Prosecution Insights
Last updated: October 02, 2026
Application No. 19/233,959

ARTIFICIAL INTELLIGENCE AND MACHINE LEARNING DEFENSE CONTROLLER FOR PROMPT AND ANSWER INSPECTION

Non-Final OA §102§103
Filed
Jun 10, 2025
Priority
Feb 13, 2025 — IN 202541012296
Examiner
RAHMAN, SM AZIZUR
Art Unit
2434
Tech Center
2400 — Computer Networks
Assignee
Cisco Technology Inc.
OA Round
1 (Non-Final)
88%
Grant Probability
Favorable
1-2
OA Rounds
1y 3m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 88% — above average
88%
Career Allowance Rate
471 granted / 532 resolved
+30.5% vs TC avg
Strong +18% interview lift
Without
With
+17.7%
Interview Lift
resolved cases with interview
Typical timeline
2y 7m
Avg Prosecution
12 currently pending
Career history
544
Total Applications
across all art units

Statute-Specific Performance

§101
7.6%
-32.4% vs TC avg
§103
53.3%
+13.3% vs TC avg
§102
33.8%
-6.2% vs TC avg
§112
3.5%
-36.5% vs TC avg
Black line = Tech Center average estimate • Based on career data from 532 resolved cases

Office Action

§102 §103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Detailed action 1. Status of Claims: Claims 1-20 are pending in this Office Action. Information Disclosure Statement 2. The information disclosure statement (IDS) submitted on 06/10/2025 and 05/15/2026 are in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Priority 3. Examiner acknowledges that this application claims priority to Indian Patent Application No. 202541012296, filed February 13, 2025, entitled “ARTIFICIAL INTELLIGENCE AND MACHINE LEARNING DEFENSE CONTROLLER FOR PROMPT AND ANSWER INSPECTION” which is incorporated by reference herein in its entirety. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 4. Claims 1-16 are rejected under 35 U.S.C. 103 as being unpatentable over US 2014/0359691 issued to Woods et al. (Woods) (Applicant IDS) in view of US 2019/0268381 issued to Narayanaswamy et al. (Narayanaswami) (Applicant IDS). As per claim 1, Woods teaches a system for inspecting machine learning (ML) based payloads (Woods: ¶ 0039 - artificial intelligence (AI)-based learning machine), comprising: a runtime inspection engine configured to determine whether to allow a request or response to or from a first machine learning model based on an inspection of a payload of the request or the response (Woods: ¶ 0039 - an open-domain Q&A system that is an NLP artificial intelligence (AI)-based learning machine. A machine of this type may combine natural language processing, machine learning, and hypothesis generation and evaluation; it receives queries and provides direct, confidence-based responses to those queries), wherein the runtime inspection engine is configured to analyze a natural language prompt in the request to determine whether the request corresponds to a permitted scope associated with an application generating the request (Woods: ¶ 0040 - generating a number of candidate passages from the corpus that answer an input query, and finds the correct resulting answer by collecting supporting evidence from the multiple passages. By analyzing all retrieved passages and that passage's metadata in parallel, there is generated an output plurality of data structures including candidate answers based upon the analyzing step), wherein the runtime inspection engine is configured to analyze an answer in the response and determine whether the response corresponds to the permitted scope (Woods: ¶ 0040 - by each of a plurality of parallel operating modules, supporting passage retrieval operations are performed upon the set of candidate answers; for each candidate answer, the data corpus is traversed to find those passages having candidate answer in addition to query terms); Woods however does not explicitly teach and a discovery engine configured to identify ML assets and applications implementing ML models, wherein the discovery engine is further configured to detect runtime usage of a workload that uses a second ML model that is unsanctioned. Narayanaswamy however explicitly teaches a discovery engine configured to identify ML assets and applications implementing ML models (Narayanaswami: ¶ 0196 - teaches the raw event data is stored in metadata store 196 analyzed using machine learning techniques to establish the baseline), wherein the discovery engine is further configured to detect runtime usage of a workload that uses a second ML model that is unsanctioned (Narayanaswamy: ¶ 0433 - detecting an attempt to transfer a content file from a sanctioned cloud computing service (CCS) to an unsanctioned CCS through modification of a file identifier (ID) of the content file by using an integrity checksum of the content file to look up a file profile of the first content file in the supplemental data store). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of Woods in view of Narayanaswami to teach a discovery engine configured to identify ML assets and applications implementing ML models, wherein the discovery engine is further configured to detect runtime usage of a workload that uses a second ML model that is unsanctioned. One would be motivated to do so as detecting an attempt to transfer a content file from a sanctioned cloud computing service (CCS) to an unsanctioned CCS through modification of a file identifier (ID) of the content file by using an integrity checksum of the content file to look up a file profile of the first content file in the supplemental data store (Narayanaswamy: ¶ 0433). As per claim 2, the modified teaching of Woods teaches the system of claim 1, wherein the runtime inspection engine includes a first pipeline configured to inspect the request or the response and approve benign traffic based on a plurality of guardrails, wherein each guardrail is configured to classify whether a prompt in the request or an answer in the response corresponds to unsafe activity (Woods: ¶ 0007 - the query is then directed to the Q&A system to determine whether the action constitutes (or may lead to) a policy violation (safe or unsafe)). As per claim 3, the modified teaching of Woods teaches the system of claim 2, wherein the runtime inspection engine includes a second pipeline configured to inspect the request or the response based on identification of unsafe activity and identify content in the request or the response that corresponds to the unsafe activity (Woods: ¶ 0007 - the Q&A system response identifies whether the action is compliant with the term of use policy document, and the response also may include supporting evidence. The user's computing device may then take an appropriate action, e.g., policy enforcement, restricting or disabling functionality, alerting or warning the user to noncompliance, or the like). As per claim 4, the modified teaching of Woods teaches the system of claim 1, wherein the system comprises a validation engine configured to: execute a plurality of tests against an application or an ML model, wherein the plurality of tests are configured to invoke a response deemed insecure or improper; and determine vulnerabilities associated with the application or the ML model based on responses associated with the plurality of tests (Narayanaswami: ¶ 0090 - whether shadow or sanctioned, cloud service usage is growing and C-suites, boards of directors, and audit committees around the world are beginning to ask whether the cloud technologies in their environment are safe, compliant with business policies, and perform according to vendor service-level agreements. Accordingly, it is desirable that IT can confidently answer these questions and assuage these concerns). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of Woods in view of Narayanaswami to teach wherein the system comprises a validation engine configured to: execute a plurality of tests against an application or an ML model, wherein the plurality of tests are configured to invoke a response deemed insecure or improper; and determine vulnerabilities associated with the application or the ML model based on responses associated with the plurality of tests. One would be motivated to do so as whether shadow or sanctioned, cloud service usage is growing and C-suites, boards of directors, and audit committees around the world are beginning to ask whether the cloud technologies in their environment are safe, compliant with business policies, and perform according to vendor service-level agreements. Accordingly, it is desirable that IT can confidently answer these questions and assuage these concerns (Narayanaswamy: ¶ 0090). As per claim 5, Woods teaches a system for inspecting machine learning (ML) based payloads (Woods: ¶ 0039 - artificial intelligence (AI)-based learning machine), comprising: a runtime inspection engine configured to determine whether to allow a request or response to or from a first machine learning model based on an inspection of a payload of the request or the response (Woods: ¶ 0039 - an open-domain Q&A system that is an NLP artificial intelligence (AI)-based learning machine. A machine of this type may combine natural language processing, machine learning, and hypothesis generation and evaluation; it receives queries and provides direct, confidence-based responses to those queries); and a training inspection engine configured to inspect data provided to an ML training service during training of a third ML model and determine whether the data includes sensitive information or unsafe content (Woods: ¶ 0007 - the query is then directed to the Q&A system to determine whether the action constitutes (or may lead to) a policy violation (safe or unsafe)). Woods however does not explicitly teach a discovery engine configured to identify runtime usage of a workload that uses a second ML model, wherein the discovery engine detects the workload based on inspection of traffic and logs; Narayanaswamy however explicitly teaches a discovery engine configured to identify runtime usage of a workload that uses a second ML model, wherein the discovery engine detects the workload based on inspection of traffic and logs (Narayanaswamy: ¶ 0396 - a content file upload, download, or modification activity (traffic) is detected. In one implementation, this is detected by evaluating an event log entry of the transaction during which the activity is performed); It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of Woods in view of Narayanaswami to teach a discovery engine configured to identify runtime usage of a workload that uses a second ML model, wherein the discovery engine detects the workload based on inspection of traffic and logs. One would be motivated to do so as a content file upload, download, or modification activity (traffic) is detected. In one implementation, this is detected by evaluating an event log entry of the transaction during which the activity is performed (Narayanaswamy: ¶ 0396). As per claim 6, the modified teaching of Woods teaches the system of claim 5, wherein the runtime inspection engine is connected to at least one of: a multicloud defense system deployed across a plurality of cloud systems for inspecting cloud-based traffic; a secure client forming a virtual private network; and a firewall associated with a private network (Woods: ¶ 0044 - the Q&A system is accessible over private network). As per claim 7, the modified teaching of Woods teaches the system of claim 5, wherein the inspection engine includes a first pipeline configured to inspect the request or the response and approve benign traffic based on a plurality of guardrails, wherein each guardrail is configured to classify whether a prompt in the request or an answer in the response corresponds to unsafe activity (Woods: ¶ 0046 - the natural language processing (NLP)-based question and answer (Q&A) system 404 is trained to understand the policy document. As will be described in more detail below, the computing device includes a policy management application or functionality that is designed to interact with the Q&A system to identify a policy violation (or a potential policy violation)). As per claim 8, the modified teaching of Woods teaches the system of claim 7, wherein the inspection engine includes a second pipeline configured to inspect the request or the response based on identification of unsafe activity and identify content in the request or the response that corresponds to the unsafe activity (Woods: ¶ 0007 - the Q&A system response identifies whether the action is compliant with the term of use policy document, and the response also may include supporting evidence). As per claim 9, the modified teaching of Woods teaches the system of claim 5, further comprising a semantic cache for identifying usage patterns and application patterns (Woods: ¶ 0031 - memory may be, for example, memory or a cache such as found in an interface and memory controller hub that may be present in communications fabric). As per claim 10, the modified teaching of Woods teaches the system of claim 5, further comprising an unsanctioned application engine configured to identify usage of an application using an unsanctioned machine learning model (Narayanaswami: ¶ 0089 - manage and secure all of the cloud services running across the organization, whether "shadow IT" (unsanctioned) or sanctioned, or to enforce security or compliance controls). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of Woods in view of Narayanaswami to teach an unsanctioned application engine configured to identify usage of an application using an unsanctioned machine learning model. One would be motivated to do so as an application can manage and secure all of the cloud services running across the organization, whether "shadow IT" (unsanctioned) or sanctioned, or to enforce security or compliance controls (Narayanaswamy: ¶ 0089). As per claim 11, the modified teaching of Woods teaches the system of claim 5, wherein the runtime inspection engine is configured to analyze a natural language prompt in the request to determine whether the request corresponds to a permitted scope associated with an application generating the request (Woods: ¶ 0041 - the Q&A system may be implemented using a natural language processing technology that allows applications to process natural language text). As per claim 12, the modified teaching of Woods teaches the system of claim 5, wherein the runtime inspection engine is configured to analyze an answer in the response and determine whether the response corresponds to a permitted scope (Woods: ¶ 0046 - policy document defines permissible actions that may be implemented by a user using a computing device while the natural language processing (NLP)-based question and answer (Q&A) system 404 is trained to understand the policy document). As per claim 13, the modified teaching of Woods teaches the system of claim 5, wherein the runtime inspection engine is configured to: inspect the request or the response for data leakage or data poisoning (Woods: ¶ 0039 - an NLP artificial intelligence (AI)-based learning machine may combine natural language processing, machine learning, and hypothesis generation and evaluation; it receives queries and provides direct, confidence-based responses to those queries). As per claim 14, the claim resembles claim 4 and is rejected under the same rationale. As per claim 15, the modified teaching of Woods teaches the system of claim 5, wherein the runtime inspection engine comprises a proxy mode for proxying requests and responses (Narayanaswami: ¶ 0266 - active proxy analyzer enforces a policy that allows upload of sensitive documents if the upload is attempted by internal users) and an inspection mode for inspecting and authorizing API requests (Narayanaswami: ¶ 0376 - the security action includes generating one or more coaching messages that identify a more enterprise-ready alternative to the API in use). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of Woods in view of Narayanaswami to teach wherein the runtime inspection engine comprises a proxy mode for proxying requests and responses and an inspection mode for inspecting and authorizing API requests. One would be motivated to do so as an active proxy analyzer enforces a policy that allows upload of sensitive documents if the upload is attempted by internal users and the security action includes generating one or more coaching messages that identify a more enterprise-ready alternative to the API in use (Narayanaswamy: ¶ 0266, ¶ 0376). As per claim 16, the modified teaching of Woods teaches the system of claim 5, further comprising a log inspection engine configured to access third-party logs and logs associated with the system to identify usage of ML models (Woods: ¶ 0048 - notifying a third party person or entity of the policy violation, writing a log entry in the user's personnel file, and many others). 5. Claim 20 is rejected under 35 U.S.C. 103 as being unpatentable over US 2014/0359691 issued to Woods et al. (Woods) (Applicant IDS) in view of US 2025/0298874 issued to Mardikar et al. (Mardikar). As per claim 20, Woods teaches the method of claim 17, further comprising: identifying ML models and applications employing ML models accessible to clients within a private network (Woods: ¶ 0044 - the Q&A system is accessible over private network); Woods however does not explicitly teach and generating signatures associated with the ML models and prompts that are denied based on testing of the ML models, wherein the authorization for the prompt or the answer is based on a comparison to the signatures. Mardikar however explicitly teaches and generating signatures associated with the ML models and prompts that are denied based on testing of the ML models, wherein the authorization for the prompt or the answer is based on a comparison to the signatures (Mardikar: Fig. 3 - generate User Signature Associated with User Account Using Machine Learning Model Trained On Training Data, Compare Subsequent User Input To User Signature Associated With User Account and if the subsequent user input does not match the signature with user account then out of band authentication is initiated (access is denied and another authentication is needed)). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of Woods in view of Mardikar to teach and generating signatures associated with the ML models and prompts that are denied based on testing of the ML models, wherein the authorization for the prompt or the answer is based on a comparison to the signatures. One would be motivated to do so as generate User Signature Associated with User Account Using Machine Learning Model Trained on Training Data, Compare Subsequent User Input to User Signature Associated With User Account and if the subsequent user input does not match the signature with user account then out of band authentication is initiated (access is denied and another authentication is needed) (Mardikar: Fig. 3). Claim Rejections - 35 USC § 102 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention. 6. Claim 17-19 are rejected under 35 U.S.C. 102 (a) (1) as being anticipated by US 2014/0359691 issued to Woods et al. (Woods) (Applicant IDS). As per claim 17, Woods teaches a method comprising: receiving, by a defense controller for machine learning (ML) or artificial intelligence (AI) based content (Woods: ¶ 0039 - artificial intelligence (AI)-based learning machine), a prompt for an ML model including a natural language task to perform (Woods: Abstract - a natural language processing (NLP)-based question and answer (Q&A) system); determining whether the prompt is authorized to be provided to the ML model based on the natural language task (Woods: ¶ 0039 - an open-domain Q&A system that is an NLP artificial intelligence (AI)-based learning machine. A machine of this type may combine natural language processing, machine learning, and hypothesis generation and evaluation; it receives queries and provides direct, confidence-based responses to those queries); providing authorization in response to the prompt based on whether the prompt is authorized; based on providing the prompt to the ML model, receiving an answer from the ML model (Woods: ¶ 0040 - generating a number of candidate passages from the corpus that answer an input query, and finds the correct resulting answer by collecting supporting evidence from the multiple passages. By analyzing all retrieved passages and that passage's metadata in parallel, there is generated an output plurality of data structures including candidate answers based upon the analyzing step), wherein the answer comprises at least a portion of natural language content (Woods: ¶ 0038 - Q&A system should be able to retrieve answers to questions posed in natural language); and determining whether the answer is authorized for a requesting device based on content within the answer (Woods: ¶ 0038 - find appropriate documents that might contain the answer, and to extract the correct answer to be delivered to the user). As per claim 18, Woods teaches the method of claim 17, wherein the prompt is provided to the defense controller by at least one of a gateway of a multicloud defense system, a secure access client for accessing a private network, or a container in a distributed application (Woods: ¶ 0044 - the Q&A system is accessible over private network). As per claim 19, Woods teaches the method of claim 17, wherein the defense controller is configured to determine whether the answer is authorized based on the prompt based and content within the answer (Woods: ¶ 0039 - an open-domain Q&A system that is an NLP artificial intelligence (AI)-based learning machine. A machine of this type may combine natural language processing, machine learning, and hypothesis generation and evaluation; it receives queries and provides direct, confidence-based responses to those queries). Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to SM AZIZUR RAHMAN whose telephone number is (571) 270-7360. The examiner can normally be reached on M-F Telework; If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Ali Shayanfar can be reached on 571-270-1050. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /SM A RAHMAN/Primary Examiner, Art Unit 2434
Read full office action

Prosecution Timeline

Jun 10, 2025
Application Filed
Aug 12, 2026
Non-Final Rejection mailed — §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12746933
SYSTEMS AND METHODS FOR TRACKING HISTORIC DRIVER DATA ON THE EDGE
2y 2m to grant Granted Sep 29, 2026
Patent 12750227
APPARATUS FOR PROVIDING MONITORING SERVICE OF NEURAL CONSENSUS-BASED BLOCKCHAIN NETWORK SYSTEM TO MANAGE SAFETY QUALITY AND DISTRIBUTION HISTORY, AND OPERATION METHOD THEREOF
1y 5m to grant Granted Sep 29, 2026
Patent 12743536
SECURITY COMPUTER DEVICE AND METHOD FOR KEY-VALUE STORE USING LOG-STRUCTURED MERGE-TREE
1y 10m to grant Granted Sep 22, 2026
Patent 12739247
WAKING SILENT NETWORK DEVICES FOR AUTHENTICATION
2y 1m to grant Granted Sep 15, 2026
Patent 12725039
GENERATION OF WEIGHTS FOR CAUSAL INFERENCES
3y 1m to grant Granted Sep 01, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
88%
Grant Probability
99%
With Interview (+17.7%)
2y 7m (~1y 3m remaining)
Median Time to Grant
Low
PTA Risk
Based on 532 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month