Detailed Action
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Acknowledgments
The Amendment filed on 05/01/2026 and the IDSs filed on 03/10/2026 and 07/14/2026 are acknowledged.
Status of Claims
Claims 22-41 are pending.
In the Amendment filed on 05/01/2026, claims 22, 32 and 41 were amended, and no claims were cancelled or added (claims 1-21 were cancelled in a previous paper).
Claims 22-41 are rejected.
Response to Arguments
Regarding priority
In view of the amendments, the indication in the previous Office Action regarding lack of support in parent application no. 18/189,952 for claims 22, 32 and 41 is withdrawn.
Regarding the objections to the drawings/specification
For clarification of the record:
The replacement drawing as filed does not comply with 37 CFR 1.121(d) ("All changes to the drawings shall be explained, in detail, in either the drawing amendment or remarks section of the amendment paper.") No explanation of the changes to the drawings was found in the entirety of the Response, including the replacement drawing, as filed.
As best understood, the instant changes to the drawings (namely, in replacement figure 17A) are as follows:
- reference numeral 1700 has been deleted
If the above-indicated changes do not constitute the entirety of the changes made to the drawings in Applicant's instant Response, then Applicant should so indicate and clarify in the next Response, in order to clarify the record.
As a courtesy to Applicant, the replacement drawing is entered.
In view of the replacement drawing and the changes to the specification, the objections to the drawings/specification are withdrawn.
Regarding the rejection under 35 U.S.C. 101
Applicant's arguments have been fully considered but they are not persuasive.
The Office responds to Applicant's arguments below. Headings and page numbers in the discussion below refer to Applicant's Response.
A. Step 1: The Claims Fall Within One of the Four Statutory Categories
The Office agrees that the claims fall within one of the four statutory categories of 35 U.S.C. 101.
B. Step 2A: Two-Prong Inquiry
1. Prong One: The Claims Do Not Recite an "Abstract Idea"
Applicant argues that the claims do not cover "'certain methods of organizing human activity', such as 'fundamental economic practices' or 'principles' and/or 'commercial' or 'legal interactions'"(p. 16). Specifically, Applicant argues:
As amended, independent claim 22 is directed to a computer-implemented
method for identifying an unauthorized activity in a computing system including at least one processor, and now recites, among other things:
generating, by a machine learning model, a risk indicator associated with unauthorized activity at the transaction channel for the processed action of the user, wherein generating the risk indicator further comprises applying log-normal scaling to a transaction amount associated with the processed action to compute a log-normal probability density score, and wherein the machine learning model is trained to retain information associated with one or more previously generated risk indicators to tune a currently generated risk indicator by optimizing one or more hyperparameters to improve model performance;
These limitations are not directed to organizing human activity, economic
practices, or commercial or legal interactions. Rather, they are directed to technical operations performed by a machine learning system, including statistical feature transformation, probabilistic inference, and adaptive model optimization. (Response, pp. 16-17; emphasis added)
In response:
The bolded content shown above in Applicant's argument represents abstract idea. The underlined content represents additional elements. The bolded portions, which Applicant also describes as "statistical feature transformation, probabilistic inference," is part of a process of determining the likelihood / probability / risk of a transaction being fraudulent, and as such is part of the abstract idea. The additional elements are generic elements, recited at a high level of generality and not described, used off-the shelf as a tool in their ordinary capacities, and as such merely apply the abstract idea, or alternatively merely generally link the use of the abstract idea to a particular technological environment or field of use.
Applicant further argues:
In particular, the claims recite applying log-normal scaling to a transaction amount to compute a log-normal probability density score. As described in the specification, the model applies logarithmic transformations to transaction amounts to approximate a statistical distribution and computes a log-normal probability density score as part of risk-indicator generation. Specification at [0045], [0092]. This is a quantitative data-processing operation used to normalize numerical inputs for machine learning inference-not a fundamental economic practice or a method of organizing human behavior. (Response, p. 17)
In response:
The log-normal scaling to compute a log-normal probability density score, or as Applicant describes it, the "quantitative data-processing operation used to normalize numerical inputs," is merely abstract idea. Again, the additional elements here referenced (machine learning) amount merely to applying the abstract idea or alternatively generally linking it to a particular technological environment or field of use.
Applicant further argues:
The claims further recite that "the machine learning model is trained to retain information associated with one or more previously generated risk indicators to tune a currently generated risk indicator by optimizing one or more hyperparameters to improve model performance." The specification explicitly describes training the model to retain information from prior indicators and using that information to tune hyperparameters through an experimental optimization process to maximize performance. Id. at [0071]. Hyperparameter tuning and retention of prior model outputs are core technical problems in machine learning system design, not abstract business rules or mental processes. (Response, pp. 17; emphasis added)
In response:
The bolded content shown above in Applicant's argument represents abstract idea. The underlined content represents additional elements. As claimed and as described here, the additional elements represent merely generic computer elements, recited at a high level of generality and not described, used off-the shelf as a tool in their ordinary capacities, in other words, the additional elements merely 'apply' the abstract idea, or alternatively, the additional elements merely generally link the use of the abstract idea to a particular technological environment or field of use. In particular, the machine learning limitations do not represent any improvement in machine learning, but merely constitute what machine learning is (in machine learning, the machine learns from its previous operations/results and refines its behavior based on those previous operations/results (feedback), in the service of improving its performance).
Applicant further argues:
As the USPTO's Memorandum on Reminders on Evaluating Subject Matter Eligibility cautions, examiners should not classify claim limitations as mental processes or methods of organizing human activity when those limitations require computer-implemented statistical analysis, historical data retention, and quantitative optimization that cannot practically be performed in the human mind. See Memorandum on Reminders on Evaluating Subject Matter Eligibility, U.S. Patent and Trademark Office (Aug. 4, 2025) ("Memorandum"). The amended claims do not recite any economic principle, commercial interaction, or human organizational activity, nor do they recite steps that could practically be carried out mentally. (Response, pp. 17-18; emphasis added)
In response:
Applicant's argument misstates the USPTO guidance that it purports to cite from. In particular, the underlined part of Applicant's argument indicated above is not included in the guidance in question1. As noted above, the claims recite a method of determining the likelihood / probability / risk of a transaction being fraudulent, which falls under "certain methods of organizing human activity," specifically, "fundamental economic practices or principles" and/or "commercial or legal interactions." In addition, the claims were not rejected based on being a mental process or being able to practically be performed in the human mind. Accordingly, this part of the argument is not on point to the rejection.
Applicant further argues:
Even if risk assessment were considered in the abstract, the claims at most involve such concepts as part of a broader technological process focused on how a machine learning model statistically generates risk indicators and adaptively improves its performance over time. The focus of the claims is on machine learning inference and optimization mechanics, not on an abstract decision-making or business practice. (Response, p. 18)
In response:
The Office respectfully disagrees. The claims are part of a more specific abstract idea, not a "broader technological process." The focus is on the statistical generation of risk indicators and treatment of transactions based on the risk indicators, which is an abstract idea. The use of a machine learning model to carry out the analysis and the improvement in performance of the machine learning model is merely applying the abstract idea using generic computer elements or generally linking the abstract idea to a particular technological environment or field of use. As seen from the rejection in the body of the Office Action hereinbelow, the vast bulk of the claims constitute abstract idea (e.g., bolded portion of independent claims) and the additional elements comprise a small amount of the claims (e.g., unbolded portion of independent claims). Further, the additional elements are recited at a high level of generality and not described, used off-the shelf as a tool in their ordinary capacities; as such, there is no improvement in the additional elements. Accordingly, the machine learning and its optimization is not the focus of the claims.
2. Prong Two: The Claims Integrate Any Alleged Abstract Idea Into a Practical Application
Applicant argues:
Amended claim 22 recites that "generating the risk indicator further comprises applying log-normal scaling to a transaction amount associated with the processed action to compute a log-normal probability density score." This is not a generic instruction to use machine learning. It is a concrete, computer-implemented statistical transformation that produces a defined probabilistic score used in the risk-indicator generation workflow. (Response, p. 19; emphasis added)
In response:
The bolded content shown above in Applicant's argument represents abstract idea. That is, the generating of the risk indicator and the applying the log-normal scaling to compute a log-normal probability density score constitutes part of the abstract idea. The "risk-indicator generation workflow" including the "statistical transformation that produces a defined probabilistic score" constitutes part of the abstract idea.
Applicant further argues:
The specification expressly describes this operation, explaining that log-norm scaling applies a logarithmic transformation to approximate normality and that the model may "consider the dollar amount of a deposit and calculate a log-normal probability density score" as part of generating the risk indicator. Specification at [0045]. The specification further supports this as a model feature representing a deposit relative to a probability distribution of previous deposits. Id. at [0092]. Thus, the amended claim does not merely "link" an abstract idea to a transactional environment-it recites how the system processes transaction amounts (via log-normal scaling and probability density score) as part of the machine learning pipeline, which imposes meaningful limits on any alleged abstract idea. (Response, p. 19)
In response:
Again, the entire discussion here, other than the term "machine learning," describes the abstract idea. This is a specifying of the abstract idea.
Applicant further argues:
Amended claim 22 further recites that the machine learning model is trained to retain information associated with one or more previously generated risk indicators to tune a currently generated risk indicator by optimizing one or more hyperparameters to improve model performance. This is a specific, technical optimization mechanism that goes well beyond "apply the exception using generic computer elements." Office Action at 11.
Again, the specification describes this exact mechanism: it states that the machine learning model is trained to retain information associated with previously generated indicators to tune a currently generated indicator, and it defines tuning as an experimental process of finding optimal hyperparameter values to maximize model performance. Specification at [0071]. These limitations therefore are not "not described by the applicant," and they are not high-level. Office Action at 11. They recite a concrete adaptive machine learning workflow that constrains the claim to a particular technical implementation.
(Response, pp. 19-20)
In response:
The subject matter here argued has already been argued by Applicant and addressed by the Office in section B.1. (Step 2A, Prong One) above. The "concrete adaptive machine learning workflow" adds to the abstract idea (i) the use of a machine learning model to perform the data processing of the abstract idea and (ii) the improvement in performance of the machine learning model based on learning from its past performance, which is simply a fundamental aspect of machine learning itself.
Note when the rejection states that the additional elements are recited at a high level of generality and are not described, this is referring to the claim language (the additional elements as recited in the claims), not to the specification.
Applicant further argues:
The Patent Trial and Appeal Board has emphasized that eligibility analysis must account for claim language reflecting improvements in artificial intelligence and machine learning technology. See Ex parte Desjardins, Appeal 2024-000567 (P.T.A.B. Sept. 26, 2025). Desjardins highlights that claims directed to improvements in model operation (such as reduced complexity or improved learning behavior) can satisfy Step 2A, Prong Two.
Here, claim 22 likewise recites improvements to machine learning operation that are inseparable from the claimed process: (i) log-normal probability density scoring used during risk-indicator generation (Specification at [0045], [0092]) and (ii) retention of previously generated indicators and hyperparameter optimization to improve model performance (Id. at [0071]). These technical features are not mere "field of use" limitations; they are the mechanism by which the claimed system computes and improves risk indicators over time.
Accordingly, even under the Office's abstract-idea characterization, amended claim 22 recites additional elements-specifically, "comput[ing] a log-normal probability density score" and "retain[ing] information associated with one or more previously generated risk indicators to tune a currently generated risk indicator by optimizing one or more hyperparameters to improve model performance," together with "generating an alert" and "queuing"-that meaningfully limit any alleged abstract idea and integrate it into a practical application. The Office's assertion that the additional elements are "not described" and recited only at a high level of generality is contradicted by the specification's disclosure of these mechanisms. Therefore, claim 22 satisfies Step 2A, Prong Two.
(Response, pp. 20-21)
In response:
The subject matter of the instant claims is not related to that of Desjardins, nor is it analogous in respect of 35 U.S.C. 101. Desjardins was found to reflect the following improvements in computer functionality:
xiii. An improved way of training a machine learning model that protected the model’s knowledge about previous tasks while allowing it to effectively learn new tasks; Ex Parte Desjardins, Appeal No. 2024-000567 (PTAB September 26, 2025, Appeals Review Panel Decision) (precedential); and
xiv. Improvements to computer component or system performance based upon adjustments to parameters of a machine learning model associated with tasks or workstreams; Ex Parte Desjardins, Appeal No. 2024-000567 (PTAB September 26, 2025, Appeals Review Panel Decision) (precedential).2
As seen from the above, Desjardins contained specific improvements to machine learning. In contrast, as explained above, the instant claims merely reflect what generic machine learning is, not an improvement to machine learning.
There is no "reduced complexity or improved learning behavior" (p. 20) in operation of the machine learning model in Applicant's claims. Rather, there is merely the use of an off-the-shelf machine learning model as a tool in its ordinary capacity, including the ordinary improvement in performance of the model based on learning from past behavior that is a part of machine learning.
The "optimizing one or more hyperparameters to improve model performance" (pp. 20-21) is not an improvement in machine learning; rather, it is machine learning itself.
Again, the "optimizing one or more hyperparameters to improve model performance" (pp. 20-21) is the mere adjustment of parameters (specifically, hyperparameters), not an "improvement to computer component or system performance based upon adjustments to parameters of a machine learning model associated with tasks or workstreams."3
The "retain[ing] information associated with one or more previously generated risk indicators to tune a currently generated risk indicator," as well as the "generating an alert," "queuing" and 'log-normal' limitations (pp. 20-21), are merely a specifying of the abstract idea. As a specifying of the abstract idea, they merely narrow the abstract idea; they do not integrate the abstract idea into a practical application.
Again, as noted above, when the rejection states that the additional elements are recited at a high level of generality and are not described, this is referring to the claim language (the additional elements as recited in the claims), not to the specification.
C. Step 2B: The Claims Recite Significantly More Than Any Alleged Judicial Exception
In this section, Applicant presents the same substance/arguments as in the previous sections (re Step 2A, Prongs Two and One). Accordingly, Applicant's arguments have been addressed above.
Nonetheless, to reiterate, the log-normal analysis, as well as the retaining of risk indicator information and tuning of a risk indicator, are merely part of the abstract idea; they are not additional elements. As Applicant describes it, the log-normal analysis is a "concrete statistical transformation," i.e., a narrowing of the abstract idea of risk analysis. Applicant's words "embedded in … machine learning technology" refer merely to the use of machine learning to perform the analysis, and the improvement in performance of the model based on learning from past behavior (optimization of hyperparameters to improve model performance), that is a part of machine learning itself. This improvement in performance of the model based on learning from its past behavior/performance, which is inherent to machine learning, is not improvement of machine learning technology.
Regarding the rejections under 35 U.S.C. 103
Applicant's arguments have been fully considered but they are moot in view of the new combinations of references being used in the current rejections.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 22-41 are rejected under 35 U.S.C. 101 because the claimed invention is directed to a judicial exception (i.e., a law of nature, a natural phenomenon, or an abstract idea) without significantly more.
Claims 22-41 are directed to a computer-implemented method, computing system, or non-transitory computer-readable medium, which are/is one of the statutory categories of invention. (Step 1: YES)
Claims 22, 32 and 41 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. The claims recite a computer-implemented method, computing system, and non-transitory computer-readable medium for determining a likelihood of fraud and preventing fraud.
For claims 22, 32 and 41 (claim 32 being deemed representative), the limitations (indicated below in bold) of:
at least one processor configured to:
receive, from a transaction channel, a processed action of a user;
generate, by a machine learning model, a risk indicator associated with unauthorized activity at the transaction channel for the processed action of the user, wherein generating the risk indicator further comprises applying log-normal scaling to a transaction amount associated with the processed action to compute a log-normal probability density score, and wherein the machine learning model is trained to retain information associated with one or more previously generated risk indicators to tune a currently generated risk indicator by optimizing one or more hyperparameters to improve model performance;
storing the generated risk indicator in a database;
generating an alert indicating a probability of unauthorized activity based on a comparison between the generated risk indicator and one or more predetermined thresholds;
transmit, by the at least one processor to the transaction channel, the alert;
queuing an ordered list of generated alerts according to their respective risk indicators relative to the one or more predetermined thresholds;
placing the processed action into the ordered list at a position based on the generated risk indicator, wherein alerts associated with a risk category are arranged in an order within the risk category according to their respective risk indicators;
generate, by the machine learning model, an action indicator based on the generated risk indicator; and
execute an outcome based on the generated action indicator.
as drafted, constitute a process that, under the broadest reasonable interpretation, covers "certain methods of organizing human activity," specifically, "fundamental economic practices or principles" and/or "commercial or legal interactions," but for recitation of generic computer components and generally linking the use of a judicial exception to a particular technological environment or field of use. The Examiner notes that "fundamental economic practices" or "fundamental economic principles" describe concepts relating to the economy and commerce, including hedging, insurance, and mitigating risks, and "commercial interactions" or "legal interactions" include agreements in the form of contracts, legal obligations, advertising, marketing or sales activities or behaviors, and business relations. MPEP 2106.04(a)(2)II.A.,B. If a claim limitation, under its broadest reasonable interpretation, covers "fundamental economic practices or principles" and/or "commercial or legal interactions," but for recitation of generic computer components and generally linking the use of a judicial exception to a particular technological environment or field of use, then it falls within the "certain methods of organizing human activity" grouping of abstract ideas. Accordingly, claims 22, 32 and 41 recite an abstract idea. (Step 2A - Prong 1: YES. The claims recite an abstract idea.)
This judicial exception is not integrated into a practical application. Claims 22, 32 and 41 recite the additional elements of at least one processor, a transaction channel, a machine learning model, the machine learning model is trained, optimizing one or more hyperparameters to improve model performance, and a database (the foregoing recited in claims 22, 32 and 41), and a non-transitory computer-readable medium storing a set of instructions for identifying unauthorized activity in a computing system including at least one processor, the set of instructions comprising one or more instructions that, when executed by the at least one processor of the computing system, cause the computing system to: [perform operations] (the foregoing recited in claim 41), that implement the abstract idea. These additional elements are not described by the applicant and they are recited at a high level of generality (i.e., one or more generic computer elements performing generic computer functions, or generally linking the use of a judicial exception to a particular technological environment or field of use), such that they amount to no more than mere instructions to apply the exception using generic computer elements (namely, at least one processor, a machine learning model, the machine learning model is trained, optimizing one or more hyperparameters to improve model performance, a database, and a non-transitory computer-readable medium storing a set of instructions for identifying unauthorized activity in a computing system including at least one processor, the set of instructions comprising one or more instructions that, when executed by the at least one processor of the computing system, cause the computing system to: [perform operations]), or such that they amount to no more than generally linking the use of a judicial exception to a particular technological environment or field of use (namely, a transaction channel, a machine learning model, the machine learning model is trained, optimizing one or more hyperparameters to improve model performance). Accordingly, even in combination these additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea. (Step 2A - prong 2: NO. The additional elements do not integrate the abstract idea into a practical application.)
The claims do not include additional elements that are sufficient to amount to significantly more than the judicial exception itself. As discussed above with respect to integration of the abstract idea into a practical application, the additional elements of at least one processor, a transaction channel, a machine learning model, the machine learning model is trained, optimizing one or more hyperparameters to improve model performance, and a database (the foregoing recited in claims 22, 32 and 41), and a non-transitory computer-readable medium storing a set of instructions for identifying unauthorized activity in a computing system including at least one processor, the set of instructions comprising one or more instructions that, when executed by the at least one processor of the computing system, cause the computing system to: [perform operations] (the foregoing recited in claim 41), to perform the noted steps amount to no more than mere instructions to apply the exception using generic computer elements or generally linking the use of a judicial exception to a particular technological environment or field of use. Mere instructions to apply an exception using generic computer elements or generally linking the use of a judicial exception to a particular technological environment or field of use cannot provide an inventive concept ("significantly more"). Accordingly, even in combination, these additional elements do not provide significantly more. As such, claims 22, 32 and 41 are not patent eligible. (Step 2B: NO. The claims do not provide significantly more.)
Dependent claims 23-31 and 33-40 are similarly rejected because they further define/narrow the abstract idea of independent claims 22, 32 and 41 as discussed above, and/or do not integrate the abstract idea into a practical application or provide an inventive concept such as would render the claims eligible, whether each is considered individually or as an ordered combination.
As for further defining/narrowing the abstract idea:
Dependent claims 23 and 33 merely further describe wherein responsive to a determination that the risk indicator is below a first predetermined threshold, assigning a low risk indicator value; responsive to a determination that the risk indicator is above the first predetermined threshold and below a second predetermined threshold, assigning a medium risk indicator value; and responsive to a determination that the risk indicator is above the second predetermined threshold, assigning a high risk indicator value.
Dependent claims 24 and 34 merely further describe wherein responsive to an assignment of the low risk indicator value, allowing the processed action of the user.
Dependent claims 25 and 35 merely further describe wherein responsive to an assignment of the medium risk indicator value, flagging the processed action of the user.
Dependent claims 26 and 36 merely further describe wherein flagging the processed action of the user comprises reviewing the processed action.
Dependent claims 27 and 37 merely further describe wherein responsive to an assignment of the high risk indicator value, stopping the processed action of the user.
Dependent claims 28 and 38 merely further describe wherein stopping the processed action of the user comprises holding the processed action of the user for a predetermined time.
Dependent claim 29 merely further describes … to predict a likelihood of unauthorized activity for the processed action.
Dependent claims 30 and 39 merely further describe wherein the risk indicator is further generated based on a log-norm scaling of a user's profile against the user’s profile.
Dependent claims 31 and 40 merely further describe further comprising appending, to the processed action, customer characteristics and historical data associated with the processed action.
As for additional elements:
Dependent claim 29 recites "training the machine learning model." This recitation is at a high level of generality such that it amounts to no more than mere instructions to apply the exception using a generic computer element or such that it amounts to no more than generally linking the use of a judicial exception to a particular technological environment or field of use. Even in combination these additional elements do not integrate the abstract idea into a practical application and do not amount to significantly more than the abstract idea itself.
Dependent claims 33-35, 37 and 40 recite "wherein the at least one processor is further configured to." This recitation is at a high level of generality such that it amounts to no more than mere instructions to apply the exception using a generic computer element. Even in combination these additional elements do not integrate the abstract idea into a practical application and do not amount to significantly more than the abstract idea itself.
Dependent claims 23-28, 30, 31, 36, 38 and 39 do not recite any additional elements, and accordingly, for the reasons provided above with respect to the independent claims, are not patent eligible.
Therefore, dependent claims 23-31 and 33-40 are not patent eligible.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries set forth in Selway v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims 22, 29, 30, 32, 39 and 41 are rejected under 35 U.S.C. 103 as being unpatentable over Selway et al. (U.S. Patent No. 2013/0013491 A1), hereafter Selway, in view of Pavlovic ("Log-normal Distribution - A simple explanation”), further in view of Shevyrev et al. (U.S. Patent Application Publication No. 2023/0281629 A1), hereafter Shevyrev, and further in view of in view of Comeaux et al. (U.S. Patent No. 11,669,844 B1), hereafter Comeaux.
Regarding Claims 22, 32 and 41
Selway teaches:
(claim 22) the method being performed by at least one processor (Fig. 6, 610) and comprising: (0040-0043, Fig. 6, 600, 610; computer system 600 instantiates duplicate transaction detection system 110 (see Fig. 1), which per 0020 (using processing system 130 of 110) identifies duplicative checks that are improper or fraudulent, e.g., by performing the processes of Figs. 3-5)
(claim 32) at least one processor configured to: (0040-0043, Fig. 6, 600, 610; computer system 600 instantiates duplicate transaction detection system 110 (see Fig. 1), which per 0020 (using processing system 130 of 110) identifies duplicative checks that are improper or fraudulent, e.g., by performing the processes of Figs. 3-5)
(claim 41) A non-transitory computer-readable medium storing a set of instructions for identifying unauthorized activity (0020) in a computing system including at least one processor, the set of instructions comprising: one or more instructions that, when executed by the at least one processor of the computing system, cause the computing system to: (0040-0043, Fig. 6, 600, 610; computer system 600 instantiates duplicate transaction detection system 110 (see Fig. 1), which per 0020 (using processing system 130 of 110) identifies duplicative checks that are improper or fraudulent, e.g., by performing the processes of Figs. 3-5)
receive, from a transaction channel (Fig. 1, any of 120a-d), a processed action of a user; (0012, 0018, 0023, Fig. 3, 310, 0026, Fig. 4, 410, 0039, Fig. 5, 522, 542, all teaching that system 110 receives transaction record from institution 120 (any of 120a-d))
generate, by a machine learning model (0031 neural model), a risk indicator (risk score) associated with unauthorized activity at the transaction channel for the processed action of the user; (0016, 0022, 0037, Fig. 4, 424)
wherein generating the risk indicator further comprises … a transaction amount associated with the processed action …, and (as per 0016, 0022, 0037, Fig. 4, 424, risk analysis/scoring module assesses risk factors (set forth in 0030-0032) to determine -- and generate a score expressing -- the likelihood that a transaction is fraudulent; per 0032 risk factors include the amount of the check, which teaches a transaction amount associated with the processed action as a risk factor based on which the risk indicator is generated)
…
transmitting, by the at least one processor to the transaction channel, the alert; (0020, 0022, 0024, Fig. 3, 316, 0037, Fig. 4, 428, 0039, Fig. 5, 544)
…
generating, by the machine learning model, an action indicator based on the generated risk indicator; and (0037, Fig. 4, 440 "It should be appreciated that in sending an alert, a risk score could also be sent to each affected institution, to permit the institution to better understand the risk and determine what kind of remedial action to take, step 440." -- "generating … an action indicator" is taught by "determine what kind of remedial action to take" (the resultant determination that is made is the action indicator that is generated); as per the language underlined above, the determining what kind of remedial action to take (generating … an action indicator) is based on the sent (transmitted) alert and the generated risk score (indicator); regarding by the machine learning model: it would be obvious to combine embodiments and use the neural models (taught in 0031 for risk assessment/prediction) for determining the remedial action (generating the action indicator) because Selway 0046 explicitly teaches such combinations of embodiments ("Moreover, the procedures described with respect to one method or process may be incorporated within other described methods or processes; likewise, system components described according to a particular structural architecture and/or with respect to one system may be organized in alternative structural architectures and/or incorporated within other described systems. Hence, while various embodiments may be described with (or without) certain features for ease of description and to illustrate exemplary features, the various components and/or features described herein with respect to a particular embodiment can be substituted, added, and/or subtracted to provide other embodiments, unless the context dictates otherwise.") and because the incorporation of neural models into such an operation would improve the operation by rendering its result more robust/accurate.)
executing an outcome based on the generated action indicator. (0037, Fig. 4, 440 "Remedial action could include various steps …, such as [1] freezing or suspending all activity on an account, …, [2] putting a hold on any future deposits into an account, or [3] notifying authorities …." -- the result of the specific remedial action (e.g., [1], [2], or [3]) performed is the outcome that is executed)
Selway does not explicitly disclose but Pavlovic teaches:
… applying log-normal scaling … to compute a log-normal probability density score, and (e.g., pp. 1-3)
It would have been obvious to one of ordinary skill in the art not later than the effective filing date of the claimed invention to have modified Selway's systems and methods for determining fraud risk and performing remedial actions, by incorporating therein these teachings of Pavlovic regarding a log-norm probability density function, because this is a known way to model various natural phenomena, see Pavlovic, p. 1, and has particular advantages under certain circumstances applicable to the combination, e.g., where the data cannot be negative, (e.g., data such as a probability of fraud / a risk value), where the data skews positive, with most values clustered near the low end and a long tail extending rightward to occasional high outliers (e.g., transaction data, which comprises mostly non-fraudulent transactions and a relatively small amount of fraudulent transactions), and where the data grows multiplicatively/ cumulatively (e.g., a plurality of historical transaction data) -- by transforming such data with a logarithm, it can be normalized, allowing for easier analysis with powerful standard statistical techniques, such as calculating z-scores, performing linear regression, estimating parameters using Maximum Likelihood Estimation (MLE), etc.
Selway in view of Pavlovic does not explicitly disclose but Shevyrev teaches:
wherein the machine learning model (Fig. 4, 308; 0028, 0078) is trained to retain information associated with one or more previously generated risk indicators to tune a currently generated risk indicator by optimizing one or more hyperparameters to improve model performance; (0080-0082: 0081 "Further, the loss function 408 can return quantifiable data regarding the difference between a given training … prediction from the training … predictions 405 and a corresponding ground truth from the ground truth check data 406 [wherein the machine learning model is trained to retain information associated with one or more previously generated risk indicators to tune a currently generated risk indicator]. In particular, the loss function 408 can return losses 410 to the … machine-learning model 308 [trained to retain information associated with one or more previously generated risk indicators] based upon which the … system 102 adjusts various parameters/hyperparameters [to tune a currently generated risk indicator by optimizing one or more hyperparameters to improve model performance]. In so doing, the … system 102 can improve the quality/accuracy of training … predictions in subsequent training iterations—by narrowing the difference between training … predictions and ground truth … data in subsequent training iterations [trained … to tune a currently generated risk indicator … to improve model performance].")
It would have been obvious to one of ordinary skill in the art not later than the effective filing date of the claimed invention to have modified the combination of Selway's systems and methods for determining fraud risk and performing remedial actions, as modified by Poduval's teachings regarding a log-norm probability density function, by incorporating therein these teachings of Shevyrev regarding adjusting parameters/hyperparameters of a machine learning model based on a loss function (data regarding difference between training prediction and ground truth), because such tuning of a machine learning model is necessary to keep the model up to date with the latest transaction data and therefore such tuning maintains the good performance of the model and the accuracy of the model results and, as such, would improve upon a system/method that does not perform tuning, see Shevyrev, 0080-0082.
Selway in view of Pavlovic and Shevyrev does not explicitly disclose but Comeaux teaches:
storing the generated risk indicator in a database (Fig. 1, 104); (7:28-30; 14:46-49, 4:40-41)
generating an alert (alert) indicating a probability of unauthorized activity based on a comparison between the generated risk indicator (alert probability score / fraud probability score) and one or more predetermined thresholds; (2:49-53, 18:21-33, 18:43-50, Fig. 2, 212, claim 1)
queuing an ordered list of generated alerts according to their respective risk indicators relative to the one or more predetermined thresholds; (4:65-67, 18:62-19:11, 5:8-11)
placing the processed action into the ordered list at a position based on the generated risk indicator, wherein alerts associated with a risk category are arranged in an order within the risk category according to their respective risk indicators; (4:65-67, 5:8-11, 14:59-15:3 (both the alerts and the events ("processed actions") are stored in database for purpose of queries, etc.), 18:62-19:11; as per 4:65-67 the fraudulent events ("processed actions") (associated with the alerts) are sorted according to a priority based on the fraud probability scores; regarding wherein alerts associated with a risk category are arranged in an order within the risk category: as per, e.g., 6:28-8:3, the system uses different scenario attribute models (6:35-36) / alert generation models (each corresponding to an algorithm) (6:56-57) / scenario models (7:1) (-- these different models correspond to different scenarios, users, etc.; thus, such a model teaches a risk category --) and the probability scores for the various events may be determined based on a given one of these models (e.g., 7:42-44, 7:51-53 "the alert-generating server 102 may then determine an alert probability score for each fraudulent and malicious event using the alert-generation model") --- thus, the ordering of alerts (as taught by 4:65-67, 5:8-11, 14:59-15:3, 18:62-19:11) is an ordering of alerts generated based on a given model, that is to say, wherein alerts associated with a risk category are arranged in an order within the risk category according to their respective risk indicators)
It would have been obvious to one of ordinary skill in the art not later than the effective filing date of the claimed invention to have modified the combination of Selway's systems and methods for determining fraud risk and performing remedial actions, as modified by Poduval's teachings regarding a log-norm probability density function, as further modified by Shevyrev's teachings regarding adjusting parameters/ hyperparameters of a machine learning model based on a loss function (data regarding difference between training prediction and ground truth), by incorporating therein these teachings of Comeaux regarding (i) storing a risk indicator in a database, (ii) generating an alert based on the risk indicator, and (iii) queuing/ordering the alerts/events based on their risk indicators (level of risk), because (i) it is useful to store the risk indicator because it is to be used and/or can be used in the future e.g., to generate alerts and to improve the model by learning from its past behavior, (ii) generating alerts facilitates taking remedial action to prevent fraud, e.g., in case an event has a high level of risk, and (iii) in light of the time-sensitive nature of the transaction fraud mitigation process, ordering the events/alerts and attending to them in order of risk level is an effective way of mitigating the greatest likelihood/extent of fraud/risk/loss, by addressing the riskiest events first.
Regarding Claim 29
Selway in view of Pavlovic, Shevyrev and Comeaux teaches the limitations of base claim 22 as set forth above. Comeaux further teaches:
further comprising training the machine learning model to predict a likelihood of unauthorized activity for the processed action. (4:56-64 (read in light of 4:46-56), 6:59-67 (read in light of 6:56-59), 7:59-8:28 (read in light of 7:51-59, 8:29-32), 8:39-9:28)
It would have been obvious to one of ordinary skill in the art not later than the effective filing date of the claimed invention to have modified the combination of Selway's systems and methods for determining fraud risk and performing remedial actions, as modified by Poduval's teachings regarding a log-norm probability density function, as further modified by Shevyrev's teachings regarding adjusting parameters/ hyperparameters of a machine learning model based on a loss function (data regarding difference between training prediction and ground truth), and as further modified by Comeaux's teachings regarding (i) storing a risk indicator in a database, (ii) generating an alert based on the risk indicator, and (iii) queuing/ordering the alerts/events based on their risk indicators (level of risk), by incorporating therein these further teachings of Comeaux regarding training a machine learning model to determine the likelihood of fraud of a transaction, because Selway teaches using a machine learning model (neural model, 0031), and a machine learning model will not work or will not perform well if not trained. Training is a crucial part of employing a machine learning model, and therefore training will permit Selway's machine learning model to perform well, and accordingly will permit Selway to perform well its intended function of assessing risk of fraudulent transactions so as to allow/provide for appropriate remedial actions.
Regarding Claims 30 and 39
Selway in view of Pavlovic, Shevyrev and Comeaux teaches the limitations of base claims 22 and 32 as set forth above. Selway further teaches:
wherein the risk indicator (risk score) is further generated based on … a user's profile … the user's profile. (0030-0031, Table 1, 0037, Fig. 4, 424, risk score is generated based on assessment of risk factors, which include factors such as "History of account … e.g., prior incidents of fraud/suspicious activity," "Account aging (how long the account … has been in existence," "Type of account," etc., which factors teach "user's profile" under broadest reasonable interpretation)
Pavlovic further teaches:
… a log-norm scaling of … against …. (Note Applicant’s specification (0045) defines “log-norm scaling” thus: “Log-norm scaling may refer to applying a logarithmic transformation to values, which transforms the values onto a scale that approximates the normality”; Pavlovic, p. 3, teaches the same thing: “Let’s say your data [values] fits a log-normal distribution. If you then take the logarithm of [applying a logarithmic transformation to] all your data points [values], the newly transformed [logarithmically transformed] points [values] will now fit a normal distribution [a scale that approximates the normality].”)
It would have been obvious to one of ordinary skill in the art not later than the effective filing date of the claimed invention to have modified the combination of Selway's systems and methods for determining fraud risk and performing remedial actions, as modified by Poduval's teachings regarding a log-norm probability density function, as further modified by Shevyrev's teachings regarding adjusting parameters/ hyperparameters of a machine learning model based on a loss function (data regarding difference between training prediction and ground truth), and as further modified by Comeaux's teachings regarding (i) storing a risk indicator in a database, (ii) generating an alert based on the risk indicator, and (iii) queuing/ordering the alerts/events based on their risk indicators (level of risk), by incorporating therein these further teachings of Pavlovic regarding log-norm scaling, because these teachings of Pavlovic are a known way to model various natural phenomena, see Pavlovic, p. 1, and they have particular advantages under certain circumstances applicable to Selway, e.g., where the data cannot be negative (e.g., data such as a probability of fraud / a risk score), where the data skews positive, with most values clustered near the low end and a long tail extending rightward to occasional high outliers (e.g., transaction data, which comprises mostly non-fraudulent transactions and a relatively small amount of fraudulent transactions), and where the data grows multiplicatively/cumulatively (e.g., a plurality of historical transaction data) -- by transforming such data with a logarithm, it can be normalized, allowing for easier analysis with powerful standard statistical techniques, such as calculating z-scores, performing linear regression, estimating parameters using Maximum Likelihood Estimation (MLE), etc.
Claims 23-28 and 33-38 are rejected under 35 U.S.C. 103 as being unpatentable over Selway et al. (U.S. Patent No. 2013/0013491 A1), hereafter Selway, in view of Pavlovic ("Log-normal Distribution - A simple explanation”), further in view of Shevyrev et al. (U.S. Patent Application Publication No. 2023/0281629 A1), hereafter Shevyrev, further in view of in view of Comeaux et al. (U.S. Patent No. 11,669,844 B1), hereafter Comeaux, and further in view of Abifaker et al. (U.S. Patent Application Publication No. 2015/0278817 A1), hereafter Abifaker.
Regarding Claims 23 and 33
Selway in view of Pavlovic, Shevyrev and Comeaux teaches the limitations of base claims 22 and 32 as set forth above. Selway in view of Pavlovic, Shevyrev and Comeaux does not explicitly disclose but Abifaker teaches:
wherein the at least one processor is further configured to: (0077 processor for implementing subject matter taught by Abifaker, e.g., operations performed by fraud detector 130)
responsive to a determination that the risk indicator (overall risk score) is below a first predetermined threshold (Fig. 3, 48), assign a low risk indicator value ("legitimate," "pass"); (0067-0070 (see 0069), 0075, Fig. 2, 225, Fig. 3)
responsive to a determination that the risk indicator is above the first predetermined threshold (Fig. 3, 48) and below a second predetermined threshold (Fig. 3, 68), assign a medium risk indicator value ("human audit," "requiring manual review"); and (0067-0070 (see 0070), 0075, Fig. 2, 225, Fig. 3)
responsive to a determination that the risk indicator is above the second predetermined threshold (Fig. 3, 68), assign a high risk indicator value ("fail," "fraudulent"). (0067-0070 (see 0068), 0075, Fig. 2, 225, Fig. 3)
It would have been obvious to one of ordinary skill in the art not later than the effective filing date of the claimed invention to have modified the combination of Selway's systems and methods for determining fraud risk and performing remedial actions, as modified by Poduval's teachings regarding a log-norm probability density function, as further modified by Shevyrev's teachings regarding adjusting parameters/ hyperparameters of a machine learning model based on a loss function (data regarding difference between training prediction and ground truth), and as further modified by Comeaux's teachings regarding (i) storing a risk indicator in a database, (ii) generating an alert based on the risk indicator, and (iii) queuing/ordering the alerts/events based on their risk indicators (level of risk), by incorporating therein these teachings of Abifaker regarding assigning a high, medium, or low risk classification to a transaction event based on the assessed level of risk, because it provides a comprehensive, fine-tuned risk assessment/scoring and consequent responsive actions, so as to more likely treat transactions appropriately according to their actual risk level, thus leading to more effective and satisfactory outcomes (e.g., medium risk transactions would be more likely to receive an intermediate level of responsive action, namely, a review, rather than being approved outright as if they were low risk or rejected outright as if they were high risk.) (Note Selway teaches or suggests that remedial action should align with the risk score, but does not flesh out how this is implemented practically. Abifaker's framework provides implementation detail appropriate to implement this under-specified aspect of Selway's systems and methods in a way that improves them.)
Regarding Claims 24 and 34
Selway in view of Pavlovic, Shevyrev, Comeaux and Abifaker teaches the limitations of base claims 22 and 32 and intervening claims 23 and 33 as set forth above. Abifaker further teaches:
wherein responsive to an assignment of the low risk indicator value, the at least one processor is further configured to allow the processed action of the user. (0067-0070 (see 0069), 0075-0076, Fig. 2, 225, 250, Fig. 3, Fig. 5, 540)
It would have been obvious to one of ordinary skill in the art not later than the effective filing date of the claimed invention to have modified the combination of Selway's systems and methods for determining fraud risk and performing remedial actions, as modified by Poduval's teachings regarding a log-norm probability density function, as further modified by Shevyrev's teachings regarding adjusting parameters/ hyperparameters of a machine learning model based on a loss function (data regarding difference between training prediction and ground truth), as further modified by Comeaux's teachings regarding (i) storing a risk indicator in a database, (ii) generating an alert based on the risk indicator, and (iii) queuing/ordering the alerts/events based on their risk indicators (level of risk), and as further modified by Abifaker's teachings regarding assigning a high, medium, or low risk classification to a transaction event based on the assessed level of risk, by incorporating therein these further teachings of Abifaker regarding approving low-risk transactions, because in any such system (e.g., for detecting and mitigating/preventing fraudulent transactions) it is appropriate and standard to approve low-risk transactions, and achieves what is considered a proper balance between risk and efficiency/ productivity. (Note this is consistent with Selway, e.g., 0022, 0037, which teaches that remedial actions such as blocking transactions or the like are appropriate when there is a high likelihood of fraud.)
Regarding Claims 25 and 35
Selway in view of Pavlovic, Shevyrev, Comeaux and Abifaker teaches the limitations of base claims 22 and 32 and intervening claim 23 as set forth above. Abifaker further teaches:
wherein responsive to an assignment of the medium risk indicator value, the at least one processor is further configured to flag the processed action of the user. (0067-0070 (see 0070), 0075, Fig. 2, 225, 245, Fig. 3, "determine that manual review … is needed," "requir[e] manual review" teach "flag")
It would have been obvious to one of ordinary skill in the art not later than the effective filing date of the claimed invention to have modified the combination of Selway's systems and methods for determining fraud risk and performing remedial actions, as modified by Poduval's teachings regarding a log-norm probability density function, as further modified by Shevyrev's teachings regarding adjusting parameters/ hyperparameters of a machine learning model based on a loss function (data regarding difference between training prediction and ground truth), as further modified by Comeaux's teachings regarding (i) storing a risk indicator in a database, (ii) generating an alert based on the risk indicator, and (iii) queuing/ordering the alerts/events based on their risk indicators (level of risk), and as further modified by Abifaker's teachings regarding assigning a high, medium, or low risk classification to a transaction event based on the assessed level of risk, by incorporating therein these further teachings of Abifaker regarding designating medium-risk transactions for manual review (human audit), because in any such system (e.g., for detecting and mitigating/preventing fraudulent transactions) it is appropriate and standard to perform manual/human review of medium-risk transactions, and achieves what is considered a proper balance between risk and efficiency/productivity. (Note this is consistent with Selway, e.g., 0022, 0037, which teaches that remedial actions such as blocking transactions or the like are appropriate when there is a high likelihood of fraud.)
Regarding Claims 26 and 36
Selway in view of Pavlovic, Shevyrev, Comeaux and Abifaker teaches the limitations of base claims 22 and 32 and intervening claims 23, 25 and 35 as set forth above. Abifaker further teaches:
wherein the flag comprises a review of the processed action. (0070-0071, 0075, Fig. 2, 225, 245, Fig. 3, human audit)
It would have been obvious to one of ordinary skill in the art not later than the effective filing date of the claimed invention to have modified the combination of Selway's systems and methods for determining fraud risk and performing remedial actions, as modified by Poduval's teachings regarding a log-norm probability density function, as further modified by Shevyrev's teachings regarding adjusting parameters/ hyperparameters of a machine learning model based on a loss function (data regarding difference between training prediction and ground truth), as further modified by Comeaux's teachings regarding (i) storing a risk indicator in a database, (ii) generating an alert based on the risk indicator, and (iii) queuing/ordering the alerts/events based on their risk indicators (level of risk), and as further modified by Abifaker's teachings regarding assigning a high, medium, or low risk classification to a transaction event based on the assessed level of risk, and designating medium-risk transactions for manual review (human audit), by incorporating therein these further teachings of Abifaker regarding performing a manual review (human audit) for medium-risk transactions, because in any such system (e.g., for detecting and mitigating/preventing fraudulent transactions) it is appropriate and standard to perform manual/human review of medium-risk transactions, and achieves what is considered a proper balance between risk and efficiency/productivity. (Note this is consistent with Selway, e.g., 0022, 0037, which teaches that remedial actions such as blocking transactions or the like are appropriate when there is a high likelihood of fraud.)
Regarding Claims 27 and 37
Selway in view of Pavlovic, Shevyrev, Comeaux and Abifaker teaches the limitations of base claims 22 and 32 and intervening claims 23 and 33 as set forth above. Abifaker further teaches:
wherein responsive to an assignment of the high risk indicator value, the at least one processor is further configured to stop the processed action of the user. (0067-0070 (see 0068), 0075-0076, Fig. 2, 225, 230, Fig. 3, Fig. 5, 540)
It would have been obvious to one of ordinary skill in the art not later than the effective filing date of the claimed invention to have modified the combination of Selway's systems and methods for determining fraud risk and performing remedial actions, as modified by Poduval's teachings regarding a log-norm probability density function, as further modified by Shevyrev's teachings regarding adjusting parameters/ hyperparameters of a machine learning model based on a loss function (data regarding difference between training prediction and ground truth), as further modified by Comeaux's teachings regarding (i) storing a risk indicator in a database, (ii) generating an alert based on the risk indicator, and (iii) queuing/ordering the alerts/events based on their risk indicators (level of risk), and as further modified by Abifaker's teachings regarding assigning a high, medium, or low risk classification to a transaction event based on the assessed level of risk, by incorporating therein these further teachings of Abifaker regarding denying high-risk transactions, because in any such system (e.g., for detecting and mitigating/preventing fraudulent transactions) it is appropriate and standard to deny high-risk transactions, and achieves what is considered a proper balance between risk and efficiency/ productivity. (Note this is consistent with Selway, e.g., 0022, 0037, which teaches that remedial actions such as blocking transactions or the like are appropriate when there is a high likelihood of fraud.)
Regarding Claims 28 and 38
Selway in view of Pavlovic, Shevyrev, Comeaux and Abifaker teaches the limitations of base claims 22 and 32 and intervening claims 23, 27, 33 and 37 as set forth above. Abifaker further teaches:
wherein the stop comprises a hold of the processed action of the user for a predetermined time. (0067-0070 (see 0068), 0075-0076, Fig. 2, 225, 230, Fig. 3, Fig. 5, 540, note under broadest reasonable interpretation "hold of the processed action of the user for a predetermined time" is taught by "deny"/"reject" the transaction because, all other things being equal, this denying/rejecting the transaction means permanently denying/rejecting it, i.e., denying/rejecting (or holding) it forever, in which case the time period for which the transaction is to be denied/rejected/held, namely, forever, is predetermined at the outset, i.e., is predetermined at the time the denial/rejection is put into effect)
It would have been obvious to one of ordinary skill in the art not later than the effective filing date of the claimed invention to have modified the combination of Selway's systems and methods for determining fraud risk and performing remedial actions, as modified by Poduval's teachings regarding a log-norm probability density function, as further modified by Shevyrev's teachings regarding adjusting parameters/ hyperparameters of a machine learning model based on a loss function (data regarding difference between training prediction and ground truth), as further modified by Comeaux's teachings regarding (i) storing a risk indicator in a database, (ii) generating an alert based on the risk indicator, and (iii) queuing/ordering the alerts/events based on their risk indicators (level of risk), and as further modified by Abifaker's teachings regarding assigning a high, medium, or low risk classification to a transaction event based on the assessed level of risk, and denying high-risk transactions, by incorporating therein these further teachings of Abifaker regarding denying/rejecting high-risk transactions, because in any such system (e.g., for detecting and mitigating/preventing fraudulent transactions) it is appropriate and standard to deny/reject high-risk transactions, meaning permanent denial/rejection, and this achieves what is considered a proper balance between risk and efficiency/ productivity. (Note this is consistent with Selway, e.g., 0022, 0037, which teaches that remedial actions such as blocking transactions (e.g., freezing, suspending, holding) or the like are appropriate when there is a high likelihood of fraud.)
Claims 31 and 40 are rejected under 35 U.S.C. 103 as being unpatentable over Selway et al. (U.S. Patent No. 2013/0013491 A1), hereafter Selway, in view of Pavlovic ("Log-normal Distribution - A simple explanation”), further in view of Shevyrev et al. (U.S. Patent Application Publication No. 2023/0281629 A1), hereafter Shevyrev, further in view of in view of Comeaux et al. (U.S. Patent No. 11,669,844 B1), hereafter Comeaux, and further in view of Chisholm (U.S. Patent Application Publication No. 2014/0351137 A1).
Regarding Claims 31 and 40
Selway in view of Pavlovic, Shevyrev and Comeaux teaches the limitations of base claims 22 and 32 as set forth above. Selway in view of Pavlovic, Shevyrev and Comeaux does not explicitly disclose but Chisholm teaches:
wherein the at least one processor is further configured to append, to the processed action, customer characteristics and historical data associated with the processed action. (0101, claims 8 and 14; note, e.g., "account number" (claim 14) teaches "customer characteristics … associated with the processed action" (compare Applicant's specification 0043 teaching account number as example of customer characteristics); e.g., "historical transaction data" (0101, claim 8), "purchase data" (claim 14) teach "historical data associated with the processed action" (compare Applicant's specification 0043 teaching historical account information, e.g., transactions, as example of historical data); "enrich" teaches "append" (compare Applicant's specification 0043 teaching "enrich" may refer to "appending"))
It would have been obvious to one of ordinary skill in the art not later than the effective filing date of the claimed invention to have modified the combination of Selway's systems and methods for determining fraud risk and performing remedial actions, as modified by Poduval's teachings regarding a log-norm probability density function, as further modified by Shevyrev's teachings regarding adjusting parameters/ hyperparameters of a machine learning model based on a loss function (data regarding difference between training prediction and ground truth), and as further modified by Comeaux's teachings regarding (i) storing a risk indicator in a database, (ii) generating an alert based on the risk indicator, and (iii) queuing/ordering the alerts/events based on their risk indicators (level of risk), by incorporating therein these teachings of Chisholm regarding enriching transaction with historical data and cardholder data to facilitate a process of determining whether a transaction is fraudulent, based on the following reasoning:
Selway (see 0012, 0020, 0024, 0030-0031, Table 1, 0037 Fig. 4, 424) teaches using other data (risk factors) in assessing risk and generating a risk score, which other data (risk factors) include data comparable to Chisholm's historical and cardholder data, but Selway does not teach "appending" this other data (risk factors) to the transaction record that is being analyzed for risk of fraud. Thus, while Selway uses this other data (risk factors) in performing the risk assessment, Selway does not provide implementation detail as to how this other data (risk factors) is obtained so that it is available for use in performing the risk assessment. However, Chisholm's enrichment process provides implementation detail appropriate to implement this under-specified aspect of Selway's systems and methods, as Chisholm's enrichment constitutes a known way of having other supplementary data at hand together with the primary data under test, for use in analyzing the primary data, as Selway requires. In addition, the combination (incorporation of Chisholm's teaching of enrichment into Selway) would have predictable results, e.g., the enrichment can be incorporated into Selway in a mechanical-like manner without adversely affecting any other relevant aspects of Selway. Thus, combining Chisholm's teaching of enrichment with Selway provides implementation detail (namely, for having the risk factors at hand for use in the risk analysis) that permits Selway to actually perform its intended function of assessing risk of fraudulent transactions so as to allow/provide for appropriate remedial actions.
Conclusion
The prior art made of record and not relied upon, as set forth in the accompanying Notice of References Cited (PTO-892), is considered pertinent to applicant's disclosure. Among the cited references:
Comeaux (US-11669844-B1) teaches evaluating a transaction for fraud, including generating an alert probability score (fraud risk score), based on a wide variety of risk factors (e.g., behavioral profile including user personal data, financial data, and user social network data; historical user financial data), generating an alert, and taking action to prevent processing of a fraudulent transaction, including using and training a machine learning model.
Comeaux (US-10567402-B1) and Comeaux (US-11722502-B1) teach fraud detection/prevention similar to Comeaux (US-11669844-B1) but to greater depth in certain aspects.
Phatak (2022/0006899) and Anderson (US-12136096-B1) teach a fraud alert queue that prioritizes fraud alerts based on fraud importance.
Vaswani (2022/0377090) teaches fraud detection/prevention (including risk scores and alerts) similar to Comeaux (US-11669844-B1).
Karpovsky (2022/0191173) teaches determining fraud risk based on VPN and/or proprietary knowledge and periodic monitoring.
Pavlovic ("Log-normal Distribution - A simple explanation”) teaches content about log-normal distribution similar to that of Applicant's disclosure (specification paragraph 0045).
Vimal (US-2023/0186311-A1) (qualifying as prior art based on Indian priority date) teaches, inter alia, benchmarking a machine learning model based on precision, recall, F1, and/or F2 scores, see 0097.
Thomas (US-10997596-B1) teaches appending a fraud accuracy tag to a declined transaction, where the fraud accuracy tag is indicative of whether the decline of the transaction is a true positive decline or a false positive decline, whereby the fraud accuracy tag is suitable to provide insight into accuracy of a fraud strategy implemented in connection with the declined transaction.
Beckman (US-10872341-B1) teaches secondary fraud detection during transaction verification, where the transaction verification process with the user itself is evaluated and scored for likelihood of fraud, using machine learning, and including assigning designations of high risk, medium risk, and low risk, such that Beckman teaches content that, for purposes of the instant claims, is comparable to that of Selway (US-2013/0013491-A1) and Comeaux (US-11669844-B1).
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to DOUGLAS W PINSKY whose telephone number is (571)272-4131. The examiner can normally be reached on 8:30 am - 5:30 pm ET.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jessica Lemieux can be reached on 571-270-3445. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/DOUGLAS W PINSKY/
Examiner, Art Unit 3626
/JESSICA LEMIEUX/Supervisory Patent Examiner, Art Unit 3626
1 Although "methods of organizing human activity" is mentioned in the guidance in question, Applicant's argument takes these words out of context and does not reflect what the guidance says in regard to these words.
2 MEMORANDUM to Patent Examining Corps, "Advance notice of change to the MPEP in light of Ex Parte Desjardins," December 5, 2025, p. 4.
3 MEMORANDUM to Patent Examining Corps, "Advance notice of change to the MPEP in light of Ex Parte Desjardins," December 5, 2025, p. 4.