshold tolerance of an expected result.). Regarding claim 7, Poliakov teaches the non-transitory storage medium of claim 1 further comprising: a model logic evaluator configured to determine information associated with one or more devices or one or more events relevant to each AI model for use in determining whether the set of conditions associated with the AI model have been met (Para [00181]-[0183]: At block 506, the protection engine 103 determines a target configuration of an AI model to protect the AI application, based on the assessed vulnerability of the AI application. In various embodiments, the target configuration can be based on the goal of the AI model, metrics provided by the metric submodule 216 of FIG. 2, and/or defense category.). Regarding claim 8, Poliakov teaches the non-transitory storage medium of claim 7, further comprising a data store to retain content associated with a plurality of model breach alerts detected by a cyber threat detection engine deployed as part of a cybersecurity appliance, wherein the data store is accessible by the model health analysis component (Para [0043]-[0046]: The defense database 114 represents one or more databases that provide solutions, sometimes referred to herein as defenses 115, to different AI security vulnerabilities. Stated differently, the defense database 114 is a source of different solutions that may be applied to one or more AI application security attacks. To that end, the protection engine 103 identifies parameters of an AI application 109 running on a computing device 110, at predetermined intervals or upon a trigger event (e.g., a new AI application becoming available or a new security concern 113 being identified by the vulnerability database 112). In one embodiment, there is a rules database 118 that is operative to provide the goal (e.g., purpose) of an AI application to the protection engine 103 by way of a data packet 119 sent over the network 106.). Regarding claim 10, Poliakov teaches A cybersecurity system, comprising: a model health analysis component configured, when executed by the one or more processors, to analyze content associated with a model breach alert, the model breach alert corresponds to a determination in which a set of conditions has been met to denote that an event or a series of events received and evaluated by the Al model violates a threshold associated with the Al model (Para [0039]. Para [0043]. [0183]: the protection engine 103 identifies parameters of an AI application 109 running on a computing device 110, upon a trigger event (e.g., a new AI application becoming available or a new security concern 113 being identified by the vulnerability database 112). At block 506, the protection engine 103 determines a target configuration of an AI model to protect the AI application, based on the assessed vulnerability of the AI application. In various embodiments, the target configuration can be based on the goal of the AI model, metrics provided by the metric submodule 216 of FIG. 2, and/or defense category.); and a model refinement component configured, when executed by one or more processors, to receive analytic results from the model health analysis component and at least one of i) determine adjustments to the threshold associated with the AI model (Para [0132]. Para [0185]-[0186]: the enhanced AI model is used to protect the AI application. Upon determining that a new attack and/or defense is available, the method updated to include the new attack and/or defense. The new attacks and/or defenses thereof, including example code of each, can be harvested from various sources, such as the databases discussed herein and other public sources. In this way, an infrastructure of continuously improved and computationally efficient protection of the AI application is provided.) or ii) generate a new AI model in substitution of the AI model in order to avoid an over-breaching condition or improve cyber threat detection; where the model health analysis component and the model refinement component are implemented in electronic circuits, with software stored in one or more non-transitory storage mediums in an executable format to be executed by one or more processors, and any combination of both (Para [0004]). Regarding claim 11, Poliakov teaches the cybersecurity system of claim 10, wherein the model health analysis component comprises (i) an alert model breach parser adapted to extract information from the content of the model breach alert to determine how or why the set of conditions associated with the AI model were met (Para [0043]-[0046]. Para [0185]-[0186]: the enhanced AI model is used to protect the AI application. Upon determining that a new attack and/or defense is available, the method updated to include the new attack and/or defense. The new attacks and/or defenses thereof, including example code of each, can be harvested from various sources, such as the databases discussed herein and other public sources. In this way, an infrastructure of continuously improved and computationally efficient protection of the AI application is provided.) and (ii) a model logic parser adapted to conduct analytics on the content of the model breach alert to determine an intended operability of the AI model (Para [0043]-[0046]. Para [0185]-[0186]: the enhanced AI model is used to protect the AI application. Upon determining that a new attack and/or defense is available, the method updated to include the new attack and/or defense. The new attacks and/or defenses thereof, including example code of each, can be harvested from various sources, such as the databases discussed herein and other public sources. In this way, an infrastructure of continuously improved and computationally efficient protection of the AI application is provided.). As per claim 13, the claims claim a cybersecurity system essentially corresponding to the non-transitory storage medium claims 4 above, and they are rejected, at least for the same reasons. Regarding claim 14, Poliakov teaches a method for adjusting content within an Artificial Intelligence (AI) model or creating a new AI model based on analysis of a model breach alert, the method comprising: analyzing content associated with a model breach alert by a model health analysis component utilizing one or more large language models to produce analytic results, the model breach alert corresponds to a determination in which a set of conditions has been met to denote that an event or a series of events received and evaluated by the Al model violates a threshold associated with the Al model (Para [0043]-[0046]: The defense database 114 represents one or more databases that provide solutions, sometimes referred to herein as defenses 115, to different AI security vulnerabilities. Stated differently, the defense database 114 is a source of different solutions that may be applied to one or more AI application security attacks. To that end, the protection engine 103 identifies parameters of an AI application 109 running on a computing device 110, at predetermined intervals or upon a trigger event (e.g., a new AI application becoming available or a new security concern 113 being identified by the vulnerability database 112). In one embodiment, there is a rules database 118 that is operative to provide the goal (e.g., purpose) of an AI application to the protection engine 103 by way of a data packet 119 sent over the network 106.); receiving the analytic results by a model refinement component (Para [0043]-[0046]. Para [0179]: the protection engine 200 suggests metrics for the remaining 45 combinations of defense that are left (that were not previously selected). Finally, the protection engine 200 chooses the combination of defenses and dataset and having the best metric and this combination will be the universal defense suitable for our AI application. Then we check it and see if this potential metric value equals to the metric value calculated by manual tests of this combination of attacks and defenses. For example, the assessment module 220 is run and attacks are executed on the AI solution with the selected defenses and dataset. If the results are within a predetermined threshold tolerance, the protection engine 103 concludes that the AI model for the subject AI application to be the appropriate one. Upon determining that the metric is not within a predetermined threshold tolerance, the protection engine 200 select additional (e.g., three) combinations from the dataset and runs the model once again. This process continues iteratively until a determination is made that the metric is within a predetermined threshold tolerance of an expected result.); and determining adjustments to the threshold associated with the AI model or generating a new AI model in substitution of the AI model in response to over-breaching condition associated with the AI model (Para [0132]. Para [0185]-[0186]: the enhanced AI model is used to protect the AI application. Upon determining that a new attack and/or defense is available, the method updated to include the new attack and/or defense. The new attacks and/or defenses thereof, including example code of each, can be harvested from various sources, such as the databases discussed herein and other public sources. In this way, an infrastructure of continuously improved and computationally efficient protection of the AI application is provided.). As per claims 15, the claims claim method essentially corresponding to the cybersecurity system claims 11 above, and they are rejected, at least for the same reasons. As per claims 16, 17, the claims claim method essentially corresponding to the non-transitory storage medium claims 3, 4 above, and they are rejected, at least for the same reasons. Regarding claim 20, Poliakov teaches the method of claim 14, wherein prior to analyzing content associated with the model breach alert, the method further comprising: determining information from one or more classifiers for use in determining whether the set of conditions associated with the AI model have been met (Para [0185]-[0186]: the enhanced AI model is used to protect the AI application. Upon determining that a new attack and/or defense is available, the method updated to include the new attack and/or defense. The new attacks and/or defenses thereof, including example code of each, can be harvested from various sources, such as the databases discussed herein and other public sources. In this way, an infrastructure of continuously improved and computationally efficient protection of the AI application is provided.) Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 2, 12 are rejected under 35 U.S.C. 103 as being unpatentable over in view of Poliakov (US 20200082097 A1) in view Thirumalachar (US 20240143776 A1). Regarding claim 2, Poliakov teaches the non-transitory storage medium of claim 1, wherein the model health analysis component includes (i) an alert model breach parser adapted to extract information from the content of the model breach alert to understand how or why the set of conditions associated with the AI model were met (Para [0043]-[0046]. Para [0185]-[0186]: the enhanced AI model is used to protect the AI application. Upon determining that a new attack and/or defense is available, the method updated to include the new attack and/or defense. The new attacks and/or defenses thereof, including example code of each, can be harvested from various sources, such as the databases discussed herein and other public sources. In this way, an infrastructure of continuously improved and computationally efficient protection of the AI application is provided.), and (iii) a model logic parser adapted to conduct analytics on the content of the model breach alert to understand an intended operability of the AI model (Para [0043]-[0046]. Para [0185]-[0186]: the enhanced AI model is used to protect the AI application. Upon determining that a new attack and/or defense is available, the method updated to include the new attack and/or defense. The new attacks and/or defenses thereof, including example code of each, can be harvested from various sources, such as the databases discussed herein and other public sources. In this way, an infrastructure of continuously improved and computationally efficient protection of the AI application is provided.). Poliakov does not explicitly disclose (ii) an Application Programming Interface (API) interaction module adapted to query logic within a cybersecurity system including the non-transitory storage medium for additional information associated with the model breach alert. Thirumalachar does disclose (ii) an Application Programming Interface (API) interaction module adapted to query logic within a cybersecurity system including the non-transitory storage medium for additional information associated with the model breach alert (Claim 8. Para [0044]: vulnerability insight module 118 may generate the alert notification including the vulnerability information and present the alert notification including the vulnerability information on a graphical user interface.). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the invention of Poliakov with the teachings of Thirumalachar to include (ii) an Application Programming Interface (API) interaction module adapted to query logic within a cybersecurity system including the non-transitory storage medium for additional information associated with the model breach alert in order to present the alert notification on a graphical user interface so that the user is aware of the impacted applications and initiates appropriate actions (Thirumalachar Para [0060]). Regarding claim 12, Poliakov teaches the cybersecurity system of claim 11. Poliakov does not explicitly disclose wherein the model health analysis component further comprises (iii) an Application Programming Interface (API) interaction module adapted to query logic for additional information associated with the model breach alert. Thirumalachar does disclose wherein the model health analysis component further comprises (iii) an Application Programming Interface (API) interaction module adapted to query logic for additional information associated with the model breach alert (Claim 8. Para [0044]: vulnerability insight module 118 may generate the alert notification including the vulnerability information and present the alert notification including the vulnerability information on a graphical user interface.). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the invention of Poliakov with the teachings of Thirumalachar to include wherein the model health analysis component further comprises (iii) an Application Programming Interface (API) interaction module adapted to query logic for additional information associated with the model breach alert in order to present the alert notification including the vulnerability information on a graphical user interface so that the user is aware of the impacted critical applications and initiates appropriate actions (Thirumalachar Para [0060]). Claims 5, 6, 9, 18, 19 are rejected under 35 U.S.C. 103 as being unpatentable over in view of Poliakov (US 20200082097 A1) in view of YE (CN 114443556 A) in view of XU (US 20240073722 A1). Regarding claim 5, Poliakov teaches the non-transitory storage medium of claim 1. Poliakov does not disclose wherein the model refinement component is configured to (i) initiate a first message to an administrator identifying at least the adjustments recommended by the model refinement component and (ii) await an acknowledgement message to the first message signifying to proceed. YE does disclose wherein the model refinement component is configured to (i) initiate a first message to an administrator identifying at least the adjustments recommended by the model refinement component (Para [0025]: such as transmitting model training control messages from the user or model training feedback messages from the AI/ML training host between the user and the human-computer terminal, and then these messages can be routed between the AI/ML training host and the human-computer terminal.) and (ii) await an acknowledgement message to the first message signifying to proceed (Para [0025]: such as transmitting model training control messages from the user or model training feedback messages from the AI/ML training host between the user and the human-computer terminal, and then these messages can be routed between the AI/ML training host and the human-computer terminal.). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the invention of Poliakov with the teachings of YE to include wherein the model refinement component is configured to (i) initiate a first message to an administrator identifying at least the adjustments recommended by the model refinement component and (ii) await an acknowledgement message to the first message signifying to proceed in order to allow the AI/ML developer to interact with the AI/ML training host and perform super-parameter fine adjustment, so as to provide better performance (YE [0020]). Poliakov in view of YE does not explicitly disclose with applying the adjustments to the threshold associated with the AI model. XU does disclose with applying the adjustments to the threshold associated with the AI model (Para [0345]-[0350]). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the invention of Poliakov in view of YE with the teachings of XU to include with applying the adjustments to the threshold associated with the AI model in order to adjust a behavior of an application layer of the AI according to the warning information (XU Para [0344]). Regarding claim 6, Poliakov in view of YE in view of XU teaches the non-transitory storage medium of claim 5, wherein the model refinement component is further configured to (i) initiate a second message to an administrator in lieu of the first message (YE Para [0025]: such as transmitting model training control messages from the user or model training feedback messages from the AI/ML training host between the user and the human-computer terminal, and then these messages can be routed between the AI/ML training host and the human-computer terminal.), the second message identifying the new AI model to be substituted for the AI model and (ii) await an acknowledgement message to the second message from the administrator signifying to proceed with substitution of the new AI model for the AI model (YE Para [0025]: such as transmitting model training control messages from the user or model training feedback messages from the AI/ML training host between the user and the human-computer terminal, and then these messages can be routed between the AI/ML training host and the human-computer terminal. Poliakov Para [0185]-[0186]: the enhanced AI model is used to protect the AI application. Upon determining that a new attack and/or defense is available, the method updated to include the new attack and/or defense. The new attacks and/or defenses thereof, including example code of each, can be harvested from various sources, such as the databases discussed herein and other public sources. In this way, an infrastructure of continuously improved and computationally efficient protection of the AI application is provided.). Regarding claim 9, Poliakov teaches the non-transitory storage medium of claim 8. Poliakov does not explicitly disclose wherein the cyber threat detection engine is further configured to send at least a portion of the content associated with the model breach alert to a graphic user interface (GUI) accessible by an administrator. YE does disclose wherein the cyber threat detection engine is further configured to send at least a portion of the content associated with the model breach alert to a graphic user interface (GUI) accessible by an administrator (Para [0025]: such as transmitting model training control messages from the user or model training feedback messages from the AI/ML training host between the user and the human-computer terminal, and then these messages can be routed between the AI/ML training host and the human-computer terminal.). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the invention of Poliakov with the teachings of YE to include wherein the cyber threat detection engine is further configured to send at least a portion of the content associated with the model breach alert to a graphic user interface (GUI) accessible by an administrator in order to allow the AI/ML developer to interact with the AI/ML training host and perform super-parameter fine adjustment, so as to provide better performance (YE [0020]). As per claims 18, 19, the claims claim method essentially corresponding to the non-transitory storage medium claims 5, 6 above, and they are rejected, at least for the same reasons. Conclusion THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to JUDY BAZNA whose telephone number is (703) 756-1258. The examiner can normally be reached Monday - Friday 08:30 AM-05:00 PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Farid Homayounmehr can be reached at (571) 272-3739. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /JUDY BAZNA/Examiner, Art Unit 2495 /FARID HOMAYOUNMEHR/Supervisory Patent Examiner, Art Unit 2495
Read full office action

Prosecution Timeline

May 30, 2024
Application Filed
Oct 06, 2025
Non-Final Rejection mailed — §102, §103
Apr 06, 2026
Response Filed
Aug 27, 2026
Final Rejection mailed — §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12739140
Automated Privacy Controls For A Schedule View Of A Shared Conference Space Digital Calendar
3y 11m to grant Granted Sep 15, 2026
Patent 12724880
MANAGING USE OF INFERENCE MODELS TRAINED TO REDUCE RECONSTRUCTABILITY OF INPUT FEATURES
2y 3m to grant Granted Sep 01, 2026
Patent 12719885
SYSTEMS AND METHODS FOR DETECTING MALICIOUS EVENTS
3y 11m to grant Granted Aug 25, 2026
Patent 12641098
METHOD AND APPARATUS FOR DETECTING ANOMALIES OF AN INFRASTRUCTURE IN A NETWORK
4y 2m to grant Granted May 26, 2026
Patent 12585784
SYSTEM FOR COMPONENT-LEVEL THREAT ASSESSMENT IN A COMPUTING ENVIRONMENT
2y 11m to grant Granted Mar 24, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
69%
Grant Probability
94%
With Interview (+24.5%)
3y 1m (~9m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 29 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month