Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
This is the initial office action that has been issued in response to patent application, 19/265,916, filed on 07/10/2025. Claims 1-15 are currently pending and have been considered below. Claims 1, and 14-15 are independent claims.
Priority
This application is a CON of 17/853,768 filed 06/29/2022 PAT 12541591.
The application claims priority of provisional application 17/853,768 has PRO 63/350,296 filed on 06/08/2022 and 17/853,768 has PRO 63/334,574 filed on 04/25/2022.
Drawings
The drawings filed on 07/10/2025 are accepted by the examiner.
Information Disclosure Statement
The information disclosure statements (IDS’s) submitted on 12/23/2025 and 07/20/2026 are in compliance with provisions of 37 CFR 1.97. Accordingly, the information disclosure statement.
Specification
The disclosure is objected to because it contains an embedded hyperlink and/or other form of browser-executable code. Applicant is required to delete the embedded hyperlink and/or other form of browser-executable code; references to websites should be limited to the top-level domain name without any prefix such as http:// or other browser-executable code. See MPEP § 608.01.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 4, 7 and 10 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claims 4, 7 and 10 recite the limitation "the image based model". There is insufficient antecedent basis for this limitation in the claim.
Double Patenting
The non-statutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A non-statutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on non-statutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/process/file/efs/guidance/eTD-info-I.jsp.
Claims 1, 3, 6 and 8-15 are rejected on the grounds of non-statutory obviousness-type double patenting as being unpatentable over claims 1, 2, 4, 6-23 of US Patent No. 12541591 B2.
Although the claims at issue are not identical, they are not patentably distinct from each other because the claims in the U.S. Patent No. 12,541,591 contain every element of claims of the instant application. The instant claims merely omit certain limitations recited in the patented claims and therefore represent broader versions of the claimed invention. The omission of those limitations does not render the instant claims patentably distinct from the patented claims. For example, please see claim 1 of current application mapping below.
This is a non-statutory obviousness-type double-patenting rejection because the pending claims are not patentably distinct from the patented claims. The pending independent claims recite the same malicious-document detection architecture and knowledge-transfer pipeline as the patented claims, while merely omitting limitations concerning maliciously labeled training documents, multipage rendered images, and a benign verdict. The removal of those limitations merely broadens the patented subject matter and does not create a distinct invention. The pending dependent claims recite limitations that are expressly claimed in corresponding dependent claims of U.S. Patent No. 12,541,591. Therefore, the pending claims are broader versions, direct restatements, or obvious variants of the patented claims.
For example, a limitation-by-limitation comparison of claim 1 of the instant application with the corresponding patented claim is provided below.
Current Application No. 19/265916
US Patent No. 12541591 B2
A system, comprising: a processor configured to: receive a document for a maliciousness determination;
determine a likelihood that the document received for the maliciousness determination represents a threat, at least in part using a raw bytes model,
wherein the raw bytes model was trained, at least in part,
using image model prediction probabilities obtained from an image model trained, at least in part,
using a plurality of images generated in a pipeline that converts a plurality of documents into a corresponding io plurality of rendered images of those documents;
and provide as output a verdict for the document based at least in part on the determined likelihood;
and a memory coupled to the processor and configured to provide the processor with instructions.
A system, comprising:
a processor configured to:
receive a document for a maliciousness determination;
determine a likelihood that the document received for the maliciousness determination represents a threat, at least in part using a raw bytes model,
wherein the raw bytes model was trained, at least in part,
using image model prediction probabilities obtained from an image model trained, at least in part,
using a plurality of images generated in a pipeline that converts a plurality of documents labeled as malicious into a corresponding plurality of rendered images of those documents,
wherein at least some of the corresponding plurality of rendered images are rendered, collectively, from a multi-page document labeled as a malicious document;
and provide as output a verdict for the document based at least in part on the determined likelihood,
wherein the verdict is that the received document is benign;
and a memory coupled to the processor and configured to provide the processor with instructions.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-4, 7-11 and 13-15 are rejected under 35 U.S.C. 103 as being unpatentable over Saxe(US Publication No. 20190236273 A1) in view of West (US Publication No. 20210326436 A1).
Regarding Claim 1:
Saxe discloses:
A system, comprising: a processor configured to(Saxe, Fig. 1, [0003], a memory and a processor):
receive a document for a maliciousness determination(Saxe, [0003], The processor receives multiple potentially malicious files, [0020], detect malware within several file formats and/or types such as, for example, Microsoft® Office documents );
determine a likelihood that the document received for the maliciousness determination represents a threat, at least in part using a raw bytes model(Saxe, [0035], a threat analyzer, and via the analyzer, can receive a potentially malicious file and calculate an attribute associated with the potentially malicious file, [0036], …the process proceeds to step 132 where raw bytes are “dumped” (i.e., read) from the central directory of the ZIP archive, and subsequently, at 133, features (e.g., data) of the document files are extracted (with the extraction being limited to the central directory…),
wherein the raw bytes model was trained, at least in part, using image model prediction probabilities obtained from an image model trained, at least in part(Saxe, [0036], the process proceeds to step 132 where raw bytes are “dumped” (i.e., read) from the central directory of the ZIP archive, [0061], with reference to FIG. 7B), and providing the first feature vector to the machine learning model to identify (at 1034) a maliciousness classification of the first potentially malicious file. Alternatively or in addition, the machine learning model can be trained using one or more other features),
using a plurality of images generated in a pipeline that converts a plurality of documents into a corresponding io plurality of rendered images of those documents(Saxe, [0030], Open XML formatted office documents contain similar objects, but are compressed as archives via ZIP standard compression. Within each archive, the path to the embedded content is specified via XML. The user interface unpacks and renders relevant content within the ZIP archive.);
and a memory coupled to the processor and configured to provide the processor with instructions(Saxe, FIG. 1, label 120 and 110, [0057], a memory and a processor communicatively coupled to the memory, the memory storing processor-executable instructions),
Saxe does not disclose:
and provide as output a verdict for the document based at least in part on the determined likelihood
West disclsoes:
and provide as output a verdict for the document based at least in part on the determined likelihood(West, [0022], the machine learning model 160 outputs a likelihood that the activity is indicative of malicious behavior,);
Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art to modify Saxe’s methods and apparatus for detecting malicious documents using machine learning by enhancing Saxe’s system to provide, as output, a verdict for a document based at least in part on a determined likelihood that the document represents a threat, as taught by West, to ensure that the likelihood generated by the machine-learning analysis is converted into an actionable classification indicating whether the document is malicious or benign.
The motivation is to ensure that the determined threat likelihood is translated into an actionable verdict that can be used to allow, block, quarantine, or further analyze the document.
Regarding Claim 2:
Saxe in view of West disclose:
The system of claim 1,
wherein the verdict is that the received document is benign(Saxe, [0055], a file, and the output is a scalar malicious or benign label. [0058], The maliciousness classifications can indicate whether the associated potentially malicious file is malicious or benign,).
Regarding Claim 3:
Saxe in view of West disclose:
The system of claim 1,
wherein determining the likelihood does not require converting a portion of the received document into an image(Saxe, [0036], a document that is being processed using process 100B is a regular XML file (non-archive), the process flow will proceed from step 131 directly to the extraction step at 133 (without passing step 132). Alternatively, if the document that is being processed using process 100B is an archive-type XML file (e.g., Office Open XML)).
Regarding Claim 4:
Saxe in view of West disclose:
The system of claim 1, wherein the image based model is trained, at least in part, using a plurality of images labeled as malicious documents(Saxe, [0063], Malicious/benign labels were assigned on a 5+/1− basis, i.e., for documents for which one or fewer vendors labeled malicious, the aggregate label benign was ascribed, while for documents for which 5 or more vendors labeled malicious,).
Regarding Claim 7:
Saxe in view of West disclose:
The system of claim 1, wherein the processor is further configured to generate the image based model(Saxe, [0047], a malware file including an image is modified to be included with a different image, while the portion of the histogram associated with the image might change).
Regarding Claim 8:
Saxe in view of West disclose:
The system of claim 1, wherein the image based model is a convolutional neural network model(Saxe, [0022], neural networks, e.g., convolutional)..
Regarding Claim 9:
Saxe in view of West disclose:
The system of claim 1, wherein the raw bytes model is a convolutional neural network model(Saxe, [0022], neural networks, e.g., convolutional).
Regarding Claim 10:
Saxe in view of West disclose:
The system of claim 1, wherein, at least in part in response to receiving an indication of a false positive result(Saxe, [0062], …These datasets were used to provide estimates of thresholds for false positive rates …),
the image based model is retrained using a benign data set that includes the false positive result(Saxe, [0062], benign Microsoft® Office documents was collected from a second data source (i.e., a “second dataset”). These datasets were used to provide estimates of thresholds for false positive), [0068], …the majority of cases, signs of malicious payloads and code obfuscation were found, suggesting that a significant number of “false positive).
Regarding Claim 11:
Saxe in view of West disclose:
The system of claim 1, wherein the document is a Microsoft Office document(Saxe, [0020], Machine learning can be used as a static countermeasure to detect malware within several file formats and/or types such as, for example, Microsoft® Office documents).
Regarding Claim 13:
Saxe in view of West disclose:
The system of claim 1, wherein a loss function used in training the raw bytes model comprises both self loss and imitation loss(Saxe, [0055], …dropout and batch normalization regularization methods can be used, with a dropout ratio of 0.2. At the final output, a sigmoid cross-entropy loss function can be used… [0056], …In some implementations, for gradient boosted ensembles, a regularized logistic sigmoid cross-entropy loss function can be used, similar to that of the neural network).
Regarding Claim 14:
Saxe discloses:
A method, comprising receiving a document for a maliciousness determination(Saxe, [0003], The processor receives multiple potentially malicious files, [0020], detect malware within several file formats and/or types such as, for example, Microsoft® Office documents );
determining a likelihood that the document received for the maliciousness determination represents a threat, at least in part using a raw bytes model(Saxe, [0035], a threat analyzer, and via the analyzer, can receive a potentially malicious file and calculate an attribute associated with the potentially malicious file, [0036], …the process proceeds to step 132 where raw bytes are “dumped” (i.e., read) from the central directory of the ZIP archive, and subsequently, at 133, features (e.g., data) of the document files are extracted (with the extraction being limited to the central directory…),
wherein the raw bytes model was trained, at least in part, using image model prediction probabilities obtained from an image model trained, at least in part(Saxe, [0036], the process proceeds to step 132 where raw bytes are “dumped” (i.e., read) from the central directory of the ZIP archive, [0061], with reference to FIG. 7B), and providing the first feature vector to the machine learning model to identify (at 1034) a maliciousness classification of the first potentially malicious file. Alternatively or in addition, the machine learning model can be trained using one or more other features),
using a plurality of images generated in a pipeline that converts a is plurality of documents into a corresponding plurality of rendered images of those documents(Saxe, [0030], Open XML formatted office documents contain similar objects, but are compressed as archives via ZIP standard compression. Within each archive, the path to the embedded content is specified via XML. The user interface unpacks and renders relevant content within the ZIP archive.);
Saxe does not disclose:
and providing as output a verdict for the document based at least in part on the determined likelihood
West discloses:
and providing as output a verdict for the document based at least in part on the determined likelihood(West, [0022], the machine learning model 160 outputs a likelihood that the activity is indicative of malicious behavior,).
Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art to modify Saxe’s methods and apparatus for detecting malicious documents using machine learning by enhancing Saxe’s system to provide, as output, a verdict for a document based at least in part on a determined likelihood that the document represents a threat, as taught by West, to ensure that the likelihood generated by the machine-learning analysis is converted into an actionable classification indicating whether the document is malicious or benign.
The motivation is to ensure that the determined threat likelihood is translated into an actionable verdict that can be used to allow, block, quarantine, or further analyze the document.
Regarding Claim 15:
Saxe discloses:
A computer program product embodied in a non-transitory computer readable medium and comprising computer instructions for(Saxe, [0004], a non-transitory processor-readable medium stores code representing instructions to be executed by a processor.):
receiving a document for a maliciousness determination(Saxe, [0003], The processor receives multiple potentially malicious files, [0020], detect malware within several file formats and/or types such as, for example, Microsoft® Office documents ); ;
determining a likelihood that the document received for the maliciousness determination represents a threat, at least in part using a raw bytes model(Saxe, [0035], a threat analyzer, and via the analyzer, can receive a potentially malicious file and calculate an attribute associated with the potentially malicious file, [0036], …the process proceeds to step 132 where raw bytes are “dumped” (i.e., read) from the central directory of the ZIP archive, and subsequently, at 133, features (e.g., data) of the document files are extracted (with the extraction being limited to the central directory…),
wherein the raw bytes model was trained, at least in part, using image model prediction probabilities obtained from an image 25 model trained, at least in part(Saxe, [0036], the process proceeds to step 132 where raw bytes are “dumped” (i.e., read) from the central directory of the ZIP archive, [0061], with reference to FIG. 7B), and providing the first feature vector to the machine learning model to identify (at 1034) a maliciousness classification of the first potentially malicious file. Alternatively or in addition, the machine learning model can be trained using one or more other features),
using a plurality of images generated in a pipeline that converts a plurality of documents into a corresponding plurality of rendered images of those documents(Saxe, [0030], Open XML formatted office documents contain similar objects, but are compressed as archives via ZIP standard compression. Within each archive, the path to the embedded content is specified via XML. The user interface unpacks and renders relevant content within the ZIP archive.);
Saxe does not disclose:
and providing as output a verdict for the document based at least in part on the determined likelihood
West discloses:
and providing as output a verdict for the document based at least in part on the determined likelihood(West, [0022], the machine learning model 160 outputs a likelihood that the activity is indicative of malicious behavior,).
Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art to modify Saxe’s methods and apparatus for detecting malicious documents using machine learning by enhancing Saxe’s system to provide, as output, a verdict for a document based at least in part on a determined likelihood that the document represents a threat, as taught by West, to ensure that the likelihood generated by the machine-learning analysis is converted into an actionable classification indicating whether the document is malicious or benign.
The motivation is to ensure that the determined threat likelihood is translated into an actionable verdict that can be used to allow, block, quarantine, or further analyze the document.
Claims 5-6 are rejected under 35 U.S.C. 103 as being unpatentable over Saxe(US Publication No. 20190236273 A1) in view of West (US Publication No. 20210326436 A1) in further view of Andriushchenko(US Publication No. 20230222762 A1).
Regarding Claim 5:
Saxe in view of West disclose:
The system of claim 1,
Saxe in view of West do not disclose:
wherein, prior to training the image model, an image hash based filtering operation is performed on at least some of the plurality of images
Andriushchenko discloses:
wherein, prior to training the image model, an image hash based filtering operation is performed on at least some of the plurality of images(Andriushchenko, [0022], the image comparison model generates a manipulation prediction (e.g., manipulated or not manipulated) and provide the manipulation prediction for display with the digital image and other provenance information. Accordingly, the visual fingerprinting system can train a deep neural... [0043], a binary hash value of a digital image, [0042], The digital image 204 can also include a frame of a digital video or a visual portion of another digital creative (e.g., a sub-portion of a digital document).
Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art to modify Saxe in view of West’s methods and apparatus for detecting malicious documents using machine learning by enhancing Saxe in view of West’s the combined system to perform an image-hash-based filtering operation on at least some of the images before training the image model, to ensure that duplicate or substantially similar images are identified and removed from the training dataset, as taught by Andriushchenko, in order to enhance training efficiency, reduce redundant processing, and prevent duplicative images from disproportionately influencing the trained model.
The motivation is to ensure that the image model is trained using a representative, nonredundant dataset while conserving memory and processing resources.
Regarding Claim 6:
Saxe in view of West in further view of Andriushchenko disclose:
The system of claim 5, wherein filtered images are stored using a TFRecord data format(Andriushchenko, [0043], a visual fingerprint can include a binary hash value of a digital image, such that duplicate copies of the digital image will have the same binary hash value. [0044], the digital image 204 with visual fingerprints of other digital images (e.g., digital images and visual fingerprints stored at the database 108).) .
Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art to modify Saxe in view of West’s methods and apparatus for detecting malicious documents using machine learning by enhancing Saxe in view of West’s the combined system to store images selected through the image-hash-based filtering operation using a TFRecord data format, to ensure that the filtered training samples are stored in a structured format suitable for efficient retrieval and model training, as taught by Andriushchenko, in order to enhance the efficiency, scalability, and throughput of the machine-learning training pipeline.
The motivation is to ensure efficient storage, retrieval, and processing of the filtered image-training data during training of the image model.
Claim 12 are rejected under 35 U.S.C. 103 as being unpatentable over Saxe(US Publication No. 20190236273 A1) in view of West (US Publication No. 20210326436 A1) in further view of Hinton(“Distilling the Knowledge in a Neural Network”)
Regarding Claim 12:
Saxe in view of West disclose:
The system of claim 1,
Saxe in view of West do not disclose:
wherein training the raw bytes model includes using knowledge distillation
Hinton discloses:
wherein training the raw bytes model includes using knowledge distillation(Hinton, Section 2, In the simplest form of distillation, knowledge is transferred to the distilled model by training it on a transfer set).
Before the effective filing date of the claimed invention, it would have been obvious to one with ordinary skill in the art to modify Saxe in view of West’s methods and apparatus for detection of malicious documents using machine learning by enhancing Saxe in view of West’s systems for training the raw bytes model using knowledge distillation to ensure that knowledge learned by a more complex model is transferred to a smaller and more computationally efficient model, as taught by Hinton, in order to enhance the efficiency and deployability of the malicious-document detection system while retaining predictive accuracy.
The motivation is to ensure accurate malicious-document detection with reduced memory usage, computational cost, and inference latency.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to MAYASA SHAAWAT whose telephone number is (571)272-3939. The examiner can normally be reached on M-F, 8 AM TO 5 PM.
If attempts to reach the examiner by telephone are unsuccessful, the examiner's supervisor, JEFFREY PWU can be reached on (571)272-6798. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see https://ppair-my.uspto.gov/pair/PrivatePair. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/MAYASA SHAAWAT/
Examiner, Art Unit 2433
/JEFFREY C PWU/Supervisory Patent Examiner, Art Unit 2433