Prosecution Insights
Last updated: October 02, 2026
Application No. 18/758,848

APPARATUS, METHOD AND COMPUTER PROGRAM

Non-Final OA §101§102§103
Filed
Jun 28, 2024
Priority
Jul 28, 2023 — IN 202311051051
Examiner
KWON, JUN
Art Unit
Tech Center
Assignee
Nokia Corporation
OA Round
1 (Non-Final)
41%
Grant Probability
Moderate
1-2
OA Rounds
2y 5m
Est. Remaining
88%
With Interview

Examiner Intelligence

Grants 41% of resolved cases
41%
Career Allowance Rate
32 granted / 78 resolved
-19.0% vs TC avg
Strong +47% interview lift
Without
With
+47.2%
Interview Lift
resolved cases with interview
Typical timeline
4y 8m
Avg Prosecution
32 currently pending
Career history
108
Total Applications
across all art units

Statute-Specific Performance

§101
28.0%
-12.0% vs TC avg
§103
48.5%
+8.5% vs TC avg
§102
9.0%
-31.0% vs TC avg
§112
13.7%
-26.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 78 resolved cases

Office Action

§101 §102 §103
Detailed Action Claims 1-17 are presently pending. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-10 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. Regarding claim 1, Step 1: Claim 1 recites an apparatus comprising: at least one processor, and at least one memory including computer program code, wherein the at least one memory and the computer program code. Therefore, it is directed to the statutory category of a machine. 2A Prong 1: obtaining a first inference output from the first machine learning model and a second inference output from the second machine learning model; (mental process of evaluation – inference, can be done in one’s mind) determining, based on the first inference output and the second inference output that the first machine learning model has been attacked; and (mental process of evaluation – determining that a model has been attacked, can be done in one’s mind) 2A Prong 2: An apparatus comprising: at least one processor, and at least one memory including computer program code, wherein the at least one memory and the computer program code are configured, with the at least one processor, to cause the apparatus at least to perform: (mere instructions to apply an exception using a generic computer component MPEP 2106.05(f)) receiving a request from an analytics consumer for analytics information from a first machine learning model; (insignificant extra-solution activity MPEP 2106.05(g)(iii) of gathering statistics) obtaining the first machine learning model; (mere instructions to apply an exception using a generic computer component MPEP 2106.05(f) – conventional machine learning model training process) obtaining a second machine learning model, the second machine learning model being trained prior to the first machine learning model, the first machine learning model and the second machine learning model having the same analytics identifier; (mere instructions to apply an exception using a generic computer component MPEP 2106.05(f) – conventional machine learning model training process) providing an indication to a network entity that the first machine learning model has been attacked. (mere instructions to apply an exception using a generic computer component MPEP 2106.05(f)) The additional elements as disclosed above alone or in combination do not integrate the judicial exception into practical application as they are mere insignificant extra solution activity, combination of generic computer functions that are implemented to perform the disclosed abstract idea above. 2B: An apparatus comprising: at least one processor, and at least one memory including computer program code, wherein the at least one memory and the computer program code are configured, with the at least one processor, to cause the apparatus at least to perform: (mere instructions to apply an exception using a generic computer component MPEP 2106.05(f)) receiving a request from an analytics consumer for analytics information from a first machine learning model; (indicated as an insignificant extra-solution activity MPEP 2106.05(g)(iii) in Step 2A Prong 2. Therefore, it is re-evaluated as well understood, routine and conventional activity MPEP 2106.05(d)(II)(iv) of gathering statistics) obtaining the first machine learning model; (mere instructions to apply an exception using a generic computer component MPEP 2106.05(f) – conventional machine learning model training process) obtaining a second machine learning model, the second machine learning model being trained prior to the first machine learning model, the first machine learning model and the second machine learning model having the same analytics identifier; (mere instructions to apply an exception using a generic computer component MPEP 2106.05(f) – conventional machine learning model training process) providing an indication to a network entity that the first machine learning model has been attacked. (mere instructions to apply an exception using a generic computer component MPEP 2106.05(f)) The additional elements as disclosed above in combination of the abstract idea are not sufficient to amount to significantly more than the judicial exception as they are well, understood, routine and conventional activity as disclosed in combination of generic computer functions that are implemented to perform the disclosed abstract idea above. Regarding claim 2, Step 1: A machine, as above. 2A Prong 1: determining a concept drift between the first inference output and the second inference output and determining that the first machine learning model has been attacked based on the determined concept drift. (mental process of evaluation – comparing the first output and the second output, which can be done in one’s mind) 2A Prong 2: The apparatus according to claim 1, wherein the at least one memory and the computer program code are configured, with the at least one processor, to cause the apparatus to perform (mere instructions to apply an exception using a generic computer component MPEP 2106.05(f)) 2B: The apparatus according to claim 1, wherein the at least one memory and the computer program code are configured, with the at least one processor, to cause the apparatus to perform (mere instructions to apply an exception using a generic computer component MPEP 2106.05(f)) Regarding claim 3, Step 1: A machine, as above. 2A Prong 1: determining that the first machine learning model has been attacked based on a concept drift threshold value. (mental process of evaluation – comparing the value to a threshold value, which can be done in one’s mind) 2A Prong 2: The apparatus according to claim 2, wherein the at least one memory and the computer program code are configured, with the at least one processor, to cause the apparatus to perform (mere instructions to apply an exception using a generic computer component MPEP 2106.05(f)) 2B: The apparatus according to claim 2, wherein the at least one memory and the computer program code are configured, with the at least one processor, to cause the apparatus to perform (mere instructions to apply an exception using a generic computer component MPEP 2106.05(f)) Regarding claim 4, Step 1: A machine, as above. 2A Prong 1: determining that the first machine learning model has been attacked further based on the feedback information. (mental process of evaluation – determining, which can be done in one’s mind) 2A Prong 2: The apparatus according to claim 1, wherein the at least one memory and the computer program code are configured, with the at least one processor, to cause the apparatus to perform providing the first inference output to the analytics consumer (mere instructions to apply an exception using generic computer components MPEP 2106.05(f)), obtaining feedback information based on the first inference output from the analytics consumer (insignificant extra-solution activity MPEP 2106.05(g)(iii) of gathering statistics) 2B: The apparatus according to claim 1, wherein the at least one memory and the computer program code are configured, with the at least one processor, to cause the apparatus to perform providing the first inference output to the analytics consumer (mere instructions to apply an exception using generic computer components MPEP 2106.05(f)), obtaining feedback information based on the first inference output from the analytics consumer (indicated as an insignificant extra-solution activity MPEP 2106.05(g)(iii) in Step 2A Prong 2. Therefore, it is re-evaluated as well understood, routine and conventional activity MPEP 2106.05(d)(II)(iv) of gathering statistics) Regarding claim 5, Step 1: A machine, as above. 2A Prong 1: determining a network function from the at least one network function where the first machine learning model was attacked based on the first training data and the second training data. (mental process of evaluation – determining which network function is involved in the attack, which can be done in one’s mind) 2A Prong 2: The apparatus according to claim 1, wherein the at least one memory and the computer program code are configured, with the at least one processor, to cause the apparatus to perform obtaining first training data used for training the first machine learning model from at least one network function, obtaining second training data used for training the second machine learning model from the at least one network function (insignificant extra-solution activity MPEP 2106.05(g)(iii) of gathering statistics) 2B: The apparatus according to claim 1, wherein the at least one memory and the computer program code are configured, with the at least one processor, to cause the apparatus to perform obtaining first training data used for training the first machine learning model from at least one network function, obtaining second training data used for training the second machine learning model from the at least one network function (indicated as an insignificant extra-solution activity MPEP 2106.05(g)(iii) in Step 2A Prong 2. Therefore, it is re-evaluated as well understood, routine and conventional activity MPEP 2106.05(d)(II)(iv) of gathering statistics) Regarding claim 6, Step 1: A machine, as above. 2A Prong 1: determining a data distribution drift based on the first training data and the second training data. (mental process of evaluation – determining a data distribution drift based on dataset, can be done in one’s mind) 2A Prong 2: The apparatus according to claim 5, wherein the at least one memory and the computer program code are configured, with the at least one processor, to cause the apparatus to perform (mere instructions to apply an exception using generic computer components MPEP 2106.05(f)) 2B: The apparatus according to claim 5, wherein the at least one memory and the computer program code are configured, with the at least one processor, to cause the apparatus to perform (mere instructions to apply an exception using generic computer components MPEP 2106.05(f)) Regarding claim 7, Step 1: A machine, as above. 2A Prong 1: determining the network function from the plurality of network functions based on a data distribution drift threshold value. (mental process of evaluation – determining a data distribution drift based on dataset, can be done in one’s mind) 2A Prong 2: The apparatus according to claim 6, wherein the at least one memory and the computer program code are configured, with the at least one processor, to cause the apparatus to perform (mere instructions to apply an exception using generic computer components MPEP 2106.05(f)) 2B: The apparatus according to claim 6, wherein the at least one memory and the computer program code are configured, with the at least one processor, to cause the apparatus to perform (mere instructions to apply an exception using generic computer components MPEP 2106.05(f)) Regarding claim 8, Step 1: A machine, as above. 2A Prong 1: Incorporates the rejection of claim 5. 2A Prong 2: The apparatus according to claim 5, wherein the at least one memory and the computer program code are configured, with the at least one processor, to cause the apparatus to perform providing an indication of the determined network function to the network entity. (insignificant extra-solution activity MPEP 2106.05(g)(iii) of presenting offer) 2B: The apparatus according to claim 5, wherein the at least one memory and the computer program code are configured, with the at least one processor, to cause the apparatus to perform providing an indication of the determined network function to the network entity. (insignificant extra-solution activity MPEP 2106.05(d)(II)(i) of transmitting data over a network) Regarding claim 9, Step 1: A machine, as above. 2A Prong 1: Incorporates the rejection of claim 1. 2A Prong 2: wherein the at least one memory and the computer program code are configured, with the at least one processor, to cause the apparatus to perform excluding the determined network function when requesting data for subsequent training of the first machine learning model. (mere instructions to apply an exception using a generic computer component MPEP 2106.05(f)) 2B: wherein the at least one memory and the computer program code are configured, with the at least one processor, to cause the apparatus to perform excluding the determined network function when requesting data for subsequent training of the first machine learning model. (mere instructions to apply an exception using a generic computer component MPEP 2106.05(f)) Regarding claim 10, Step 1: A machine, as above. 2A Prong 1: Incorporates the rejection of claim 1. 2A Prong 2: wherein the network entity comprises a network analytics function, an operations and management function or a user equipment. (mere instructions to apply an exception using a generic computer component MPEP 2106.05(f)) 2B: wherein the network entity comprises a network analytics function, an operations and management function or a user equipment. (mere instructions to apply an exception using a generic computer component MPEP 2106.05(f)) Claim Rejections - 35 USC § 102 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention. (a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention. Claims 14-17 are rejected under 35 U.S.C. 102(a)(2) as being anticipated by Karampatsis et al. (US 20230345297 A1, hereinafter ‘Karampatsis’). Regarding claim 14, Karampatsis teaches: An apparatus comprising: at least one processor, and at least one memory including computer program code, wherein the at least one memory and the computer program code are configured, with the at least one processor, to cause the apparatus at least to perform: ([Karampatsis, 0106]-[0107] and [0113] discloses that the apparatus is implemented using processors and memories) receiving a request for receiving a request from a network entity for a machine learning model associated with an analytics identifier; and ([Karampatsis, Fig. 5, block 505], [0106] and [0120] The processor 405 receives a first request for a trained ML model from a Network Function that supports analytics generation. The first request may be based on an Analytics Request sent by a Consumer network function) providing the machine learning model associated with the analytics identifier to the network entity. ([0061]-[0062] The MMTF-NWDAF 260 receives initial ML models from an ML model Designer 265 and collects data from Data Producer Network Functions, and the AGF-NWDAF 255 receives the trained ML models from the MMTF-NWDAFs 260 and uses the trained model to derive network analytics) Regarding claim 15, Karampatsis teaches: The apparatus according to claim 14, wherein the at least one memory and the computer program code are configured, with the at least one processor, to cause the apparatus to perform receiving a request from the network entity for training data from at least one network function used for training the machine learning model associated with the analytics identifier and providing the training data to the network entity. ([Karampatsis, Fig. 5, block 505], [0106] and [0120] The processor 405 receives a first request for a trained ML model from a Network Function that supports analytics generation. The first request may be based on an Analytics Request (request for training data) sent by a Consumer network function. [Karampatsis, Fig. 5, block 510-515], and [0061]-[0062] The MMTF-NWDAF 260 receives initial ML models from an ML model Designer 265 and collects data from Data Producer Network Functions (network function used for training the ML model) to train the model, and the AGF-NWDAF 255 receives the trained ML models from the MMTF-NWDAFs 260 and uses the trained model to derive network analytics) Regarding claim 16, Karampatsis teaches: The apparatus according to claim 14, wherein the apparatus comprises an analytics data repository function or a data repository comprising the machine learning model and the training data. ([Karampatsis, Fig. 2B, block 260] and [0062] The MMTF-NWDAFs 260 (analytics data repository function) receives trained ML models and training data and the AGF-NWDAF 255 uses the trained model) Regarding claim 17, Karampatsis teaches: The apparatus according to claim 14, wherein the network entity comprises an analytics network function or a radio access network node. ([Karampatsis, Fig. 2B] and [0052]-[0053] The NWDAF includes analytics generation function 255, consumer NF, model training functions, ML model designer, and Data producer NFs/DDCF 270. NF denotes ‘Network Function’) Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-4 and 9-10 are rejected under 35 U.S.C. 103 as being unpatentable over Karampatsis et al. (US 20230345297 A1, hereinafter ‘Karampatsis’) in view of Sethi et al. (“Handling adversarial concept drift in streaming data”, 2018, hereinafter ‘Sethi’) and further in view of Bosansky et al. (US 20230130651 A1, hereinafter ‘Bosansky’). Regarding claim 1, Karampatsis teaches: An apparatus comprising: ([Karampatsis, 0106]-[0107] and [0113] discloses that the apparatus is implemented using processors and memories) at least one processor, and at least one memory including computer program code, wherein the at least one memory and the computer program code are configured, with the at least one processor, to cause the apparatus at least to perform: ([Karampatsis, 0106]-[0107] and [0113] discloses that the apparatus is implemented using processors and memories) receiving a request from an analytics consumer for analytics information from a first machine learning model; ([Karampatsis, Fig. 5, block 505], [0106] and [0120] The processor 405 receives a first request for a trained ML model from a Network Function that supports analytics generation. The first request may be based on an Analytics Request sent by a Consumer network function) obtaining the first machine learning model; ([Karampatsis, Fig. 5, block 510] and [0120] The first trained ML model is provided to the NF. [0061] The MMTF-NWDAF 260 receives initial ML models from an ML model Designer 265 and collect historical data from a DDCF 136 to train the received initial ML models) obtaining a second machine learning model, [Karampatsis, Fig. 5, block 515] [Fig. 2B] and [0062] The analytics generation function 255 receives the trained ML models from the MMTF-NWDAFs 260 and uses the trained model. [0061] The MMTF-NWDAF 260 receives initial ML models from an ML model Designer 265 and collects historical data from a DDCF 136 to train the received initial ML models. The initial ML model’s’ include the first and the second machine learning model. The first machine learning model 260 and the second machine learning model 260 share the same analytics generation function 255) obtaining a first inference output from the first machine learning model [Karampatsis, Fig. 5, block 515] and [0058]-[0059] The analysis generation function 255 uses a trained ML model to derive analytics, and provides analytics info to consumer Network Function 210) determining, based on the first inference output [Karampatsis, Fig. 5, block 520], [0120] and [0125]-[0126] The method determines that the first trained ML model is invalid) providing an indication to a network entity that the first machine learning model has been [Karampatsis, Fig. 5, block 525], [0120]-[0122] After determining that the first trained ML model is invalid, the method notifies the NF that the validity of the first trained ML model has changed) However, Karampatsis does not specifically disclose: obtaining a second machine learning model, the second machine learning model being trained prior to the first machine learning model obtaining a first inference output from the first machine learning model and a second inference output from the second machine learning model; determining, based on the first inference output and the second inference output that the first machine learning model has been attacked; Sethi teaches: obtaining a first inference output from the first machine learning model and a second inference output from the second machine learning model; ([Sethi, page 25, Fig. 9] and [page 27, Algorithm 2] and [page 27, left col, line 1 – right col, line 23] Prediction outputs from detect models C p and C D (the first machine learning model and the second machine learning model) are compared to compute disagreement score - D i s ( x = X t ) ) determining, based on the first inference output and the second inference output that the first machine learning model has been attacked; ([Sethi, page 25, Fig. 9] and [page 27, Algorithm 2] and [page 27, left col, line 1 – right col, line 23] Prediction outputs from detect models C p and C D (the first machine learning model and the second machine learning model) are compared to compute disagreement score - D i s ( x = X t ) . The score P D t is calculated based on the disagreement score, and if P D t is larger than the P D R e f threshold value, then the algorithm 2 concludes that the adversarial drift is detected. [page 26, 3.2.3. Detecting adversarial drift reliably from unlabeled data, line 1 – right col, line 18] discloses that the adversarial aware drift detection algorithm detects attacks to input data stream X (legitimate/malicious) ) It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to use the method of determining whether a machine learning model is attacked by comparing the output of the machine learning model and another machine learning model of Sethi to implement the data poisoning attack detection method of the present invention. The suggestion and/or motivation for doing so is to improve the performance of the concept drift detection system. The prediction-detection streaming framework of Sethi provides early and reliable unsupervised indication of concept drift and help Karampatsis to capture adversaries/invalidity by misdirecting them into revealing themselves [Sethi, ABSTRACT]. However, Karampatsis in view of Sethi do not specifically disclose: obtaining a second machine learning model, the second machine learning model being trained prior to the first machine learning model Bosansky teaches: obtaining a second machine learning model, the second machine learning model being trained prior to the first machine learning model ([Bosansky, Claim 1], [0031], and [Fig. 4] A machine-learning model is trained in a first subsequent time period, and then another machine learning model is trained using the same training data) It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to use the method of training a second machine learning model prior to the first machine learning model of Bosansky to implement the data poisoning attack detection method of the present invention. The suggestion and/or motivation for doing so is to improve the efficiency and accuracy of the concept drift detection system by allowing the system to be trained using new training data with new threats collected from different time windows [Bosansky, 0005]. Regarding claim 2, Karampatsis in view of Sethi teaches: The apparatus according to claim 1, wherein the at least one memory and the computer program code are configured, with the at least one processor, to cause the apparatus to perform determining a concept drift between the first inference output and the second inference output and determining that the first machine learning model has been attacked based on the determined concept drift. ([Sethi, page 25, Fig. 9] and [page 27, Algorithm 2] and [page 27, left col, line 1 – right col, line 23] Prediction outputs from detect models C p and C D (the first machine learning model and the second machine learning model) are compared to compute disagreement score - D i s ( x = X t ) . The score P D t is calculated based on the disagreement score, and if P D t is larger than the P D R e f threshold value, then the algorithm 2 concludes that the adversarial drift is detected. [page 26, 3.2.3. Detecting adversarial drift reliably from unlabeled data, line 1 – right col, line 18] discloses that the adversarial aware drift detection algorithm detects attacks to input data stream X (legitimate/malicious) ) Regarding claim 3, Karampatsis in view of Sethi teaches: The apparatus according to claim 2, wherein the at least one memory and the computer program code are configured, with the at least one processor, to cause the apparatus to perform determining that the first machine learning model has been attacked based on a concept drift threshold value. ([Sethi, page 25, Fig. 9] and [page 27, Algorithm 2] and [page 27, left col, line 1 – right col, line 23] Prediction outputs from detect models C p and C D (the first machine learning model and the second machine learning model) are compared to compute disagreement score - D i s ( x = X t ) . The score P D t is calculated based on the disagreement score, and if P D t is larger than the P D R e f threshold value, then the algorithm 2 concludes that the adversarial drift is detected. [page 26, 3.2.3. Detecting adversarial drift reliably from unlabeled data, line 1 – right col, line 18] discloses that the adversarial aware drift detection algorithm detects attacks to input data stream X (legitimate/malicious) ) Regarding claim 4, Karampatsis teaches: The apparatus according to claim 1, wherein the at least one memory and the computer program code are configured, with the at least one processor, to cause the apparatus to perform providing the first inference output to the analytics consumer, obtaining feedback information based on the first inference output from the analytics consumer and determining that the first machine learning model has been [Karampatsis, 0056]-[0057] The consumer NF receive periodic analytic information, and the consumer NF may provide feedback about if the given data to a machine learning model is valid or invalid) Sethi teaches: determining that the first machine learning model has been attacked ([Sethi, page 26, 3.2.3. Detecting adversarial drift reliably from unlabeled data, line 1 – right col, line 18] discloses that the adversarial aware drift detection algorithm detects attacks to input data stream X (legitimate/malicious) ) Regarding claim 9, Karampatsis teaches: The apparatus according to claim 1, wherein the at least one memory and the computer program code are configured, with the at least one processor, to cause the apparatus to perform excluding the determined network function when requesting data for subsequent training of the first machine learning model. ([Karampatsis, 0109] Subsequent to training and determining the first ML model, a second ML model is trained. If the validity time of the data collected from an NF is invalid, then new training data may be collected (excluding invalid data)) Regarding claim 10, Karampatsis teaches: The apparatus according to claim 1, wherein the network entity comprises a network analytics function, an operations and management function or a user equipment. ([Karampatsis, Fig. 2B] and [0052]-[0053] The NWDAF includes analytics generation function 255, consumer NF, model training functions, ML model designer, and Data producer NFs/DDCF 270. NF denotes ‘Network Function’) Claims 5-8 are rejected under 35 U.S.C. 103 as being unpatentable over Karampatsis in view of Sethi in view of Bosansky and further in view of Prabakaran et al. (“Predicting Attack Pattern via Machine Learning by Exploiting Stateful Firewall as Virtual Network Function in an SDN Network”, 2022, hereinafter ‘Prabakaran’) Regarding claim 5, Karampatsis teaches: The apparatus according to claim 1, wherein the at least one memory and the computer program code are configured, with the at least one processor, to cause the apparatus to perform obtaining first training data used for training the first machine learning model from at least one network function, obtaining second training data used for training the second machine learning model from the at least one network function and determining a network function from the at least one network function where the first machine learning model was attacked based on the first training data [Karampatsis, Fig. 5, block 515] [Fig. 2B] and [0062] The analytics generation function 255 receives the trained ML models from the MMTF-NWDAFs 260 and uses the trained model. [0061] The MMTF-NWDAF 260 receives initial ML models from an ML model Designer 265 and collects historical data from a DDCF 136 to train the received initial ML models. The initial ML model’s’ include the first and the second machine learning model. The first machine learning model 260 and the second machine learning model 260 share the same analytics generation function 255) Sethi teaches: determining [Sethi, page 25, Fig. 9] and [page 27, Algorithm 2] and [page 27, left col, line 1 – right col, line 23] Prediction outputs from detect models C p and C D (the first machine learning model and the second machine learning model) are compared to compute disagreement score - D i s ( x = X t ) . The score P D t is calculated based on the disagreement score, and if P D t is larger than the P D R e f threshold value, then the algorithm 2 concludes that the adversarial drift is detected. [page 26, 3.2.3. Detecting adversarial drift reliably from unlabeled data, line 1 – right col, line 18] discloses that the adversarial aware drift detection algorithm detects attacks to input data stream X (legitimate/malicious) ) However, Karampatsis in view of Sethi and further in view of Bosansky do not specifically disclose: determining where the first machine learning model was attacked Parabakaran teaches: determining where the first machine learning model was attacked ([Prabakaran, page 4, lines 3-22] and [page 8, paragraph below Figure 3, lines 1-10] discloses determining the target host for attackers by using machine learning algorithms and denying access to the target host) It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to use the method of determining where the first machine learning model was attacked of Parabakaran to implement the data poisoning attack detection method of the present invention. The suggestion and/or motivation for doing so is to improve the security and efficiency of the data poisoning attack detection method, as localizing the location of the attack and blocking the attack location prevents future attackers from gaining access to the system [Parabankaran, page 4, lines 3-11]. Regarding claim 6, Karampatsis in view of Sethi teaches: The apparatus according to claim 5, wherein the at least one memory and the computer program code are configured, with the at least one processor, to cause the apparatus to perform determining a data distribution drift based on the first training data and the second training data. ([Sethi, page 26, right col, Algorithm 1] and [page 26, left col, 3rd para, lines 1-33] discloses generating a few splits of training data (first training data and second training data) to train the first model and the second model. [Sethi, page 25, Fig. 9] and [page 27, Algorithm 2] and [page 27, left col, line 1 – right col, line 23] Prediction outputs from detect models C p and C D (the first machine learning model and the second machine learning model) are compared to compute disagreement score - D i s ( x = X t ) . The score P D t (current distribution) is calculated based on the disagreement score, and if P D t is larger than the P D R e f (reference distribution) threshold value, then the algorithm 2 concludes that the adversarial drift is detected. [page 26, 3.2.3. Detecting adversarial drift reliably from unlabeled data, line 1 – right col, line 18] discloses that the adversarial aware drift detection algorithm detects attacks to input data stream X (legitimate/malicious) ) Regarding claim 7, Karampatsis in view of Sethi teaches: The apparatus according to claim 6, wherein the at least one memory and the computer program code are configured, with the at least one processor, to cause the apparatus to perform determining [Sethi, page 26, right col, Algorithm 1] and [page 26, left col, 3rd para, lines 1-33] discloses generating a few splits of training data (first training data and second training data) to train the first model and the second model. [Sethi, page 25, Fig. 9] and [page 27, Algorithm 2] and [page 27, left col, line 1 – right col, line 23] Prediction outputs from detect models C p and C D (the first machine learning model and the second machine learning model) are compared to compute disagreement score - D i s ( x = X t ) . The score P D t (current distribution) is calculated based on the disagreement score, and if P D t is larger than the P D R e f (reference distribution) threshold value, then the algorithm 2 concludes that the adversarial drift is detected. [page 26, 3.2.3. Detecting adversarial drift reliably from unlabeled data, line 1 – right col, line 18] discloses that the adversarial aware drift detection algorithm detects attacks to input data stream X (legitimate/malicious) ) However, Karampatsis in view of Sethi and further in view of Bosansky do not specifically disclose: to perform determining the network function from the plurality of network functions. Prabakaran teaches: to perform determining the network function from the plurality of network functions ([Prabakaran, page 4, lines 3-22] and [page 8, paragraph below Figure 3, lines 1-10] discloses determining the target host for attackers by using machine learning algorithms and denying access to the target host) Regarding claim 8, Karampatsis teaches: The apparatus according to claim 5, wherein the at least one memory and the computer program code are configured, with the at least one processor, to cause the apparatus to perform providing an indication of the determined network function to the network entity. ([Karampatsis, Fig. 2B] and [0052]-[0053] The NWDAF includes analytics generation function 255, consumer NF, model training functions, ML model designer, and Data producer NFs/DDCF 270. [0058]-[0059] The analysis generation function 255 uses a trained ML model to derive analytics, and provides analytics info to consumer Network Function 210) Claims 11 and 13 are rejected under 35 U.S.C. 103 as being unpatentable over Karampatsis in view of Sethi. Regarding claim 11, Karampatsis teaches: An apparatus comprising: at least one processor, and at least one memory including computer program code, wherein the at least one memory and the computer program code are configured, with the at least one processor, to cause the apparatus at least to perform: ([Karampatsis, 0106]-[0107] and [0113] discloses that the apparatus is implemented using processors and memories) receiving a request from a network entity for a first machine learning model; ([Karampatsis, Fig. 5, block 505], [0106] and [0120] The processor 405 receives a first request for a trained ML model from a Network Function that supports analytics generation. The first request may be based on an Analytics Request sent by a Consumer network function) providing the first machine learning model; and ([0061]-[0062] The MMTF-NWDAF 260 receives initial ML models from an ML model Designer 265 and collects data from Data Producer Network Functions, and the AGF-NWDAF 255 receives the trained ML models from the MMTF-NWDAFs 260 and uses the trained model to derive network analytics) receiving an indication from the network entity that the first machine learning model has been (invalid). ([Karampatsis, Fig. 5, block 520], [0120] and [0125]-[0126] The method determines that the first trained ML model is invalid, and then the method notifies the NF that the validity of the first trained ML model has changed) Karampatsis does not specifically disclose: receiving an indication from the network entity that the first machine learning model has been attacked. Sethi teaches: receiving an indication attacked. ([page 26, 3.2.3. Detecting adversarial drift reliably from unlabeled data, line 1 – right col, line 18] discloses that the adversarial aware drift detection algorithm detects attacks to input data stream X (legitimate/malicious) ) It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to use the method of determining whether a machine learning model is attacked by comparing the output of the machine learning model and another machine learning model of Sethi to implement the data poisoning attack detection method of the present invention. The suggestion and/or motivation for doing so is to improve the performance of the concept drift detection system. The prediction-detection streaming framework of Sethi provides early and reliable unsupervised indication of concept drift and help Karampatsis to capture adversaries/invalidity by misdirecting them into revealing themselves [Sethi, ABSTRACT]. Regarding claim 13, Karampatsis teaches: The apparatus according to claim 11, wherein the network entity comprises an analytics network function, a radio access network node or an operations and management function. ([Karampatsis, Fig. 2B] and [0052]-[0053] The NWDAF includes analytics generation function 255, consumer NF, model training functions, ML model designer, and Data producer NFs/DDCF 270. NF denotes ‘Network Function’) Claim 12 is rejected under 35 U.S.C. 103 as being unpatentable over Karampatsis in view of Sethi and further in view of Prabakaran. Regarding claim 12, Karampatsis teaches: The apparatus according to claim 11, comprising wherein the at least one memory and the computer program code are configured, with the at least one processor, to cause the apparatus to perform receiving a request from the network entity for first training data from at least one network function used for training the first machine learning model, providing the first training data to the network entity and receiving an indication from the network entity, based on the first training data, of a network function determined from the at least one network function model was [Karampatsis, Fig. 5, block 515] [Fig. 2B] and [0062] The analytics generation function 255 receives the trained ML models from the MMTF-NWDAFs 260 and uses the trained model. [0061] The MMTF-NWDAF 260 receives initial ML models from an ML model Designer 265 and collects historical data from a DDCF 136 to train the received initial ML models. The initial ML model’s’ include the first and the second machine learning model. The first machine learning model 260 and the second machine learning model 260 share the same analytics generation function 255) However, Karampatsis does not specifically disclose: determined from the at least one network function where the first machine learning model was attacked. Sethi teaches: determined attacked. ([page 26, 3.2.3. Detecting adversarial drift reliably from unlabeled data, line 1 – right col, line 18] discloses that the adversarial aware drift detection algorithm detects attacks to input data stream X (legitimate/malicious) ) However, Karampatsis in view of Sethi do not specifically disclose: determined from at least one network function where the first machine learning model was attacked. Prabakaran teaches: determined from at least one network function where the first machine learning model was attacked. ([Prabakaran, page 4, lines 3-22] and [page 8, paragraph below Figure 3, lines 1-10] discloses determining the target host for attackers by using machine learning algorithms and denying access to the target host) It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to use the method of determining where the first machine learning model was attacked of Parabakaran to implement the data poisoning attack detection method of the present invention. The suggestion and/or motivation for doing so is to improve the security and efficiency of the data poisoning attack detection method, as localizing the location of the attack and blocking the attack location prevents future attackers from gaining access to the system [Parabankaran, page 4, lines 3-11]. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to JUN KWON whose telephone number is (571)272-2072. The examiner can normally be reached Monday – Friday 8:00AM – 5:00PM ET. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Abdullah Kawsar can be reached at (571)270-3169. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /JUN KWON/Examiner, Art Unit 2127 /BRIAN M SMITH/Primary Examiner, Art Unit 2122
Read full office action

Prosecution Timeline

Jun 28, 2024
Application Filed
Sep 10, 2026
Non-Final Rejection mailed — §101, §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12737633
TRAINING A FEDERATED GENERATIVE ADVERSARIAL NETWORK
3y 9m to grant Granted Sep 15, 2026
Patent 12731035
LABEL INFERENCE IN SPLIT LEARNING DEFENSES
3y 8m to grant Granted Sep 08, 2026
Patent 12718063
DEEP LEARNING ARCHITECTURE FOR ADVERSE MEDIA SCREENING
3y 11m to grant Granted Aug 25, 2026
Patent 12711383
ACCURATE ENSEMBLE BY MUTATING NEURAL NETWORK PARAMETERS
7y 3m to grant Granted Aug 18, 2026
Patent 12705504
KNOWLEDGE BASE CONSTRUCTION
8y 5m to grant Granted Aug 11, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
41%
Grant Probability
88%
With Interview (+47.2%)
4y 8m (~2y 5m remaining)
Median Time to Grant
Low
PTA Risk
Based on 78 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month