DETAILED ACTION
This action is in response to the Applicant Response filed 17 April 2024 for application 18/701,935 filed 17 April 2024.
Claim(s) 1-7 is/are currently amended.
Claim(s) 1-7 is/are pending.
Claim(s) 1-7 is/are rejected.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Specification
The title of the invention is not descriptive. A new title is required that is clearly indicative of the invention to which the claims are directed.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claim(s) 1-7 is/are rejected under 35 U.S.C. 101, because the claim(s) is/are directed to an abstract idea, and because the claim elements, whether considered individually or in combination, do not amount to significantly more than the abstract idea, see Alice Corporation Pty. Ltd. V. CLS Bank International et al., 573 US 208 (2014).
Regarding claim 1, the claim is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Step 1 Analysis: Claim 1 is directed to a(n) calculation device, which is directed to a machine, one of the statutory categories.
Step 2A Prong One Analysis: The claim recites a(n) calculation device.
The limitation of create a second data set adjacent to a first data set based on the first data set, as drafted, is a process that, under its broadest reasonable interpretation, covers a mental process. The limitation is directed to observation, evaluation, judgment and opinion and is a process capable of being performed by a human mentally or using pen and paper.
The limitation of determine whether the training data used for the learning of the Bayesian NN is the first data set or the second data set based on an output of the Bayesian NN learned, as drafted, is a process that, under its broadest reasonable interpretation, covers a mental process. The limitation is directed to observation, evaluation, judgment and opinion and is a process capable of being performed by a human mentally or using pen and paper.
The limitation of calculate a privacy risk based on a determination result, as drafted, is a process that, under its broadest reasonable interpretation, covers a mathematical concept. The limitation encompasses calculating a risk score.
If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation in the mind, then it falls within the "Mental Processes" grouping. If a claim limitation, under its broadest reasonable interpretation, covers performance of mathematical concepts, then it falls within the "Mathematical Concepts" grouping. Accordingly, the claim recites an abstract idea.
Step 2A Prong Two Analysis: With respect to the abstract idea, the judicial exception is not integrated into a practical application.
The claim recites additional element(s) – calculation device, processing circuitry. The additional element(s) is/are recited at a high-level of generality (i.e., as generic computer components performing generic computer functions of executing instructions on the computers) such that it amounts to no more than mere instructions to apply the exception using generic computer components (MPEP 2106.05(b)).
The claim recites additional element(s) – Bayesian neural network. The additional element(s) is/are recited at a high-level of generality such that it amounts to no more than indicating a field of use or technological environment in which to apply the judicial exception (MPEP 2106.05(h)).
The claim recites perform learning of a Bayesian neural network (NN) by using either the first data set or the second data set as training data which is simply generic training to perform the abstract idea of model generation and amounts to mere instructions to apply the exception (MPEP 2106.05(f)).
Accordingly, the additional element(s) do(es) not integrate the abstract idea into a practical application because the additional element(s) do(es) not impose any meaningful limits on practicing the abstract idea, and, therefore, the claim is directed to an abstract idea.
Step 2B Analysis: The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to the integration of the abstract idea into a practical application, the additional element(s) of:
calculation device, processing circuitry amount(s) to no more than mere instructions to apply the exception using generic computer components (MPEP 2106.05(b))
generic training to perform the abstract idea amount(s) to no more than mere instructions to apply the exception (MPEP 2106.05(f))
Bayesian neural network amount(s) to no more than indicating a field of use or technological environment in which to apply the judicial exception (MPEP 2106.05(h))
The additional element(s) do(es) not provide an inventive concept, and, therefore, the claim is not patent eligible.
Regarding claim 2, the claim is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Step 1 Analysis: Claim 2 is directed to a(n) calculation device, which is directed to a machine, one of the statutory categories.
Step 2A Prong One Analysis: The claim recites a(n) calculation device.
The limitation of determine whether the training data used for learning of the Bayesian NN is the first data set or the second data set based on information obtained by integrating a plurality of outputs obtained by inputting one sample to the Bayesian NN learned a plurality of times or inputting each of a plurality of samples to the Bayesian NN one or more times, as drafted, is a process that, under its broadest reasonable interpretation, covers a mental process. The limitation is directed to observation, evaluation, judgment and opinion and is a process capable of being performed by a human mentally or using pen and paper.
If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation in the mind, then it falls within the "Mental Processes" grouping. Accordingly, the claim recites an abstract idea.
Step 2A Prong Two Analysis: With respect to the abstract idea, the judicial exception is not integrated
into a practical application. The claim does not recite any additional elements which integrate the
abstract idea into a practical application and, therefore, does not impose any meaningful limits on
practicing the abstract idea. Therefore, the claim is directed to an abstract idea.
Step 2B Analysis: The claim does not include additional elements that are sufficient to amount to
significantly more than the judicial exception. As discussed above with respect to the integration of the
abstract idea into a practical application, the claim does not recite any additional elements which
provide an inventive concept, and, therefore, the claim is not patent eligible.
Regarding claim 3, the claim is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Step 1 Analysis: Claim 3 is directed to a(n) calculation device, which is directed to a machine, one of the statutory categories.
Step 2A Prong One Analysis: The claim recites a(n) calculation device.
The limitation of wherein, when the Bayesian NN outputs a statistical value of posterior distribution, ... determine whether the training data used for learning of the Bayesian NN is the first data set or the second data set based on the statistical value, as drafted, is a process that, under its broadest reasonable interpretation, covers a mental process. The limitation is directed to observation, evaluation, judgment and opinion and is a process capable of being performed by a human mentally or using pen and paper.
If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation in the mind, then it falls within the "Mental Processes" grouping. Accordingly, the claim recites an abstract idea.
Step 2A Prong Two Analysis: With respect to the abstract idea, the judicial exception is not integrated
into a practical application. The claim does not recite any additional elements which integrate the
abstract idea into a practical application and, therefore, does not impose any meaningful limits on
practicing the abstract idea. Therefore, the claim is directed to an abstract idea.
Step 2B Analysis: The claim does not include additional elements that are sufficient to amount to
significantly more than the judicial exception. As discussed above with respect to the integration of the
abstract idea into a practical application, the claim does not recite any additional elements which
provide an inventive concept, and, therefore, the claim is not patent eligible.
Regarding claim 4, the claim is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Step 1 Analysis: Claim 4 is directed to a(n) calculation device, which is directed to a machine, one of the statutory categories.
Step 2A Prong One Analysis: The claim recites a(n) calculation device.
The limitation of wherein, when the Bayesian NN outputs a plurality of predicted values sampled from posterior distribution, ... determine whether the training data used for learning of the Bayesian NN is the first data set or the second data set based on a statistical value regarding the predicted values, as drafted, is a process that, under its broadest reasonable interpretation, covers a mental process. The limitation is directed to observation, evaluation, judgment and opinion and is a process capable of being performed by a human mentally or using pen and paper.
If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation in the mind, then it falls within the "Mental Processes" grouping. Accordingly, the claim recites an abstract idea.
Step 2A Prong Two Analysis: With respect to the abstract idea, the judicial exception is not integrated
into a practical application. The claim does not recite any additional elements which integrate the
abstract idea into a practical application and, therefore, does not impose any meaningful limits on
practicing the abstract idea. Therefore, the claim is directed to an abstract idea.
Step 2B Analysis: The claim does not include additional elements that are sufficient to amount to
significantly more than the judicial exception. As discussed above with respect to the integration of the
abstract idea into a practical application, the claim does not recite any additional elements which
provide an inventive concept, and, therefore, the claim is not patent eligible.
Regarding claim 5, the claim is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Step 1 Analysis: Claim 5 is directed to a(n) calculation device, which is directed to a machine, one of the statutory categories.
Step 2A Prong One Analysis: The claim recites a(n) calculation device.
The limitation of determine whether the training data used for learning of the Bayesian NN is the first data set or the second data set depending on whether the statistical value is equal to or greater than a threshold, as drafted, is a process that, under its broadest reasonable interpretation, covers a mental process. The limitation is directed to observation, evaluation, judgment and opinion and is a process capable of being performed by a human mentally or using pen and paper.
If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation in the mind, then it falls within the "Mental Processes" grouping. Accordingly, the claim recites an abstract idea.
Step 2A Prong Two Analysis: With respect to the abstract idea, the judicial exception is not integrated
into a practical application. The claim does not recite any additional elements which integrate the
abstract idea into a practical application and, therefore, does not impose any meaningful limits on
practicing the abstract idea. Therefore, the claim is directed to an abstract idea.
Step 2B Analysis: The claim does not include additional elements that are sufficient to amount to
significantly more than the judicial exception. As discussed above with respect to the integration of the
abstract idea into a practical application, the claim does not recite any additional elements which
provide an inventive concept, and, therefore, the claim is not patent eligible.
Regarding claim 6, the claim is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Step 1 Analysis: Claim 6 is directed to a method, which is directed to a process, one of the statutory categories.
Step 2A Prong One Analysis: The claim recites a(n) calculation method performed by a calculation device.
The limitation of creating a second data set adjacent to a first data set based on the first data set, as drafted, is a process that, under its broadest reasonable interpretation, covers a mental process. The limitation is directed to observation, evaluation, judgment and opinion and is a process capable of being performed by a human mentally or using pen and paper.
The limitation of determining whether the training data used for the learning of the model is the first data set or the second data set based on an output of the model learned, as drafted, is a process that, under its broadest reasonable interpretation, covers a mental process. The limitation is directed to observation, evaluation, judgment and opinion and is a process capable of being performed by a human mentally or using pen and paper.
The limitation of calculating a privacy risk based on a determination result, as drafted, is a process that, under its broadest reasonable interpretation, covers a mathematical concept. The limitation encompasses calculating a risk score.
If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation in the mind, then it falls within the "Mental Processes" grouping. If a claim limitation, under its broadest reasonable interpretation, covers performance of mathematical concepts, then it falls within the "Mathematical Concepts" grouping. Accordingly, the claim recites an abstract idea.
Step 2A Prong Two Analysis: With respect to the abstract idea, the judicial exception is not integrated into a practical application.
The claim recites additional element(s) – calculation device. The additional element(s) is/are recited at a high-level of generality (i.e., as generic computer components performing generic computer functions of executing instructions on the computers) such that it amounts to no more than mere instructions to apply the exception using generic computer components (MPEP 2106.05(b)).
The claim recites additional element(s) – model. The additional element(s) is/are recited at a high-level of generality such that it amounts to no more than indicating a field of use or technological environment in which to apply the judicial exception (MPEP 2106.05(h)).
The claim recites performing learning of a model by using either the first data set or the second data set as training data which is simply generic training to perform the abstract idea of model generation and amounts to mere instructions to apply the exception (MPEP 2106.05(f)).
Accordingly, the additional element(s) do(es) not integrate the abstract idea into a practical application because the additional element(s) do(es) not impose any meaningful limits on practicing the abstract idea, and, therefore, the claim is directed to an abstract idea.
Step 2B Analysis: The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to the integration of the abstract idea into a practical application, the additional element(s) of:
calculation device amount(s) to no more than mere instructions to apply the exception using generic computer components (MPEP 2106.05(b))
generic training to perform the abstract idea amount(s) to no more than mere instructions to apply the exception (MPEP 2106.05(f))
model amount(s) to no more than indicating a field of use or technological environment in which to apply the judicial exception (MPEP 2106.05(h))
The additional element(s) do(es) not provide an inventive concept, and, therefore, the claim is not patent eligible.
Regarding claim 7, the claim is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Step 1 Analysis: Claim 7 is directed to a(n) computer-readable recording medium, which is directed to an article of manufacture, one of the statutory categories.
Step 2A Prong One Analysis: The claim recites a(n) computer-readable recording medium.
The limitation of creating a second data set adjacent to a first data set based on the first data set, as drafted, is a process that, under its broadest reasonable interpretation, covers a mental process. The limitation is directed to observation, evaluation, judgment and opinion and is a process capable of being performed by a human mentally or using pen and paper.
The limitation of determining whether the training data used for the learning of the model is the first data set or the second data set based on an output of the model learned, as drafted, is a process that, under its broadest reasonable interpretation, covers a mental process. The limitation is directed to observation, evaluation, judgment and opinion and is a process capable of being performed by a human mentally or using pen and paper.
The limitation of calculating a privacy risk based on a determination result, as drafted, is a process that, under its broadest reasonable interpretation, covers a mathematical concept. The limitation encompasses calculating a risk score.
If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation in the mind, then it falls within the "Mental Processes" grouping. If a claim limitation, under its broadest reasonable interpretation, covers performance of mathematical concepts, then it falls within the "Mathematical Concepts" grouping. Accordingly, the claim recites an abstract idea.
Step 2A Prong Two Analysis: With respect to the abstract idea, the judicial exception is not integrated into a practical application.
The claim recites additional element(s) – computer-readable recording medium, calculation program, computer. The additional element(s) is/are recited at a high-level of generality (i.e., as generic computer components performing generic computer functions of executing instructions on the computers) such that it amounts to no more than mere instructions to apply the exception using generic computer components (MPEP 2106.05(b)).
The claim recites additional element(s) – model. The additional element(s) is/are recited at a high-level of generality such that it amounts to no more than indicating a field of use or technological environment in which to apply the judicial exception (MPEP 2106.05(h)).
The claim recites performing learning of a model by using either the first data set or the second data set as training data which is simply generic training to perform the abstract idea of model generation and amounts to mere instructions to apply the exception (MPEP 2106.05(f)).
Accordingly, the additional element(s) do(es) not integrate the abstract idea into a practical application because the additional element(s) do(es) not impose any meaningful limits on practicing the abstract idea, and, therefore, the claim is directed to an abstract idea.
Step 2B Analysis: The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to the integration of the abstract idea into a practical application, the additional element(s) of:
computer-readable recording medium, calculation program, computer amount(s) to no more than mere instructions to apply the exception using generic computer components (MPEP 2106.05(b))
generic training to perform the abstract idea amount(s) to no more than mere instructions to apply the exception (MPEP 2106.05(f))
model amount(s) to no more than indicating a field of use or technological environment in which to apply the judicial exception (MPEP 2106.05(h))
The additional element(s) do(es) not provide an inventive concept, and, therefore, the claim is not patent eligible.
Claim Rejections - 35 USC § 102
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claim(s) 6-7 is/are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Nasr et al. (Adversary Instantiation: Lower Bound for Differentially Private Machine Learning, hereinafter referred to as “Nasr”).
Regarding claim 6 (Currently Amended), Nasr teaches a calculation method performed by a calculation device, the calculation method comprising:
creating a second data set adjacent to a first data set based on the first data set (Nasr, section III.B – teaches two dataset, D and D’, where the datasets differ by exactly one instance);
performing learning of a model by using either the first data set or the second data set as training data (Nasr, section III.B – teaches training a model on either dataset D or dataset D’);
determining whether the training data used for the learning of the model is the first data set or the second data set based on an output of the model learned (Nasr, section III.B – teaches determining whether the model was trained on dataset D or dataset D’); and
calculating a privacy risk based on a determination result (Nasr, section III.C – teaches determining a privacy risk based on the results).
Regarding claim 7, it is the computer-readable recording medium embodiment of claim 6 with similar limitations to claim 6 and is rejected using the same reasoning found in claim 6.
Nasr further teaches a non-transitory computer-readable recording medium storing therein a calculation program that causes a computer to execute a process comprising (Nasr, section IV.A – teaches running experiments on computers/GPUs) …
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claim(s) 1-2 is/are rejected under 35 U.S.C. 103 as being unpatentable over Nasr et al. (Adversary Instantiation: Lower Bound for Differentially Private Machine Learning, hereinafter referred to as “Nasr”) in view of Galinkin, Erick (Who’s Afraid of Thomas Bayes?, hereinafter referred to as “Galinkin”).
Regarding claim 1 (Currently Amended), Nasr teaches a calculation device comprising: processing circuitry (Nasr, section IV.A – teaches running experiments on computers/GPUs) configured to:
create a second data set adjacent to a first data set based on the first data set (Nasr, section III.B – teaches two dataset, D and D’, where the datasets differ by exactly one instance);
perform learning of a Bayesian neural network (NN) by using either the first data set or the second data set as training data (Nasr, section III.B – teaches training a model on either dataset D or dataset D’; Nasr, section IV.A – teaches neural network model);
determine whether the training data used for the learning of the Bayesian NN is the first data set or the second data set based on an output of the Bayesian NN learned (Nasr, section III.B – teaches determining whether the model was trained on dataset D or dataset D’); and
calculate a privacy risk based on a determination result (Nasr, section III.C – teaches determining a privacy risk based on the results).
While Nasr teaches performing the steps of the claim using a neural network, Nasr does not explicitly teach that the model is a Bayesian neural network.
Galinkin teaches
perform learning of a Bayesian neural network (NN) by using either the first data set or the second data set as training data (Galinkin, section 3.1 - teaches training Bayesian neural networks to identify adversarial attacks; Galinkin, section 3.2 - teaches first and second datasets for adversarial attacks);
determine whether the training data used for the learning of the Bayesian NN is the first data set or the second data set based on an output of the Bayesian NN learned (Galinkin, section 4- teaches identifying adversarial attacks from the trained models).
It would have been obvious to one of ordinary skill in the art before the filing date of the claimed invention to modify Nasr with the teachings of Galinkin in order to determine the security of Bayesian models in the field of differential privacy for Bayesian inference (Galinkin, Abstract – “In many cases, neural networks perform well on test data, but tend to overestimate their confidence on out-of-distribution data. This has led to adoption of Bayesian neural networks, which better capture uncertainty and therefore more accurately reflect the model’s confidence. For machine learning security researchers, this raises the natural question of how making a model Bayesian affects the security of the model. In this work, we explore the interplay between Bayesianism and two measures of security: model privacy and adversarial robustness. We demonstrate that Bayesian neural networks are more vulnerable to membership inference attacks in general, but are at least as robust as their non-Bayesian counterparts to adversarial examples.”).
Regarding claim 2 (Currently Amended), Nasr in view of Galinkin teaches all of the limitations of the calculation device of claim 1 as noted above. Nasr further teaches wherein the processing circuitry is further configured to determine whether the training data used for learning of the Bayesian NN is the first data set or the second data set based on information obtained by integrating a plurality of outputs obtained by inputting one sample to the Bayesian NN learned a plurality of times or inputting each of a plurality of samples to the Bayesian NN one or more times (Nasr, section III.C – teaches iterating through the training (for a selected dataset) a given number of times).
It would have been obvious to one of ordinary skill in the art before the filing data of the claimed invention to combine the teachings of Nasr and Galinkin for the same reasons as disclosed in claim 1 above.
Claim(s) 3-5 is/are rejected under 35 U.S.C. 103 as being unpatentable over Nasr in view of Galinkin and further in view of Triastcyn et al. (Bayesian Differential Privacy for Machine Learning, hereinafter referred to as “Triastcyn”)
Regarding claim 3 (Currently Amended), Nasr in view of Galinkin teaches all of the limitations of the calculation device of claim 1 as noted above. However, Nasr in view of Galinkin does not explicitly teach wherein, when the Bayesian NN outputs a statistical value of posterior distribution, the processing circuitry is further configured to determine whether the training data used for learning of the Bayesian NN is the first data set or the second data set based on the statistical value.
Triastcyn teaches wherein, when the Bayesian NN outputs a statistical value of posterior distribution, the processing circuitry is further configured to determine whether the training data used for learning of the Bayesian NN is the first data set or the second data set based on the statistical value (Triastcyn, section 4.1 – teaches strong Bayesian differential privacy wherein probability is taken over the randomness of the model outcome and the additional example of the second dataset; see also Triastcyn, section 3).
It would have been obvious to one of ordinary skill in the art before the filing date of the claimed invention to modify Nasr in view of Galinkin with the teachings of Triastcyn in order to generate stronger privacy while maintaining classification accuracy in the field of differential privacy for Bayesian inference (Triastcyn, Abstract – “Traditional differential privacy is independent of the data distribution. However, this is not well-matched with the modern machine learning context, where models are trained on specific data. As a result, achieving meaningful privacy guarantees in ML often excessively reduces accuracy. We propose Bayesian differential privacy (BDP), which takes into account the data distribution to provide more practical privacy guarantees. We also derive a general privacy accounting method under BDP, building upon the well-known moments accountant. Our experiments demonstrate that in-distribution samples in classic machine learning datasets, such as MNIST and CIFAR-10, enjoy significantly stronger privacy guarantees than postulated by DP, while models maintain high classification accuracy.”).
Regarding claim 4 (Currently Amended), Nasr in view of Galinkin teaches all of the limitations of the calculation device of claim 1 as noted above. However, Nasr in view of Galinkin does not explicitly teach wherein, when the Bayesian NN outputs a plurality of predicted values sampled from posterior distribution, the processing circuitry is further configured to determine whether the training data used for learning of the Bayesian NN is the first data set or the second data set based on a statistical value regarding the predicted values.
Triastcyn teaches wherein, when the Bayesian NN outputs a plurality of predicted values sampled from posterior distribution, the processing circuitry is further configured to determine whether the training data used for learning of the Bayesian NN is the first data set or the second data set based on a statistical value regarding the predicted values (Triastcyn, section 4.1 – teaches weak Bayesian differential privacy based on a probability for any set of outcomes; see also Triastcyn, section 3).
It would have been obvious to one of ordinary skill in the art before the filing date of the claimed invention to modify Nasr in view of Galinkin with the teachings of Triastcyn in order to generate stronger privacy while maintaining classification accuracy in the field of differential privacy for Bayesian inference (Triastcyn, Abstract – “Traditional differential privacy is independent of the data distribution. However, this is not well-matched with the modern machine learning context, where models are trained on specific data. As a result, achieving meaningful privacy guarantees in ML often excessively reduces accuracy. We propose Bayesian differential privacy (BDP), which takes into account the data distribution to provide more practical privacy guarantees. We also derive a general privacy accounting method under BDP, building upon the well-known moments accountant. Our experiments demonstrate that in-distribution samples in classic machine learning datasets, such as MNIST and CIFAR-10, enjoy significantly stronger privacy guarantees than postulated by DP, while models maintain high classification accuracy.”).
Regarding claim 5 (Currently Amended), Nasr in view of Galinkin and further in view of Triastcyn teaches all of the limitations of the calculation device of claim 3 as noted above. Triastcyn further teaches wherein the processing circuitry is further configured to determine whether the training data used for learning of the Bayesian NN is the first data set or the second data set depending on whether the statistical value is equal to or greater than a threshold (Triastcyn, section 3 - teaches determining the dataset based on an outcome probability threshold; see also Triastcyn, section A.1).
It would have been obvious to one of ordinary skill in the art before the filing date of the claimed invention to combine the teachings of Nasr, Galinkin and Triastcyn in order to determine a training dataset to generate stronger privacy while maintaining classification accuracy (Triastcyn, Abstract).
Conclusion
Any inquiry concerning this communication or earlier communication from the examiner should be directed to MARSHALL WERNER whose telephone number is (469) 295-9143. The examiner can normally be reached on Monday – Thursday 7:30 AM – 4:30 PM ET.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Kamran Afshar, can be reached at (571) 272-7796. The fax number for the organization where this application or proceeding is assigned is (571) 273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/MARSHALL L WERNER/ Primary Examiner, Art Unit 2125