Prosecution Insights
Last updated: October 04, 2026
Application No. 19/196,620

Scanning and Detecting Threats in Machine Learning Models

Non-Final OA §102§112
Filed
May 01, 2025
Priority
Feb 23, 2023 — continuation of 12/314,380
Examiner
GAVRILENKO, VLADIMIR I
Art Unit
Tech Center
Assignee
HiddenLayer, Inc.
OA Round
1 (Non-Final)
71%
Grant Probability
Favorable
1-2
OA Rounds
1y 8m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 71% — above average
71%
Career Allowance Rate
138 granted / 195 resolved
+10.8% vs TC avg
Strong +28% interview lift
Without
With
+28.3%
Interview Lift
resolved cases with interview
Typical timeline
3y 1m
Avg Prosecution
15 currently pending
Career history
207
Total Applications
across all art units

Statute-Specific Performance

§101
7.3%
-32.7% vs TC avg
§103
62.1%
+22.1% vs TC avg
§102
16.1%
-23.9% vs TC avg
§112
10.4%
-29.6% vs TC avg
Black line = Tech Center average estimate • Based on career data from 195 resolved cases

Office Action

§102 §112
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION Claims 1 – 20 posted on 05/01/2025 are presently pending in the application and have been examined below, of which claims 1, 8 and 15 are presented in independent form. Priority This application is a continuation of application 18/113444, now patent No. 12314380, which claimed priority date by 02/23/2023. Accordingly, the effective priority date for the subject matter defined in the pending claims of the instant application is 02/23/2023. Drawings The drawings were received on 05/01/2025. These drawings are accepted. Information Disclosure Statement The information disclosure statements (IDS) dated 08/15/2025 and 01/23/2026 have been received and considered. Examiner Notes Examiner cites paragraphs, columns and line numbers in the references as applied to the claims below for the convenience of the applicant. Although the specified citations are representative of the teachings in the art and are applied to the specific limitations within the individual claim, other passages and figures may apply as well. It is respectfully requested that, in preparing responses, the applicant fully consider the references in entirety as potentially teaching all or part of the claimed invention, as well as the context of the passage as taught by prior art or disclosed by the examiner. Claim Objections Claims 8 – 14 objected under 37 CFR 1.75 as being substantial duplicates of claims 1 – 7, respectively. The recited two sets of claims in an application both claiming methods, however, claims 8 – 14 are duplicates or else are so close in content to claims 1 – 7, respectively, that they cover the same things, despite a slight difference in wording. Accordingly, the recited methods are patentable indistinct, see MPEP § 608.01(m). Appropriate actions are required. Double Patenting The non-statutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the "right to exclude" granted by a patent and to prevent possible harassment by multiple assignees. A non-statutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on non-statutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). [AltContent: rect] The filing of a terminal disclaimer by itself is not a complete reply to a non-statutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13. [AltContent: rect] The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/ patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/ patents/apply/applying-online/eterminal-disclaimer. Claims 1 – 20 rejected on the ground of non-statutory obviousness-type double patenting as being unpatentable over claims 1 - 21 of U.S. Patent No. 12314380 (Reference Patent) in view of Tormasov et al. (US 20240205256). Although the claims at issue are not identical, they are not patentably distinct from each other because claims 1 – 21 of the Reference Patent anticipate the instant claims 1 – 16 as shown below for the first claim set where most of the limitations in claim 1 of instant application are anticipated by limitations in claims 1 and 16 of the reference patent. Claim # Instant Application Reference Patent (12314380) Claim # 1 A method for implementation by one or more computing devices for scanning a machine learning model for threats comprising receiving, by a scanning module, data for a machine learning model which is associated with model parameters and is received before execution of the machine learning model; performing, by the scanning module, a plurality of checks based on the received machine learning model data, the checks performed while the machine learning model is not executing, at least one of the checks identifying differences between the machine learning model and a corresponding base machine learning model; identifying, by the scanning module, whether the machine learning model includes a threat within the machine learning model based on results of the plurality of checks; and reporting, by the scanning module, the results to a remote computing device. 5.The method of claim 1, wherein performing a plurality of checks comprises determining an expected entropy for the machine learning model; determining the actual entropy for the machine learning model; calculating the difference between the expected entropy and the actual entropy; and identifying a threat if the difference in expected entropy and actual entropy exceeds a threshold. A method for scanning a machine learning model for threats, comprising: receiving, by a scanning module, data for a machine learning model, the scanning module stored on a first server, the data associated with model parameters and received before execution of the machine learning model; performing, by the scanning module, a plurality of checks based on the received machine learning model data, the checks performed while the machine learning model is not executing, the performing comprising: determining weights and biases of the machine learning model; determining an expected entropy for the machine learning model based on clustering of known machine learning models guided by calculated entropy; determining, based on the weights and biases, an actual entropy for the machine learning model; and calculating the difference between the expected entropy and the actual entropy; identifying, by the scanning module and based on the calculated difference, whether the machine learning model includes a threat within the machine learning model based on results of the plurality of checks; and adding, by the scanning module and based on the identifying, an indicator to the machine learning model characterizing actual, potential or detected threats within the machine learning model. 1 The reference patent (12314380) discloses a method for detecting potential threats in a network using machine learning models. Comparison between instant application and reference patent indicates that both are based on the same SPECS using identical drawings with respective disclosure. Both document sets, i.e., the instant application and the reference patent, have the same applicant/assignee and same inventors and both documents disclose the same inventive concept. Limitations related to the entropy metrics as related to the detected threat analysis are moved from independent claims to dependent claims. Accordingly, obviousness rejections in this office action are based on the application of Tormasov as indicated below, see MPEP § 804, § 2136, § 2137, § 2138, and § 2154. It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify the reference patent, in view of the teaching of Tormasov which discloses a method for threats detection in a network using entropy metrics for machine learning model training. The independent claims are rejected under the judicially created doctrine of double patenting as being directed to the same invention as that set forth in claims of the United States Patent No. 12314380 in view of Tormasov. The dependent claims of the current application recite language similar to the dependent claims of the reference patent and are covered by the reference patent in view of Tormasov. Accordingly, the instant application is identified as obviousness-type double patenting. Claim Rejections - 35 USC § 112 The following is a quotation of the first paragraph of 35 U.S.C. 112(a): (a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention. The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112: The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention. Claims 2, 5, 9, 12, 16 and 19 rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention. Claims 5, 12, 19 are using limitation ‘threshold’, i.e., specified criteria, by referring to a comparative analysis of entropy within the machine learning model. Specification appears silent as to support the claims using this limitation, see MPEP 2166. Claims 2, 9, and 16 are using limitation “generating a certificate”, i.e., a document containing certified statements, that is not supported by SPECS. For examination this limitation is considered as “generating a signature”. Claim Rejections - 35 USC § 102 The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention Claims 1 – 20 are rejected under 35 U.S.C. 102(a) (2) as being anticipated by Tormasov et al. (US 20240205256) (hereafter Tormasov). As per claim 1 Tormasov discloses: A method for implementation by one or more computing devices for scanning a machine learning model for threats (Tormasov, in para. [0014] discloses a threat detection method using machine learning module implementing a threat classification based on a machine-learning model) comprising receiving, by a scanning module, data for a machine learning model which is associated with model parameters and is received before execution of the machine learning model (Tormasov, in para. [0021] discloses operation of a scanning for threats withing the disclosed threat detection method); performing, by the scanning module, a plurality of checks based on the received machine learning model data, the checks performed while the machine learning model is not executing, at least one of the checks identifying differences between the machine learning model and a corresponding base machine learning model (Tormasov, in para. [0014, 0023] discloses threat detection procedure using a comparative analysis of the received data and those stored in a database using machine learning model); identifying, by the scanning module, whether the machine learning model includes a threat within the machine learning model based on results of the plurality of checks; and reporting, by the scanning module, the results to a remote computing device (Tormasov, in para. [0024 – 0026] discloses functionality of a threat testing environment to store detected threat, to identify detected threats for further implementation of the obtained threat features as numeric feature vectors for training the machine learning model). As per claim 2 Tormasov discloses: The method of claim 1 further comprising: generating a certificate based on determining that the machine learning model does not include a threat; and embedding the generated certificate within the data for the machine learning model device (Tormasov, in para. [0024] discloses generation a signature, i.e., a certificate, as related to a detected threat to train the machine learning model, [0026]). As per claim 3 Tormasov discloses: The method of claim 1, wherein the plurality of checks includes two or more of a file format check, a vulnerability check, a tampering check, and a stenography check (Tormasov, in para. [0034] discloses different testing scenarios for threat detection, i.e., plurality of threat checks). As per claim 4 Tormasov discloses: The method of claim 1 further comprising: executing the machine learning model in an isolated environment; monitoring the execution of the machine learning in the isolated environment to detect suspicious activity (Tormasov, in para. [0024] discloses secure threat testing to be implemented in isolated computing system). As per claim 5 Tormasov discloses: The method of claim 1, wherein performing a plurality of checks comprises determining an expected entropy for the machine learning model; determining the actual entropy for the machine learning model; calculating the difference between the expected entropy and the actual entropy (Tormasov, in para. [0014, 0023] discloses threat detection procedure using a comparative analysis of the received data and those stored in a database using machine learning model); and identifying a threat if the difference in expected entropy and actual entropy exceeds a threshold (Tormasov, in para. [0029, 0034] discloses collection of data entropy metrics, as well as usage of measured high entropy for file analysis and modifications [0023, 0039]). As per claim 6 Tormasov discloses: The method of claim 1, wherein an identified threat may be a potential threat or an actual threat (Tormasov, in para. [0025] discloses identification of detected threats as a class of threats or as a particular threat). As per claim 7 Tormasov discloses: The method of claim 1, wherein the scanning module is stored on a server forming part of a computing environment that includes the machine learning model (Tormasov, in para. [0024] discloses storage of detected malicious objects in database for analysis and machine learning model training). As per claim 8, claim 8 encompasses same or similar scope as claim 1. Therefore, claim 8 is rejected based on the same reasons set forth above in rejecting claim 1. As per claims 9 – 14, claims 9 – 14 encompass same or similar scope as claims 2 – 7, respectively. Therefore, claims 9 – 14 are rejected based on the same reasons set forth above in rejecting claim 2 – 7. As per claim 15, claim 15 encompasses same or similar scope as claim 1. Therefore, claim 15 is rejected based on the same reasons set forth above in rejecting claim 1. As per claims 16 – 20, claims 16 – 20 encompass same or similar scope as claims 2 – 6, respectively. Therefore, claims 16 – 20 are rejected based on the same reasons set forth above in rejecting claim 2 – 6. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure: Anderson US_11128664, Tellez US_11843622, Yellapragada US_20230205891. Any inquiry concerning this communication or earlier communications from the examiner should be directed to VLADIMIR IVANOVICH GAVRILENKO whose telephone number is (313)446-6530. The examiner can normally be reached on Monday-Friday 7:30-4:30 EST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Lynn Feild can be reached on (571) 272-2092. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see https://ppair-my.uspto.gov/pair/PrivatePair. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /VLADIMIR I GAVRILENKO/Examiner, Art Unit 2431
Read full office action

Prosecution Timeline

May 01, 2025
Application Filed
Aug 26, 2026
Non-Final Rejection mailed — §102, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12748871
RESOURCE MANAGEMENT METHOD, COMPUTING DEVICE, COMPUTING EQUIPMENT, AND READABLE STORAGE MEDIUM
3y 10m to grant Granted Sep 29, 2026
Patent 12732375
METHOD AND PROGRAM
3y 1m to grant Granted Sep 08, 2026
Patent 12706756
COMPUTER-IMPLEMENTED SYSTEM AND METHOD INCLUDING PUBLIC KEY COMBINATION VERIFICATION
1y 10m to grant Granted Aug 11, 2026
Patent 12699810
DE-IDENTIFICATION PROCESSING METHOD FOR MANAGEMENT OF PERSONAL IDENTIFICATION INFORMATION AND APPARATUS THEREFOR
1y 10m to grant Granted Aug 04, 2026
Patent 12689532
SMART CONTRACT ENABLED USER ACCOUNT ACCESS
2y 4m to grant Granted Jul 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
71%
Grant Probability
99%
With Interview (+28.3%)
3y 1m (~1y 8m remaining)
Median Time to Grant
Low
PTA Risk
Based on 195 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month