Prosecution Insights
Last updated: August 16, 2026
Application No. 19/185,882

OVERLY OPTIMISTIC DATA PATTERNS AND LEARNED ADVERSARIAL LATENT FEATURES

Non-Final OA §101§103§112
Filed
Apr 22, 2025
Priority
Nov 23, 2020 — continuation of 11/818,147 +1 more
Examiner
AHMED, MAHABUB S
Art Unit
Tech Center
Assignee
Fair Isaac Corporation
OA Round
1 (Non-Final)
86%
Grant Probability
Favorable
1-2
OA Rounds
1y 0m
Est. Remaining
94%
With Interview

Examiner Intelligence

Grants 86% — above average
86%
Career Allowance Rate
253 granted / 296 resolved
+25.5% vs TC avg
Moderate +8% lift
Without
With
+8.2%
Interview Lift
resolved cases with interview
Typical timeline
2y 4m
Avg Prosecution
16 currently pending
Career history
315
Total Applications
across all art units

Statute-Specific Performance

§101
14.9%
-25.1% vs TC avg
§103
48.7%
+8.7% vs TC avg
§102
6.5%
-33.5% vs TC avg
§112
17.7%
-22.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 296 resolved cases

Office Action

§101 §103 §112
DETAILED ACTION The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This office action is in response to communication filed on 04/22/2025. Status of claims in the instant application: Claims 1-20 are pending. Priority This application is a CON of 18/379,019 filed on 10/11/2023 now PAT US 12323440 B2 which is a CON of 17/102,295 filed on 11/23/2020 now PAT 11,818,147. Information Disclosure Statement Information Disclosure Statements (IDS) filed on 06/26/2025 have been considered, and a signed copies of the IDS forms have been attached to this office action. Drawings Drawings filed on 04/22/2025 have been inspected, and it’s in compliance with MPEP 608.02. Specification Specification filed on 04/22/2025 has been inspected and it’s in compliance with MPEP 608.01. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 10-11 and 19 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor, or for pre-AIA the applicant regards as the invention. Claim 10 recites, “The system of claim 9, wherein as various transactions of the training dataset are scored through the MLSC model, the activation of one or more hidden nodes in the MLSC model is observed and aggregated …” However, “the MLSC” is missing antecedent basis, as there is no earlier recitation of “a MLSC” that “the MLSC” refers to. Furthermore, the abbreviated term “MLSC” needs to be used in its full form (like in claim 8) along with the abbreviated term, before using the abbreviated term only. Therefore claim 10 is indefinite for missing antecedent, and hence rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor, or for pre-AIA the applicant regards as the invention. The dependent claim 11 is also similarly rejected as it inherits the issue in the base claim 10. Claim 19 also recites “the MLSC” that is also missing antecedent basis, and hence rejected as claim 10. Appropriate corrections required. *** Note: (1) First use of “MLSC” needs to be in the full form, along with the abbreviation before any subsequent use inn abbreviated form. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-16 and 20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to non-statutory subject matter. The claims do not fall within at least one of the four categories of patent eligible subject matter because the claims are directed to “software per se”. Claims 1 and 20 is directed to computer implemented system, however there are no hardware elements in the body of the claims that perform the claimed functions. Although the claims recite “computer“, but it’s only in the preambles of the claims, and not being referred to by any limitations in the main body of the claims. Therefore, the system claims 1 and 17, having no positively claimed hardware element in the body of the claims, are just software that are not patent eligible subject matter. Therefore claims 1 and 17 are rejected under 35 U.S.C. 101 because the claimed invention is directed to non-statutory subject matter and the claims do not fall within at least one of the four categories of patent eligible subject matter. The dependent claims 2-16 are also rejected for the same reason as the independent claim 1, as they inherit the issue from the independent claim, and that they do not rectify the issue in the independent claim. Appropriate corrections required. *** Applicant is advised to positively claim hardware element(s) in the main body of the claim(s) that perform the claimed/recited functions. Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/process/file/efs/guidance/eTD-info-I.jsp. Claims 1-20 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-20 of U.S. Patent No. US 12323440 B2. Although the claims at issue are not identical, they are not patentably distinct from each other because the claims of the instant application are just broader version of claims of the issued patent US 12323440 B2 that make the claims of the instant application obvious. Instant Application Reference Patent (US 12323440 B2) 1. A computer-implemented artificial intelligence system comprising one or more microprocessors configured for: monitoring a plurality of transactions by a machine learning decision model, wherein a first score is generated by the machine learning decision model in association with a first transaction from among the plurality of transactions being transmitted over a network; identifying the first transaction as belonging to a first class, responsive to at least one of the first score being lower than a certain score threshold or the first transaction having a low occurrence likelihood; determining at least one adversarial latent transaction feature exploited by the first transaction, responsive to a second score determined for the first transaction by an adversary detection model based on one or more adversarial latent features associated with the first transaction; detecting a first volume of activations of the at least one adversarial latent feature spanning across the plurality of transactions; and blocking a set of transactions among the plurality of transactions that match the at least one adversarial latent feature. 2. The system of claim 1, further comprising aggregating a plurality of attributes and adversarial latent features of the adversary detection model using a plurality of moving average features across the plurality of transactions, wherein a moving average feature from among the moving average features goes through a quantile estimation process for outlier detection by a self-calibrating outlier detection model to generate a system level self-calibrating score as follows: Score=.Math.wi⁢q⁡(xi⁢.Math.t), wherein tis a threshold set and w.sub.i is a weight associated with a quantile estimation feature q of a moving average ratio x as indexed by an index value i, and wherein the network is determined as being under a concerted adversarial attack, in response to determining that the system level self-calibrating score falls in at least a predetermined range. 1. A computer-implemented artificial intelligence system comprising a machine learning decision model, wherein security of the artificial intelligence system is improved by operations performed by one or more microprocessors, the operations comprising: monitoring one or more transactions received by the machine learning decision model; receiving a first score generated by the machine learning decision model in association with a first transaction; identifying the first transaction as belonging to a first class, in response to the first score being lower than a certain score threshold and the first transaction having a low occurrence likelihood; receiving a second score in association with the first transaction based on one or more adversarial latent features associated with the first transaction as detectable by an adversary detection model; determining at least one adversarial latent transaction feature being exploited by the first transaction, in response to determining that the second score falls above the certain score threshold; detecting a first volume of activations of the at least one adversarial latent feature spanning across a plurality of transactions scored by the adversary detection model; blocking transactions, received by the machine learning decision model, that match the at least one adversarial latent feature; aggregating a plurality of attributes and adversarial latent features of the adversary detection model using a plurality of moving average features across various transactions, a moving average feature from among the moving average features going through a quantile estimation process, wherein the moving average feature goes through the quantile estimation process using an equation as follows: qi=q⁢(xi|t)=min⁢(max⁢(si-TpTR-TL,0),C)∈[0,C]; and generating one or more top reasons, in response to a system level score going above a threshold. 3. The system of claim 2, wherein the first transaction is determined to have a low occurrence likelihood based on comparing attributes of the first transaction with attributes of one or more other transactions, wherein the first score is based on one or more features extracted from the first transaction and related transaction history, and wherein various attributes and the adversarial latent features of the adversary detection model are aggregated using the moving averages across various transactions that score low by the decision model and high by the adversary detection model in the production system. 4. The system of claim 3, wherein the adversary detection model is implemented based on newly labeled adversarial transactions during the training phase to determine the latent features describing features relationships in an adversarial space, and the one or more extracted features for a second transaction in a training dataset are binned into ranges of values observed in the training dataset. 5. The system of claim 4, wherein a feature f is binned in ranges, f.sub.i, indexed by i, such that a probability distribution of scores is attached to a binned value of the feature, f.sub.i, and a calculated score distribution probability density function for the feature f is calculated based on a likelihood of observing a given score Sj for its observed value being in the feature bin i, given by score distribution probability density function: P⁡(j⁢.Math.i)=P⁡(score =Sj⁢.Math.f∈fi)=Cij.Math.jcij+ε(1) where C.sub.ij is a count of observations of the score bin j and feature bin i. 2. The system of claim 1, wherein the first score is based on one or more features extracted from the first transaction, by a feature extraction module, and related transaction history. 3. The system of claim 2, wherein the first transaction is determined to have a low occurrence likelihood based on comparing attributes of the first transaction with attributes of one or more other transactions. 4. The system of claim 3, wherein the adversary detection model is implemented based on newly labeled adversarial transactions during the training phase to determine the latent features describing features relationships in an adversarial space, and the one or more extracted features for a second transaction in a training dataset are binned into ranges of values observed in the training dataset. 5. The system of claim 4, wherein a feature f is binned in ranges, f.sub.i indexed by i, such that a probability distribution of scores is attached to a binned value of the feature, f.sub.i, and a calculated score distribution probability density function for the feature f is calculated based on a likelihood of observing a given score Sj for its observed value being in the feature bin i, given by score distribution probability density function: P⁢(j|i)=P⁢(score= Sj|f∈fi)=Cij.Math.j⁢Cij+ε(1) where C.sub.ijis a count of observations of the score bin j and feature bin i, and ϵ is a value added to the denominator to determine whether distribution probability should be zero. 6. The system of claim 5, wherein in response to determining that the second transaction is assigned an improbably low score S.sub.k by the decision model, considering a totality of features and transactions, a likelihood L for the first transaction T.sub.k is computed, T.sub.k having an observed score S.sub.k such that observed values of at least one of the features f E F belong to corresponding feature bins f.sub.x according to: L⁢(Tk)= minf∈F(P⁡(score=Sk⁢.Math.f∈fk)) 6. The system of claim 5, wherein in response to determining that the second transaction is assigned an improbably low score S.sub.k by the decision model, considering a totality of features and transactions, a likelihood [AltContent: rect] for the first transaction T.sub.k is computed, T.sub.k having an observed score S.sub.k such that observed values of at least one of the features f∈F belong to corresponding feature bins f.sub.k according to:[AltContent: rect](T.sub.k)=min.sub.f∈F(P(score=S.sub.k|f∈f.sub.k))  7. The system of claim 6, wherein based on equation (2) a transaction in a training dataset is assigned a tag which indicates whether the tagged transaction is associated with a likely adversarial attack path or not. 7. The system of claim 6, wherein based on equation (2) a transaction in a training dataset is assigned a tag which indicates whether the tagged transaction is associated with a likely adversarial attack path or not. 8. The system of claim 7, wherein in response to determining that an insufficient number of transactions are tagged, a multi-layered self-calibrated (MLSC) model is utilized, the MLSC having a set of features, at least one feature f being scaled using a z-scaling process to normalize inputs according to: f^=f-f_fσ(3) where, f is the mean value of feature f, across the entire dataset and f.sub.σ is the standard deviation of feature f. 8. The system of claim 7, wherein in response to determining that an insufficient number of transactions are tagged, a multi-layered self-calibrated (MLSC) model is utilized, the MLSC having a set of features, at least one feature f being scaled using a z-scaling process to normalize inputs according to: fˆ=f-f¯fσ(3) where, f is the mean value of feature f, across the entire dataset and f.sub.σ is the standard deviation of feature f. 9. The system of claim 7, wherein the features are grouped together into a factor group based on at least one of: similarity of information, principal component analysis, or expert knowledge. 9. The system of claim 7, wherein the features are grouped together into a factor group based on at least one of: similarity of information, principal component analysis, or expert knowledge. 10. The system of claim 9, wherein as various transactions of the training dataset are scored through the MLSC model, the activation of one or more hidden nodes in the MLSC model is observed and aggregated, such that the activation of a hidden node, h.sub.k, for a given transaction, T, is given by h.sub.k(T) and the strength of a hidden node is then given by equation by Strength=.Math.Thk(T)N(4) where, Nis the number of transactions. 10. The system of claim 9, wherein as various transactions of the training dataset are scored through the MLSC model, the activation of one or more hidden nodes in the MLSC model is observed and aggregated, such that the activation of a hidden node, h.sub.k, for a given transaction, T, is given by h.sub.k(T) and the strength of a hidden node is then given by equation by Strength=.Math.T⁢hk(T)N(4) where, N is the number of transactions. 11. The system of claim 10, wherein the strength is computed for a subset of features that are adversarial latent features and based on measuring value of the strength, hidden nodes with positive strength are identified and remaining hidden nodes are discarded. 11. The system of claim 10, wherein the strength is computed for a subset of features that are adversarial latent features and based on measuring value of the strength, hidden nodes with positive strength are identified and remaining hidden nodes are discarded. 12. The system of claim 8, wherein in response to determining that a sufficient number of transactions are tagged, a neural network model is utilized, the neural network having a set of features, at least one feature f being scaled using a z-scaling process as per equation (3) above, and wherein sparsity constraints are applied on the neural network to simplify the hidden nodes that represent the adversarial latent features. 12. The system of claim 8, wherein in response to determining that a sufficient number of transactions are tagged, a neural network model is utilized, the neural network having a set of features, at least one feature f being scaled using a z-scaling process as per equation (3) above, and wherein sparsity constraints are applied on the neural network to simplify the hidden nodes that represent the adversarial latent features. 14. The system of claim 13, wherein the one or more top reasons are generated, in response to the system level score going above a threshold, as follows: Top reasons= TopN(sort.sub.i(w.sub.iq.sub.i)), wherein percentage of contribution of the one or more top reasons is associated based on a percentage of contribution of qi=wi⁢qi.Math.iwi⁢qi*100. 14. The system of claim 13, wherein a self-calibrating outlier detection model is implemented using quantile estimation features to generate a system level self-calibrating score as follows: Score=Σw.sub.iq(x.sub.i|t)  (7) and wherein the one or more top reasons are generated, in response to the system level score going above a threshold, as follows: Top reasons=TopN(sort.sub.i(w.sub.iq.sub.i)).  15. The system of claim 14, wherein for adversarial system level scores above a threshold, an abnormal volume of an adversarial latent feature between short and medium or long time scales identifies an adversarial attack and the latent feature attack vector and wherein transactions corresponding to high adversarial scores and shared latent feature attack vector are blocked for additional decision rules and review. 15. The system of claim 14, wherein for adversarial system level scores above a threshold, an abnormal volume of an adversarial latent feature between short and medium or long time scales identifies an adversarial attack and the latent feature attack vector and wherein transactions corresponding to high adversarial scores and shared latent feature attack vector are blocked for additional decision rules and review. 16. The system of claim 15, wherein when a transaction scores low by the decision model and high by the adversary detection model, followed by a high system level score by a self-calibrating outlier detection model, if the transaction's attributes and adversarial latent features match a system level top attribute and adversarial latent features as given by equation (8.a), then the transaction is stopped. 16. The system of claim 15, wherein when a transaction scores low by the decision model and high by the adversary detection model, followed by a high system level score by a self-calibrating outlier detection model, if the transaction's attributes and adversarial latent features match a system level top attribute and adversarial latent features as given by equation (8.a), then the transaction is stopped. 17. A method for improving security of a computer-implemented artificial intelligence system, the method comprising: monitoring one or more transactions received by the machine learning decision model; receiving a first score generated by the machine learning decision model in association with a first transaction; identifying the first transaction as belonging to a first class, in response to the first score being lower than a certain score threshold and the first transaction having a low occurrence likelihood; receiving a second score in association with the first transaction based on one or more adversarial latent features associated with the first transaction as detectable by an adversary detection model; determining at least one adversarial latent transaction feature being exploited by the first transaction, in response to determining that the second score falls above the certain score threshold; detecting a first volume of activations of the at least one adversarial latent feature spanning across a plurality of transactions scored by the adversary detection model; blocking transactions, received by the machine learning decision model, that match the at least one adversarial latent feature; aggregating a plurality of attributes and adversarial latent features of the adversary detection model using a plurality of moving average features across various transactions, a moving average feature from among the moving average features going through a quantile estimation process; and generating one or more top reasons, in response to a system level score above a threshold. 17. A method for improving security of a computer- implemented artificial intelligence system, the method comprising: monitoring one or more transactions received by the machine learning decision model; receiving a first score generated by the machine learning decision model in association with a first transaction; identifying the first transaction as belonging to a first class, in response to the first score being lower than a certain score threshold and the first transaction having a low occurrence likelihood; receiving a second score in association with the first transaction based on one or more adversarial latent features associated with the first transaction as detectable by an adversary detection model; determining at least one adversarial latent transaction feature being exploited by the first transaction, in response to determining that the second score falls above the certain score threshold; detecting a first volume of activations of the at least one adversarial latent feature spanning across a plurality of transactions scored by the adversary detection model; blocking transactions, received by the machine learning decision model, that match the at least one adversarial latent feature; aggregating a plurality of attributes and adversarial latent features of the adversary detection model using a plurality of moving average features across various transactions, a moving average feature from among the moving average features going through a quantile estimation process, wherein the moving average feature goes through the quantile estimation process using an equation as follows: qi=q⁢(xi|t)=min⁢(max⁢(si-TpTR-TL,0),C)∈[0,C]; generating one or more top reasons, in response to a system level score going above a threshold. 18. A computer program product comprising a non-transitory machine-readable medium storing instructions that, when executed by at least one programmable processor, cause the at least one programmable processor to perform operations comprising: generating a corpus of transactions comprising first transactions identified as likely adversarial and second transactions not identified as likely adversarial, the generating comprising, for each transaction of a plurality of transactions: calculating a first score, the calculating comprising applying a first scoring model with inputs comprising a transaction feature extracted from the transaction and a transaction history for the transaction; identifying as the first likely adversarial transactions those transactions having improbably low first scores within a first range and having a low occurrence likelihood based on comparing the first score and attributes of the transaction with those of one or more other transactions in the plurality of transactions; identifying the second transactions as those remaining transactions of the plurality of transactions that are not identified as the first transactions; and training an adversary detection model based on attributes of the transactions in the corpus. 18. A computer program product comprising a non-transitory machine-readable medium storing instructions that, when executed by at least one programmable microprocessor, cause the at least one programmable microprocessor to perform operations comprising: generating a corpus of transactions comprising first transactions identified as likely adversarial and second transactions not identified as likely adversarial, the generating comprising, for at least one transaction of a plurality of transactions: calculating a first score, the calculating comprising applying a first scoring model with inputs comprising a transaction feature extracted from the transaction and a transaction history for the transaction; identifying as the first likely adversarial transactions those transactions having improbably low first scores within a first range and having a low occurrence likelihood based on comparing the first score and attributes of the transaction with those of one or more other transactions in the plurality of transactions; identifying the second transactions as those remaining transactions of the plurality of transactions that are not identified as the first transactions; and training an adversary detection model based on attributes of the transactions in the corpus, wherein a plurality of attributes and adversarial latent features of the adversary detection model are aggregated using a plurality of moving average features across various transactions, a moving average feature from among the moving average features going through a quantile estimation process, wherein the moving average feature goes through the quantile estimation process using an equation as follows: qi=q⁡(xi|t)=min⁡(max⁡(si-TPTR-TL,0),C)∈[0,C]. Claims 1-20 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-20 of U.S. Patent No. US 11818147 B2. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1 is rejected under 35 U.S.C. 103 as being unpatentable over Pub. No.: US 20210194896 A1 to Seymour et al. (hereinafter “Seymour”) in view of Pub. No.: US 20220012741 A1 to Raj et al. (hereinafter “Raj”). Regarding Claim 1. Seymour discloses A computer-implemented artificial intelligence system comprising one or more microprocessors (Seymour, Abstract, Para [0037, 0042, 0017]: … Techniques are disclosed relating to reporting for network events within a computer network. A computer system may access a set of data corresponding to a particular network event within a computer network, where the set of data includes captured attributes of the particular network event. … Security system 250, in the illustrated example, includes pre-processing module 240 for providing pre-processed signals 242 to security module 120. For example, pre-processing module 240 may be a machine learning module that determines whether a domain name associated with a particular network event 102 was generated using a domain name generation algorithm (DGA). … Modules may be implemented in multiple ways, including as a hardwired circuit or as a memory having program instructions stored therein that are executable by one or more processors to perform the operations …) configured for: monitoring a plurality of transactions by a machine learning decision model, wherein a first score is generated by the machine learning decision model in association with a first transaction from among the plurality of transactions being transmitted over a network (Seymour, Para [0024, 0034-0038], FIG. 7: … Monitoring module 214 of one of host systems 210 monitors activity of the host system and reports information associated with one or more connections 202 attempted by the host system e.g., with domains 216. For example, monitoring module 214 may be a firewall or some sort of network security system that provides a barrier between computer network 200 and systems external to the computer network … Security system 250, in the illustrated example, includes pre-processing module 240 for providing pre-processed signals 242 to security module 120. For example, pre-processing module 240 may be a machine learning module … In this example, pre-processing module 240 sends the determination (signals 242) whether the domains associated with network events 102 were generated using a DGA to the security module 120. In some embodiments, pre-processed signals 242 are used in calculating security and actionability scores …); identifying the first transaction as belonging to a first class, responsive to at least one of the first score being lower than a certain score threshold or the first transaction having a low occurrence likelihood (Seymour, Para [0029, 0037, 0069], FIG. 7: … actionability may be measured vis-à-vis some determined set of data fields for a network event. An actionability score may be used to establish actionability along a spectrum (e.g., from 0 to 1, 0 to 10, 0 to 100, etc.). Thus, in one example, if a network event indication includes a threshold number of some determined set of data fields, that event may be deemed to be actionable (e.g., 0.8 of 1 for its actionability score). In this instance, the actionability score may have a low impact on the suspiciousness score. On the other hand, if a network event indication includes less than a threshold number of the determined set of data fields, that event may be deemed to be inactionable (e.g., 0.2 of 1 for its actionability), meaning that the event in many cases will not be reported for corrective action regardless of the suspiciousness score for the event … pre-processing module 240 sends the determination (signals 242) whether the domains associated with network events 102 were generated using a DGA to the security module 120. In some embodiments, pre-processed signals 242 are used in calculating security and actionability scores. For example, a network event that is associated with a domain generated by a DGA may be more suspiciousness than network events associated with non-DGA domains … if a domain was not generated using a DGA, then the network event associated with that domain may have a lower likelihood of suspiciousness … if the actionability score of a particular network event is small, it may lower the chances of the event being alerted on by penalizing the overall suspiciousness of the network event …); determining at least one [adversarial latent] transaction feature exploited by the first transaction, responsive to a second score determined for the first transaction by an adversary detection model based on one or more [adversarial latent] features associated with the first transaction (Seymour, Para [0063-0064], FIG. 6-7: … the combined score is determined by multiplying the actionability score (0.25) by the security score 602A for the network event (determined by the security module 120 to be 95). The combined score for the network event in the illustrated embodiment is 23.75, which is then compared to a security threshold to determine whether to report the network event for further review … the actionability score may be determined for a different network event such as network event 102A where only one particular attribute from a set of attributes for the network event is missing. In scoring example 620, with a penalization parameter of 0.5, actionability module 130 determines that the actionability score is 0.5. Further, the combined score for this network event, based on a security score 602B of 100, would be 50. In this example, the combined score for the network event satisfies the security threshold of 50 and, therefore, security system 250 sends a notification to perform further review for the network event (i.e., a security alert is triggered 604B) …); However, Seymour does not explicitly teach, but Raj from same or similar field of endeavor teaches, “one or more adversarial latent features (Raj, Para [0046-0048]: … in FIG. 5, diagram 500 includes: embedding block 502 (this block generates an embedding of each categorical feature in the transaction, such as but not limited to merchant name, zip code, etc., as a vector representation, typically in low-dimension, to efficiently capture and encode the feature relationships in the transaction data); continuous features block 504 (this block generates a scaled and/or normalized feature for the continuous values, such as but not limited to the amount and time of transaction); encoder neural network 506 (this block generates a distilled representation in latent space capturing the complex interactions of the categorical and continuous features in the original transaction data=the encoder neural network block 506 is not limited to feed-forward networks and could be sequential); auxiliary network 508 (this block takes the intermediate encoded representation to perform an auxiliary task, which in one embodiment is to reconstruct (generate) some input feature, such as but not limited to the user id or age, in the transaction using the same latent features as the classifier); classification network block 510 (this block takes in the encoder's representation to classify (predict) the transaction as fraudulent (or not fraudulent)); and gradient boosting framework 512. Gradient boosting framework 512 is combined with the classification network 510 to obtain the prediction(s) as fraudulent (or non-fraudulent) transactions. Auxiliary network 508 is used only during the training phase and not during the inference phase …)” Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Raj into the teachings of Seymour, because it discloses that “Embedding block 502 and continuous features block 504 represent two (2) types of input data received pursuant to a credit card transaction. Encoder neural network block 506 converts the inputs to an internal representation more amenable to analysis performed at blocks downstream of block 506. Auxiliary network 508 performs auxiliary tasks like predicting the identity of the card holder based on other information in the transaction. This is a capability which can be used to further improve fraud detection. Classification network block 510 classifies fraud/non-fraud. In various embodiments of the present invention, classification network block 510 take many forms such as, neural network-based approach, a gradient boosted approach, logistic regression, any other classification algorithm and/or various combinations of the foregoing enumerate types (Raj, Para [0047])”. Raj further discloses: “detecting a first volume of activations of the at least one adversarial latent feature spanning across the plurality of transactions (Raj, Para [0035-0037]: … As shown in FIG. 3, multi-task learning algorithm 308 includes: underlying learning structure 302; and multi-task instructions 304. Underlying learning structure 302 is, in this example embodiment, a deep learning style learning structure that performs deep learning (see the definition of “deep learning,” above, in the Background section). Alternatively, other types of machine learning structures (now known or to be developed in the future) may be used as the underlying learning structure. The multi-task instructions cause the underlying learning structure to be accessed (for example, trained, re-trained and/or used to do fraud detection procedures on new financial transactions) in a multi-task manner … Processing proceeds to operation S265, where receive input data mod 310 receives data relating to a new financial transaction involving a bank (represented by client sub-system 106), a customer (represented by client sub-system 108) and a credit card company (represented by client sub-system 110). Program 300 will determine whether the current financial transaction raises concerns about potential fraud by the customer … Processing proceeds to operation S275, where fraud determination mod 312 applies underlying learning structure 302, running on encoder neural network software 314, to the input data characterizing the current financial transaction to determine whether fraud is likely. In this example, fraud likelihood quotient is determined to be 9.9 out of 10.0 … Processing proceeds to operation S280, where fraud determination module determines that fraud is sufficiently likely such that further investigation should take place. More specifically, in this example, if the fraud likelihood quotient, of 9.9, is greater than a threshold value of 9.0, meaning that corrective action should be taken. Processing proceeds to operation S285 where take corrective action mod 316 takes corrective action in response to the likely fraud (as shown by the fraud alert text message screen shot 400 of FIG. 4). In this example, the types of possible corrective actions are as follows: (i) decline the transaction so the purchase is not completed; (ii) annotate this account as having suspicious activity so as to increase the likelihood that a future transaction is labeled as fraud; (iii) invalidate this card number so it cannot be used in future transactions; (iv) increment the number of suspicious purchases at this merchant so that future purchases at the merchant will be more likely to be labelled fraud; and (v) use this example to improve training and accuracy of fraud detection models. In some embodiments, a text message is corrective action in the form of two-factor authentication, where a separate, non-compromised form of communication is used to check the integrity of another (the card transaction) …); and blocking a set of transactions among the plurality of transactions that match the at least one adversarial latent feature (Raj, Para [0035-0037], FIG. 4: … processing proceeds to operation S285 where take corrective action mod 316 takes corrective action in response to the likely fraud (as shown by the fraud alert text message screen shot 400 of FIG. 4). In this example, the types of possible corrective actions are as follows: (i) decline the transaction so the purchase is not completed; (ii) annotate this account as having suspicious activity so as to increase the likelihood that a future transaction is labeled as fraud; (iii) invalidate this card number so it cannot be used in future transactions; (iv) increment the number of suspicious purchases at this merchant so that future purchases at the merchant will be more likely to be labelled fraud; and (v) use this example to improve training and accuracy of fraud detection models. In some embodiments, a text message is corrective action in the form of two-factor authentication, where a separate, non-compromised form of communication is used to check the integrity of another (the card transaction) …)”. Claim 17 is rejected under 35 U.S.C. 103 as being unpatentable over Pub. No.: US 20210194896 A1 to Seymour et al. (hereinafter “Seymour”) in view of Pub. No.: US 20220012741 A1 to Raj et al. (hereinafter “Raj”), and further in view of Pub. No.: US 20170206466 A1 to Zoldi et al. (hereinafter “Zoldi”). Regarding Claim 17. A method for improving security of a computer-implemented artificial intelligence system (Seymour, Abstract, Para [0037, 0042, 0017]: … Techniques are disclosed relating to reporting for network events within a computer network. A computer system may access a set of data corresponding to a particular network event within a computer network, where the set of data includes captured attributes of the particular network event. … Security system 250, in the illustrated example, includes pre-processing module 240 for providing pre-processed signals 242 to security module 120. For example, pre-processing module 240 may be a machine learning module that determines whether a domain name associated with a particular network event 102 was generated using a domain name generation algorithm (DGA). … Modules may be implemented in multiple ways, including as a hardwired circuit or as a memory having program instructions stored therein that are executable by one or more processors to perform the operations …), the method comprising: monitoring one or more transactions received by the machine learning decision model (Seymour, Para [0024, 0034-0038], FIG. 7: … Monitoring module 214 of one of host systems 210 monitors activity of the host system and reports information associated with one or more connections 202 attempted by the host system e.g., with domains 216. For example, monitoring module 214 may be a firewall or some sort of network security system that provides a barrier between computer network 200 and systems external to the computer network … Security system 250, in the illustrated example, includes pre-processing module 240 for providing pre-processed signals 242 to security module 120. For example, pre-processing module 240 may be a machine learning module … In this example, pre-processing module 240 sends the determination (signals 242) whether the domains associated with network events 102 were generated using a DGA to the security module 120. In some embodiments, pre-processed signals 242 are used in calculating security and actionability scores …); receiving a first score generated by the machine learning decision model in association with a first transaction (Seymour, Para [0024, 0037-0038], FIG. 7: … FIG. 1 is a block diagram illustrating an example computer system that generates a notification for a network event based on a security score 122 and an actionability score 132 … pre-processing module 240 may be a machine learning module that determines whether a domain name associated with a particular network event 102 was generated using a domain name generation algorithm (DGA). In this example, pre-processing module 240 sends the determination (signals 242) whether the domains associated with network events 102 were generated using a DGA to the security module 120. In some embodiments, pre-processed signals 242 are used in calculating security and actionability scores …); identifying the first transaction as belonging to a first class, in response to the first score being lower than a certain score threshold and the first transaction having a low occurrence likelihood (Seymour, Para [0029, 0037, 0069], FIG. 7: … actionability may be measured vis-à-vis some determined set of data fields for a network event. An actionability score may be used to establish actionability along a spectrum (e.g., from 0 to 1, 0 to 10, 0 to 100, etc.). Thus, in one example, if a network event indication includes a threshold number of some determined set of data fields, that event may be deemed to be actionable (e.g., 0.8 of 1 for its actionability score). In this instance, the actionability score may have a low impact on the suspiciousness score. On the other hand, if a network event indication includes less than a threshold number of the determined set of data fields, that event may be deemed to be inactionable (e.g., 0.2 of 1 for its actionability), meaning that the event in many cases will not be reported for corrective action regardless of the suspiciousness score for the event … pre-processing module 240 sends the determination (signals 242) whether the domains associated with network events 102 were generated using a DGA to the security module 120. In some embodiments, pre-processed signals 242 are used in calculating security and actionability scores. For example, a network event that is associated with a domain generated by a DGA may be more suspiciousness than network events associated with non-DGA domains … if a domain was not generated using a DGA, then the network event associated with that domain may have a lower likelihood of suspiciousness … if the actionability score of a particular network event is small, it may lower the chances of the event being alerted on by penalizing the overall suspiciousness of the network event …); receiving a second score in association with the first transaction based on one or more adversarial [latent] features associated with the first transaction as detectable by an adversary detection model (Seymour, Abstract, FIG. 1, 6-7 : … Techniques are disclosed relating to reporting for network events within a computer network. A computer system may access a set of data corresponding to a particular network event within a computer network, where the set of data includes captured attributes of the particular network event. The computer system may then calculate, using the set of data, a security score indicative of suspiciousness of the event and an actionability score that is based on an extent to which of a particular group of attributes are missing from the set of data. The computer system may determine, based on the two scores, a combined score for the event. The computer system may then report a notification for the event, based on the combined score. Such techniques may decrease a number of reported events for a network, which may advantageously allow resources to be focused on a smaller set of events …); However, Seymour does not explicitly teach, but Raj from same or similar field of endeavor teaches, “one or more adversarial latent features (Raj, Para [0046-0048]: … in FIG. 5, diagram 500 includes: embedding block 502 (this block generates an embedding of each categorical feature in the transaction, such as but not limited to merchant name, zip code, etc., as a vector representation, typically in low-dimension, to efficiently capture and encode the feature relationships in the transaction data); continuous features block 504 (this block generates a scaled and/or normalized feature for the continuous values, such as but not limited to the amount and time of transaction); encoder neural network 506 (this block generates a distilled representation in latent space capturing the complex interactions of the categorical and continuous features in the original transaction data=the encoder neural network block 506 is not limited to feed-forward networks and could be sequential); auxiliary network 508 (this block takes the intermediate encoded representation to perform an auxiliary task, which in one embodiment is to reconstruct (generate) some input feature, such as but not limited to the user id or age, in the transaction using the same latent features as the classifier); classification network block 510 (this block takes in the encoder's representation to classify (predict) the transaction as fraudulent (or not fraudulent)); and gradient boosting framework 512. Gradient boosting framework 512 is combined with the classification network 510 to obtain the prediction(s) as fraudulent (or non-fraudulent) transactions. Auxiliary network 508 is used only during the training phase and not during the inference phase …)” Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Raj into the teachings of Seymour, because it discloses that “Embedding block 502 and continuous features block 504 represent two (2) types of input data received pursuant to a credit card transaction. Encoder neural network block 506 converts the inputs to an internal representation more amenable to analysis performed at blocks downstream of block 506. Auxiliary network 508 performs auxiliary tasks like predicting the identity of the card holder based on other information in the transaction. This is a capability which can be used to further improve fraud detection. Classification network block 510 classifies fraud/non-fraud. In various embodiments of the present invention, classification network block 510 take many forms such as, neural network-based approach, a gradient boosted approach, logistic regression, any other classification algorithm and/or various combinations of the foregoing enumerate types (Raj, Para [0047])”. Seymour further discloses: determining at least one adversarial latent transaction feature being exploited by the first transaction, in response to determining that the second score falls above the certain score threshold (Seymour, Para [0063-0064], FIG. 6-7: … the combined score is determined by multiplying the actionability score (0.25) by the security score 602A for the network event (determined by the security module 120 to be 95). The combined score for the network event in the illustrated embodiment is 23.75, which is then compared to a security threshold to determine whether to report the network event for further review … the actionability score may be determined for a different network event such as network event 102A where only one particular attribute from a set of attributes for the network event is missing. In scoring example 620, with a penalization parameter of 0.5, actionability module 130 determines that the actionability score is 0.5. Further, the combined score for this network event, based on a security score 602B of 100, would be 50. In this example, the combined score for the network event satisfies the security threshold of 50 and, therefore, security system 250 sends a notification to perform further review for the network event (i.e., a security alert is triggered 604B) …), (Examiner’s Note: Raj already discloses adversarial latent feature, as combined with Seymour previously); Raj further discloses: “detecting a first volume of activations of the at least one adversarial latent feature spanning across a plurality of transactions scored by the adversary detection model (Raj, Para [0035-0037]: … As shown in FIG. 3, multi-task learning algorithm 308 includes: underlying learning structure 302; and multi-task instructions 304. Underlying learning structure 302 is, in this example embodiment, a deep learning style learning structure that performs deep learning (see the definition of “deep learning,” above, in the Background section). Alternatively, other types of machine learning structures (now known or to be developed in the future) may be used as the underlying learning structure. The multi-task instructions cause the underlying learning structure to be accessed (for example, trained, re-trained and/or used to do fraud detection procedures on new financial transactions) in a multi-task manner … Processing proceeds to operation S265, where receive input data mod 310 receives data relating to a new financial transaction involving a bank (represented by client sub-system 106), a customer (represented by client sub-system 108) and a credit card company (represented by client sub-system 110). Program 300 will determine whether the current financial transaction raises concerns about potential fraud by the customer … Processing proceeds to operation S275, where fraud determination mod 312 applies underlying learning structure 302, running on encoder neural network software 314, to the input data characterizing the current financial transaction to determine whether fraud is likely. In this example, fraud likelihood quotient is determined to be 9.9 out of 10.0 … Processing proceeds to operation S280, where fraud determination module determines that fraud is sufficiently likely such that further investigation should take place. More specifically, in this example, if the fraud likelihood quotient, of 9.9, is greater than a threshold value of 9.0, meaning that corrective action should be taken. Processing proceeds to operation S285 where take corrective action mod 316 takes corrective action in response to the likely fraud (as shown by the fraud alert text message screen shot 400 of FIG. 4). In this example, the types of possible corrective actions are as follows: (i) decline the transaction so the purchase is not completed; (ii) annotate this account as having suspicious activity so as to increase the likelihood that a future transaction is labeled as fraud; (iii) invalidate this card number so it cannot be used in future transactions; (iv) increment the number of suspicious purchases at this merchant so that future purchases at the merchant will be more likely to be labelled fraud; and (v) use this example to improve training and accuracy of fraud detection models. In some embodiments, a text message is corrective action in the form of two-factor authentication, where a separate, non-compromised form of communication is used to check the integrity of another (the card transaction) …); blocking transactions, received by the machine learning decision model, that match the at least one adversarial latent feature (Raj, Para [0035-0037], FIG. 4: … processing proceeds to operation S285 where take corrective action mod 316 takes corrective action in response to the likely fraud (as shown by the fraud alert text message screen shot 400 of FIG. 4). In this example, the types of possible corrective actions are as follows: (i) decline the transaction so the purchase is not completed; (ii) annotate this account as having suspicious activity so as to increase the likelihood that a future transaction is labeled as fraud; (iii) invalidate this card number so it cannot be used in future transactions; (iv) increment the number of suspicious purchases at this merchant so that future purchases at the merchant will be more likely to be labelled fraud; and (v) use this example to improve training and accuracy of fraud detection models. In some embodiments, a text message is corrective action in the form of two-factor authentication, where a separate, non-compromised form of communication is used to check the integrity of another (the card transaction) …)”; Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to further combine the teachings of Raj, because it discloses that “The multi-task learning instructions: (a) solve multiple learning tasks in a temporally overlapping manner while exploiting commonalities and differences across tasks resulting in improved learning efficiency and prediction accuracy for the task-specific models, when compared to training multiple models separately, and (b) improve generalization by using the domain information contained in the training signals of related tasks as an inductive bias by learning tasks in parallel while using a shared representation so that what is learned for each task can help other tasks be learned (Raj, Para [0005])”. However, the combination of Seymour-Raj does not explicitly teach, but Zoldi from same or similar field of endeavor teaches: “aggregating a plurality of attributes and adversarial latent features of the adversary detection model using a plurality of moving average features across various transactions, a moving average feature from among the moving average features going through a quantile estimation process (Zoldi, Abstract, Para [0046, 0056, 0075]: … The current subject matter describes a method and system of detecting frauds or anomalous behavior. The procedures include extracting characteristics from a dataset to generate words and documents, executing a topic model to obtain the respective probabilities of appearance of a document in each latent archetype, dividing the dataset into a plurality of subsets based upon the archetypes. The formed subsets are further utilized to estimate the quantiles and calculate scores using a self-calibrating outlier model … The detection system with the LDA archetypes and self-calibrating outlier model is implemented with the sliding window technique incorporating new transactions into the topic model … Each transaction is characterized by the transaction date, transaction time, location, MCC, etc., and those quantities may be used directly as raw variables or indirectly by derived variables. For example, a moving average of spending amount may be defined as a derived variable to reveal the offset from the trend. In Falcon® models, derived variables may include “Ratio of Transaction Amount to Daily Average Transaction Amount”, “Ratio of Current Transaction to the Maximum Value”, etc. The set of variables is computed for each transaction and utilized for purpose of outlier detection according to an embodiment … In case the PAN of the new transaction is not in the existing subsets, the entire dataset can be combined together for quantile calculations, which may be referred to as global estimation. The global estimation may yield average performance. In real-time, the new transaction which has a new PAN may be added into the existing PAN pool for updating LDA document-archetype matrix. With quantiles calculated for each variable, the same procedure as above may apply to score such a transaction … The transactions of PANs are characterized by some selected words so that the LDA model can be executed on the latent topics to aggregate the PANs into archetypes. Transactions of a PAN are assigned to a subset associated with the archetype …); and generating one or more top reasons, in response to a system level score above a threshold (Zoldi, Abstract, Para [0042, 0066]: … To reduce the occurrences of the low probability assigned to an archetype and improve the resolution with a concentration of higher probability for each archetype, in one implementation, a threshold Pt may be chosen such that only the PANs with maximum probability greater than the threshold Pt are assigned to the corresponding archetypes …)”. Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Zoldi into the combined teachings of Seymour-Raj because it discloses that “It should be noted from FIG. 8 that the performance curve of the LDA archetype and self-calibrating outlier model (solid line) is above that of the self-calibrating outlier model (dashed line), indicating the advantageous contribution from the subsetting technique in terms of the latent LDA archetype. It may be understood that the LDA archetype groups similar entities (PANs and corresponding transactions) together, resulting in finer-grained clarification of the transactions on top of the coarse-grained clarification using the simple self-calibrating outlier model over the entire dataset (which mixes all the archetypes) (Zoldi, Para [0062])”. Claim 18 is rejected under 35 U.S.C. 103 as being unpatentable over Pub. No.: US 20210194896 A1 to Seymour et al. (hereinafter “Seymour”) in view of Pub. No.: US 20180053188 A1 to Zoldi et al. (hereinafter “Zoldi2”). Regarding Claim 18. A computer program product comprising a non-transitory machine-readable medium storing instructions that, when executed by at least one programmable processor (Seymour, Para [0076-0080]: … FIG. 8, a block diagram of a computing device (which may also be referred to as a computing system) 810 is depicted, according to some embodiments. Computing device 810 may be used to implement various portions of this disclosure … computing device 810 includes processing unit 850, storage subsystem 812 … Processing unit 850 includes one or more processors and, in some embodiments, includes one or more coprocessor units. In some embodiments, multiple instances of processing unit 850 may be coupled to interconnect 860. Processing unit 850 (or each processor within processing unit 850) may contain a cache or other form of on-board memory … Storage subsystem 812 is usable by processing unit 850 (e.g., to store instructions executable by and data used by processing unit 850). Storage subsystem 812 may be implemented by any suitable type of physical memory media …), cause the at least one programmable processor to perform operations comprising: generating a corpus of transactions (Seymour, Para [0036, 0056-0057]: … Host reporting system 220, in the illustrated example, generates different signals 222 and 224 for network events based on network event data 218. In some embodiments, host reporting system 220 receives network event data 218 from one or more systems that interface with computer network 200. Host reporting system 220 sends signals 222 and 224 to security system 250. In some embodiments, host reporting system 220 is included in computer network 200. Signals generated by host reporting system 220 are discussed in further detail below with reference to FIG. 5 … FIG. 5 is a block diagram illustrating an example host reporting system that generates attributes for a network event based on data received from the computer network. In the illustrated embodiment, host reporting system 220 includes modules 510, 520, 530, and 540 for generating network-based signals 222, host-based signals 224, and domain information 542 …) comprising first transactions identified as likely adversarial and second transactions not identified as likely adversarial, the generating comprising , (Seymour, Para [0029]: … As used herein, “actionability” is a broad term that refers to the amount of data that is included in the indication of a particular event 102. In some cases, actionability may be measured vis-à-vis some determined set of data fields for a network event. An actionability score may be used to establish actionability along a spectrum (e.g., from 0 to 1, 0 to 10, 0 to 100, etc.). Thus, in one example, if a network event indication includes a threshold number of some determined set of data fields, that event may be deemed to be actionable (e.g., 0.8 of 1 for its actionability score). In this instance, the actionability score may have a low impact on the suspiciousness score. On the other hand, if a network event indication includes less than a threshold number of the determined set of data fields, that event may be deemed to be inactionable (e.g., 0.2 of 1 for its actionability), meaning that the event in many cases will not be reported for corrective action regardless of the suspiciousness score for the event. Generally speaking, the more data that is present for a network event 102, the more likely it is that this event is actionable, such that a network administrator (or a program analyzing network data) is actually able to take meaningful action on the event. The term “actionability” stands in distinction to the suspiciousness of the event. Accordingly, even if an event is highly suspicious, it might be indicated as low on actionability, meaning that some highly suspicious events may not be reported for corrective action …) for each transaction of a plurality of transactions: However Seymour does not explicitly teach, but Zoldi2 from same or similar field of endeavor teaches: “calculating a first score, the calculating comprising applying a first scoring model with inputs comprising a transaction feature extracted from the transaction and a transaction history for the transaction(Zoldi2, Para [0022-0024]: … For merchants, which share the cluster distribution of customers with the card issuers or card processors, the archetype cluster distribution is thus generated as a reference to incoming transactions from the historical data. The fraud rates may be obtained for each archetype cluster as well in case the tags are complete in the dataset. The new transactions are evaluated by identifying the archetype cluster that their PANs belong to, and then comparing with the reference archetype cluster distribution. The transaction risks are scored based on the archetype clusters associated with the transaction and their distribution characteristics. On the other hand, for existing customers making multiple purchases in a given period, transaction risks may be estimated based on the length of the history of card on file, history of IP addresses, frequency of the purchase items … Card transactions may be characterized with features or attributes such as transaction date, time, amount, location, merchant category etc. These raw features of transactions may be directly utilized in model development. In general, features from the raw variables are frequently transformed into other variables in order to effectively reveal the fraudulent characteristics. Those derived (transformed) variables may be mingled with the raw variables to form a feature set. It should be noted that not all the features have the same significance in contributing to the classification capability and thus only a limited and practical pool of features may be used in the model construction. In addition, in some embodiments, business knowledge may also be considered in the procedure of selecting final variables … In one or more embodiments, a process includes two phases: a training phase and a testing phase. For example the historical transactions may be used in the training phase to build a machine learning model. Thus the machine learning model is data-driven. In the testing phase, the transactions in the given testing dataset are fed into the built machine learning model. The characteristic for each new transaction is predicted based on the features in the current transaction. Note a score for each new transaction is predicted based on the features in the current transaction and compared to the actual classes if available, as they appear in the testing dataset, which is subsequently represented in an accuracy measure to assess the performance of the built learning model. In commercial practice, the training phase includes building a predictive model using historical transactions and the testing phase involves the operational stage at which the model is installed to monitor all the incoming transactions …); identifying as the first likely adversarial transactions those transactions having improbably low first scores within a first range and having a low occurrence likelihood based on comparing the first score and attributes of the transaction with those of one or more other transactions in the plurality of transactions (Zoldi2, Para [0051-0052]: … To assess fraud risks with the new transactions, the merchant may want to look into the behavior of the existing customers as a benchmark to determine potential fraud risks. FIG. 5 illustrates a distribution of archetype clusters and fraud rates for one merchant in a transaction dataset. In this example the dataset has all the tags for all the transactions (such as in Table 1). The x-axis is the archetype cluster (50 archetype clusters in this example) and the left y-axis denotes the archetype cluster distribution and the y-axis is the fraud rate distribution. The black circle-line corresponds to the percentage of number of PANs (pertaining to the left Y-axis) belonging to each archetype cluster. The distribution has a peak at archetype cluster 16. The red triangle-line corresponds to fraud rates in each archetype cluster by counting the number (F) of fraud transaction and the number (NF) of legitimate transactions and obtaining the ratio of F/(F+NF). The fraud rate curve (red line) exhibits non-uniform distribution in all the archetype clusters. The archetype cluster percentage and fraud rate in the archetype cluster may be correlated, that is, at higher percentage of archetype cluster distribution (e.g., black line at archetype clusters 8, 16) the fraud rate is very low (red line at archetype clusters 8, 16), whereas at lower percentage of archetype cluster distribution (e.g., black line at archetype clusters 10, 42), the fraud rate is relatively higher than those at the large archetype cluster percentage … The correlation shown in FIG. 5 is in good agreement with intuition and customer's spending behavior. Customers who are in the same archetype clusters make purchases at a merchant frequently, even they are first time buyer at this merchant, have low fraud rate for the transactions in this merchant; on the contrary customers of some type rarely visit some merchant, the fraud risks may be much higher. Such kind of correlation is a good indicator for a merchant and may be utilized to predict the fraud risks with some customers of an archetype cluster …)”; Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Zoldi2 into the teachings of Seymour, because it discloses that “The system may be implemented for online operation so that new CNP transactions are faster to participate into the model, resulting in improved predictive capability. While training a topic model such as LDA model proves expensive and time-consuming on a full scale, the existing topic model can be updated with new transactions without retraining the entire model … features extracted from the topic model may be transported to merchants for evaluating fraud risks for incoming new transactions or may be combined together with other transaction attributes to train a fraud detection model in block (Zoldi2, Para [0071])”. Seymour further discloses: “identifying the second transactions as those remaining transactions of the plurality of transactions that are not identified as the first transactions (Seymour, Para [0029]: … As used herein, “actionability” is a broad term that refers to the amount of data that is included in the indication of a particular event 102. In some cases, actionability may be measured vis-à-vis some determined set of data fields for a network event. An actionability score may be used to establish actionability along a spectrum (e.g., from 0 to 1, 0 to 10, 0 to 100, etc.). Thus, in one example, if a network event (first transaction) indication includes a threshold number of some determined set of data fields, that event may be deemed to be actionable (e.g., 0.8 of 1 for its actionability score). In this instance, the actionability score may have a low impact on the suspiciousness score. On the other hand, if a network event (second transaction) indication includes less than a threshold number of the determined set of data fields, that event may be deemed to be inactionable (e.g., 0.2 of 1 for its actionability), meaning that the event in many cases will not be reported for corrective action regardless of the suspiciousness score for the event. Generally speaking, the more data that is present for a network event 102, the more likely it is that this event is actionable, such that a network administrator (or a program analyzing network data) is actually able to take meaningful action on the event. The term “actionability” stands in distinction to the suspiciousness of the event. Accordingly, even if an event is highly suspicious, it might be indicated as low on actionability, meaning that some highly suspicious events may not be reported for corrective action …); and Zoldi2 further discloses: “training an adversary detection model based on attributes of the transactions in the corpus (Zoldi2, Para [0022-0024]: … For merchants, which share the cluster distribution of customers with the card issuers or card processors, the archetype cluster distribution is thus generated as a reference to incoming transactions from the historical data. The fraud rates may be obtained for each archetype cluster as well in case the tags are complete in the dataset. The new transactions are evaluated by identifying the archetype cluster that their PANs belong to, and then comparing with the reference archetype cluster distribution. The transaction risks are scored based on the archetype clusters associated with the transaction and their distribution characteristics. On the other hand, for existing customers making multiple purchases in a given period, transaction risks may be estimated based on the length of the history of card on file, history of IP addresses, frequency of the purchase items … Card transactions may be characterized with features or attributes such as transaction date, time, amount, location, merchant category etc. These raw features of transactions may be directly utilized in model development. In general, features from the raw variables are frequently transformed into other variables in order to effectively reveal the fraudulent characteristics. Those derived (transformed) variables may be mingled with the raw variables to form a feature set. It should be noted that not all the features have the same significance in contributing to the classification capability and thus only a limited and practical pool of features may be used in the model construction. In addition, in some embodiments, business knowledge may also be considered in the procedure of selecting final variables … In one or more embodiments, a process includes two phases: a training phase and a testing phase. For example the historical transactions may be used in the training phase to build a machine learning model. Thus the machine learning model is data-driven. In the testing phase, the transactions in the given testing dataset are fed into the built machine learning model. The characteristic for each new transaction is predicted based on the features in the current transaction. Note a score for each new transaction is predicted based on the features in the current transaction and compared to the actual classes if available, as they appear in the testing dataset, which is subsequently represented in an accuracy measure to assess the performance of the built learning model. In commercial practice, the training phase includes building a predictive model using historical transactions and the testing phase involves the operational stage at which the model is installed to monitor all the incoming transactions …)”. The motivation to further combine Zoldi2 remains same as before. Claim 20 is rejected under 35 U.S.C. 103 as being unpatentable over Pub. No.: US 20210194896 A1 to Seymour et al. (hereinafter “Seymour”) in view of Pub. No.: US 20180053188 A1 to Zoldi et al. (hereinafter “Zoldi2”), and further in view of Pub. No.: US 20220012741 A1 to Raj et al. (hereinafter “Raj”). Regarding Claim 20. Seymour discloses A computer-implemented system (Seymour: Abstract, Para [0003], Fig. 2) comprising: a first artificial intelligence (AI) model for calculating a first score for a first transaction based on one or more features extracted from the first transaction and transaction history associated with the first transaction (Seymour, Para [0037-0042]: … Security system 250, in the illustrated example, includes pre-processing module 240 for providing pre-processed signals 242 to security module 120. For example, pre-processing module 240 may be a machine learning module that determines whether a domain name associated with a particular network event 102 was generated using a domain name generation algorithm (DGA). In this example, pre-processing module 240 sends the determination (signals 242) whether the domains associated with network events 102 were generated using a DGA to the security module 120. In some embodiments, pre-processed signals 242 are used in calculating security and actionability scores …), However Seymour does not explicitly teach, but Zoldi2 from same or similar field of endeavor teaches: “the first transaction being tagged as potentially adversarial, in response to determining that the first score is in an improbable range based on comparing first attributes associated with the first transaction with second attributes associated with at least a second transaction, the comparison indicating the first transaction has a low likelihood of occurrence (Zoldi2, Para [0022-0024, 0051-0052]: … To assess fraud risks with the new transactions, the merchant may want to look into the behavior of the existing customers as a benchmark to determine potential fraud risks. FIG. 5 illustrates a distribution of archetype clusters and fraud rates for one merchant in a transaction dataset. In this example the dataset has all the tags for all the transactions (such as in Table 1). The x-axis is the archetype cluster (50 archetype clusters in this example) and the left y-axis denotes the archetype cluster distribution and the y-axis is the fraud rate distribution. The black circle-line corresponds to the percentage of number of PANs (pertaining to the left Y-axis) belonging to each archetype cluster. The distribution has a peak at archetype cluster 16. The red triangle-line corresponds to fraud rates in each archetype cluster by counting the number (F) of fraud transaction and the number (NF) of legitimate transactions and obtaining the ratio of F/(F+NF). The fraud rate curve (red line) exhibits non-uniform distribution in all the archetype clusters. The archetype cluster percentage and fraud rate in the archetype cluster may be correlated, that is, at higher percentage of archetype cluster distribution (e.g., black line at archetype clusters 8, 16) the fraud rate is very low (red line at archetype clusters 8, 16), whereas at lower percentage of archetype cluster distribution (e.g., black line at archetype clusters 10, 42), the fraud rate is relatively higher than those at the large archetype cluster percentage … The correlation shown in FIG. 5 is in good agreement with intuition and customer's spending behavior. Customers who are in the same archetype clusters make purchases at a merchant frequently, even they are first time buyer at this merchant, have low fraud rate for the transactions in this merchant; on the contrary customers of some type rarely visit some merchant, the fraud risks may be much higher. Such kind of correlation is a good indicator for a merchant and may be utilized to predict the fraud risks with some customers of an archetype cluster …)”; and Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Zoldi2 into the teachings of Seymour, because it discloses that “The system may be implemented for online operation so that new CNP transactions are faster to participate into the model, resulting in improved predictive capability. While training a topic model such as LDA model proves expensive and time-consuming on a full scale, the existing topic model can be updated with new transactions without retraining the entire model … features extracted from the topic model may be transported to merchants for evaluating fraud risks for incoming new transactions or may be combined together with other transaction attributes to train a fraud detection model in block (Zoldi2, Para [0071])”. However the combination of Seymour-Zoldi2 does not explicitly teach, but Raj from same or similar field of endeavor teaches: “at least one of: a second AI model for identifying adversarial transactions, in response to determining that number of plurality of example transactions scored by the first model is sufficient to train the second AI model, the second AI model being trained using a supervised learning approach based on features associated with the plurality of example transactions scored by the first AI model, the training of the second AI model being according to a stochastic gradient descent method (Raj, FIG. 5, Para [0046-0049]: … auxiliary network 508 (this block takes the intermediate encoded representation to perform an auxiliary task, which in one embodiment is to reconstruct (generate) some input feature, such as but not limited to the user id or age, in the transaction using the same latent features as the classifier); classification network block 510 (this block takes in the encoder's representation to classify (predict) the transaction as fraudulent (or not fraudulent)); and gradient boosting framework 512. Gradient boosting framework 512 is combined with the classification network 510 to obtain the prediction(s) as fraudulent (or non-fraudulent) transactions. Auxiliary network 508 is used only during the training phase and not during the inference phase … classification network block 510 take many forms such as, neural network-based approach, a gradient boosted approach, logistic regression, any other classification algorithm and/or various combinations of the foregoing enumerate types … Decoded output from a decoder, as one embodiment of the auxiliary network 508 in FIG. 5; (iii) p_t: Predicted class probability (i.e. model's assessment of the probability that the transaction is in the fraudulent or non-fraudulent class of transactions), as the output of classification network block 510 in FIG. 5 …)”, and Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Raj into the teachings of Seymour-Zoldi2, because it discloses that “The multi-task learning instructions: (a) solve multiple learning tasks in a temporally overlapping manner while exploiting commonalities and differences across tasks resulting in improved learning efficiency and prediction accuracy for the task-specific models, when compared to training multiple models separately, and (b) improve generalization by using the domain information contained in the training signals of related tasks as an inductive bias by learning tasks in parallel while using a shared representation so that what is learned for each task can help other tasks be learned (Raj, Para [0006])”. a third AI model for identifying adversarial transactions, in response to determining the number of the plurality of example transactions scored by the AI model is insufficient to train the second AI model, the third AI model being trained using a semi-supervised learning approach in which a large corpus of possible latent features associated with adversarial transactions is defined and used to detect adversarial transactions, strength of one or more hidden nodes of the third model being calculated such that the hidden nodes with strength values below a threshold are eliminated to make the third model more efficient.” Allowable Subject Matter Claims 2-16 and 19 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. As allowable subject matter has been indicated, applicant's reply must either comply with all formal requirements or specifically traverse each requirement not complied with. See 37 CFR 1.111(b) and MPEP § 707.07(a). Examiner notes that Applicant’s response shall address all other rejections (112, double patenting, 101 …) and objections issued in this office action. Examiner also notes that, should Applicant amends claims, all the independent claims be made similar in scope. Reasons for allowance will be furnished upon allowance. Pertinent Prior Arts The following prior arts made of record and not relied upon are considered pertinent to applicant's disclosure. US 20170230417 A1; Amar et al.: Amar discloses Systems and methods for monitoring user authenticity during user activities in a user session on an application server is provided. The method being carried out in a distributed manner by a distributed server system. The method comprises a user modeling-process and a user-verification process. The user-modeling process is performed on a user-model server in which a user model is adapted session-by-session to user activity data received from the application server. The user-verification process is performed on the application server on the basis of the user model adapted on the user-model server. The user-verification process comprises comparing the user model with features extracted from user activity in the user session on the application server and determining a total risk-score value based on the comparison. If the total risk-score value is greater than a given threshold, a corrective action is performed. The invention relates generally to computers and computer software and, more particularly, to systems, methods, and computer program products for monitoring user authenticity during user activities on an application server in a distributed computer system. US 20180350006 A1; Agrawal et al.: Agrawal discloses a system, method and computer readable medium for detecting at least one non-compliant commercial card transaction for a plurality of transactions received from a merchant, and for generating at least one score for a received transaction, based at least partially on a scoring model, to determine whether a transaction is non-compliant. The scoring model includes at least one score determined by unsupervised learning with feedback from score influencing rules, case disposition data, transactional data, historical data and old scoring models and automatically modifying, at predefined intervals, the scoring model based on current score influencing rules and case disposition data. Machine learning is programmed to score the model based at least partially on a probability-based outlier detection algorithm and a clustering algorithm and to provide a case presentation system for audit and review of scored transactions and to receive input comprising case disposition data and score influencing rules. This invention relates generally to misuse and abuse detection systems for transactions of commercial cards, and in one particular embodiment, a system, method, and apparatus for self-adaptive scoring to detect misuse or abuse of commercial cards. US 20190295088 A1; Jia et al.: Jia discloses methods, systems, and computer program products are provided for using pre-purchase scoring to efficiently detect fraud on an e-commerce platform. In particular, high dimension pre-purchase information may be consolidated into one or more scores to be carried over and applied to a real time machine learning model at the purchase stage. More specifically, a large amount of information is available, for example, when a user initially connects to the e-commerce platform, creates an account thereon, subsequently logs in using that account, or adds a payment instrument to their account. Such information is applied to a machine learning model that consolidates the information into a score to be carried over, and used further at the purchase stage. US 20150193768 A1; Douglas et al.: Douglas discloses systems and methods are provided for providing alerts to a user. The systems and methods may include a financial service provider including a memory device storing instructions. The financial service provider may also include at least one processor configured to execute the instructions to receive data relating to a transaction made by the user, compare the received data to a set of data associated with the user, determine whether the data relating to the transaction deviates from a set of data associated with the user by more than a threshold value, and send an alert message to a user device associated with the user when the processor determines that the data relating to the transaction deviates from the set of data associated with the user by more than the threshold value. The FSP (financial service provider) may identify suspicious transactions. Suspicious transactions may include fraudulent transactions or transactions that are not necessarily fraudulent but are likely to be subject to future disputes. The FSP may identify suspicious transactions before, during, or after the FSP customers conduct such transactions. For example, after the FSP identifies a suspicious transaction, the FSP app may send an alert message to the user to caution the user that the transaction appears to be out of a normal range of amounts or volumes, the transaction may be fraudulent, or that the merchant has poor ratings or reviews, which may mean that the products and/or services purchased from the merchant may have a high likelihood of being subject to future disputes. Based on a user response received from the user, the FSP may provide, e.g., through the FSP app, further information to the user regarding the merchant, such as ratings and reviews of the merchant, to assist the user to make a decision as to whether the transaction should be avoided or canceled to avoid future trouble or disputes. Thus, disclosed methods and systems may ultimately reduce the likelihood of fraud, dispute, and abuse. NPL: Credit Card Fraud Detection: A Hybrid Approach Using Fuzzy Clustering & Neural Network; Behera et al. ; IEEE Xplore: 26 October 2015: Behera discloses a novel approach towards credit card fraud detection in which the fraud detection is done in three phases. The first phase does the initial user authentication and verification of card details. If the check is successfully cleared, then the transaction is passed to the next phase where fuzzy c-means clustering algorithm is applied to find out the normal usage patterns of credit card users based on their past activity. A suspicion score is calculated according to the extent of deviation from the normal patterns and thereby the transaction is classified as legitimate or suspicious or fraudulent. Once a transaction is found to be suspicious, neural network based learning mechanism is applied to determine whether it was actually a fraudulent activity or an occasional deviation by a genuine user. Extensive experimentation with stochastic models shows that the combined use of clustering technique along with learning helps in detecting fraudulent activities effectively while minimizing the generation of false. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to MAHABUB S AHMED whose telephone number is (571)272-0364. The examiner can normally be reached on 9AM-5PM EST M-F. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Ali Shayanfar can be reached on 571-270-1050. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /MAHABUB S AHMED/Examiner, Art Unit 2434 /TESHOME HAILU/Primary Examiner, Art Unit 2434
Read full office action

Prosecution Timeline

Apr 22, 2025
Application Filed
Jul 29, 2026
Non-Final Rejection mailed — §101, §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12671707
Method for monitoring and enforcing secure policies in a device
2y 6m to grant Granted Jun 30, 2026
Patent 12665916
LIGHTWEIGHT REAL-TIME ABNORMALITY DETECTION METHOD USING CAN MESSAGE ANALYSIS AND NEURAL NETWORK MODEL
2y 0m to grant Granted Jun 23, 2026
Patent 12647444
SYSTEM AND METHOD FOR EMULATING A KNOWN ATTACK ON A TARGET COMPUTER NETWORK
2y 3m to grant Granted Jun 02, 2026
Patent 12647445
SYSTEM AND METHOD FOR EMULATING A KNOWN ATTACK ON A TARGET COMPUTER NETWORK
2y 3m to grant Granted Jun 02, 2026
Patent 12632528
INFORMATION PROCESSING DEVICE, AND INFORMATION PROCESSING METHOD
3y 3m to grant Granted May 19, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
86%
Grant Probability
94%
With Interview (+8.2%)
2y 4m (~1y 0m remaining)
Median Time to Grant
Low
PTA Risk
Based on 296 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month