Prosecution Insights
Last updated: October 04, 2026
Application No. 19/221,071

Attack Mitigation for Artificial Intelligence and Machine Learning Systems

Non-Final OA §103
Filed
May 28, 2025
Priority
May 29, 2024 — provisional 63/653,016
Examiner
REZA, MOHAMMAD W
Art Unit
Tech Center
Assignee
Styrk Inc.
OA Round
1 (Non-Final)
88%
Grant Probability
Favorable
1-2
OA Rounds
1y 4m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 88% — above average
88%
Career Allowance Rate
839 granted / 959 resolved
+27.5% vs TC avg
Moderate +11% lift
Without
With
+11.2%
Interview Lift
resolved cases with interview
Typical timeline
2y 8m
Avg Prosecution
11 currently pending
Career history
974
Total Applications
across all art units

Statute-Specific Performance

§101
17.5%
-22.5% vs TC avg
§103
46.0%
+6.0% vs TC avg
§102
6.7%
-33.3% vs TC avg
§112
12.6%
-27.4% vs TC avg
Black line = Tech Center average estimate • Based on career data from 959 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION Claims 1-21 are presented for examination. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 3. Claims 1-21 are rejected under 35 U.S.C. 103 as being unpatentable over DiValentin et al hereafter DiValentin (US pat. App. Pub. 20240386096) and in view of Amballa et al hereafter Amballa (US pat. App. 20260187251). 4. As per claim 1, and 14, DiValentin discloses a method and a non-transitory computer-readable medium storing executable code comprising: receiving data to be analyzed by an artificial intelligence (AI) system, wherein the data is perturbed by an attack (paragraphs: 20, 41, and 47, wherein it emphasizes input the data into an artificial intelligence system for analysis wherein the data is perturbed); and performing a counterattack on the data as a part of an attack mitigation, wherein the counterattack comprises further perturbing the data (paragraphs: 13, 21, and 51-52, wherein it elaborates performing a defense of the attack by further perturbing the data). Although, DiValentin teaches data to be analyzed by an AI system, wherein the data is perturbed. In the same field of endeavor, Amballa discloses data to be analyzed by an artificial intelligence (AI) system wherein the data is perturbed by an attack (paragraphs: 12-13, 17, and 22-23). Accordingly, it would been obvious to one of ordinary skill in the network security art before the effective filing date of the claimed invention to have incorporated Amballa’s teachings of data to be analyzed by an artificial intelligence (AI) system wherein the data is perturbed by an attack with the teachings of DiValentin, for the purpose of effectively protecting the data from any unauthorized intruders. 5. As per claim 2, DiValentin and in view of Amballa discloses the method, wherein the counterattack is a fast gradient sign method (FGSM) attack (DiValentin, paragraphs: 70-71). 6. As per claim 3, DiValentin and in view of Amballa discloses the method, wherein the counterattack increases a loss on one or more incorrect labels in the data, thereby compensating for mislabeling in the data caused by the perturbation due to the attack (DiValentin, paragraphs: 39-41). 7. As per claim 4, DiValentin and in view of Amballa discloses the method, wherein the data is known to be perturbed by the attack, but a nature of the attack is unknown (DiValentin, paragraphs: 43-45). 8. As per claim 5, DiValentin and in view of Amballa discloses the method, further comprising detecting the perturbation due to the attack in the data (DiValentin, paragraphs: 48, 50, and 51). 9. As per claim 6, DiValentin and in view of Amballa discloses the method, wherein the counterattack is performed responsive to the detecting (DiValentin, paragraphs: 57-59). 10. As per claim 7, DiValentin and in view of Amballa discloses the method, wherein the counterattack is agnostic to a nature or a type of the attack (DiValentin, paragraphs: 83, 85, and 93). 11. As per claim 8, DiValentin and in view of Amballa discloses the method, wherein the counterattack reduces or eliminates an effect of the perturbation (DiValentin, paragraphs: 100, and 106). 12. As per claim 9, DiValentin discloses a method comprising: receiving data to be analyzed by an artificial intelligence (AI) system running on a computing system; analyzing the data to determine a presence of a perturbation (paragraphs: 20, 41, and 47); responsive to determining the presence, performing an attack mitigation; and inputting the data after the attack mitigation to the AI system for the analysis (paragraphs: 13, 21, and 51-52). Although, DiValentin teaches analyzing the data to determine a presence of a perturbation. In the same field of endeavor, Amballa discloses analyzing the data to determine a presence of a perturbation or an attack (paragraphs: 12-13, 17, and 22-23). Accordingly, it would been obvious to one of ordinary skill in the network security art before the effective filing date of the claimed invention to have incorporated Amballa’s teachings of analyzing the data to determine a presence of a perturbation or an attack with the teachings of DiValentin, for the purpose of effectively protecting the data from any unauthorized intruders. 13. As per claim 10, DiValentin and in view of Amballa discloses the method, wherein the attack mitigation comprises further perturbing the data via a counterattack (DiValentin, paragraphs: 19, and 20). 14. As per claim 11, DiValentin and in view of Amballa discloses the method, wherein the counterattack is a fast gradient sign method (FGSM) attack (DiValentin, paragraphs: 70-71). 15. As per claim 12, DiValentin and in view of Amballa discloses the method, wherein the counterattack increases a loss on one or more incorrect labels in the data, thereby compensating for mislabeling in the data caused by the perturbation or attack (DiValentin, paragraphs: 39-41). 16. As per claim 13, DiValentin and in view of Amballa discloses the method, wherein the attack mitigation process is agnostic to a nature or a type of the perturbation or attack (DiValentin, paragraphs: 83, 85, and 93). 17. Claims 15-21 are listed all the same elements of claims 2-8. Therefore, the supporting rationales of the rejection to claims 2-8 apply equally as well to claims 15-21. Citation of References 18. The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. The following references are cited but not been replied upon for this office action: Lee et al (US pat. app. Pub. 20220180242): discusses obfuscating a trained configuration of a trained machine learning model. A trained machine learning model processes input data to generate an initial output vector having classification values for each of the plurality of predefined classes. A perturbation insertion engine determines a subset of classification values in the initial output vector into which to insert perturbations. A perturbation insertion engine modifies classification values in the subset of classification values by inserting a perturbation in a function associated with generating the output vector for the classification values in the subset of classification values, to thereby generate a modified output vector. The trained machine learning model outputs the modified output vector. The perturbation modifies the subset of classification values to obfuscate the trained configuration of the trained machine learning model while maintaining accuracy of classification of the input data. Dixon et al (US pat. 12619770): elaborates that a trained artificial intelligence (AI) component, and a disinformation processing module and processing circuitry configured to execute stored instructions to perform actions including providing customer information stored in the customer database as input to the trained AI component, receiving potential customer disinformation as output from the trained AI component, analyzing and modifying the potential customer disinformation using the disinformation processing module to yield customer disinformation, and providing a portion of the customer disinformation to an untrusted client device, a malicious website, a third party service, or any combination thereof. Conclusion 19. Any inquiry concerning this communication or earlier communications from the examiner should be directed to MOHAMMAD W REZA whose telephone number is (571)272-6590. The examiner can normally be reached on Monday-Friday 8:30-5:30 ET. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Cathy Thiaw can be reached on 571-270-1138. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). /MOHAMMAD W REZA/Primary Examiner, Art Unit 2407
Read full office action

Prosecution Timeline

May 28, 2025
Application Filed
Sep 22, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12748886
Format-Preserving Tokenization
2y 8m to grant Granted Sep 29, 2026
Patent 12748891
METHODS AND SYSTEMS FOR SUBJECT INFORMATION DATA CLEANSING AND MANAGEMENT USING MACHINE LEARNING
1y 10m to grant Granted Sep 29, 2026
Patent 12732386
STATEMENT PROOF AND VERIFICATION
1y 11m to grant Granted Sep 08, 2026
Patent 12717938
ACCESS CONTROL SYSTEM FOR AUTOMATICALLY ADJUSTING ACCESS TO RESOURCES IN RESPONSE TO DETECTING A ROLE CHANGE
2y 9m to grant Granted Aug 25, 2026
Patent 12711268
A SYSTEM AND METHOD FOR DATA MANAGEMENT IN A VEHICLE
2y 7m to grant Granted Aug 18, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
88%
Grant Probability
99%
With Interview (+11.2%)
2y 8m (~1y 4m remaining)
Median Time to Grant
Low
PTA Risk
Based on 959 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month