CTNF 18/993,755 CTNF 80275 DETAILED ACTION 07-03-aia AIA 15-10-aia The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA. The preliminary amendment filed 1/13/2025 has been placed of record in the file. Claims 1-12 and 28-35 are presented for examination. The IDS filed 8/13/2025 has been considered. Claim Rejections - 35 USC § 101 07-04-01 AIA 07-04 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claim 35 is rejected under 35 U.S.C. 101 because it is directed to one or more "computer-readable storage media." It is believed that such “media” would reasonably be interpreted by one of ordinary skill as the abstract idea of any portion of a communication, including the forms of energy, per se, used in communications. Therefore, the claims in question do not appear to fall within a statutory category of invention as set forth in 35 U.S.C. 101. It is recommended that the applicant amend the claim to recite one or more “non-transitory computer-readable storage media” or the like. Claim Rejections - 35 USC § 102 07-06 AIA 15-10-15 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. 07-07-aia AIA 07-07 The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – 07-12-aia AIA (a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention. 07-15-03-aia AIA Claim s 1-10, 12, and 28-35 are rejected under 35 U.S.C. 102(a)(2) as being anticipated by Yang et al. (U.S. Patent Application Publication Number 2023/0259638), hereinafter referred to as Yang . Regarding claim 1 , Yang discloses a method, comprising: receiving, by a hardware device, data representing a machine learning model comprising a plurality of model parameters for inference operations, wherein the hardware device comprises a set of computation units arranged in one or more processing elements (paragraph 67, neural network parameters loaded into ALUs and parameters used for inferencing); obtaining instructions for performing obfuscating operations configured to obfuscate one or more measurable characteristics of the machine learning model when the machine learning model is executed by the one or more processing elements (paragraph 41, obfuscating operations); causing a first portion of the set of computation units to perform the inference operations of the machine learning model (paragraph 47, real computations); and causing a second portion of the set of computation units to perform the obfuscating operations concurrently with the first portion of the set of computation units performing the inference operations (paragraph 47, producing noise to obfuscate). Regarding claim 2 , Yang discloses wherein the machine learning model is a neural network, wherein the obfuscating operations are configured to obscure at least one of a number of network layers of the neural network, a number of nodes in a network layer of the neural network, a nodal operation for a node in a network layer of the neural network, or a weight value associated with a node in a network layer of the neural network (paragraph 67, parameters configure neurons or layers of neural network). Regarding claim 3 , Yang discloses wherein the one or more measurable characteristics of the machine learning model comprises at least one of a power profile, an electromagnetic profile, or a time profile (paragraph 51, obfuscation changes SPA, DPA, etc.). Regarding claim 4 , Yang discloses wherein at least a subset of the first portion of the set of computation units and a corresponding subset of the second portion of the set of computation units are located within a common processing element (paragraph 73, ALUs within same processor). Regarding claim 5 , Yang discloses wherein at least a subset of the first portion of the set of computation units are located in a first processing element, and at least a subset of the second portion of the set of computation units are located in a second processing element that is different from the first processing element (paragraph 73, ALUs distributed between different processors). Regarding claim 6 , Yang discloses wherein the obfuscating operations include an obfuscating nodal operation for a particular node in a network layer to be performed concurrently with a corresponding nodal operation for the particular node (paragraph 67, neurons of neural network, and paragraph 47, real computations and producing noise to obfuscate). Regarding claim 7 , Yang discloses wherein obfuscating nodal operation specifies an activation function for the particular node that is different from an actual activation function of the particular node (paragraph 72, activations from neurons, and paragraph 47, real computations and producing noise to obfuscate). Regarding claim 8 , Yang discloses wherein causing the second portion of the set of computation units to perform the obfuscating operations concurrently with the first portion of the set of computation units performing the inference operations comprises assigning the obfuscating operations to a dedicated processing element that performs the obfuscating operations (paragraph 76, dedicated computational resource). Regarding claim 9 , Yang discloses wherein the dedicated processing element includes one or more processing elements or computation units that are additionally incorporated into a hardware device and are configured to perform substantially only corresponding obfuscating operations (paragraph 76, separate computational hardware that includes ALUs). Regarding claim 10 , Yang discloses wherein causing the second portion of the set of computation units to perform the obfuscating operations concurrently with the first portion of the set of computation units performing the inference operations comprises: assigning the obfuscating operations to one or more processing elements that also perform inference operations for one or more machine learning models; and reassigning a subset of the inference operations from the one or more processing elements to other processing elements of the hardware device (paragraph 47, multiple stages perform computational operations but only one is real). Regarding claim 12 , Yang discloses a system comprising a hardware device and one or more storage devices storing instructions that when executed by the hardware device cause the hardware device to perform operations, the operations comprising: receiving, by the hardware device, data representing a machine learning model comprising a plurality of model parameters for inference operations, wherein the hardware device comprises a set of computation units arranged in one or more processing elements (paragraph 67, neural network parameters loaded into ALUs and parameters used for inferencing); obtaining instructions for performing obfuscating operations configured to obfuscate one or more measurable characteristics of the machine learning model when the machine learning model is executed by the one or more processing elements (paragraph 41, obfuscating operations); causing a first portion of the set of computation units to perform the inference operations of the machine learning model (paragraph 47, real computations); and causing a second portion of the set of computation units to perform the obfuscating operations concurrently with the first portion of the set of computation units performing the inference operations (paragraph 47, producing noise to obfuscate). Regarding claim 28 , Yang discloses wherein the machine learning model is a neural network, wherein the obfuscating operations are configured to obscure at least one of a number of network layers of the neural network, a number of nodes in a network layer of the neural network, a nodal operation for a node in a network layer of the neural network, or a weight value associated with a node in a network layer of the neural network (paragraph 67, parameters configure neurons or layers of neural network). Regarding claim 29 , Yang discloses wherein the one or more measurable characteristics of the machine learning model comprises at least one of a power profile, an electromagnetic profile, or a time profile (paragraph 51, obfuscation changes SPA, DPA, etc.). Regarding claim 30 , Yang discloses wherein at least a subset of the first portion of the set of computation units and a corresponding subset of the second portion of the set of computation units are located within a common processing element (paragraph 73, ALUs within same processor). Regarding claim 31 , Yang discloses wherein at least a subset of the first portion of the set of computation units are located in a first processing element, and at least a subset of the second portion of the set of computation units are located in a second processing element that is different from the first processing element (paragraph 73, ALUs distributed between different processors). Regarding claim 32 , Yang discloses wherein the obfuscating operations include an obfuscating nodal operation for a particular node in a network layer to be performed concurrently with a corresponding nodal operation for the particular node (paragraph 67, neurons of neural network, and paragraph 47, real computations and producing noise to obfuscate). Regarding claim 33 , Yang discloses wherein obfuscating nodal operation specifies an activation function for the particular node that is different from an actual activation function of the particular node (paragraph 72, activations from neurons, and paragraph 47, real computations and producing noise to obfuscate). Regarding claim 34 , Yang discloses wherein causing the second portion of the set of computation units to perform the obfuscating operations concurrently with the first portion of the set of computation units performing the inference operations comprises assigning the obfuscating operations to a dedicated processing element that performs the obfuscating operations (paragraph 76, dedicated computational resource). Regarding claim 35 , Yang discloses one or more computer-readable storage media storing instructions that when executed by one or more computers cause the one or more computers to perform operations comprising: receiving, by a hardware device, data representing a machine learning model comprising a plurality of model parameters for inference operations, wherein the hardware device comprises a set of computation units arranged in one or more processing elements (paragraph 67, neural network parameters loaded into ALUs and parameters used for inferencing); obtaining instructions for performing obfuscating operations configured to obfuscate one or more measurable characteristics of the machine learning model when the machine learning model is executed by the one or more processing elements (paragraph 41, obfuscating operations); causing a first portion of the set of computation units to perform the inference operations of the machine learning model (paragraph 47, real computations); and causing a second portion of the set of computation units to perform the obfuscating operations concurrently with the first portion of the set of computation units performing the inference operations (paragraph 47, producing noise to obfuscate) . Claim Rejections - 35 USC § 103 07-20-aia AIA The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 07-21-aia AIA Claim 11 is rejected under 35 U.S.C. 103 as being unpatentable over Yang . Regarding claim 11 , Yang discloses wherein the neural network is configured to perform image recognition tasks (paragraph 131, image recognition). Yang does not explicitly state that the image recognition tasks are human face recognition tasks for unlocking devices. However, facial recognition was a common type of image recognition. Since Yang already teaches image recognition and since facial recognition for unlocking devices was common practice in the art, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the system of Yang by adding the ability that the image recognition tasks are human face recognition tasks for unlocking devices. One of ordinary skill in the art would have been motivated to utilize Yang’s image recognition in any well known image recognition scenario, such as facial recognition . Conclusion 07-96 AIA The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Li et al. (U.S. Patent Application Publication Number 2023/0401422) disclosed techniques for obfuscating a neural network architecture while preserving its functionality. Any inquiry concerning this communication or earlier communications from the examiner should be directed to Victor Lesniewski whose telephone number is (571)272-2812. The examiner can normally be reached Monday thru Friday, 9am to 5pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Carl Colin can be reached at 571-272-3862. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /Victor Lesniewski/Primary Examiner, Art Unit 2493 Application/Control Number: 18/993,755 Page 2 Art Unit: 2493 Application/Control Number: 18/993,755 Page 3 Art Unit: 2493 Application/Control Number: 18/993,755 Page 4 Art Unit: 2493 Application/Control Number: 18/993,755 Page 5 Art Unit: 2493 Application/Control Number: 18/993,755 Page 6 Art Unit: 2493 Application/Control Number: 18/993,755 Page 7 Art Unit: 2493 Application/Control Number: 18/993,755 Page 8 Art Unit: 2493 Application/Control Number: 18/993,755 Page 9 Art Unit: 2493 Application/Control Number: 18/993,755 Page 10 Art Unit: 2493