Prosecution Insights
Last updated: August 17, 2026
Application No. 19/044,678

METHOD AND SYSTEM FOR MACHINE LEARNING MODEL GENERATION AND ANOMALOUS EVENT DETECTION

Non-Final OA §102§103
Filed
Feb 04, 2025
Priority
Nov 22, 2022 — continuation of 12/238,122
Examiner
DOAN, HUAN V
Art Unit
Tech Center
Assignee
Verizon Communications Inc.
OA Round
1 (Non-Final)
80%
Grant Probability
Favorable
1-2
OA Rounds
1y 5m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 80% — above average
80%
Career Allowance Rate
229 granted / 285 resolved
+20.4% vs TC avg
Strong +42% interview lift
Without
With
+42.1%
Interview Lift
resolved cases with interview
Typical timeline
2y 12m
Avg Prosecution
11 currently pending
Career history
293
Total Applications
across all art units

Statute-Specific Performance

§101
12.6%
-27.4% vs TC avg
§103
58.3%
+18.3% vs TC avg
§102
15.1%
-24.9% vs TC avg
§112
11.9%
-28.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 285 resolved cases

Office Action

§102 §103
DETAILED ACTION 1. This office action is in response to the communication filed on 02/04/2025. 2. Claims 1-20 are pending. Notice of Pre-AIA or AIA Status 3. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claim Rejections - 35 USC § 102 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale or otherwise available to the public before the effective filing date of the claimed invention. (a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention. 4. Claim(s) 1-3, 7-14, and 17- 20 is/are rejected under 35 U.S.C. 102(a)(1)/102(a)(2) as being anticipated by Jenson (US 2018/0218283 A1). Regarding claim(s) 1: Jenson discloses method comprising: generating, based upon combinations of fields from one or more datasets, a plurality of machine learning models comprising: a first machine learning model associated with a first field combination of the combinations; and a second machine learning model associated with a second field combination of the combinations (see paras. 34-37 where machine learning models (i.e., first and second machine learning models) are created and trained based on content data (i.e., one or more datasets) including features (i.e., first and second combinations of features/fields) associated with events to detect frauds/attacks, wherein features are associated with types/categories, and wherein a machine learning model is categorized as a type associated with the category of features used to create/train the machine learning model); deploying the plurality of machine learning models in a real-time data monitoring pipeline; and detecting, using the plurality of machine learning models, an anomalous event based upon network data, indicative of one or more network events of a network, passing through the real-time data monitoring pipeline (see para. 39 where a trained machine learning model is applied to content associated with a social networking system in order to determine fraud; see para. 36 where machine learning models identify new frauds, a volume attack associated with a known fraud being occurring; see paras. 64, 66 where user/entities communicate with each other through communication channels (i.e., real-time data monitoring pipeline) for content data; see para. 34 where content data is associated with events). Regarding claim(s) 14, and 20: See the rejection to claim 1. Regarding claim(s) 2: Jenson discloses: wherein the anomalous event is associated with at least one of fraudulent activity, malware, a cyber-attack, misconduct or operational misbehavior performed by one or more entities, the method comprising in response to detecting the anomalous event, at least one of: blocking the one or more entities from accessing one or more resources; reporting the one or more entities to law enforcement; deactivating one or more infected computers; or removing malware installed on the one or more infected computers (see paras. 44-45 where an action is taken when a content associated with a social networking system is determined to be fraudulent, wherein an action includes providing the content item for manual review, removing the content item from further publication on the social networking system, block the content item, etc.). Regarding claim(s) 3: Jenson discloses: wherein the anomalous event is associated with theft from a financial account, the method comprising in response to detecting the anomalous event, at least one of: blocking an illegitimate transfer from being performed; blocking a malicious entity associated with the anomalous event from accessing a financial account platform; blacklisting the financial account; deactivating the financial account; or reporting the financial account to law enforcement (see para. 28 where fraud related to illegitimate activity committed in an online environment is detected; see paras. 35, 41 where content data include features related to finance and user account; see paras. 44-45 where an action is taken when a content is determined to be fraudulent, wherein an action includes providing the content item for manual review, deactivating/suspending an account, etc.). Regarding claim(s) 7 and 17: Jenson discloses: determining a first significance score associated with a first field based upon at least one of: a quantity of first data units, associated with the first field, in the one or more datasets; a measure of data, of the one or more datasets, associated with the first field; a mean of data units, associated with the first field, in the one or more datasets; a median of data units, associated with the first field, in the one or more datasets; a standard deviation of data units, associated with the first field, in the one or more datasets; a variance coefficient of data units, associated with the first field, in the one or more datasets; a standard error of data units, associated with the first field, in the one or more datasets; or a margin of error of data units, associated with the first field, in the one or more datasets (see paras. 34-37 where features (i.e., first and second combinations of features/fields) associated with events are used to detect frauds/attacks, wherein a high score is generated when a volume attack (i.e., a volume/quantity of attack (i.e., first data units) with a known fraud being occurring). Regarding claim(s) 8 and 18: Jenson discloses: determining a plurality of event types, associated with fields used to generate the combinations, comprising: a first event type of first events associated with a first subset of fields of the fields; and a second event type of second events associated with a second subset of fields of the fields, wherein: the first field combination is associated with the first event type; the second field combination is associated with the second event type; and generating the combinations comprises: determining the first field combination based upon the first subset of fields; and determining the second field combination, that is associated with the second event type, based upon the second subset of fields (see para. 26 where various types of content are created; see paras. 34-37 where machine learning models (i.e., first and second machine learning models) are created and trained based on content data (i.e., one or more datasets) including features (i.e., first and second combinations of features/fields) associated with events to detect frauds/attacks, wherein features are associated with types/categories, and wherein a machine learning model is categorized as a type associated with the category of features used to create/train the machine learning model; see para. 36 where types/categories of features are determined for training a machine learning model, wherein training data includes a particular category of features). Regarding claim(s) 9 and 19: Jenson discloses: wherein generating the plurality of machine learning models comprises: training the first machine learning model of the plurality of machine learning models using data units of fields of the first field combination; and training the second machine learning model of the plurality of machine learning models using data units of fields of the second field combination (see paras. 34-37 where machine learning models (i.e., first and second machine learning models) are created and trained based on content data (i.e., one or more datasets) including features (i.e., first and second combinations of features/fields) associated with events to detect frauds/attacks, wherein features are associated with types/categories, and wherein a machine learning model is categorized as a type associated with the category of features used to create/train the machine learning model). Regarding claim(s) 10: Jenson discloses: wherein: the first field combination comprises a first field and a second field; and the second field combination comprises the first field and a third field (see para. 35 where features relate to aggregation, wherein aggregation features indicate any features that are based on aggregated data/information, e.g., a number of people (i.e., first field) disabled on an IP address (i.e., second field), a number of people (i.e., first field) associated with a blacklisted credit card (i.e., third field)). Regarding claim(s) 11: Jenson discloses: wherein generating the plurality of machine learning models comprises: generating a second plurality of machine learning models based upon the combinations; testing the second plurality of machine learning models to determine testing results (see paras. 34-37 where machine learning models (i.e., first and second machine learning models) are created and trained based on content data (i.e., one or more datasets) including features (i.e., first and second combinations of features/fields) associated with events to detect frauds/attacks, wherein features are associated with types/categories, and wherein a machine learning model is categorized as a type associated with the category of features used to create/train the machine learning model); and selecting the plurality of machine learning models from the second plurality of machine learning models based upon the testing results (see paras. 38-39 where a machine learning model is refined/retrained in order to achieve desired results, wherein a trained machine learning model is applied to content to determine fraud; see para. 42 where a weight for each machine learning model is determined based on how accurate each model's scores for content items compared to actual fraudulent or not fraudulent labels for content items). Regarding claim(s) 12: Jenson discloses: wherein the testing results comprise at least one of: a confidence score of the first machine learning model; a variance score of the first machine learning model; a margin of error of the first machine learning model; or a coefficient of determination of the first machine learning model (see paras. 38-39 where a machine learning model is refined/retrained in order to achieve desired results, wherein a trained machine learning model is applied to content to determine fraud; see para. 42 where a weight for each machine learning model is determined based on how accurate each model's scores for content items compared to actual fraudulent or not fraudulent labels for content items). Regarding claim(s) 13: Jenson discloses: wherein: generating the plurality of machine learning models comprises: testing the plurality of machine learning models to determine testing results; and assigning prioritization scores to the plurality of machine learning models based upon the testing results (see paras. 34-37 where machine learning models (i.e., first and second machine learning models) are created and trained based on content data (i.e., one or more datasets) including features (i.e., first and second combinations of features/fields) associated with events to detect frauds/attacks, wherein features are associated with types/categories; see para. 42 where a weight for each machine learning model is determined based on how accurate each model's scores for content items compared to actual fraudulent or not fraudulent labels for content items); and detecting the anomalous event comprises: determining machine learning model outputs, of the plurality of machine learning models, based upon the data passing through the real-time data monitoring pipeline; weighting the machine learning model outputs according to the prioritization scores to generate weighted machine learning model outputs; and identifying the anomalous event based upon the weighted machine learning model outputs (see para. 27 where a machine learning model provides predicted scores as outputs, wherein a weight is determined for a machine learning model based on the predicted scores; see para. 36 where machine learning models identify new frauds, a volume attack associated with a known fraud being occurring; see paras. 64, 66 where user/entities communicate with each other through communication channels (i.e., real-time data monitoring pipeline) for content data; see paras. 38-39 where a machine learning model is refined/retrained in order to achieve desired results, wherein a trained machine learning model is applied to content to determine fraud; see para. 42 where a weight for each machine learning model is determined based on how accurate each model's scores for content items compared to actual fraudulent or not fraudulent labels for content items). Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 5. Claim(s) 4-6, and 15-16 is/are rejected under 35 U.S.C. 103 as being unpatentable over Jenson in view of Johnson et al. (US 2023/0117120 A1, hereafter Johnson). Regarding claim(s) 4: Jenson does not, but Johnson discloses: wherein the anomalous event is associated with at least one of a network outage or a malfunction of an entity in the network, the method comprising in response to detecting the anomalous event, at least one of: identifying a malfunctioning component in the network; deploying one or more resources to the malfunctioning component; reconfiguring the malfunctioning component; repairing the malfunctioning component; or replacing the malfunctioning component (see Johnson, abstract, where anomalous events are detected, wherein risk entities associated with an anomalous event are provided in a graphical representation; see para. 32 where a risk entity includes a location, an actor, a model associated with the event, or an object that the actor accessed; see para. 54 where the relationship between the risk entities is determined from an event log entry associated with the event (i.e., an entity as a component associated with other entities in a network is identified). It would have been obvious to one having ordinary skill in the art to which the claimed invention pertains, before the effective filing date of the claimed invention, to modify Jenson's invention by enhancing it for the anomalous event is associated with at least one of a network outage or a malfunction of an entity in the network, the method comprising in response to detecting the anomalous event, at least one of: identifying a malfunctioning component in the network; deploying one or more resources to the malfunctioning component; reconfiguring the malfunctioning component; repairing the malfunctioning component; or replacing the malfunctioning component, as taught by Johnson, in order to enable a user associated with a client device (i.e., threat detection device) to review risk entities and provide feedback regarding an anomalous event (Johnson, para. 103). Regarding claim(s) 5 and 15: Jenson does not, but Johnson discloses: in response to detecting the anomalous event, transmitting an indication of the anomalous event to a threat detection device (see Johnson, paras. 16, 103 and/or 122). It would have been obvious to one having ordinary skill in the art to which the claimed invention pertains, before the effective filing date of the claimed invention, to modify Jenson's invention by enhancing it to, in response to detecting the anomalous event, transmitting an indication of the anomalous event to a threat detection device, as taught by Johnson, in order to enable a user associated with a client device (i.e., threat detection device) to review risk entities and provide feedback regarding an anomalous event (Johnson, para. 103). Regarding claim(s) 6 and 16: Jenson does not, but Johnson discloses: in response to detecting the anomalous event, displaying an indication of the anomalous event via a threat detection interface on a threat detection device (see Johnson, abstract and para. 16). It would have been obvious to one having ordinary skill in the art to which the claimed invention pertains, before the effective filing date of the claimed invention, to modify Jenson's invention by enhancing it to, in response to detecting the anomalous event, displaying an indication of the anomalous event via a threat detection interface on a threat detection device, as taught by Johnson, in order to enable a user associated with a client device (i.e., threat detection device) to review risk entities and provide feedback regarding an anomalous event (Johnson, para. 103). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure: Chivu et al. (US 12238119 B1), Determining threats from anomalous events based on artificial intelligence models. Song et al. (US 2024/0220610 A1), SECURITY DATA PROCESSING DEVICE, SECURITY DATA PROCESSING METHOD, AND COMPUTER-READABLE STORAGE MEDIUM FOR STORING PROGRAM FOR PROCESSING SECURITY DATA. Shen et al. (US 2022/0103589 A1), PREDICTING DATA TAMPERING USING AUGMENTED MACHINE LEARNING MODELS. Any inquiry concerning this communication or earlier communications from the examiner should be directed to HUAN V. DOAN whose telephone number is 571-272-3809. The examiner can normally be reached on Monday – Thursday, 9:00am – 5:00pm EST. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, PHILIP CHEA, can be reached on 571-272-3951. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /HUAN V DOAN/Primary Examiner, Art Unit 2499
Read full office action

Prosecution Timeline

Feb 04, 2025
Application Filed
Jul 29, 2026
Non-Final Rejection mailed — §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12706739
METHOD, APPARATUS, DEVICE AND MEDIUM FOR PROCESSING GENETIC DATA
1y 12m to grant Granted Aug 11, 2026
Patent 12706910
MIGRATION OF USER AUTHENTICATION FROM ON-PREMISE TO THE CLOUD
1y 9m to grant Granted Aug 11, 2026
Patent 12683959
BIOMETRIC AUTHENTICATION DURING VOICE DATA TRANSFERS
3y 1m to grant Granted Jul 14, 2026
Patent 12670256
IDENTIFY MALICIOUS SOFTWARE
1y 8m to grant Granted Jun 30, 2026
Patent 12665882
GATEWAY AND METHOD FOR OPERATING A GATEWAY
2y 11m to grant Granted Jun 23, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
80%
Grant Probability
99%
With Interview (+42.1%)
2y 12m (~1y 5m remaining)
Median Time to Grant
Low
PTA Risk
Based on 285 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month