Prosecution Insights
Last updated: September 17, 2026
Application No. 19/196,556

SYSTEM AND METHOD FOR GENERATING FRAUD REPORT USING LARGE LANGUAGE MODEL

Non-Final OA §103§112
Filed
May 01, 2025
Priority
May 23, 2024 — provisional 63/651,363
Examiner
OLAEGBE, MUDASIRU K
Art Unit
Tech Center
Assignee
Barracuda Networks Inc.
OA Round
1 (Non-Final)
74%
Grant Probability
Favorable
1-2
OA Rounds
1y 9m
Est. Remaining
88%
With Interview

Examiner Intelligence

Grants 74% — above average
74%
Career Allowance Rate
64 granted / 87 resolved
+13.6% vs TC avg
Moderate +15% lift
Without
With
+14.6%
Interview Lift
resolved cases with interview
Typical timeline
3y 1m
Avg Prosecution
25 currently pending
Career history
120
Total Applications
across all art units

Statute-Specific Performance

§101
3.9%
-36.1% vs TC avg
§103
63.5%
+23.5% vs TC avg
§102
17.7%
-22.3% vs TC avg
§112
12.6%
-27.4% vs TC avg
Black line = Tech Center average estimate • Based on career data from 87 resolved cases

Office Action

§103 §112
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This communication is in response to the application filed on 05/01/2025. Claims 1-23 are currently pending in the application. Claim Interpretation The claims in this application are given their broadest reasonable interpretation using the plain meaning of the claim language in light of the specification as it would be understood by one of ordinary skill in the art. The broadest reasonable interpretation of a claim element (also commonly referred to as a claim limitation) is limited by the description in the specification when 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is invoked. As explained in MPEP § 2181, subsection I, claim limitations that meet the following three-prong test will be interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph: (A) the claim limitation uses the term “means” or “step” or a term used as a substitute for “means” that is a generic placeholder (also called a nonce term or a non-structural term having no specific structural meaning) for performing the claimed function; (B) the term “means” or “step” or the generic placeholder is modified by functional language, typically, but not always linked by the transition word “for” (e.g., “means for”) or another linking word or phrase, such as “configured to” or “so that”; and (C) the term “means” or “step” or the generic placeholder is not modified by sufficient structure, material, or acts for performing the claimed function. Use of the word “means” (or “step”) in a claim with functional language creates a rebuttable presumption that the claim limitation is to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites sufficient structure, material, or acts to entirely perform the recited function. Absence of the word “means” (or “step”) in a claim creates a rebuttable presumption that the claim limitation is not to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is not interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites function without reciting sufficient structure, material or acts to entirely perform the recited function. Claim limitations in this application that use the word “means” (or “step”) are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action. Conversely, claim limitations in this application that do not use the word “means” (or “step”) are not being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action. Claim 1 limitation of this application is given a broadest reasonable interpretation (BRI) under 112(f) because of the use of term “configured to” PRONG 1: The use of the term configured to with a functional language indicates a presumption that applicant intends to invoke 112(f). In this case, the limitation (“a fraud detection engine configured to derive a plurality of features from a piece of content for fraud detection; classify the plurality of features of the piece of content into one or more fraud categories using one or more classification models”; “a prompt generation engine configured to accept the plurality of derived features and their corresponding one or more fraud categories; generate an input prompt to a large language model (LLM), wherein the input prompt is specific to the one or more fraud categories and/or the plurality of derived features”; and “a report generation engine configured to utilize the LLM to generate a fraud report of the original piece of content for a user based on the input prompt specific to the one or more fraud categories.”) that appear in claim 1 establish the applicant presumption to invoke 112(f). PRONG 2: a fraud detection engine, a prompt generation engine, and a report generation engine are modified by functional language: (“a fraud detection engine configured to derive a plurality of features from a piece of content for fraud detection…”; “a prompt generation engine configured to accept the plurality of derived features and their corresponding one or more fraud categories…”; and “a report generation engine configured to utilize the LLM to generate a fraud report of the original piece of content…”); This prong also establishes the applicant presumption to invoke 112(f). PRONG 3: Applicant does not recite sufficient structure, material or acts to entirely perform the recited functions of “derive a plurality of features from a piece of content for fraud detection…”; “accept the plurality of derived features and their corresponding one or more fraud categories…”; and “utilize the LLM to generate a fraud report of the original piece of content…”; In other words, the term “means” or “step” or the generic placeholder (configurations) that appear in the claim is not modified by sufficient structure, material, or acts for performing the claimed functions. As such, (“a fraud detection engine configured to derive a plurality of features from a piece of content for fraud detection…”; “a prompt generation engine configured to accept the plurality of derived features and their corresponding one or more fraud categories…”; and “a report generation engine configured to utilize the LLM to generate a fraud report of the original piece of content…”); in claim 1 and not modified by sufficient structure, material, or acts for performing the claimed functions also establish the applicant presumption to invoke 112(f). 4. However, paragraph 13 of applicant’s specification as originally filed recites sufficient structure, material, or acts for performing the claimed functions. (“In the example of FIG. 1, the system 100 includes at least a fraud detection engine 102, a prompt generation engine 104, and a report generation engine 106. Each engine in the system 100 runs on one or more computing units/appliances/devices/hosts (not shown) each having one or more processors and software instructions stored in a storage unit, such as a non-volatile memory of the computing unit for practicing one or more processes. When the software instructions are executed, at least a subset of the software instructions is loaded into memory (also referred to as primary memory) by one of the computing units, which becomes a special purposed one for practicing the processes. The processes may also be at least partially embodied in the computing units into which computer program code is loaded and/or executed, such that, the host becomes a special purpose computing unit for practicing the processes.”). Therefore, the independent claim 1 and its dependent claims are not rejected under 35 U.S.C. 112(f). Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claims 1-6, 9-17, and 20-23 are rejected under 35 U.S.C. 103 as being unpatentable over US. PGPub. No. 20220114594 to Nunes et al. (hereinafter Nunes) in view of US. PGPub. No. 20240419941 to He et al. (hereinafter He). Regarding claim 1, Nunes discloses a system (abstract, “There are provided systems and methods for actionable insight into user interaction data…”), comprising: a fraud detection engine (FIGs.1 and 2, (Event detection server 150) configured to derive a plurality of features from a piece of content for fraud detection (¶0026-¶0028, …The analysis system may extract topics using Latent Dirichlet Allocation (LDA), and select the best performing feature extraction model to extract features from the customer inputs. In some embodiments, the analysis system may also augment the model with information regarding the caller/sender of the customer input. Once a customer input is classified in one of these categories, further action can be taken on each interaction.”), (¶0001, “The present application generally relates to machine learning models trained for user interaction data analysis and more particularly to an engine having a machine learning model trained to analyze user interaction data for actionable insight into the user interaction data”); classify the plurality of features of the piece of content into one or more fraud categories using one or more classification models (¶0026-¶0028, “…the analysis system may classify customer inputs (e.g., customer complaints and/or issues reported by e-mails, voice calls, and/or chat sessions) into respective categories for automated analysis and remedial action. The analysis system may classify a customer input into one or more fraud categories based on matching the customer input to one or more known (or stored) fraud patterns…”); a prompt generation engine configured to accept the plurality of derived features and their corresponding one or more fraud categories (FIG. 2, classification module 230 of the event detection server 150 receives the output of feature extraction module 210, ¶0073, “The classification module 230 includes a preprocessing module 231, a classifier 232, a fraud class module 233, a voice scoring module 234, a phishing class module 235, a malware class module 236, other class module 237 and a noise class module 238. In some embodiments, the classification module 230 may determine an intent of the communication based on the extracted features, and may select a machine learning-trained classifier to classify the communication in one or more of communication categories.”), (¶0078-¶0080, “…the classifier 232 of the event detection server 150 classifies the extracted features into one of many actionable insight categories with a machine learning-trained classifier. For example, a first actionable insight category may correspond to a fraudulent activity implemented with the fraud class module 233, a second actionable insight category may correspond to a phishing activity implemented with the phishing class module 235, a third actionable insight category may correspond to a malware activity implemented with the malware class module 236, a fourth actionable insight category may correspond to a noise activity implemented with the noise class module 238, and a fifth actionable insight category may correspond to other (or miscellaneous) activities implemented with the other class module 237. The output of the fraud class module 233 is fed to the first pass fraud detection module 240…”); generate an input prompt to a Machine Learning Model wherein the input prompt is specific to the one or more fraud categories and/or the plurality of derived features (¶0026, “…an analysis system may be configured to automatically classify and analyze customer inputs (e.g., email, phone, chat, etc.) for producing actionable insights related to fraud campaigns, phishing attacks, malware distribution, or product issues.”), (¶0079, “the classifier 232 of the event detection server 150 classifies the extracted features into one of many actionable insight categories with a machine learning-trained classifier. For example, a first actionable insight category may correspond to a fraudulent activity implemented with the fraud class module 233, a second actionable insight category may correspond to a phishing activity implemented with the phishing class module 235, a third actionable insight category may correspond to a malware activity implemented with the malware class module 236…”), (¶0084, “the classification module 230 may include one or more processors adapted to generate multiple machine learning-based networks based on the actionable insight categories. In some aspects, the machine learning-based networks correspond to the respective actionable insight categories. The one or more processors in the classification module 230 may be adapted to train each of the machine learning-based networks with a respective training dataset to form different machine learning-trained classifiers. In some aspects, the respective training dataset facilitates supervised learning by including labeled interaction data indicating what information pertains to which of the actionable insight categories…”), (¶0138, “…the classification module 230 can select a select number of classifiers that correspond to different user attribute combinations based on different attributes in one or more of the user attributes or the user account information.”); and a report generation engine configured to utilize the Machine Learning Model to generate a fraud report of the original piece of content for a user based on the input prompt specific to the one or more fraud categories (¶0029, “…When the customer input is classified as a fraud complaint, the analysis system may cluster the customer input with other similar reported fraud activities (e.g., other customer inputs that have been classified as the same category)….Once a cluster reaches a certain number of complaints, a report generation model can be triggered to generate a report. The analysis system may identify specific information from the complaints, such as email addresses of the customers or any transaction details, and derive patterns from the complaints that belong the same cluster such as country of origin of the customers, customer age range, network addresses used for the transaction, transaction amount that was charged, a description of the service if any, and so on. This information can be added to the report with all the insights gathered and forwarded to an agent device for further analysis and action”), (¶0152, FIG. 2, “report generation module 260”, “…For example, at action 840, the fraud class module 233 can retrieve account information for which the same caller called for review in a prior occasion. If a match is found, the fraud class module 233, in coordination with the report generation module 260, can alert an agent associated with the agent device 120, indicating that the current caller called previously for a different user account…”), (¶0153, FIG. 2, “report generation module 260”, “at step 1020, the report generation module 260 can send a notification to a communication device associated with the service provider server 110 (e.g., the agent device 120). In some aspects, the notification may include an indication of whether the user device interacted with the service provider server in the prior interaction. For example, at action 834, the report generation module 260 sends notification of detected fraudulent callers to the agent device 120.”). However, Nunes does not explicitly disclose that the machine learning model includes Large Language Models (LLMs). He discloses applying LLM to transaction data in order to detect fraud in the transaction (¶0002-¶0003, “… an online concierge system requests a large language model (LLM) to determine, based on a prompt input into the LLM, information about a refund event for a first order placed with an online concierge system by a user of the online concierge system. The online concierge system accesses a computer model of the online concierge system trained to detect a fraudulent behavior associated with an order placed with the online concierge system. The online concierge system applies the computer model to determine a score associated with the refund event, based on the information about the refund event received from the LLM. “), see also ¶0030-¶0031, (¶0077, “Based on the prompt 305 input into the LLM 310, the LLM 310 may generate responses 315, 320 and 325. Although FIG. 3 illustrates the LLM 310 generating three separate responses, it should be understood that the LLM 310 can alternatively generate more or fewer responses that cumulatively include the same information as the responses 315, 320 and 325. The response 315 may include information about one or more refunded/replaced items associated with the order and at least one reason provided by the picker for the refund event…”). Thus, one of ordinary skill in the art would have found it obvious before the effective filing date of applicant’s claimed invention to include using LLM for fraud detection as disclosed by He and be motivated in doing so because LLM is capable of handling massive amount of text data, often involving billions of words or text unit-He ¶0030 in parts. Regarding claim 13, Nunes discloses a computer-implemented method (¶0154, “… each of the devices utilized by users and service providers may be implemented as computer system 1100”), comprising: deriving a plurality of features from a piece of content for fraud detection (¶0026-¶0028, …The analysis system may extract topics using Latent Dirichlet Allocation (LDA), and select the best performing feature extraction model to extract features from the customer inputs. In some embodiments, the analysis system may also augment the model with information regarding the caller/sender of the customer input. Once a customer input is classified in one of these categories, further action can be taken on each interaction.”), (¶0001, “The present application generally relates to machine learning models trained for user interaction data analysis and more particularly to an engine having a machine learning model trained to analyze user interaction data for actionable insight into the user interaction data”); classifying the plurality of features of the piece of content into one or more fraud categories using one or more classification models (¶0026-¶0028, “…the analysis system may classify customer inputs (e.g., customer complaints and/or issues reported by e-mails, voice calls, and/or chat sessions) into respective categories for automated analysis and remedial action. The analysis system may classify a customer input into one or more fraud categories based on matching the customer input to one or more known (or stored) fraud patterns…”); accepting the plurality of derived features and their corresponding one or more fraud categories (FIG. 2, classification module 230 of the event detection server 150 receives the output of feature extraction module 210, ¶0073, “The classification module 230 includes a preprocessing module 231, a classifier 232, a fraud class module 233, a voice scoring module 234, a phishing class module 235, a malware class module 236, other class module 237 and a noise class module 238. In some embodiments, the classification module 230 may determine an intent of the communication based on the extracted features, and may select a machine learning-trained classifier to classify the communication in one or more of communication categories.”), (¶0078-¶0080, “…the classifier 232 of the event detection server 150 classifies the extracted features into one of many actionable insight categories with a machine learning-trained classifier. For example, a first actionable insight category may correspond to a fraudulent activity implemented with the fraud class module 233, a second actionable insight category may correspond to a phishing activity implemented with the phishing class module 235, a third actionable insight category may correspond to a malware activity implemented with the malware class module 236, a fourth actionable insight category may correspond to a noise activity implemented with the noise class module 238, and a fifth actionable insight category may correspond to other (or miscellaneous) activities implemented with the other class module 237. The output of the fraud class module 233 is fed to the first pass fraud detection module 240…”); generating an input prompt to a Machine Learning Model wherein the input prompt is specific to the one or more fraud categories and/or the plurality of derived features (¶0026, “…an analysis system may be configured to automatically classify and analyze customer inputs (e.g., email, phone, chat, etc.) for producing actionable insights related to fraud campaigns, phishing attacks, malware distribution, or product issues.”), (¶0079, “the classifier 232 of the event detection server 150 classifies the extracted features into one of many actionable insight categories with a machine learning-trained classifier. For example, a first actionable insight category may correspond to a fraudulent activity implemented with the fraud class module 233, a second actionable insight category may correspond to a phishing activity implemented with the phishing class module 235, a third actionable insight category may correspond to a malware activity implemented with the malware class module 236…”), (¶0084, “the classification module 230 may include one or more processors adapted to generate multiple machine learning-based networks based on the actionable insight categories. In some aspects, the machine learning-based networks correspond to the respective actionable insight categories. The one or more processors in the classification module 230 may be adapted to train each of the machine learning-based networks with a respective training dataset to form different machine learning-trained classifiers. In some aspects, the respective training dataset facilitates supervised learning by including labeled interaction data indicating what information pertains to which of the actionable insight categories…”), (¶0138, “…the classification module 230 can select a select number of classifiers that correspond to different user attribute combinations based on different attributes in one or more of the user attributes or the user account information.”); and utilizing the Machine Learning Model to generate a fraud report of the original piece of content for a user based on the input prompt specific to the one or more fraud categories (¶0029, “…When the customer input is classified as a fraud complaint, the analysis system may cluster the customer input with other similar reported fraud activities (e.g., other customer inputs that have been classified as the same category)…. Once a cluster reaches a certain number of complaints, a report generation model can be triggered to generate a report. The analysis system may identify specific information from the complaints, such as email addresses of the customers or any transaction details, and derive patterns from the complaints that belong the same cluster such as country of origin of the customers, customer age range, network addresses used for the transaction, transaction amount that was charged, a description of the service if any, and so on. This information can be added to the report with all the insights gathered and forwarded to an agent device for further analysis and action”), (¶0152, FIG. 2, “report generation module 260”, “…For example, at action 840, the fraud class module 233 can retrieve account information for which the same caller called for review in a prior occasion. If a match is found, the fraud class module 233, in coordination with the report generation module 260, can alert an agent associated with the agent device 120, indicating that the current caller called previously for a different user account…”), (¶0153, FIG. 2, “report generation module 260”, “at step 1020, the report generation module 260 can send a notification to a communication device associated with the service provider server 110 (e.g., the agent device 120). In some aspects, the notification may include an indication of whether the user device interacted with the service provider server in the prior interaction. For example, at action 834, the report generation module 260 sends notification of detected fraudulent callers to the agent device 120.”). However, Nunes does not explicitly disclose that the machine learning model includes Large Language Models (LLMs). He discloses applying LLM to transaction data in order to detect fraud in the transaction (¶0002-¶0003, “… an online concierge system requests a large language model (LLM) to determine, based on a prompt input into the LLM, information about a refund event for a first order placed with an online concierge system by a user of the online concierge system. The online concierge system accesses a computer model of the online concierge system trained to detect a fraudulent behavior associated with an order placed with the online concierge system. The online concierge system applies the computer model to determine a score associated with the refund event, based on the information about the refund event received from the LLM. “), see also ¶0030-¶0031, (¶0077, “Based on the prompt 305 input into the LLM 310, the LLM 310 may generate responses 315, 320 and 325. Although FIG. 3 illustrates the LLM 310 generating three separate responses, it should be understood that the LLM 310 can alternatively generate more or fewer responses that cumulatively include the same information as the responses 315, 320 and 325. The response 315 may include information about one or more refunded/replaced items associated with the order and at least one reason provided by the picker for the refund event…”). Thus, one of ordinary skill in the art would have found it obvious before the effective filing date of applicant’s claimed invention to include using LLM for fraud detection as disclosed by He and be motivated in doing so because LLM is capable of handling massive amount of text data, often involving billions of words or text unit-He ¶0030 in parts. Regarding claim 23, Nunes discloses a non-transitory storage medium having software instructions stored thereon that when executed cause a system to (¶0089, “Some examples of computing devices, such as computer system 1100 may include non-transitory, tangible, machine readable media that include executable code that when run by one or more processors (e.g., processor 1112) may cause the one or more processors to perform the steps of process 400”): derive a plurality of features from a piece of content for fraud detection (¶0026-¶0028, …The analysis system may extract topics using Latent Dirichlet Allocation (LDA), and select the best performing feature extraction model to extract features from the customer inputs. In some embodiments, the analysis system may also augment the model with information regarding the caller/sender of the customer input. Once a customer input is classified in one of these categories, further action can be taken on each interaction.”), (¶0001, “The present application generally relates to machine learning models trained for user interaction data analysis and more particularly to an engine having a machine learning model trained to analyze user interaction data for actionable insight into the user interaction data”); classify the plurality of features of the piece of content into one or more fraud categories using one or more classification models (¶0026-¶0028, “…the analysis system may classify customer inputs (e.g., customer complaints and/or issues reported by e-mails, voice calls, and/or chat sessions) into respective categories for automated analysis and remedial action. The analysis system may classify a customer input into one or more fraud categories based on matching the customer input to one or more known (or stored) fraud patterns…”); accept the plurality of derived features and their corresponding one or more fraud categories (FIG. 2, classification module 230 of the event detection server 150 receives the output of feature extraction module 210, ¶0073, “The classification module 230 includes a preprocessing module 231, a classifier 232, a fraud class module 233, a voice scoring module 234, a phishing class module 235, a malware class module 236, other class module 237 and a noise class module 238. In some embodiments, the classification module 230 may determine an intent of the communication based on the extracted features, and may select a machine learning-trained classifier to classify the communication in one or more of communication categories.”), (¶0078-¶0080, “…the classifier 232 of the event detection server 150 classifies the extracted features into one of many actionable insight categories with a machine learning-trained classifier. For example, a first actionable insight category may correspond to a fraudulent activity implemented with the fraud class module 233, a second actionable insight category may correspond to a phishing activity implemented with the phishing class module 235, a third actionable insight category may correspond to a malware activity implemented with the malware class module 236, a fourth actionable insight category may correspond to a noise activity implemented with the noise class module 238, and a fifth actionable insight category may correspond to other (or miscellaneous) activities implemented with the other class module 237. The output of the fraud class module 233 is fed to the first pass fraud detection module 240…”) and /or the plurality of derived features; generate an input prompt to a Machine Learning Model wherein the input prompt is specific to the one or more fraud categories (¶0026, “…an analysis system may be configured to automatically classify and analyze customer inputs (e.g., email, phone, chat, etc.) for producing actionable insights related to fraud campaigns, phishing attacks, malware distribution, or product issues.”), (¶0079, “the classifier 232 of the event detection server 150 classifies the extracted features into one of many actionable insight categories with a machine learning-trained classifier. For example, a first actionable insight category may correspond to a fraudulent activity implemented with the fraud class module 233, a second actionable insight category may correspond to a phishing activity implemented with the phishing class module 235, a third actionable insight category may correspond to a malware activity implemented with the malware class module 236…”), (¶0084, “the classification module 230 may include one or more processors adapted to generate multiple machine learning-based networks based on the actionable insight categories. In some aspects, the machine learning-based networks correspond to the respective actionable insight categories. The one or more processors in the classification module 230 may be adapted to train each of the machine learning-based networks with a respective training dataset to form different machine learning-trained classifiers. In some aspects, the respective training dataset facilitates supervised learning by including labeled interaction data indicating what information pertains to which of the actionable insight categories…”), (¶0138, “…the classification module 230 can select a select number of classifiers that correspond to different user attribute combinations based on different attributes in one or more of the user attributes or the user account information.”); and utilize the Machine Learning Model to generate a fraud report of the original piece of content for a user based on the input prompt specific to the one or more fraud categories (¶0029, “…When the customer input is classified as a fraud complaint, the analysis system may cluster the customer input with other similar reported fraud activities (e.g., other customer inputs that have been classified as the same category)…. Once a cluster reaches a certain number of complaints, a report generation model can be triggered to generate a report. The analysis system may identify specific information from the complaints, such as email addresses of the customers or any transaction details, and derive patterns from the complaints that belong the same cluster such as country of origin of the customers, customer age range, network addresses used for the transaction, transaction amount that was charged, a description of the service if any, and so on. This information can be added to the report with all the insights gathered and forwarded to an agent device for further analysis and action”), (¶0152, FIG. 2, “report generation module 260”, “…For example, at action 840, the fraud class module 233 can retrieve account information for which the same caller called for review in a prior occasion. If a match is found, the fraud class module 233, in coordination with the report generation module 260, can alert an agent associated with the agent device 120, indicating that the current caller called previously for a different user account…”), (¶0153, FIG. 2, “report generation module 260”, “at step 1020, the report generation module 260 can send a notification to a communication device associated with the service provider server 110 (e.g., the agent device 120). In some aspects, the notification may include an indication of whether the user device interacted with the service provider server in the prior interaction. For example, at action 834, the report generation module 260 sends notification of detected fraudulent callers to the agent device 120.”). However, Nunes does not explicitly disclose that the machine learning model includes Large Language Models (LLMs). He discloses applying LLM to transaction data in order to detect fraud in the transaction (¶0002-¶0003, “… an online concierge system requests a large language model (LLM) to determine, based on a prompt input into the LLM, information about a refund event for a first order placed with an online concierge system by a user of the online concierge system. The online concierge system accesses a computer model of the online concierge system trained to detect a fraudulent behavior associated with an order placed with the online concierge system. The online concierge system applies the computer model to determine a score associated with the refund event, based on the information about the refund event received from the LLM. “), see also ¶0030-¶0031, (¶0077, “Based on the prompt 305 input into the LLM 310, the LLM 310 may generate responses 315, 320 and 325. Although FIG. 3 illustrates the LLM 310 generating three separate responses, it should be understood that the LLM 310 can alternatively generate more or fewer responses that cumulatively include the same information as the responses 315, 320 and 325. The response 315 may include information about one or more refunded/replaced items associated with the order and at least one reason provided by the picker for the refund event…”). Thus, one of ordinary skill in the art would have found it obvious before the effective filing date of applicant’s claimed invention to include using LLM for fraud detection as disclosed by He and be motivated in doing so because LLM is capable of handling massive amount of text data, often involving billions of words or text unit-He ¶0030 in parts. Regarding claim 2, Nunes in view He discloses the system of claim 1. Nunes further discloses wherein: the piece of content is an electronic message containing one or more types of content elements (¶0025-¶0027, “The online service provider that provides electronic transaction services may receive a large amount of communication attempts from legitimate users and malicious users, which include emails that are transmitted to a dedicated e-mail address associated with the online service provider, phone calls received via a support hotline associated with the online service provider, chat sessions initiated via a website of the online service provider, etc. These e-mails, calls, and chat interactions with the online service provider can be collectively referred to as customer inputs…”). Regarding claim 3, Nunes in view He discloses the system of claim 1. Nunes further discloses wherein: the fraud detection engine is configured to derive the plurality of features either directly from the piece of content (¶0028, “…The analysis system may extract topics using Latent Dirichlet Allocation (LDA), and select the best performing feature extraction model to extract features from the customer inputs..”), (¶0071, “… when the event detection server 150 detects a communication (e.g., an email, a call, a chat) from a user device to the service provider server 110, the feature extraction module 210 may extract features from the communication. The extracted features may include textual data features extracted from a text portion of the communication and/or audio data features extracted from an audio portion of the communication.”) or indirectly from an external source associated with the piece of content. Regarding claim 14, Nunes in view He discloses the method of claim 13. Nunes further discloses further comprising: deriving the plurality of features either directly from the piece of content or indirectly from an external source associated with the piece of content (¶0028, “…The analysis system may extract topics using Latent Dirichlet Allocation (LDA), and select the best performing feature extraction model to extract features from the customer inputs..”), (¶0071, “… when the event detection server 150 detects a communication (e.g., an email, a call, a chat) from a user device to the service provider server 110, the feature extraction module 210 may extract features from the communication. The extracted features may include textual data features extracted from a text portion of the communication and/or audio data features extracted from an audio portion of the communication.”) or indirectly from an external source associated with the piece of content. Regarding claim 4, Nunes in view He discloses the system of claim 1. Nunes further discloses wherein: the fraud detection engine is configured to transform the plurality of derived features into a set of numerical values representing the one or more fraud categories to facilitate classification by the one or more classification models (¶0044-¶0046, “the voice authentication system may determine whether the caller is a legitimate user of the user account using a voice model associated with the user account and corresponding to the call intention. When comparing the caller's audio sample (e.g., the keyword(s) extracted from the voice data) against the selected voice model, the voice authentication system or the voice model may generate an “accuracy” or “confidence” score. In some embodiments, the voice model may output a value (e.g., a confidence score) indicating how close the audio sample is to a voice of the same phrase generated by the model… upon detecting the incoming call, the voice authentication system may generate a voice vector based on the voice data of the incoming call. The voice authentication system may then compare the voice vector associated with the voice data of the caller with the voice vector generated for the voice model using the techniques disclosed herein. The voice authentication system and/or the voice model may determine a confidence score based on a similarity between the two voice vectors…”). See also ¶0140-0141. Regarding claim 15, Nunes in view He discloses the method of claim 13. Nunes further discloses further comprising: transforming the plurality of derived features into a set of numerical values representing the one or more fraud categories to facilitate classification by the one or more classification models (¶0044-¶0046, “the voice authentication system may determine whether the caller is a legitimate user of the user account using a voice model associated with the user account and corresponding to the call intention. When comparing the caller's audio sample (e.g., the keyword(s) extracted from the voice data) against the selected voice model, the voice authentication system or the voice model may generate an “accuracy” or “confidence” score. In some embodiments, the voice model may output a value (e.g., a confidence score) indicating how close the audio sample is to a voice of the same phrase generated by the model… upon detecting the incoming call, the voice authentication system may generate a voice vector based on the voice data of the incoming call. The voice authentication system may then compare the voice vector associated with the voice data of the caller with the voice vector generated for the voice model using the techniques disclosed herein. The voice authentication system and/or the voice model may determine a confidence score based on a similarity between the two voice vectors…”). See also ¶0140-0141. Regarding claim 5, Nunes in view He discloses the system of claim 1. Nunes further discloses wherein: the fraud detection engine is configured to block the piece of content if the piece of content is classified as fraudulent (¶0027, “…the analysis system may detect that a customer input is associated with a phishing scheme. The analysis system may then forward the customer input to a phishing sub-module for analysis and action. In another example, the analysis system may detect whether a customer input (e.g., an email) includes an attachment (e.g., a data file) that is malicious. The analysis system may then generate a signature for the attachment and may block the customer input from being presented in an email inbox.”). Regarding claim 16, Nunes in view He discloses the method of claim 13. Nunes further discloses further comprising: blocking the piece of content if the piece of content is classified as fraudulent (¶0027, “…the analysis system may detect that a customer input is associated with a phishing scheme. The analysis system may then forward the customer input to a phishing sub-module for analysis and action. In another example, the analysis system may detect whether a customer input (e.g., an email) includes an attachment (e.g., a data file) that is malicious. The analysis system may then generate a signature for the attachment and may block the customer input from being presented in an email inbox.”). Regarding claim 6, Nunes in view He discloses the system of claim 1. He further discloses wherein: the input prompt is pre-defined by a user for each of the one or more fraud categories (¶0003, “an online concierge system requests a large language model (LLM) to determine, based on a prompt input into the LLM, information about a refund event for a first order placed with an online concierge system by a user of the online concierge system. The online concierge system accesses a computer model of the online concierge system trained to detect a fraudulent behavior associated with an order placed with the online concierge system. The online concierge system applies the computer model to determine a score associated with the refund event, based on the information about the refund event received from the LLM. The online concierge system determines, based on the score, whether the refund event was due to a fraudulent behavior of the user. The online concierge system performs at least one action associated with the online concierge system, based on the determination of whether the refund event was due to the fraudulent behavior.”), (¶0082, “… the prompt comprises at least one of: a transcript of a conversation between a picker of the online concierge system 140 and the user, a transcript of a conversation between a user service of the online concierge system 140 and the user, a coded reason from the picker for the refund event, a request for classification of a reason for the refund event, or an image of a receipt associated with the first order. The LLM may be a multi-modal LLM configured to operate based on the prompt comprising textual data and image data.”), see also FIG. 4, ¶0081-¶0084. Thus, one of ordinary skill in the art would have found it obvious before the effective filing date of applicant’s claimed invention to modify the invention of Nunes and He to include the input prompt predefined by the user as disclosed by He and be motivated in doing so in order to determine if the refund for a transaction was due to a fraudulent behavior of the user-He ¶0003 in parts. Regarding claim 17, Nunes in view He discloses the method of claim 13. He further discloses wherein: the input prompt is pre-defined by a user for each of the one or more fraud categories (¶0003, “an online concierge system requests a large language model (LLM) to determine, based on a prompt input into the LLM, information about a refund event for a first order placed with an online concierge system by a user of the online concierge system. The online concierge system accesses a computer model of the online concierge system trained to detect a fraudulent behavior associated with an order placed with the online concierge system. The online concierge system applies the computer model to determine a score associated with the refund event, based on the information about the refund event received from the LLM. The online concierge system determines, based on the score, whether the refund event was due to a fraudulent behavior of the user. The online concierge system performs at least one action associated with the online concierge system, based on the determination of whether the refund event was due to the fraudulent behavior.”), (¶0082, “… the prompt comprises at least one of: a transcript of a conversation between a picker of the online concierge system 140 and the user, a transcript of a conversation between a user service of the online concierge system 140 and the user, a coded reason from the picker for the refund event, a request for classification of a reason for the refund event, or an image of a receipt associated with the first order. The LLM may be a multi-modal LLM configured to operate based on the prompt comprising textual data and image data.”), see also FIG. 4, ¶0081-¶0084. Thus, one of ordinary skill in the art would have found it obvious before the effective filing date of applicant’s claimed invention to modify the invention of Nunes and He to include the input prompt predefined by the user as disclosed by He and be motivated in doing so in order to determine if the refund for a transaction was due to a fraudulent behavior of the user-He ¶0003 in parts. Regarding claim 9, Nunes in view He discloses the system of claim 1. Nunes further discloses wherein: the report generation engine is configured to generate the fraud report at the input prompt either automatically without manual intervention by a human operator (¶0029, “… Once a cluster reaches a certain number of complaints, a report generation model can be triggered to generate a report…”), (¶0030, “…Once a predetermined number of complaints (e.g., exceeding a threshold) is identified, the analysis system may be triggered to generate a report…”) or upon a request from the user. Regarding claim 20, Nunes in view He discloses the method of claim 13. Nunes further discloses further comprising: generating the fraud report at the input prompt either automatically without manual intervention by a human operator (¶0029, “… Once a cluster reaches a certain number of complaints, a report generation model can be triggered to generate a report…”), (¶0030, “…Once a predetermined number of complaints (e.g., exceeding a threshold) is identified, the analysis system may be triggered to generate a report…”) or upon a request from the user. Regarding claim 10, Nunes in view He discloses the system of claim 1. Nunes further discloses wherein: the report generation engine is configured to personalize the generated fraud report to provide one or more insights for the user (¶0026, “… an analysis system may be configured to automatically classify and analyze customer inputs (e.g., email, phone, chat, etc.) for producing actionable insights related to fraud campaigns, phishing attacks, malware distribution, or product issues.”), (¶0035, “the browser analysis system provides in-depth and automatic testing of current and pre-release web applications with the intent of generating a comprehensive database of their behaviors, features, and functionality in order to provide additional capabilities for detection and mitigation of malicious actors using modified or spoofed client devices. The browser analysis system may also allow base lining for statistical modeling of browser traffic and can generate alert notifications of new functionality that can be implemented into anti-fraud defense mechanisms.”), (¶0029, “The analysis system may identify specific information from the complaints, such as email addresses of the customers or any transaction details, and derive patterns from the complaints that belong the same cluster such as country of origin of the customers, customer age range, network addresses used for the transaction, transaction amount that was charged, a description of the service if any, and so on. This information can be added to the report with all the insights gathered and forwarded to an agent device for further analysis and action. As such, the analysis system may increase the efficiency of handling customer inputs (e.g., legitimate customer inputs may be forwarded to the right personnel or chatbots to handle), while malicious customer inputs are properly classified and forwarded to different modules for further analysis and actions.”). Regarding claim 21, Nunes in view He discloses the method of claim 13. Nunes further discloses further comprising: personalizing the generated fraud report to provide one or more insights for the user (¶0026, “… an analysis system may be configured to automatically classify and analyze customer inputs (e.g., email, phone, chat, etc.) for producing actionable insights related to fraud campaigns, phishing attacks, malware distribution, or product issues.”), (¶0035, “the browser analysis system provides in-depth and automatic testing of current and pre-release web applications with the intent of generating a comprehensive database of their behaviors, features, and functionality in order to provide additional capabilities for detection and mitigation of malicious actors using modified or spoofed client devices. The browser analysis system may also allow base lining for statistical modeling of browser traffic and can generate alert notifications of new functionality that can be implemented into anti-fraud defense mechanisms.”), (¶0029, “The analysis system may identify specific information from the complaints, such as email addresses of the customers or any transaction details, and derive patterns from the complaints that belong the same cluster such as country of origin of the customers, customer age range, network addresses used for the transaction, transaction amount that was charged, a description of the service if any, and so on. This information can be added to the report with all the insights gathered and forwarded to an agent device for further analysis and action. As such, the analysis system may increase the efficiency of handling customer inputs (e.g., legitimate customer inputs may be forwarded to the right personnel or chatbots to handle), while malicious customer inputs are properly classified and forwarded to different modules for further analysis and actions.”). Regarding claim 11, Nunes in view He discloses the system of claim 1. He further discloses wherein: the report generation engine is configured to fine-tune the LLM by utilizing previously available data (¶0068-¶0069, “…when the model serving system 150 is included in the online concierge system 140, the machine-learning training module 230 may further train parameters of the machine-learned model based on data specific to the online concierge system 140 stored in the data store 240. As an example, the machine-learning training module 230 may obtain a pre-trained transformer language model and further fine tune the parameters of the transformer model using training data stored in the data store 240….”). Thus, one of ordinary skill in the art would have found it obvious before the effective filing date of applicant’s claimed invention to modify the invention of Nunes and He to include fine-tuning the model as disclosed He and be motivated in doing so in order to improve the performance and efficiency of the model. Regarding claim 22, Nunes in view He discloses the method of claim 13. He further discloses further comprising: fine-tuning the LLM by utilizing previously available data, wherein the previously available data includes previously generated fraud reports for the same or similar input prompt (¶0068-¶0069, “…when the model serving system 150 is included in the online concierge system 140, the machine-learning training module 230 may further train parameters of the machine-learned model based on data specific to the online concierge system 140 stored in the data store 240. As an example, the machine-learning training module 230 may obtain a pre-trained transformer language model and further fine tune the parameters of the transformer model using training data stored in the data store 240….”). Thus, one of ordinary skill in the art would have found it obvious before the effective filing date of applicant’s claimed invention to modify the invention of Nunes and He to include fine-tuning the model as disclosed He and be motivated in doing so in order to improve the performance and efficiency of the model. Regarding claim 12, Nunes in view He discloses the system of claim 11. Nunes further discloses wherein: the previously available data includes previously generated fraud reports for the same or similar input prompt (¶0029, “When the customer input is classified as a fraud complaint, the analysis system may cluster the customer input with other similar reported fraud activities (e.g., other customer inputs that have been classified as the same category). For example, a user may contact the online service provider to complain about receiving invoices related to renewing a website domain from a domain provider. When the analysis system classifies such a customer input as a fraud complaint, the analysis system may cluster such a customer input with other related complaints over invoices associated with renewing website domains…”). Claims 7 and 18 is rejected under 35 U.S.C. 103 as being unpatentable over US. PGPub. No. 20220114594 to Nunes et al. (hereinafter Nunes) in view of US. PGPub. No. 20240419941 to He et al. (hereinafter He) and further in view of US. PHPub. No. 20250165990 to BUTINCU et al. (hereinafter BUTINCU). Regarding claim 7, Nunes in view He discloses the system of claim 6. However, Nunes in view of He does not explicitly disclose the following limitation: wherein: the prompt generation engine is configured to accept a plurality of pre-defined category-specific prompts from the user; and maintain one or more pairs of the plurality of pre-defined category- specific prompts together with their corresponding fraud categories in a lookup table. BUTINCU discloses wherein: the prompt generation engine is configured to accept a plurality of pre-defined category-specific prompts from the user (¶0035, FIG. 1, “…In a further step 214, chatbot agent 20 may formulate an LM prompt 24 (FIG. 1) according to the current user message. An LM prompt herein denotes at least a part of an input to a natural language model. FIG. 4 shows an exemplary LM prompt 24 according to some embodiments of the present invention. Prompt 24 may include a set of LM instructions 24a. 24c specifying how LM model 40 should process the contents of a conversation and formulate questions and/or answers for the user. For instance, such instructions may set various parameters of LM 40, such as a style of conversation, a personality/avatar/name of the respective chatbot, a format for date and time, etc. Instructions 24a, 24c may further indicate a preferred output format of LM 40, for instance as text formulated in a natural language, as a set of attribute-value pairs, as a data object having a particular set of fields, etc.”); maintain one or more pairs of the plurality of pre-defined category- specific prompts together with their corresponding fraud categories in a lookup table (¶0056, “…knowledgebase 54a may store a table mapping text summaries to fraud categories, thus enabling NLP 34 to determine whether a text message is indicative of fraud according to a summary of the respective message. Such a table/mapping may be determined a-priori according to a reference corpus of messages comprising both legitimate and fraudulent messages belonging to various categories. Knowledgebase 54a may further store a table mapping fraud categories to category-specific explanations, recommendations, and/or advice for display to the user”). Thus, one of ordinary skill in the art would have found it obvious before the effective filing date of applicant’s claimed invention to modify the invention of Nunes and He to include maintain one or more pairs of the plurality of pre-defined category- specific prompts together with their corresponding fraud categories in a lookup table as disclosed by BUTINCU and be motivated in doing so in order to improve scalability for large language model applications and making prompt retrieval easy. Regarding claim 18, Nunes in view He discloses the method of claim 17. However, Nunes in view of He does not explicitly discloses the following limitation: further comprising: accepting a plurality of pre-defined category-specific prompts from the user; and maintaining one or more pairs of the plurality of pre-defined category-specific prompts together with their corresponding fraud categories in a lookup table. BUTINCU discloses accepting a plurality of pre-defined category-specific prompts from the user (¶0035, FIG. 1, “…In a further step 214, chatbot agent 20 may formulate an LM prompt 24 (FIG. 1) according to the current user message. An LM prompt herein denotes at least a part of an input to a natural language model. FIG. 4 shows an exemplary LM prompt 24 according to some embodiments of the present invention. Prompt 24 may include a set of LM instructions 24a. 24c specifying how LM model 40 should process the contents of a conversation and formulate questions and/or answers for the user. For instance, such instructions may set various parameters of LM 40, such as a style of conversation, a personality/avatar/name of the respective chatbot, a format for date and time, etc. Instructions 24a, 24c may further indicate a preferred output format of LM 40, for instance as text formulated in a natural language, as a set of attribute-value pairs, as a data object having a particular set of fields, etc.”); and maintaining one or more pairs of the plurality of pre-defined category-specific prompts together with their corresponding fraud categories in a lookup table (¶0056, “…knowledgebase 54a may store a table mapping text summaries to fraud categories, thus enabling NLP 34 to determine whether a text message is indicative of fraud according to a summary of the respective message. Such a table/mapping may be determined a-priori according to a reference corpus of messages comprising both legitimate and fraudulent messages belonging to various categories. Knowledgebase 54a may further store a table mapping fraud categories to category-specific explanations, recommendations, and/or advice for display to the user”). Thus, one of ordinary skill in the art would have found it obvious before the effective filing date of applicant’s claimed invention to modify the invention of Nunes and He to include maintain one or more pairs of the plurality of pre-defined category- specific prompts together with their corresponding fraud categories in a lookup table as disclosed by BUTINCU and be motivated in doing so in order to improve scalability for large language model applications and making prompt retrieval easy. Claims 8 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over US. PGPub. No. 20220114594 to Nunes et al. (hereinafter Nunes) in view of US. PGPub. No. 20240419941 to He et al. (hereinafter He) and further in view of US. PGPub. No. 20250165990 to BUTINCU et al. (hereinafter BUTINCU) and further in view of US. Pat. No. 7813944 to Luk et al. (hereinafter Luk). Regarding claim 8, Nunes in view He and further in view of BUTINCU discloses the system of claim 7. However, their combination does not explicitly disclose the following limitation: wherein: the prompt generation engine is configured to look up the one or more fraud categories and retrieve the corresponding input prompt from the lookup table. Luk discloses wherein: the prompt generation engine is configured to look up the one or more fraud categories and retrieve the corresponding input prompt from the lookup table (Coln. 14, Lines 20-29, “The system database 404 is structured into a useful arrangement of reference tables 608a that are used as the data source for the detection of premium fraud and abuse. In addition, the system database 404 optionally includes a results table 608b, which is used to store the model scores and explanations in association with their policies. Generally, the tables are organized around the insurance policies so that pertinent data for any insurance policy can be easily looked up or retrieved given a policy number or other keys.”), (Coln. 18, Lines 29-45, the lookup tables 616 may store values for peer group risk variables associated with one or more different classifications of policyholders or claimants into peer groups. The values are retrieved from the lookup tables 616 by looking up the appropriate value given the an applicable peer group risk value for the policy. Preferably, a given policy is classified as being in multiple different peer groups, with respect to various classification schemes. Thus, a policy may have an SIC peer group, an NCCI peer group, a peer group based on corporate legal form, a peer group based on policy age, and a peer group based on geographic location. The variable derivation process 614 may obtain the appropriate peer group risk variable for each of the peer groups of the policy.”, wherein values for peer group risk variables associated with one or more different classifications of policyholders or claimants is interpreted as the input prompt for the fraud categories). See also coln. 31, lines 15-28 and coln. 32, lines 39-51. Thus, one of ordinary skill in the art would have found it obvious before the effective filing date of applicant’s claimed invention to modify the invention of Nunes, He, BUTINCU to include retrieving of fraud categories input prompt in a lookup table as disclosed by Luk and be motivated in doing so in order to apply insurance policies on the retrieve prompt and thereby prevent fraudulent claims by policy holders- Luk Coln. 18, Lines 29. Regarding claim 19, Nunes in view He and further in view of BUTINCU discloses the method of claim 18. However, their combination does not explicitly disclose the following limitation: further comprising: looking up the one or more fraud categories and retrieve the corresponding input prompt from the lookup table. Luk discloses looking up the one or more fraud categories and retrieve the corresponding input prompt from the lookup table (Coln. 14, Lines 20-29, “The system database 404 is structured into a useful arrangement of reference tables 608a that are used as the data source for the detection of premium fraud and abuse. In addition, the system database 404 optionally includes a results table 608b, which is used to store the model scores and explanations in association with their policies. Generally, the tables are organized around the insurance policies so that pertinent data for any insurance policy can be easily looked up or retrieved given a policy number or other keys.”), (Coln. 18, Lines 29-45, the lookup tables 616 may store values for peer group risk variables associated with one or more different classifications of policyholders or claimants into peer groups. The values are retrieved from the lookup tables 616 by looking up the appropriate value given the an applicable peer group risk value for the policy. Preferably, a given policy is classified as being in multiple different peer groups, with respect to various classification schemes. Thus, a policy may have an SIC peer group, an NCCI peer group, a peer group based on corporate legal form, a peer group based on policy age, and a peer group based on geographic location. The variable derivation process 614 may obtain the appropriate peer group risk variable for each of the peer groups of the policy.”, wherein values for peer group risk variables associated with one or more different classifications of policyholders or claimants is interpreted as the input prompt for the fraud categories). See also coln. 31, lines 15-28 and coln. 32, lines 39-51. Thus, one of ordinary skill in the art would have found it obvious before the effective filing date of applicant’s claimed invention to modify the invention of Nunes, He, BUTINCU to include retrieving of fraud categories input prompt in a lookup table as disclosed by Luk and be motivated in doing so in order to apply insurance policies on the retrieve prompt and thereby prevent fraudulent claims by policy holders- Luk Coln. 18, Lines 29. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to MUDASIRU K OLAEGBE whose telephone number is (571)272-2082. The examiner can normally be reached MON-FRI. 7.30AM-5.30PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Farid Homayounmehr can be reached at 5712723739. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /MUDASIRU K OLAEGBE/Examiner, Art Unit 2495
Read full office action

Prosecution Timeline

May 01, 2025
Application Filed
Aug 05, 2026
Non-Final Rejection mailed — §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12688317
SYSTEM AND METHOD FOR ELECTRONIC ACCESS CONTROL IN MESH NETWORKED SITES
3y 8m to grant Granted Jul 21, 2026
Patent 12683932
DYNAMIC ROUTING OF APPLICATION TRAFFIC TO ZTNA CONNECTORS
3y 6m to grant Granted Jul 14, 2026
Patent 12676887
METHOD AND SYSTEM FOR GENERATING DECOY FILES USING A DEEP LEARNING ENGINE FOR PROTECTION AGAINST RANSOMWARE ATTACKS
3y 4m to grant Granted Jul 07, 2026
Patent 12621320
SYSTEMS, METHODS, AND APPARATUSES FOR DETERMINING RESOURCE MISAPPROPRIATION BASED ON DISTRIBUTION FREQUENCY IN AN ELECTRONIC NETWORK
3y 5m to grant Granted May 05, 2026
Patent 12574406
SYSTEM AND METHOD FOR DATA FILTERING IN MACHINE LEARNING MODEL TO DETECT IMPERSONATION ATTACKS
5y 3m to grant Granted Mar 10, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
74%
Grant Probability
88%
With Interview (+14.6%)
3y 1m (~1y 9m remaining)
Median Time to Grant
Low
PTA Risk
Based on 87 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month