Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
DETAILED ACTION
The following FINAL Office Action is in response to communication filed on 7/13/2026.
Priority
Receipt is acknowledged of papers submitted under 35 U.S.C. 119(a)-(d), which papers have been placed of record in the file.
Status of Claims
Claims 1-5, 8-12, 15-19, 21 are currently pending.
Claims 1, 8, 15 are amended.
Claim 21 is new.
Claims 6-7, 13-14, 20 are cancelled.
Claims 1-5, 8-12, 15-19, 21 are currently under examination and have been rejected as follows.
-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
Response to Amendment
The previously pending rejections under 35 USC 101 will be maintained. The 101 rejection is updated in view of the amendments.
New grounds for rejection 35 USC 103 are applied as necessitated by the amendments.
-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
Response to Arguments
Regarding Applicant’s remarks pertaining to 35 USC 101:
Step 2A Prong 2:
Applicant argues on page 12 of remarks 7/13/2026:
“Even assuming an abstract idea were recited, the claims, as amended, integrate it into a practical application by reciting a specific improvement to anomaly-detection technology. The specification identifies concrete technical shortcomings of prior approaches: rule-based detection by business personnel is "not replicable and scalable, [has] relatively simple logic, and may not identify complex hidden abnormal behaviors," while model-based detection suffers because "it may be impossible to design new features in the model, and the scalability of the model may be poor" (Applicant's specification, at ¶ [0026]). The claimed solution addresses these problems through a particular, ordered technique, i.e., constructing a multi-object behavior relationship graph, deriving an abnormal behavior subgraph from known abnormal nodes and a preset condition, and propagating detection to additional abnormal nodes by computing and comparing subgraph feature vectors, so as to "simultaneously analyze abnormal behaviors from the dimensions of multiple objects and ... detect potential abnormal behaviors" without reliance on hand-crafted rules (id., at ¶ [0043]). This is an improvement in the functioning of the detection technology itself, reflected in the claim language, and renders the claims eligible under M.P.E.P. § 2106.05(a). See Enfish, LLC v. Microsoft… and McRO, Inc. v. Bandai Namco… (claims directed to a specific technical improvement are not directed to an abstract idea).”
Examiner respectfully disagrees. Observing patterns of behavior among entities (such as between customers and merchants, insurance fraud, and fake orders, as in Applicant specification ¶ [0003]), evaluating relationships based on the behavior, comparing behaviors and relationships to known abnormal behaviors, and determining behaviors thus to be abnormal, are considered by Examiner to be abstract entrepreneurial activities. The claims as amended do not appear to present any new additional computer-based elements beyond the original “electronic device”, “memory”, “processor”, and “non-transitory computer-readable storage medium”, which are recited at a high level of generality (i.e. as a generic computer performing functions of gathering, comparing, evaluating, and presenting data, etc.) such that they amount to no more than mere instructions to apply the exception using generic computer components. Though Examiner acknowledges the comparison with Enfish, the detection of abnormal behaviors falls short of Enfish’s improvement to the operation of the computer itself, including a self-referential model for more effective storage of images and unstructured text, on-the-fly configuration, and indexing technique for faster searching of data regardless of computational resources. Similarly, McRo improved/changed the operation of the computer system by defined a specific way, namely use of particular rules to set morph weights and transitions through phonemes, to solve the problem of producing accurate and realistic lip synchronization and facial expressions in animated characters, and thus were not directed to an abstract idea, which Examiner has submitted the present invention is.
Step 2B:
Applicant argues on page 13 of remarks 7/13/2026:
“The amended claims recite a specific, non-conventional ordered combination, that is, segmenting suspicious subgraphs about a suspicious node derived from known abnormal nodes, and selecting an abnormal subgraph by feature-vector similarity to a known abnormal behavior subgraph. The ordered combination is not well-understood, routine, and conventional. Critically, the Office has provided no factual evidence that this combination is well-understood, routine, and conventional, as required by Berkheimer v. HP Inc…. and M.P.E.P. § 2106.05(d). An unsupported conclusion of conventionality cannot sustain a § 101 rejection.”
Examiner respectfully disagrees. The conventionality test in MPEP 2106.05(d) [i.e. Berkheimer test] is merely an option among MEP 2106.05(a)-(h). Examiner relied on MPEP 2106.05(f), specifically MPEP 2106.05(f)(2) in submitting the claims represent mere invocation of computers to perform existing processes. Examiner also pointed to 2106.05(f)(1), considering whether the claim recites only the idea of a solution or outcome i.e., the claims fail to recite sufficient technological details of how the actual technological solution to the actual technological problem is accomplished. The recitation of claim limitations that attempt to cover an entrepreneurial problem with insufficient technological details on how the technological result is accomplished do not provide significantly more than the judicial exception.
Accordingly the rejections under 35 USC 101 will be maintained. The 101 rejection is updated in view of the amendments.
-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
Regarding Applicant’s remarks pertaining to 35 USC 103:
Applicant argues on page 17 of remarks 7/13/2026:
“Accordingly, neither of Dong or Zheng discloses or suggests determining a feature vector of a subgraph, as recited in amended claim 1…. As described above, "feature distribution" of Zheng represents "a quantity of types of the social behavior features possessed by" a set of users. See Zheng, at ¶ [0023]. Applicant respectfully submits that a distribution over the types of behavior features possessed by users is not a feature vector of a subgraph. In other words, Zheng also fails to disclose or suggest "determining a first feature vector of the abnormal behavior subgraph," as recited in amended claim 1.
Examiner respectfully disagrees. Applicant specification ¶ [0054] states: “The features in the feature vector may include multiple features such as the number of nodes, the number of edges, node attributes, node relationships, subgraph densities, abnormal marks (such as whether there are known abnormal nodes in the subgraph) and the like;
and above-mentioned data may be combined into the feature vector.” Examiner interprets, based on the claims and the specification definition above, that a feature vector is an organized collection of attributes for an entity, node, or set of entities. Zheng at ¶ [0023] discusses “social behavior features in the user social behavior feature set”. Thus, features are attribute of users in a set of users, analogous with a subgraph. Examiner’s broadest reasonable interpretation of “subgraph” is a smaller portion of a larger set or graph, supported throughout Dong indirectly and directly by Zheng at ¶ [0117]. Examiner combines the two references to remove ambiguity in the broadest reasonable interpretation. Additional citations, details, and rationale are included in the 103 rejection section below.
Applicant argues starting on page 17 of remarks 7/13/2026:
“…Applicant respectfully submits that identifying an abnormal subgraph because its feature vector is similar to that of a known abnormal behavior subgraph, as recited in amended claim 1, is not disclosed or suggested by a reference that teaches flagging abnormality based on feature-distribution difference, as Zheng clearly does, at least because making a determination based on "difference" as compared to a "difference threshold" is operationally opposite to making a determination based on "similarity" as compared to a "similarity threshold." As such, Zheng, like Dong, fails to disclose or suggest "determining a second feature vector of each of the plurality of suspicious subgraphs; determining similarity between the first feature vector and the second feature vector; and determining a suspicious subgraph that satisfies a similarity threshold to be the abnormal behavior subgraph, wherein the suspicious node in the abnormal behavior subgraph is the abnormal node," as recited in amended claim 1.
Examiner respectfully disagrees. Examiner interprets values remaining within a threshold range as analogous to a measure of similarity, rather than being operationally opposite, thus is not persuaded. However, in arguendo, Examiner points to additional support provided by primary reference Dong at ¶ [0017] which in combination with Zheng teaches the claims limitations as amended. Additional citations, details, and rationale are included in the 103 rejection section below.
Applicant argues on page 19 of remarks 7/13/2026:
“Newly added claim 21 is allowable at least by virtue of its dependence from claim 1, and also on its own merits. Applicant respectfully requests allowance of claim 21.
Examiner considers the new claim but finds the argument moot. Examiner points to additional reference Wang US 20220343329 A1, hereinafter Wang, which in combination with Dong and Zheng, teaches the new feature of claim 21 at Wang ¶ [0029]. Additional citations, details, and rationale are included in the 103 rejection section below.
Accordingly, new grounds for rejection 35 USC 103 are applied as necessitated by the amendments.
-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-5, 8-12, 15-19, 21 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Claims 1-5, 21 are directed to a method or process which is a statutory category. Claims 8-12 are directed to an electronic device or machine which is a statutory category.
Claims 15-19 are directed to a storage medium or article of manufacture which is a statutory category.
Step 2A Prong One: The claims recite, describe, or set forth a judicial exception of an abstract idea (see MPEP 2106.04(a)). Specifically, the claims recite, describe or set forth insurance, mitigating risk, observation, evaluation, and judgement including: “obtaining behavior information, wherein the behavior information includes behavior information of at least two objects”, “constructing a behavior relationship graph according to the behavior information”, “based on one or more known abnormal nodes in the behavior relationship graph and a preset condition, determining an abnormal behavior subgraph in the behavior relationship graph, wherein the behavior information of the one or more known abnormal nodes is abnormal”, “based on the abnormal behavior subgraph, determining an abnormal node in the behavior relationship graph”, “determining a first feature vector of the abnormal behavior subgraph”, “selecting the abnormal node from the behavior relationship graph based on the first feature vector”, “using a suspicious node in the behavior relationship graph as a central node, segmenting the behavior relationship graph to obtain a plurality of suspicious subgraphs”, “determining a second feature vector of each of the plurality of suspicious subgraphs”, “determining similarity between the first feature vector and the second feature vector”, and “determining a suspicious subgraph that satisfies a similarity threshold to be the abnormal behavior subgraph, wherein the suspicious node in the abnormal behavior subgraph is the abnormal node”. Observing patterns of behavior among entities (such as customers and/or merchants), evaluating relationships based on the behavior, comparing behaviors and relationships to known abnormal behaviors, and determining behaviors thus to be abnormal fall within insurance and mitigating risk as they pertain to fundamental economic practices, and business relations as it pertains to commercial or legal interactions, each under the larger abstract subgrouping of Certain Methods of Organizing Human Activity (MPEP 2106.04(a)(2) II); as well as observation, evaluation, and judgement as they pertain to the abstract subgrouping Mental Processes1 (MPEP 2106.04(a)(2) III).
Step 2A Prong Two: Independent claims 8, 15 recite the following additional elements: “electronic device”, “memory”, “processor”, and “non-transitory computer-readable storage medium”. The functions of these additional elements include obtaining information, constructing graphs and sub-graphs based on obtained information, determining abnormal nodes, determining feature vectors, selecting abnormal nodes based on feature vectors, determining similarity between feature vectors. The additional elements are recited at a high level of generality (i.e. as a generic computer performing functions of gathering, comparing, evaluating, and presenting data, etc.) such that they amount to no more than mere instructions to apply the exception using generic computer components. Therefore, these functions can be viewed as not meaningfully different than a business method or mathematical algorithm being applied on a general-purpose computer as tested per MPEP 2106.05(f)(2)(i). The claims are directed to an abstract idea and the judicial exception does not integrate the abstract idea into a practical application.
Step 2B: According to MPEP 2106.05(f)(1), considering whether the claim recites only the idea of a solution or outcome i.e., the claims fail to recite the technological details of how the actual technological solution to the actual technological problem is accomplished. The recitation of claim limitations that attempt to cover an entrepreneurial and thus abstract solution to an entrepreneurial problem with no technological details on how the technological result is accomplished and no description of the mechanism for accomplishing the result do not provide significantly more than the judicial exception.
Dependent claim 21 recites the additional element “graph convolutional network (GCN)”. The function of this additional element is extracting a feature vector from a subgraph. The additional element is also recited at a high level of generality (i.e. as a generic computer performing functions of gathering and storing data, etc.) such that it amounts to no more than mere instructions to apply the exception using generic computer components.
Independent claim 1 and dependent claims 2-5, 9-12, 16-19, 21 do not appear to provide any further additional computer-based elements, let alone for such additional computer-based elements to integrate the abstract idea into practical application (Step 2A Prong Two) or providing significantly more (Step 2B).
Further, dependent claims 9-12, 16-19, 21 merely incorporate the additional elements recited in claims 8, 15 (claim 1 and its dependent claims not appearing to have any additional computer-based elements) along with further narrowing of the abstract idea of claims 8, 15 and their execution of the abstract idea. Specifically, the dependent claims narrow the “electronic device”, “memory”, “processor”, and “non-transitory computer-readable storage medium” to capabilities such as determining, connecting, segmenting, marking, and selecting various forms of data such as objects, nodes, suspicious nodes, abnormal nodes, intermediate nodes, graphs, subgraphs, edges, connections, feature vectors, thresholds, similarities, etc. which, when evaluated per MPEP 2106.05(f)(2) represent mere invocation of computers to perform existing processes. Therefore, the additional elements recited in the claimed invention individually and in combination fail to integrate a judicial exception into a practical application (Step 2A prong two) and for the same reasons they also fail to provide significantly more (Step 2B). Thus, claims 1-5, 8-12, 15-19, 21 are reasoned to be patent ineligible.
-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
REJECTIONS BASED ON PRIOR ART
Examiner Note: Some rejections will contain bracketed comments preceded by an “EN” that will denote an examiner note. This will be placed to further explain a rejection.
-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims 1-5, 8-12, 15-19 are rejected under 35 U.S.C. 103 as being unpatentable over:
Dong US 20250029000 A1, hereinafter Dong in view of
Zheng US 20220172090 A1, hereinafter Zheng. As per,
Regarding claims 1, 8, 15: Dong teaches:
(claim 1) An abnormal behavior detection method, comprising:
(claim 8) An electronic device, comprising: a memory, configured to store a computer program; and one or more processors, configured to, when the computer program is executed, perform:
(claim 15) A non-transitory computer-readable storage medium, containing a computer program that when being executed, causes a processor to perform:
obtaining behavior information, wherein the behavior information includes behavior information of at least two objects (Dong ¶ [0021]: In the illustrated embodiment, one or more user devices 130 receive user input 102 from users and based on this input transmit one or more electronic communication requests 132 to server system 120. For example, the electronic communication requests 132 may be requests for transmission of data between servers of a network of servers, text messages, electronic transactions (e.g., a person-to-person transaction), etc. Based on such requests, server system 120 gathers and stores electronic communication data 152 [which] may include source attributes indicating entities [EN: objects] (e.g., user, businesses, etc.) involved in the communications, types of information being communicated between entities, amounts of data being communicated (e.g., a transaction amount), etc);
constructing a behavior relationship graph according to the behavior information (Dong ¶ mid-[0023]: Server system 120 inputs the electronic communication data 152 into graph module 160. Graph module 160 generates a network graph 112 based on the electronic communication data 152. For example, graph module 160 may generate a network graph 112 that includes nodes representing entities and edges representing the electronic communications that occurred between the entities. [Also see Figs. 2B, 2C, 4, 5, and 6]);
based on one or more known abnormal nodes in the behavior relationship graph and a preset condition, determining an abnormal behavior [..] in the behavior relationship graph, wherein the behavior information of the one or more known abnormal nodes is abnormal; and based on the abnormal behavior [..], determining an abnormal node in the behavior relationship graph (Dong mid-¶ [0038]: Community diffusion module 320 determines, for example, that if a given node is located in a community of nodes that are known to be anomalous [EN: abnormal behavior subgraph], then the given node is likely anomalous…. Still further in this example if the connectivity density of edges between the given node and one or more known anomalous nodes is higher than a predetermined threshold connectivity density [EN: preset condition], community diffusion module 320 determines that the given node is likely anomalous), wherein determining the abnormal node in the behavior relationship graph based on the abnormal behavior [sub]graph comprises:
determining a [..] feature vector of the abnormal behavior [sub]graph (Dong mid-¶ [0052]: The H in the equation above is the community diffusion score of all nodes in a network graph. For example, H is a vector and each entry in the vector is the score of a given node); and
[..]
using a suspicious node in the behavior relationship graph as a central node (Dong end-¶ [0037]: whether the given node is in a community of nodes formed by anomalous nodes (e.g., a wallet could belong to a community of known suspicious wallets), the distance between the given wallet and one or more center nodes of the community, and a connectivity density of edges between the given node and one or more known anomalous (or not anomalous) nodes),
[..]
determining a [..] vector of each of the plurality of suspicious [sub]graphs (Dong mid-¶ [0052]: The H in the equation above is the community diffusion score of all nodes in a network graph. For example, H is a vector and each entry in the vector is the score of a given node);
determining similarity [..] (Dong ¶ [0017]: To address these shortcomings, the disclosed techniques measure the similarity in behavior between a given entity (e.g., wallet or account) and one or more other entities based on proximity of those entities within an electronic communication network graph); and
determining a suspicious subgraph that satisfies a similarity [..] to be the abnormal behavior subgraph [..] (Dong mid-¶ [0017]: …based on their similarity and proximity, assign a label to the given entity based on known labels already assigned to the other entities that are similar or in close proximity to the given entity. Based on the determine[d] behavior similarity and proximity data, the disclosed techniques generate features for training machine learning models to classify… entities. Such feature extraction techniques generate node behavior feature… neighbor convolution features… and community diffusion features (e.g., features that indicate whether and where a node representing an entity is located in an anomalous community [EN: suspicious subgraph] within the network graph, the given node corresponding to the community diffusion feature being calculated).
Although Dong teaches constructing a behavior relationship graph to identify abnormal nodes based on preset conditions and known abnormal nodes, Dong does not specifically teach determining an abnormal behavior subgraph in the behavior relationship graph, determining a first feature vector, detecting an abnormal node based on the first feature, determining a second feature vector, or determining similarity between the features.
However, Zheng in analogous art of abnormal behavior detection with network graphs teaches or suggests:
determining an abnormal behavior subgraph in the behavior relationship graph (Zheng end-¶ [0117]: The relationship topology graph is divided into at least two topology sub graphs by using a clustering algorithm. A set of the users corresponding to the nodes in one of the at least two topology sub-graphs is used as the target user set),
[..]
determining a first feature [..] of the abnormal behavior subgraph (Zheng ¶ [0023]: a feature distribution determination unit, configured to determine a first feature distribution of the abnormal users according to the social behavior features in the user social behavior feature set, the first feature distribution being used for representing a quantity of types of the social behavior features possessed by the abnormal users); and
selecting the abnormal node from the behavior relationship graph based on the first feature [..] (Zheng ¶ [0029]: The second status determination unit is further configured to determine the status of the target user set as abnormal in a case that the feature distribution difference is greater than or equal to the difference threshold and the first feature distribution is less than the distribution threshold), wherein selecting the abnormal node from the behavior relationship graph based on the first feature vector comprises:
[..] segmenting the behavior relationship graph to obtain a plurality of suspicious subgraphs (Zheng Claim 8: …dividing the relationship topology graph into the at least two topology sub-graphs by using the clustering algorithm comprises:… determining a jump probability between the first node and an association node in the sampling path based on an edge weight in the relationship topology graph… and dividing the updated relationship topology graph to obtain the at least two topology sub-graphs);
determining a second feature [..] of each of the plurality of suspicious subgraphs (Zheng ¶ [0024]: and further configured to determine a second feature distribution of the users in the target user set according to the social behavior features in the user social behavior feature set, the second feature distribution being used for representing a quantity of types of the social behavior features possessed by the users in the target user set);
determining similarity between the first feature [..] and the second feature [..] (Zheng ¶ [0025]: a feature distribution difference determination unit, configured to determine a feature distribution difference between the abnormal user and the users in the target user set according to the first feature distribution and the second feature distribution); and
determining a suspicious subgraph that satisfies a [..] threshold to be the abnormal behavior subgraph, wherein the suspicious node in the abnormal behavior subgraph is the abnormal node (Zheng ¶ [0027]: The second status determination unit is further configured to determine the status of the target user set as the normal state in a case that the feature distribution difference is less than a difference threshold and the first feature distribution is less than a distribution threshold. ¶ [00561]: The diffusion-abnormal user identification module includes: … ¶ [0056]: a second diffusion-abnormal user determination unit, configured to: acquire abnormal user nodes corresponding to the abnormal users, acquire association user nodes corresponding to the users having the social relationship with the abnormal users, determine, as a diffusion abnormal node, the association user node having an edge weight with one of the abnormal user nodes greater than an association threshold, and determine the user corresponding to the diffusion-abnormal node as the diffusion-abnormal user).
Zheng and Dong are found as analogous art of abnormal behavior detection with network graphs. It would have been obvious to one skilled in the art, before the effective filing date of the invention, to have modified Dong’s label and network graph expansion using multiple feature extraction procedures system and method to have included Zheng’s teachings around behavior subgraph segmentation. The benefit of these additional features would have improved efficient and rapid identification of abnormal users to reduce incidents of fraud. (Zheng ¶ [0003-0004]). The predictability of such modifications and/or variations, would have been corroborated by the broad level of skill of one of ordinary skills in the art as articulated by Dong in view of Zheng (see MPEP 2143 G).
Further, the claimed invention could have also been viewed as a mere combination of old elements in a similar field of abnormal behavior detection with network graphs. In such combination each element would have merely performed the same function as it did separately. Thus, one of ordinary skill in the art would have recognized that, given existing technical ability to combine the elements, as evidenced by Dong in view of Zheng above, the to- be combined elements would have fit together like pieces of a puzzle in a logical, complementary, technologically feasible and/or economically desirable manner. Thus, it would have been reasoned that the results of the combination would have been predictable (see MPEP 2143 A).
Regarding claims 2, 9, 16: Dong / Zheng teaches all the limitations of claims 1, 8, 15 above.
Dong further teaches:
determining each object of the behavior information to be a node of the behavior relationship graph (Dong ¶ mid-[0030]: …network graph 112 is implemented as a non-bi-partite graph that include nodes representing entities [EN: objects]. [Also see Fig. 5 and related text]); and
connecting objects with an association relationship as an edge of the behavior relationship graph (Dong end-¶ [0030]: …and edges representing the electronic communications between the entities, as shown in the example network graph 512 discussed in further detail below with reference to FIG. 5).
Regarding claims 3, 10, 17: Dong / Zheng teaches all the limitations of claims 2, 9, 16 above.
Although Dong teaches constructing a behavior relationship graph to identify abnormal nodes based on preset conditions and known abnormal nodes, Dong does not specifically teach determining abnormal nodes based on frequency of marking suspicious nodes satisfying a threshold.
However, Zheng in analogous art of abnormal behavior detection with network graphs teaches or suggests:
in response to that a number of times, that a suspicious node in the behavior relationship graph is marked, satisfies a threshold, determining the suspicious node to be an abnormal node (Zheng mid-¶ [0120]: According to social behavior records between the users having the social relationship, an initial weight may be set for the edge between the nodes k…. The social behavior records herein may be… a transfer frequency, a communication frequency… between the users having the social relationship. A… higher transfer frequency, a higher communication frequency between the two users leads to a larger initial weight set for the edge between the two users. End-¶ [0111]: The association user nodes [EN: suspicious nodes] having an edge weight with one of the abnormal user nodes greater than an association threshold are determined as a diffusion-abnormal node. In this way, the user corresponding to the diffusion-abnormal node is determined as the diffusion-abnormal user).
Zheng and Dong are found as analogous art of abnormal behavior detection with network graphs. It would have been obvious to one skilled in the art, before the effective filing date of the invention, to have modified Dong’s label and network graph expansion using multiple feature extraction procedures system and method to have included Zheng’s teachings around determining abnormal nodes based on frequency of marking suspicious nodes satisfying a threshold. The benefit of these additional features would have improved efficient and rapid identification of abnormal users to reduce incidents of fraud. (Zheng ¶ [0003-0004]). The predictability of such modifications and/or variations, would have been corroborated by the broad level of skill of one of ordinary skills in the art as articulated by Dong in view of Zheng (see MPEP 2143 G).
Further, the claimed invention could have also been viewed as a mere combination of old elements in a similar field of abnormal behavior detection with network graphs. In such combination each element would have merely performed the same function as it did separately. Thus, one of ordinary skill in the art would have recognized that, given existing technical ability to combine the elements, as evidenced by Dong in view of Zheng above, the to- be combined elements would have fit together like pieces of a puzzle in a logical, complementary, technologically feasible and/or economically desirable manner. Thus, it would have been reasoned that the results of the combination would have been predictable (see MPEP 2143 A).
Regarding claims 4, 11, 18: Dong / Zheng teaches all the limitations of claims 3, 10, 17 above.
Dong further teaches:
determining a node, directly connected to a known abnormal node in the behavior relationship graph, to be the suspicious node; or determining a node, directly connected to a plurality of suspicious nodes, also to be the suspicious node (Dong ¶ [0016]: Traditionally, electronic communications processing systems evaluate a set of known entities (e.g., known to be anomalous in some way) to identify other entities that are close to the set of known entities within an electronic communication network graph. For example, if an unknown entity is within one communication hop of a known entity included in the set of known entities, then the system will identify the unknown entity as suspicious. End-¶ [0017]: …the disclosed techniques measure the similarity in behavior between a given entity (e.g., wallet or account) and one or more other entities based on proximity of those entities within an electronic communication network graph… based on their similarity and proximity, assign a label [EN: suspicious node] to the given entity based on known labels already assigned to the other entities that are similar or in close proximity to the given entity).
Regarding claims 5, 12, 19: Dong / Zheng teaches all the limitations of claims 4, 11, 18 above.
Dong further teaches:
determining an abnormal node based on the preset condition (Dong mid-¶ [0038]: …if the connectivity density of edges between the given node and one or more known anomalous nodes is higher than a predetermined threshold connectivity density [EN: preset condition], community diffusion module 320 determines that the given node is likely anomalous);
[..].
Although Dong teaches constructing a behavior relationship graph to identify abnormal nodes based on preset conditions and known abnormal nodes, Dong does not specifically teach determining intermediate nodes or segmenting behavior graphs into subgraphs.
However, Zheng in analogous art of abnormal behavior detection with network graphs teaches or suggests:
determining the abnormal node and the one or more known abnormal nodes in the behavior relationship graph as intermediate nodes (Zheng ¶ [0041]: an intermediate node acquisition subunit, configured to acquire an intermediate node between the node k and the association node from the sampling path in a case that there is no edge between the node k and the association node, the node k reaching the association node through the intermediate node); and
according to the intermediate nodes, segmenting the behavior relationship graph to obtain the abnormal behavior subgraph in the behavior relationship graph (Zheng Claim 8: …dividing the relationship topology graph into the at least two topology sub-graphs by using the clustering algorithm comprises:… determining a jump probability between the first node and an association node in the sampling path based on an edge weight in the relationship topology graph… and dividing the updated relationship topology graph to obtain the at least two topology sub-graphs).
Zheng and Dong are found as analogous art of abnormal behavior detection with network graphs. It would have been obvious to one skilled in the art, before the effective filing date of the invention, to have modified Dong’s label and network graph expansion using multiple feature extraction procedures system and method to have included Zheng’s teachings around determining intermediate nodes and segmenting behavior graphs into subgraphs. The benefit of these additional features would have improved efficient and rapid identification of abnormal users to reduce incidents of fraud. (Zheng ¶ [0003-0004]). The predictability of such modifications and/or variations, would have been corroborated by the broad level of skill of one of ordinary skills in the art as articulated by Dong in view of Zheng (see MPEP 2143 G).
Further, the claimed invention could have also been viewed as a mere combination of old elements in a similar field of abnormal behavior detection with network graphs. In such combination each element would have merely performed the same function as it did separately. Thus, one of ordinary skill in the art would have recognized that, given existing technical ability to combine the elements, as evidenced by Dong in view of Zheng above, the to- be combined elements would have fit together like pieces of a puzzle in a logical, complementary, technologically feasible and/or economically desirable manner. Thus, it would have been reasoned that the results of the combination would have been predictable (see MPEP 2143 A).
Regarding claims 6-7, 13-14, 20: cancelled.
------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
Claim 21 is rejected under 35 U.S.C. 103 as being unpatentable over:
Dong / Zheng as applied above, in further view of
Wang US 20220343329 A1, hereinafter Wang. As per,
Regarding claim 21: Dong / Zheng teaches all the limitations of claim 1 above.
Although Dong teaches constructing a behavior relationship graph to identify abnormal nodes based on preset conditions and known abnormal nodes, Dong does not specifically teach using a Graph Convolutional Network (GCN) to detect abnormal nodes.
However, Wang in analogous art of abnormal behavior detection with network graphs teaches or suggests:
wherein determining the first feature vector of the abnormal behavior subgraph comprises extracting the first feature vector of the abnormal behavior subgraph through a graph convolutional network (GCN) (Wang ¶ [0029]: Training module 170 trains a machine learning model using final matrix 162 as a training input. After inputting the final matrix 162 into the machine learning model, training module 170 verifies that the model has been trained properly by inputting transactions in the testing set 134 into the model and observing whether output of the model matches known labels for transactions included in the testing set 134…. Training module 170 may train any of various types of machine learning models including neural networks (e.g., graph convolutional network (GCN)), isolation forests, logistic regression, decision trees (e.g., XGBoost), etc.).
Wang, Zheng and Dong are found as analogous art of abnormal behavior detection with network graphs. It would have been obvious to one skilled in the art, before the effective filing date of the invention, to have modified Dong’s label and network graph expansion using multiple feature extraction procedures system and method to have included Wang’s teachings around using a Graph Convolutional Network (GCN) to detect abnormal nodes. The benefit of these additional features would have improved scalability and accuracy in transaction risk assessments (Wang ¶ [0015]). The predictability of such modifications and/or variations, would have been corroborated by the broad level of skill of one of ordinary skills in the art as articulated by Dong in view of Zheng and Wang (see MPEP 2143 G).
Further, the claimed invention could have also been viewed as a mere combination of old elements in a similar field of abnormal behavior detection with network graphs. In such combination each element would have merely performed the same function as it did separately. Thus, one of ordinary skill in the art would have recognized that, given existing technical ability to combine the elements, as evidenced by Dong in view of Zheng and Wang above, the to- be combined elements would have fit together like pieces of a puzzle in a logical, complementary, technologically feasible and/or economically desirable manner. Thus, it would have been reasoned that the results of the combination would have been predictable (see MPEP 2143 A).
------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
Conclusion
The following art is made of record and considered pertinent to Applicant’s disclosure:
Agrawal; Bhavna et al. US 20240333739 A1, Detecting and mitigating system anomalies using knowledge graphs.
Apostolopoulos; Georgios US 20180219888 A1, Graph-Based Network Security Threat Detection Across Time and Entities.
Bertiger; Anna Swanson et al. US 11418526 B2, Detecting anomalous network activity.
Erlingsson; Úlfar et al. US 12489771 B1, Detecting anomalous behavior of nodes in a hierarchical cloud deployment.
LAVID BEN LOLO; Deddy et al. US 20240235861 A1, System and method for machine learning based security incidents detection and classification in a blockchain ecosystem.
Louizos; Louizos Alexandros et al. US 20210158161 A1, Methods and Systems for Detecting Spurious Data Patterns.
Mezic; Igor et al. US 10673886 B1, Assigning and representing security risks on a computer network.
Muddu; Sudhakar et al. US 9516053 B1, Network security threat detection by user/user-entity behavioral analysis.
Muthuswamy; Srinivasan S. et al. US 20220172211 A1, Applying machine learning to learn relationship weightage in risk networks.
Reddy; Surendra et al. US 20190259033 A1, System and method for using a data genome to identify suspicious financial transactions.
SIKAND; Samarth et al. US 20210224588 A1, Recruitment process graph based unsupervised anomaly detection.
Song; Le et al. US 20200204577 A1, Graphical structure model-based prevention and control of abnormal accounts.
Tang; Yuang et al. US 11810001 B1, Systems and methods for generating and implementing knowledge graphs for knowledge representation and analysis
Wang; Jisheng et al. US 20240430282 A1, Generalized behavior analytics framework for detecting and preventing different types of api security vulnerabilities.
Yuan et al. WO 2020042024 A1, Node abnormality detection method and device based on graph algorithm and storage device.
Jiang et al., "Anomaly Detection with Graph Convolutional Networks for Insider Threat and Fraud Detection," MILCOM 2019 - 2019 IEEE Military Communications Conference (MILCOM), Norfolk, VA, USA, 2019, pp. 109-114, doi: 10.1109/MILCOM47813.2019.9020760.
------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to REED M. BOND whose telephone number is (571) 270-0585. The examiner can normally be reached Monday - Friday 8:00 am - 5:00 pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Patricia Munson can be reached at (571) 270-5396. The fax phone number for the organization where this application or proceeding is assigned is (571) 273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/REED M. BOND/Examiner, Art Unit 3624 August 28, 2026
/HAMZEH OBAID/Primary Examiner, Art Unit 3624
1 MPEP 2106.04(a): “examiners should identify at least one abstract idea grouping, but preferably identify all groupings to the extent possible”.