Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
This action is responsive to the following communication: Preliminary Amendment filed Jun. 26, 2024.
Claims 1-20 are pending in the case. Claims 1, 9 and 17 are independent claims.
Claim Rejections - 35 USC § 112
The term “substantially” in claims 5, 6, 13 and 14 is a relative term which renders the claim indefinite. The term “substantially” is not defined by the claim, the specification does not provide a standard for ascertaining the requisite degree, and one of ordinary skill in the art would not be reasonably apprised of the scope of the invention. Claims 5, 6, 13 and 14 are rejected.
Claim Rejections - 35 USC § 102
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claims 1-2, 6, 9-10, 14 and 17-18 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Hong et al. (hereinafter Hong) ”Security Analysis of Deep Neural Networks Operating In The Presence of Cache Side Channel Attacks” Jan, 2020 .
With respect to independent claim 1, Hong teaches a computer-implemented method performed on a device, the method comprising:
receiving input data that describes one or more machine learning (ML) model characteristics of an ML model (see e.g., Page 10 Table 5 and Sect. 5.1 – “To evaluate our defense, we train these TinyNets at the same time as the victim’s process is running ResNet50, and we measure the number of errors in the extracted attributes. The results are listed in Table 5. We experiment with three TinyNets: 1) only with a Conv. layer (C:1), 2) Conv. with a ReLU layer (C:1, R:1), and 3) two Conv. and ReLU layers with a Merge layer.”);
determining, based on the one or more ML model characteristics of the ML model, one or more obfuscation instructions that are used to obfuscate a profile of a measurable parameter associated with the device when the device executes model instructions for the ML model (see e.g., Sect. 5.1 – “a defender can choose the attributes to obfuscate. Since the defender can control what noise gets introduced, they can also dynamically and adaptively change what noise is added into the attackers observations.” The defense uses configurable TinyNets having selected layer/function combinations and adaptively changing the introduced noise.); and
executing the one or more obfuscation instructions concurrently or sequentially with execution of the model instructions (see e.g., Page 10 Sect. 5.1 – “simultaneously with the actual process, we develop a simple but effective defensive strategy. The decoy process also invokes the target functions in the shared framework, which obfuscates the architecture attributes and computation sequences.”).
With respect to dependent claim 2, Hong teaches a number of the one or more obfuscation instructions executed is proportional to a number of layers of the ML model (see e.g. Page 10 and Sect. 5.1 – TinyNets with selected counts of convolution, ReLU and merge layers.).
With respect to dependent claim 6, Hong teaches executing the one or more obfuscation instructions concurrently or sequentially with execution of the model instructions comprises: executing one or more obfuscation instructions that render changes in the measurable parameter of the device due to execution of the model instructions substantially random (see e.g. Sect. 5.2).
Claim 9 is rejected for the similar reasons discussed above with respect to claim 1. Claim 10 is rejected for the similar reasons discussed above with respect to claim 2. Claim 14 is rejected for the similar reasons discussed above with respect to claim 6. Claim 17 is rejected for the similar reasons discussed above with respect to claim 1. Claim 18 is rejected for the similar reasons discussed above with respect to claim 2.
Claims 3, 11 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Hong in view of Marson et al. (hereinafter Marson) U.S. Patent Publication No. 2022/0197981.
With respect to dependent claim 1, Hong does not expressly show a number of the one or more obfuscation instructions executed is proportional to a number of nodes within each of the layers of the ML model. However, Marson teaches similar feature (see e.g. para [76]-[78] – “In some implementations, dummy nodes may be used to obfuscate a number of nodes in various layers of the NN. In some implementations, dummy nodes may be used to mask a nature of the NN, e.g. to present (to an attacker) a convolutional network (or a convolutional sub-network of a larger network) as a deconvolutional NN or a NN of fully-connected layers. For example, a portion of a layer may be made of dummy nodes (e.g. constant-output nodes), with the nodes of the next layer connected to the dummy nodes adjusting or canceling the inputs from the dummy nodes.” Although Marson doses not expressly show “proportional,” however, it would have been obvious because the applying of obfuscation/dummy operations is based on a per-layer, node-count.). Both Hong and Marson are directed to obfuscation of neural network. Accordingly, it would have been obvious to the skilled artisan before the effective filing date of the claimed invention having Hong and Marson in front of them to modify the system of Hong to include the above feature. The motivation to combine Hong and Marson comes from Marson. Marson discloses the motivation to applying of obfuscation/dummy operations on a per-layer, node-count basis so that performance can be improved (see e.g. para [76]-[78]).
Claim 11 is rejected for the similar reasons discussed above with respect to claim 3. Claim 19 is rejected for the similar reasons discussed above with respect to claim 3.
Claims 4, 12 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Hong in view of Satpathy et al. (hereinafter Satpathy) U.S. Patent Publication No. 2021/0185023.
With respect to dependent claim 4, Hong does not expressly show the feature shown below. However, Satpathy teaches the device comprises a plurality of processing units, wherein executing the one or more obfuscation instructions concurrently (see e.g. para [48][51] – “The simultaneous operation of encryption engine 41 and decryption engine 43 creates cross-engine “noise” in that the combination of power trace signatures of encryption engine 41 and decryption engine 43 obfuscate one another when sniffed by SCA hardware, such as an SCA analyzer … encryption engine 41 and decryption engine 43 are implemented separately in silicon at non-overlapping locations, the switching activity of one engine functions as obfuscating noise with respect to the power trace signature of the other engine in cases of simultaneous operation with different AES keys.”) or sequentially with execution of the model instructions comprises: executing the model instructions on a subset of the plurality of processing units; and executing the one or more obfuscation instructions on a different subset of the plurality of processing units. (see e.g. para [146] – “encryption engine 41 and decryption engine 43 to generate key-dissonant signal interference between one another, thereby obfuscating the overall power trace signature exhibited by HMD 12. Scheduler 3 thereby prevents SCA analyzers 7 and 9 from successfully performing CPA 160, because of the obfuscation of AES power traces 166.”). Both Hong and Satpathy are directed to executing obfuscation instructions. Accordingly, it would have been obvious to the skilled artisan before the effective filing date of the claimed invention having Hong and Satpathy in front of them to modify the system of Hong to include the above feature. The motivation to combine Hong and Satpathy comes from Satpathy. Satpathy discloses the motivation to executing obfuscation instructions on different processors so that performance can be improved (see e.g. para [48][51][146]).
Claim 12 is rejected for the similar reasons discussed above with respect to claim 4. Claim 20 is rejected for the similar reasons discussed above with respect to claim 4.
Claims 5, 7, 8, 13, 15 and 16 are rejected under 35 U.S.C. 103 as being unpatentable over Hong in view of Chong et al. (hereinafter Chong) U.S. Patent Publication No. 2020/0004992.
With respect to dependent claim 5, Hong does not expressly show teaches executing the one or more obfuscation instructions concurrently or sequentially with execution of the model instructions comprises: executing one or more obfuscation instructions that render changes in the measurable parameter of the device due to execution of the model instructions substantially undetectable. However, Chong teaches similar feature (see e.g., Abstract and Claim 1 – “the apparatus emits first analog electrical characteristics when the at least one genuine computation is performed and emits second analog electrical characteristics when the at least one redundant computation is performed, wherein a metric of similarity between the first analog electrical characteristics and the second analog electrical characteristics satisfies a threshold.”) Both Hong and Chong are directed to security countermeasure methods. Accordingly, it would have been obvious to the skilled artisan before the effective filing date of the claimed invention having Hong and Chong in front of them to modify the system of Hong to include the above feature. The motivation to combine Hong and Chong comes from Chong. Chong discloses the motivation to introduce redundant/partial redundant operation so that security can be improved (see e.g. Chong Abstract and Claim 1).
With respect to dependent claim 7, the modified Hong teaches the measurable parameter corresponds to a power dissipation of the device, wherein executing the one or more obfuscation instructions comprises: executing one or more obfuscation instructions that modulate the power dissipation of the device to thereby obfuscate a power dissipation profile associated with the execution of the ML instructions (see e.g. Chong Para [113][131] – “the first analog electrical characteristics or the second analog electrical characteristics include at least one of power dissipation or electromagnetic emission.”).
With respect to dependent claim 8, the modified Hong the measurable parameter corresponds to electromagnetic energy emanating from the device, wherein executing the one or more obfuscation instructions comprises: executing one or more obfuscation instructions that modulate the electromagnetic energy of the device to thereby obfuscate an electromagnetic energy profile associated with the model instructions (see e.g. Chong Para [113][131] – “the first analog electrical characteristics or the second analog electrical characteristics include at least one of power dissipation or electromagnetic emission.”).
Claim 13 is rejected for the similar reasons discussed above with respect to claim 5.
Claim 15 is rejected for the similar reasons discussed above with respect to claim 7.
Claim 16 is rejected for the similar reasons discussed above with respect to claim 8.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to PEIYONG WENG whose telephone number is (571)270-1660. The examiner can normally be reached on Mon.-Fri. 8 am to 5 pm.
If attempts to reach the examiner by telephone are unsuccessful, the examiner's supervisor, Matthew Ell, can be reached on (571) 270-3264. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://portal.uspto.gov/external/portal. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free).
/PEI YONG WENG/Primary Examiner, Art Unit 2141