Prosecution Insights
Last updated: October 02, 2026
Application No. 18/786,766

SYSTEMS AND METHODS FOR DETECTING VISUALLY SIMILAR EMAILS

Final Rejection §103
Filed
Jul 29, 2024
Priority
Dec 27, 2023 — provisional 63/614,993
Examiner
MCFARLAND-BARNES, KELAH JANAE
Art Unit
2431
Tech Center
2400 — Computer Networks
Assignee
Cisco Technology Inc.
OA Round
2 (Final)
80%
Grant Probability
Favorable
3-4
OA Rounds
11m
Est. Remaining
88%
With Interview

Examiner Intelligence

Grants 80% — above average
80%
Career Allowance Rate
8 granted / 10 resolved
+22.0% vs TC avg
Moderate +8% lift
Without
With
+8.3%
Interview Lift
resolved cases with interview
Typical timeline
3y 1m
Avg Prosecution
10 currently pending
Career history
30
Total Applications
across all art units

Statute-Specific Performance

§101
9.3%
-30.7% vs TC avg
§103
65.0%
+25.0% vs TC avg
§102
9.3%
-30.7% vs TC avg
§112
13.4%
-26.6% vs TC avg
Black line = Tech Center average estimate • Based on career data from 10 resolved cases

Office Action

§103
DETAILED ACTION In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. This Office Action is in response to the communication filed on 07/07/2026. Claims 1, 7-8, and 14-15 have been amended. Claims 1-20 are pending for consideration. Response to Arguments Applicant's arguments filed 07/07/2026 have been fully considered but they are not persuasive. Applicant argues that Graziano, Bartik, and Xu fail to teach the amended language, “in response to determining a first vector and a second vector of the plurality of vectors are visually similar, determining that a first email and a second email of the plurality of emails associated with the first vector and the second vector of the plurality of vectors, respectively, were created using a same email kit” because Xu uses the vector comparison method to determine whether the known vector is associated with a particular solution rather than for identifying email kits. Examiner disagrees. Xu teaches the use of feature vectors to determine whether images of solution incidents are similar (Figs. 3A and 3B; Col 8 lines 23-33). While Xu does not explicitly use the vector comparison to identify similarities between images of emails, the amended language exemplifies an intended use of Xu’s image comparison method. Furthermore, extracting and encoding features into vectors for comparison is a well-known method in the art of image processing. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-2, 8-9, and 15-16 are rejected under 35 U.S.C. 103 as being unpatentable over Graziano et al. (U.S. 2025/0106249)(hereinafter Graziano) in view of Bartik et al. (U.S. 10,601,866)(hereinafter Bartik), and in further view of Xu et al. (US 10,896,018)(hereinafter Xu). Regarding claims 1, 8, and 15, rendering each of a plurality of emails to generate an image (Graziano: see Page 6 paragraph 0074, "In particular, in the embodiment considered, the computer receives, in a step 1100, the (source) code COD of the e-mail or webpage, and the corresponding source data SRC. Moreover, once the code COD of the e-mail or of the webpages is obtained, the computer generates the image IMG via a rendering of the code COD"). However, Graziano does not teach generation of a plurality of images. Nevertheless, Bartik-which is in the same field of endeavor- teaches generation of a plurality of images (Bartik: see Col 9 lines 22-26, "Next at 206, the downloaded content is rendered and screenshots of the suspicious URL and the domain landing page URL are produced. Rendering URL content may consist of processing the downloaded content image to generate a screenshot (i.e., a realistic image of the webpage)"). Graziano and Bartik are analogous art because they are from the same field of endeavor. Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art to combine Graziano’s email rendering to produce an image with Bartik’s method for producing a plurality of images. The suggestion/motivation for doing so would be to process multiple sections of the screenshots and increase the amount of data that could be used for reference or historical data when performing similarity analysis. Graziano and Bartik do not teach teaches extracting a plurality of features from each of the plurality of processed images; encoding the plurality of features into a vector for each of the plurality of processed images to generate a plurality of vectors; determining whether two or more of the plurality of vectors are visually similar; and in response to determining a first vector and a second vector of the plurality of vectors are visually similar, determining that a first email and a second email of the plurality of emails associated with the first vector and the second vector of the plurality of vectors, respectively, were created using a same email kit. Nevertheless, Xu-which is in the same field of endeavor- teaches extracting a plurality of features from each of the plurality of processed images (Xu: see Col 13 lines 44-47, "providing the image for processing through an image model, the image model providing an initial set of features, each feature in the initial set of features being representative of the image"); encoding the plurality of features into a vector for each of the plurality of processed images to generate a plurality of vectors (Xu: see Col 13 lines 39-42, "processing, by the one or more processors, the image to generate a vector, the vector comprising features representative of the image, at least one feature representing one of more keywords of the image"); determining whether two or more of the plurality of vectors are visually similar (Xu: see Col 8 lines 23-29, "In some implementations, the vector module 212 provides the image vector to the comparison module 214. In some examples, the comparison module 214 compares the image vector to known vectors of the known vector DB 216. In some examples, the image vector is compared to known vectors in an effort to identify at least one known vector that is determined to be sufficiently similar to the image vector") and in response to determining a first vector and a second vector of the plurality of vectors are visually similar, determining that a first email and a second email of the plurality of emails associated with the first vector and the second vector of the plurality of vectors, respectively, were created using a same email kit (Xu: see Col 8 lines 23-33, "In some implementations, the vector module 212 provides the image vector to the comparison module 214. In some examples, the comparison module 214 compares the image vector to known vectors of the known vector DB 216. In some examples, the image vector is compared to known vectors in an effort to identify at least one known vector that is determined to be sufficiently similar to the image vector. In further detail, the image vector can be compared to each known vector (or a sub-set of known vectors) and a similarity score can be provided for each image vector (IV)—known vector (KV) pair"). Graziano, Bartik, and Xu are analogous art because they are from the same field of endeavor. Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art to use the images generated by Graziano and Bartik with Xu’s vector encoding to determine the similarity between images. The suggestion/motivation for doing so would be to detect a phishing attack; specifically attacks that utilize trusted icons, logos or information to convince a user to interact with the attack. Regarding claims 2, 9, and 16, Graziano teaches rendering a HyperText Markup Language (HTML) source for each of the plurality of emails (Graziano: see Page 6 paragraph 0074, “The code COD of an e-mail or of a webpage is typically in HTML (HyperText Markup Language) code, and the solutions for carrying out a graphic rendering of this HTML code are commonly known”). Claims 3-4, 10-11, and 17-18 are rejected under 35 U.S.C. 103 as being unpatentable over Graziano, Bartik, and Xu, as applied to claims 1-2, 8-9, and 15-16 above, and in further view of Choudhary et al. (US 12,020, 484)(hereinafter Choudhary). Regarding claims 3, 10, and 17, Graziano, Bartik, and Xu teach the invention detailed above. However, Graziano, Bartik, and Xu fail to teach each of the plurality of vectors captures a numerical representation of visual elements embedded within a single email. Nevertheless, Choudhary-which is in the same field of endeavor- teaches each of the plurality of vectors captures a numerical representation of visual elements embedded within a single email (Choudhary: see Col 10 lines 6-13, "The summarization of the extracted features by the dense layer allows the neural network processor 103 to generate an n-dimensional feature vector. In an example, if the 1-D array, representing the normalized pixel values of the reference image, at the input layer of the neural network model is of 3×32×32 dimensions, the dense layer may generate a 128-dimensional feature vector of the reference image"). Graziano, Bartik, Xu, and Choudhary are analogous art because they are from the same field of endeavor. Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art to use numerical representations of the vectors generated by Graziano, Bartik, and Xu when determining similarities between images. The suggestion/motivation for doing so would be to improve the efficiency and scalability of the matching technique. Regarding claims 4, 11, and 18, Graziano, Bartik, Xu and Choudhary teach grouping two or more of the plurality of vectors that are visually similar together using a clustering algorithm or a similarity threshold (Choudhary: see Col 10 lines 30-42, "The cluster generating engine 104 may create clusters including images that are similar to each other. The similarities between two images may be determined by measuring the cosine distance between the feature vectors of the two images"). Motivation to combine Graziano, Bartik, Xu and Choudhary, in the instant claim, is the same as that in claims 3, 10, and 17. Claims 5, 12, and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Graziano, Bartik, Xu, and Choudhary, as applied to claims 3-4, 10-11, and 17-18, and in further view of Kalman (US 8,260,078)(hereinafter Kalman). Regarding claims 5, 12, and 19, Graziano, Bartik, Xu, and Choudhary teach normalizing each of the plurality of images to modify pixel values to adhere to a particular range and distribution (Choudhary: see Col 17 lines 54-56, "The pixel values of each of the plurality of images may be normalized such that the pixel values fall in the range 0-1"). However, Graziano, Bartik, Xu, and Choudhary fail to teach sharpening each of the plurality of images to accentuate edges and intricate details. Nevertheless, Kalman-which is in the same field of endeavor- teaches sharpening each of the plurality of images to accentuate edges and intricate details (Kalman: see Col 1 lines 65-67- Col 2 lines 1-4, "For example, sharpening artifacts known as "bright overshoot" and "dark undershoot," known collectively as "overshoot," may be introduced into the digital image by the sharpening filter within regions of the digital image that rapidly transition from a bright area to a dark area. Such a region may be indicative of an edge between different objects represented by the digital image"). Graziano, Bartik, Xu, Choudhary and Kalman are analogous art because they are from the same field of endeavor. Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art to utilize Choudhary’s method for normalization of image pixels with Kalman’s method for sharpening the images of Graziano, Bartik, and Xu. The suggestion/motivation for doing so would be to improve the accuracy of the detection system by sharpening edges and details that will be used when determining similarities. Claims 6, 13, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Graziano, Bartik, Xu, as applied to claims 1-2, 8-9, and 15-16 above, and in further view of Nutt et al. (US 10,027,610)(hereinafter Nutt). Regarding claims 6, 13, and 20, Graziano, Bartik, and Xu teach the invention detailed above. However, Graziano, Bartik, and Xu fail to teach cropping each of the plurality of images to eliminate outer segments, the outer segments including an email header and redundant spaces surrounding a body of each of the plurality of images. Nevertheless, Nutt-which is in the same field of endeavor- teaches cropping each of the plurality of images to eliminate outer segments, the outer segments including an email header and redundant spaces surrounding a body of each of the plurality of images (Nutt: see Col 2 lines 1-5, "Some example embodiments could include embodiments where cropping an image includes at least loading the content source, crop the image, identify any html tags, crop the html tags, locate coordinates and dimensions of any links within the content source"). Graziano, Bartik, Xu, and Nutt are analogous art because they are from the same field of endeavor. Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art to utilize Nutt’s method for cropping the image generated by Graziano, Bartik, and Xu. The suggestion/motivation for doing so would be to make smaller or closer similarity thresholds by focusing on specific areas. Claims 7 and 14 are rejected under 35 U.S.C. 103 as being unpatentable over Graziano, Bartik, and Xu, as applied to claims as applied to claims 1-2, 8-9, and 15-16 above, and in further view of Luo et al. (US 12,333,394)(hereinafter Luo). Regarding claims 7 and 14, Graziano, Bartik, and Xu teach the invention detailed above. However, Graziano, Bartik, and Xu fail to teach the plurality of emails comprise historic emails and new emails, wherein the first email is a historic email and the second email is a new email; the historic emails represent emails that have been manually reclassified to include correct labels, the correct labels comprising spam, phishing, and graymail labels; and the new emails have been filtered to only include emails with one or more visual components. Nevertheless, Luo-which is in the same field of endeavor- teaches the plurality of emails comprise historic emails and new emails, wherein the first email is a historic email and the second email is a new email (Luo: see Col 8 lines 13-17, “At 302, labeled email features are received. The labeled email features may be such things as identifying a given email address as being associated with spam or a label that identifies a particular IP address as being associated with a computer that is known to send good email”; Col 8 lines 47-49, “The unlabeled emails may include but are not limited to newly received emails that have come into an email system from an external network”); the historic emails represent emails that have been manually reclassified to include correct labels (Luo: see Col 27 lines 8-17, "receiving a labeled cluster comprising an email-category label and seed data; assigning the email-category label to the unlabeled email based on a first derivative edge in an expansion graph thereby creating a labeled email, wherein the first derivative edge is a directional edge from the labeled cluster to the feature and the first derivative edge represents first inference logic that the email-category label associated with the labeled cluster is also associated with the unlabeled email"; Col 27 claim 4, " the seed data comprise a previously labeled email, a denylist, an allowlist, or a communication graph"), the correct labels comprising spam, phishing, and graymail labels (Luo: see Col 5 lines 22-34, "...It may be a “spam” email which is electronic junk mail that is unsolicited and often contains advertising from some product. The email 104 may be a “phishing” email which is a fraudulent email falsely claiming to be an established legitimate enterprise in an attempt to scam the user into surrendering private information that will be used for identity theft or other crime. “Bulk” email is another possibility for the email 104. Bulk email is email that is sent to large groups at once. It is typically comprised of advertising or marketing messages that are sent as mass email"; Col 8 lines 38-42, "These initial labels may be referred to as “seeds” because they provide a starting point for creating a cluster of emails or of email features that are similar, and thus, are believed to be associated with the same label (e.g., good, spam, bulk email, etc.)"); and the new emails have been filtered to only include emails with one or more visual components (Luo: see Col 8 lines 45-49, "At 304, unlabeled emails are received. These unlabeled emails may be emails that already exist within an email system. The unlabeled emails may include but are not limited to newly received emails that have come into an email system from an external network"; Col 11 lines 3-10, "FIG. 7 shows a different use of clustering in which various features of an unlabeled email 700 are used to provide potential labels for the unlabeled email 700. Labels may be associated with the unlabeled email 700 based on clusters to which features of the unlabeled email 700 belong. In this example, the clusters are labeled email addresses 702, labeled host servers 704, labeled URLs 706, and labeled fingerprints 708"). Graziano, Bartik, Xu, and Luo are analogous art because they are from the same field of endeavor. Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art to utilize Luo’s method of utilizing previously categorized emails to categorize unlabeled emails. The suggestion/motivation for doing so would be to continuously train a system to identify different categories of emails. Conclusion THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to KELAH JANAE MCFARLAND-BARNES whose telephone number is (571)272-5953. The examiner can normally be reached Monday through Friday 8:00am until 4:00pm Central Time. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Lynn D Feild can be reached at 571-272-2092. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /KELAH JANAE MCFARLAND-BARNES/Examiner, Art Unit 2431 /SHIN-HON (ERIC) CHEN/Primary Examiner, Art Unit 2431
Read full office action

Prosecution Timeline

Jul 29, 2024
Application Filed
Oct 17, 2025
Non-Final Rejection mailed — §103
Jan 15, 2026
Examiner Interview Summary
Jan 15, 2026
Applicant Interview (Telephonic)
Jul 07, 2026
Response Filed
Aug 26, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12701102
UNIVERSAL SERIAL BUS DEVICE WITH SECURITY CHECK
2y 6m to grant Granted Aug 04, 2026
Patent 12641089
METHOD OF PREVENTING VEHICLE CONTROLLER FROM BEING HACKED AND SYSTEM THEREOF
3y 2m to grant Granted May 26, 2026
Patent 12613988
CONCEPT FOR HANDLING REQUESTS FOR DATA
3y 1m to grant Granted Apr 28, 2026
Patent 12579256
LARGE LANGUAGE MODEL (LLM) SUPPLY CHAIN SECURITY
2y 6m to grant Granted Mar 17, 2026
Study what changed to get past this examiner. Based on 4 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
80%
Grant Probability
88%
With Interview (+8.3%)
3y 1m (~11m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 10 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month