Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
Claims 1-21 are presented for examination.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
3. Claims 1-21 are rejected under 35 U.S.C. 103 as being unpatentable over DiValentin et al hereafter DiValentin (US pat. App. Pub. 20240386096) and in view of Amballa et al hereafter Amballa (US pat. App. 20260187251).
4. As per claim 1, and 14, DiValentin discloses a method and a non-transitory computer-readable medium storing executable code comprising: receiving data to be analyzed by an artificial intelligence (AI) system, wherein the data is perturbed by an attack (paragraphs: 20, 41, and 47, wherein it emphasizes input the data into an artificial intelligence system for analysis wherein the data is perturbed); and performing a counterattack on the data as a part of an attack mitigation, wherein the counterattack comprises further perturbing the data (paragraphs: 13, 21, and 51-52, wherein it elaborates performing a defense of the attack by further perturbing the data). Although, DiValentin teaches data to be analyzed by an AI system, wherein the data is perturbed. In the same field of endeavor, Amballa discloses data to be analyzed by an artificial intelligence (AI) system wherein the data is perturbed by an attack (paragraphs: 12-13, 17, and 22-23).
Accordingly, it would been obvious to one of ordinary skill in the network security art before the effective filing date of the claimed invention to have incorporated Amballa’s teachings of data to be analyzed by an artificial intelligence (AI) system wherein the data is perturbed by an attack with the teachings of DiValentin, for the purpose of effectively protecting the data from any unauthorized intruders.
5. As per claim 2, DiValentin and in view of Amballa discloses the method, wherein the counterattack is a fast gradient sign method (FGSM) attack (DiValentin, paragraphs: 70-71).
6. As per claim 3, DiValentin and in view of Amballa discloses the method, wherein the counterattack increases a loss on one or more incorrect labels in the data, thereby compensating for mislabeling in the data caused by the perturbation due to the attack (DiValentin, paragraphs: 39-41).
7. As per claim 4, DiValentin and in view of Amballa discloses the method, wherein the data is known to be perturbed by the attack, but a nature of the attack is unknown (DiValentin, paragraphs: 43-45).
8. As per claim 5, DiValentin and in view of Amballa discloses the method, further comprising detecting the perturbation due to the attack in the data (DiValentin, paragraphs: 48, 50, and 51).
9. As per claim 6, DiValentin and in view of Amballa discloses the method, wherein the counterattack is performed responsive to the detecting (DiValentin, paragraphs: 57-59).
10. As per claim 7, DiValentin and in view of Amballa discloses the method, wherein the counterattack is agnostic to a nature or a type of the attack (DiValentin, paragraphs: 83, 85, and 93).
11. As per claim 8, DiValentin and in view of Amballa discloses the method, wherein the counterattack reduces or eliminates an effect of the perturbation (DiValentin, paragraphs: 100, and 106).
12. As per claim 9, DiValentin discloses a method comprising: receiving data to be analyzed by an artificial intelligence (AI) system running on a computing system; analyzing the data to determine a presence of a perturbation (paragraphs: 20, 41, and 47); responsive to determining the presence, performing an attack mitigation; and inputting the data after the attack mitigation to the AI system for the analysis (paragraphs: 13, 21, and 51-52). Although, DiValentin teaches analyzing the data to determine a presence of a perturbation. In the same field of endeavor, Amballa discloses analyzing the data to determine a presence of a perturbation or an attack (paragraphs: 12-13, 17, and 22-23).
Accordingly, it would been obvious to one of ordinary skill in the network security art before the effective filing date of the claimed invention to have incorporated Amballa’s teachings of analyzing the data to determine a presence of a perturbation or an attack with the teachings of DiValentin, for the purpose of effectively protecting the data from any unauthorized intruders.
13. As per claim 10, DiValentin and in view of Amballa discloses the method, wherein the attack mitigation comprises further perturbing the data via a counterattack (DiValentin, paragraphs: 19, and 20).
14. As per claim 11, DiValentin and in view of Amballa discloses the method, wherein the counterattack is a fast gradient sign method (FGSM) attack (DiValentin, paragraphs: 70-71).
15. As per claim 12, DiValentin and in view of Amballa discloses the method, wherein the counterattack increases a loss on one or more incorrect labels in the data, thereby compensating for mislabeling in the data caused by the perturbation or attack (DiValentin, paragraphs: 39-41).
16. As per claim 13, DiValentin and in view of Amballa discloses the method, wherein the attack mitigation process is agnostic to a nature or a type of the perturbation or attack (DiValentin, paragraphs: 83, 85, and 93).
17. Claims 15-21 are listed all the same elements of claims 2-8. Therefore, the supporting rationales of the rejection to claims 2-8 apply equally as well to claims 15-21.
Citation of References
18. The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. The following references are cited but not been replied upon for this office action:
Lee et al (US pat. app. Pub. 20220180242): discusses obfuscating a trained configuration of a trained machine learning model. A trained machine learning model processes input data to generate an initial output vector having classification values for each of the plurality of predefined classes. A perturbation insertion engine determines a subset of classification values in the initial output vector into which to insert perturbations. A perturbation insertion engine modifies classification values in the subset of classification values by inserting a perturbation in a function associated with generating the output vector for the classification values in the subset of classification values, to thereby generate a modified output vector. The trained machine learning model outputs the modified output vector. The perturbation modifies the subset of classification values to obfuscate the trained configuration of the trained machine learning model while maintaining accuracy of classification of the input data.
Dixon et al (US pat. 12619770): elaborates that a trained artificial intelligence (AI) component, and a disinformation processing module and processing circuitry configured to execute stored instructions to perform actions including providing customer information stored in the customer database as input to the trained AI component, receiving potential customer disinformation as output from the trained AI component, analyzing and modifying the potential customer disinformation using the disinformation processing module to yield customer disinformation, and providing a portion of the customer disinformation to an untrusted client device, a malicious website, a third party service, or any combination thereof.
Conclusion
19. Any inquiry concerning this communication or earlier communications from the examiner should be directed to MOHAMMAD W REZA whose telephone number is (571)272-6590. The examiner can normally be reached on Monday-Friday 8:30-5:30 ET.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Cathy Thiaw can be reached on 571-270-1138. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free).
/MOHAMMAD W REZA/Primary Examiner, Art Unit 2407