IP Library Granted Patent US 12,437,239
Granted Patent B2
US 12,437,239 · App. 17/168,913 · Granted Oct 7, 2025

Methods and apparatus for management of a machine-learning model to adapt to changes in landscape of potentially malicious artifacts

Inventors: Richard Harang (Alexandria, VA); Felipe Ducau (Oxford, GB)
Assignee: Sophos Limited
G06N20/20G06F18/213G06F18/214G06F18/2178G06F18/22G06N5/01G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,437,239
App. No.
17/168,913
Granted
Oct 7, 2025
Kind
B2
Abstract

An apparatus can include a memory and a processor. The processor can be configured to train a machine-learning (ML) model to output (1) an identification of whether an artifact is malicious and (2) a confidence value associated with the identification of whether the artifact is malicious. The processor can further be configured to receive a set of artifacts during a set of time periods, and provide a representation of each artifact from the set of artifacts to obtain as an output of the ML model including an indication of whether that artifact is malicious and a confidence value associated with the indication. The processor can be further configured to calculate a confidence metric for each time period based on the confidence value associated with each artifact and send an indication to retrain the ML model based on the confidence metric for at least one time period meeting a retraining criterion.

Claims (35)

1. An apparatus, comprising:

a memory; and

a processor operatively coupled to the memory, the processor configured to:

train, at a first time, a machine learning model to output (1) an identification of whether an artifact is malicious and (2) a confidence value associated with the identification of whether the artifact is malicious;

receive a set of artifacts during each time period from a set of time periods, each time period from the set of time periods being after the first time;

for each time period from the set of time periods, provide a feature vector representative of each artifact from the set of artifacts received during that time period to the machine learning model to obtain as an output of the machine learning model an indication of whether that artifact is malicious and a confidence value associated with the indication of whether that artifact is malicious based on a degree of similarity of the feature vector with a set of feature vectors representative of a set of training artifacts used to train the machine learning model at the first time;

calculate a confidence metric for each time period from the set of time periods based on the confidence value associated with a number of artifacts from the set of artifacts received during that time period meeting a confidence value threshold;

calculate a rate of change in confidence based on the confidence metric for at least two time periods from the set of time periods;

in response to the rate of change in confidence meeting a retraining criterion:

receive, over a network and at a second time after the first time, an updated set of training artifacts; and

retrain, based on the updated set of training artifacts, the machine learning model.

2. The apparatus of claim 1 , wherein each time period from the set of time periods overlaps at least one remaining time period from the set of time periods.

3. The apparatus of claim 1 , wherein each time period from the set of time periods is mutually exclusive of remaining time periods from the set of time periods.

4. The apparatus of claim 1 , wherein the machine learning model is at least one of a neural network, a decision tree or a random forest.

5. The apparatus of claim 1 , wherein the confidence metric for each time period from the set of time periods is a percentage associated with (1) the number of artifacts from the set of artifacts received during that time period that have a confidence value above the confidence value threshold and (2) a total number of artifacts from the set of artifacts received during that time period.

6. A method, comprising:

training, at a first time, a machine learning model to output (1) an identification of whether an artifact is malicious and (2) a confidence value associated with the identification of whether the artifact is malicious;

receiving, during a first time period after the first time, a set of artifacts;

for each artifact from the set of artifacts, providing a feature vector representative of that artifact as an input to the machine learning model to obtain as an output of the machine learning model an indication of whether that artifact is malicious and a confidence value associated with the indication of whether that artifact is malicious based on a degree of similarity of the feature vector with a set of feature vectors representative of a set of training artifacts used to train the machine learning model at the first time;

comparing the confidence value for each artifact from the set of artifacts to a confidence criterion to identify a first metric associated with a first number of artifacts having confidence values that do not meet the confidence criterion; and

in response to a rate of change between the first metric and a second metric meeting a retraining criterion:

receiving, over a network and at a second time after the first time, an updated set of training artifacts; and

retraining, based on the updated set of training artifacts, the machine learning model;

the second metric associated with a second number of artifacts including artifacts (1) from a set of artifacts received during a second time period after the first time period and (2) having confidence values not meeting the confidence criterion.

7. The method of claim 6 , wherein the first metric is a percentage associated with (1) the first number of artifacts and (2) a total number of artifacts received during the first time period.

8. The method of claim 6 , wherein the machine learning model is at least one of a neural network, a decision tree or a random forest.

9. The apparatus of claim 1 , wherein the confidence value threshold includes a high confidence criterion and a low confidence criterion, the processor is further configured to:

compare the confidence value for each artifact from the set of artifacts, for a time period from the set of time periods, to the high confidence criterion to identify a number of artifacts having confidence values that meet the high confidence criterion; and

compare the confidence value for each artifact from the set of artifacts, for a time period from the set of time periods, to the low confidence criterion to identify a number of artifacts having confidence values that meet the low confidence criterion;

the confidence metric for that time period from the set of time periods being based on at least one of (1) the number of artifacts having confidence values that meet the high confidence criterion from the set of artifacts received during that time period, or (2) the number of artifacts having confidence values that meet the low confidence criterion from the set of artifacts received during that time period.

10. The apparatus of claim 9 , wherein the confidence metric is based on the number of artifacts, from the set of artifacts received during that time period, having confidence values that meet the high confidence criterion.

11. The apparatus of claim 9 , wherein the confidence metric is based on the number of artifacts, from the set of artifacts received during that time period, having confidence values that meet the low confidence criterion.

12. The apparatus of claim 1 , wherein the degree of similarity is defined by a Euclidean distance between the feature vector of each artifact from the set of artifacts received during that time period and the set of feature vectors of the set of training artifacts used to train the machine learning model at the first time.

13. The method of claim 6 , wherein the degree of similarity is defined by a Euclidean distance between the feature vector of each artifact from the set of artifacts received during the first time period and the set of feature vectors of the set of training artifacts used to train the machine learning model at the first time.

14. The method of claim 6 , wherein the first metric is at least one of a median of the first number of artifacts or a standard deviation of the first number of artifacts.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 9, 2021
From: HARANG, RICHARD; DUCAU, FELIPE
To: SOPHOS LIMITED
Reel/Frame 055200/0151 →
Continuity (3)
Continuation PCTGB2019052222 · Aug 7, 2019
Provisional Application 62715762 · Aug 7, 2018
Related Publication 20210241175A1 · Aug 5, 2021
References Cited (279)
US 7069589B2 · Schmall et al. · 2006 [cited by applicant]
US 7204152B2 · Woodward et al. · 2007 [cited by applicant]
US 7219148B2 · Rounthwaite et al. · 2007 [cited by applicant]
US 7545986B2 · Bachmann · 2009 [cited by applicant]
US 7558832B2 · Rounthwaite et al. · 2009 [cited by applicant]
US 7711663B2 · Weng · 2010 [cited by applicant]
US 7769772B2 · Weyl et al. · 2010 [cited by applicant]
US 7934103B2 · Kidron · 2011 [cited by applicant]
US 8413244B1 · Nachenberg · 2013 [cited by examiner]
US 8458794B1 · Sallam · 2013 [cited by applicant]
US 8635700B2 · Richard et al. · 2014 [cited by applicant]
US 8709924B2 · Hanawa et al. · 2014 [cited by applicant]
US 9189730B1 · Coenen et al. · 2015 [cited by applicant]
US 9404833B2 · Stadlbauer et al. · 2016 [cited by applicant]
US 9465940B1 · Wojnowicz et al. · 2016 [cited by applicant]
US 9514391B2 · Perronnin et al. · 2016 [cited by applicant]
US 9531742B2 · Kohout et al. · 2016 [cited by applicant]
US 9672358B1 · Long et al. · 2017 [cited by applicant]
US 9680868B2 · Bailey et al. · 2017 [cited by applicant]
US 9690938B1 · Saxe et al. · 2017 [cited by applicant]
US 9721097B1 · Davis et al. · 2017 [cited by applicant]
US 9792492B2 · Soldevila et al. · 2017 [cited by applicant]
US 9807113B2 · Yang et al. · 2017 [cited by applicant]
US 9864956B1 · Sai · 2018 [cited by applicant]
US 10015150B2 · Basin · 2018 [cited by applicant]
US 10193902B1 · Caspi · 2019 [cited by applicant]
US 10380498B1 · Chaoji · 2019 [cited by examiner]
US 10521587B1 · Agranonik et al. · 2019 [cited by applicant]
US 10599844B2 · Schmidtler et al. · 2020 [cited by applicant]
US 10635813B2 · Saxe et al. · 2020 [cited by applicant]
US 10742591B2 · Nguyen et al. · 2020 [cited by applicant]
US 10834128B1 · Rajagopalan et al. · 2020 [cited by applicant]
US 10924503B1 · Pereira · 2021 [cited by examiner]
US 10956477B1 · Fang et al. · 2021 [cited by applicant]
US 11003774B2 · Saxe et al. · 2021 [cited by applicant]
US 11063881B1 · Vijayasuganthan et al. · 2021 [cited by applicant]
US 11069082B1 · Ebrahimi Afrouzi et al. · 2021 [cited by applicant]
US 11170104B1 · Stickle · 2021 [cited by examiner]
US 11188649B2 · Chistyakov · 2021 [cited by examiner]
US 11270205B2 · Harang · 2022 [cited by applicant]
US 11321607B2 · Shah et al. · 2022 [cited by applicant]
US 11409869B2 · Schmidtler et al. · 2022 [cited by applicant]
US 11568301B1 · Yueh · 2023 [cited by examiner]
US 11574052B2 · Harang · 2023 [cited by applicant]
US 11609991B2 · Saxe et al. · 2023 [cited by applicant]
US 11620713B2 · Ashly · 2023 [cited by examiner]
US 11663602B2 · Hindi · 2023 [cited by examiner]
US 11822374B2 · Saxe et al. · 2023 [cited by applicant]
US 11941491B2 · Harang et al. · 2024 [cited by applicant]
US 11947668B2 · Harang · 2024 [cited by applicant]
US 11961410B1 · Lin · 2024 [cited by examiner]
US 12010129B2 · Vörös et al. · 2024 [cited by applicant]
US 12248572B2 · Saxe et al. · 2025 [cited by applicant]
US 20060013475A1 · Philomin et al. · 2006 [cited by applicant]
US 20080025208A1 · Chan · 2008 [cited by applicant]
US 20090003264A1 · Sastry · 2009 [cited by applicant]
US 20090122718A1 · Klessig et al. · 2009 [cited by applicant]
US 20090254992A1 · Schultz et al. · 2009 [cited by applicant]
US 20090300765A1 · Moskovitch et al. · 2009 [cited by applicant]
US 20130067579A1 · Beveridge et al. · 2013 [cited by applicant]
US 20140090061A1 · Avasarala et al. · 2014 [cited by applicant]
US 20140143869A1 · Pereira et al. · 2014 [cited by applicant]
US 20150046850A1 · Kurabayashi et al. · 2015 [cited by applicant]
US 20150067853A1 · Amrutkar et al. · 2015 [cited by applicant]
US 20150213376A1 · Ideses et al. · 2015 [cited by applicant]
US 20150363294A1 · Carback, III et al. · 2015 [cited by applicant]
US 20160065597A1 · Nguyen et al. · 2016 [cited by applicant]
US 20160217368A1 · Ioffe et al. · 2016 [cited by applicant]
US 20160218933A1 · Porras et al. · 2016 [cited by applicant]
US 20160253500A1 · Alme et al. · 2016 [cited by applicant]
US 20170046616A1 · Socher et al. · 2017 [cited by applicant]
US 20170078317A1 · Gertner et al. · 2017 [cited by applicant]
US 20170092264A1 · Hakkani-Tur et al. · 2017 [cited by applicant]
US 20170109615A1 · Yatziv et al. · 2017 [cited by applicant]
US 20170212829A1 · Bales et al. · 2017 [cited by applicant]
US 20170227995A1 · Lee · 2017 [cited by examiner]
US 20170351948A1 · Lee et al. · 2017 [cited by applicant]
US 20170372071A1 · Saxe et al. · 2017 [cited by applicant]
US 20180004803A1 · Hao et al. · 2018 [cited by applicant]
US 20180053084A1 · Li et al. · 2018 [cited by applicant]
US 20180060580A1 · Zhao et al. · 2018 [cited by applicant]
US 20180101682A1 · Krukov et al. · 2018 [cited by applicant]
US 20180121802A1 · Ruckauer et al. · 2018 [cited by applicant]
US 20180129786A1 · Khine · 2018 [cited by applicant]
US 20180137642A1 · Malisiewicz et al. · 2018 [cited by applicant]
US 20180144242A1 · Simard · 2018 [cited by applicant]
US 20180152471A1 · Jakobsson · 2018 [cited by applicant]
US 20180198812A1 · Christodorescu · 2018 [cited by examiner]
US 20180211041A1 · Davis · 2018 [cited by applicant]
US 20180268304A1 · Manadhata · 2018 [cited by examiner]
US 20180285740A1 · Smyth et al. · 2018 [cited by applicant]
US 20180285773A1 · Hsiao et al. · 2018 [cited by applicant]
US 20180288086A1 · Amiri et al. · 2018 [cited by applicant]
US 20180293381A1 · Tseng et al. · 2018 [cited by applicant]
US 20190026106A1 · Burton · 2019 [cited by examiner]
US 20190065744A1 · Gaustad · 2019 [cited by applicant]
US 20190095805A1 · Tristan · 2019 [cited by applicant]
US 20190108338A1 · Saxe et al. · 2019 [cited by applicant]
US 20190132355A1 · Egbert et al. · 2019 [cited by applicant]
US 20190205402A1 · Sernau et al. · 2019 [cited by applicant]
US 20190236273A1 · Saxe et al. · 2019 [cited by applicant]
US 20190236490A1 · Harang et al. · 2019 [cited by applicant]
US 20190258807A1 · DiMaggio et al. · 2019 [cited by applicant]
US 20190266492A1 · Harang et al. · 2019 [cited by applicant]
US 20190295114A1 · Pavletic et al. · 2019 [cited by applicant]
US 20190319987A1 · Levy · 2019 [cited by examiner]
US 20190347287A1 · Crossno et al. · 2019 [cited by applicant]
US 20190378050A1 · Edkin et al. · 2019 [cited by applicant]
US 20190387005A1 · Zawoad et al. · 2019 [cited by applicant]
US 20200076835A1 · Ladnai · 2020 [cited by examiner]
US 20200097817A1 · Harris et al. · 2020 [cited by applicant]
US 20200104636A1 · Halevi et al. · 2020 [cited by applicant]
US 20200117975A1 · Harang et al. · 2020 [cited by applicant]
US 20200228998A1 · Bai et al. · 2020 [cited by applicant]
US 20200233962A1 · Chantry · 2020 [cited by examiner]
US 20200250309A1 · Harang et al. · 2020 [cited by applicant]
US 20200257799A1 · Saxe et al. · 2020 [cited by applicant]
US 20200279140A1 · Pai · 2020 [cited by examiner]
US 20200285737A1 · Kraus · 2020 [cited by examiner]
US 20200311586A1 · Sandstrom · 2020 [cited by applicant]
US 20200342337A1 · Choudhary et al. · 2020 [cited by applicant]
US 20200394300A1 · Harris · 2020 [cited by examiner]
US 20210014247A1 · Wosotowsky et al. · 2021 [cited by applicant]
US 20210073377A1 · Coull et al. · 2021 [cited by applicant]
US 20210073661A1 · Matlick et al. · 2021 [cited by applicant]
US 20210092140A1 · Kazerounian et al. · 2021 [cited by applicant]
US 20210093973A1 · Edridge et al. · 2021 [cited by applicant]
US 20210120013A1 · Hines et al. · 2021 [cited by applicant]
US 20210168165A1 · Alsaeed et al. · 2021 [cited by applicant]
US 20210211450A1 · Aleidan · 2021 [cited by applicant]
US 20210287354A1 · Kumar et al. · 2021 [cited by applicant]
US 20210326440A1 · Saxe et al. · 2021 [cited by applicant]
US 20210328801A1 · Sly et al. · 2021 [cited by applicant]
US 20210328969A1 · Gaddam et al. · 2021 [cited by applicant]
US 20210397956A1 · Rasamsetti et al. · 2021 [cited by applicant]
US 20220036194A1 · Sundaresan et al. · 2022 [cited by applicant]
US 20220083662A1 · Grobman et al. · 2022 [cited by applicant]
US 20220083900A1 · Khanna · 2022 [cited by applicant]
US 20220124543A1 · Orhan et al. · 2022 [cited by applicant]
US 20220284283A1 · Yin et al. · 2022 [cited by applicant]
US 20220353284A1 · Vörös et al. · 2022 [cited by applicant]
US 20230089380A1 · Jiang et al. · 2023 [cited by applicant]
US 20230229772A1 · Saxe et al. · 2023 [cited by applicant]
US 20240119150A1 · Saxe et al. · 2024 [cited by applicant]
BR 102018077168A2 · 2019 [cited by examiner]
CA 2799691C · 2014 [cited by applicant]
CA 3015240A1 · 2019 [cited by examiner]
CA 2951723C · 2021 [cited by examiner]
CN 109145601A · 2019 [cited by examiner]
CN 110020861A · 2019 [cited by examiner]
CN 110545305A · 2019 [cited by examiner]
CN 110728575A · 2020 [cited by examiner]
CN 110858247A · 2020 [cited by examiner]
EP 3018879A1 · 2016 [cited by examiner]
EP 3076328A1 · 2016 [cited by examiner]
EP 3892198A1 · 2021 [cited by examiner]
JP 2012027710A · 2012 [cited by applicant]
JP 2022518646A · 2022 [cited by examiner]
RU 2680736C1 · 2019 [cited by examiner]
WO WO2007117636A2 · 2007 [cited by applicant]
WO WO2019071095A1 · 2019 [cited by applicant]
WO WO2019150079A1 · 2019 [cited by applicant]
WO WO2019145912A1 · 2019 [cited by applicant]
WO WO2019166989A1 · 2019 [cited by applicant]
WO WO2020030913A1 · 2020 [cited by applicant]
WO WO2020157479A1 · 2020 [cited by applicant]
WO WO2022223940A1 · 2022 [cited by applicant]
U.S. Appl. No. 15/907,807, Office Action mailed Apr. 27, 2021, 18 pages. [cited by applicant]
Augasta and Kathirvalavakumar, “Pruning algorithms of neural networks—a comparative study”, Cent. Eur. J. Comp. Sci. (2013); 3(3): 105-115. [cited by applicant]
Chiba, et al., “Analyzing Spatial Structure of IP Addresses for Detecting Malicious Websites”, Journal of Information Processing (Jul. 2013); 21(3): 539-550. [cited by applicant]
Engelbrecht, Andries P., “A New Pruning Heuristic Based on Variance Analysis of Sensitivity Information”, IEEE Transactions on Neural Networks (Nov. 2001); vol. 12, No. 6, pp. 1386-1399. [cited by applicant]
Kim, Hae-Jung, “Image-Based Malware Classification Using Convolutional Neural Network”, In: Park J., Loia V., Yi G., Sung Y. (eds) Advances in Computer Science and Ubiquitous Computing. Lecture Notes in Electrical Engin… [cited by applicant]
Lison and Mavroeidis, “Neural Reputation Models learned from Passive DNS Data”, “Neural reputation models learned from passive DNS data,” 2017 IEEE International Conference on Big Data (Big Data), Boston, MA (Dec. 11-14… [cited by applicant]
Pennington and Worah, et al., “The Spectrum of the Fisher Information Matrix of a Single-Hidden-Layer Neural Network”, 32nd Conference on Neural Information Processing Systems (NeurIPS 2018), Montréal, Canada, pp. 1-16. [cited by applicant]
Shah, S., et al., “Virus Detection using Artificial Neural Networks; International Journal of Computer Applications”, International Journal of Computer Applications (0975-8887) (Dec. 2013); vol. 84, No. 5, pp. 17-23. [cited by applicant]
Tu, M., et al., “Reducing the Model Order of Deep Neural Networks Using Information Theory”, IEEE Computer Society (2016); 2016 IEEE Computer Society Annual Symposium on VLSI, pp. 93-98. [cited by applicant]
Ba, et al., “Layer Normalization.” [Online] Retrieved from the Internet https://arxiv.org/pdf/1607.06450.pdf>, Submitted on Jul. 21, 2016, 14 pages. [cited by applicant]
Cheplyaka, R., “Rank vs Order in R”, Mar. 19, 2016 https://ro-che.info/articles/2016-03-19-rank-vs-order-r (Year: 2016), 4 pages. [cited by applicant]
Deo, A., et al., “Prescience: Probabilistic Guidance on the Retraining Conundrum for Malware Detection”, AlSec '16 Proceedings of the 2016 ACM Workshop on Artificial Intelligence and Security, Oct. 28, 2016, Vienna, Aus… [cited by applicant]
Harang and Ducau, “Measuring the speed of the Red Queen's Race”, BlackHat USA 2018, Aug. 4-9, 2018, Las Vegas, NV, USA, 18 pages. [cited by applicant]
Harang and Ducau, “Measuring the speed of the Red Queen's Race”, SOPHOS Presentation (2018), Retrieved from the Internet https://i.blackhat.com/us-18/Wed-August-8/us-18-Harang-Measuring-the-Speed-of-the-Red-Queens-Race.… [cited by applicant]
Harang and Rudd, “Principled Uncertainty Estimation for Deep Neural Networks”. [Online] arXiv:1810.12278 [cs.LG], [v1] Oct. 29, 2018, Retrieved from the Internet https://arxiv.org/abs/1810.12278v1.pdf, 8 pages. [cited by applicant]
Harang, R. “Estimating weight sharing in multi-task networks via approximate Fisher information,” SOPHOS, [online] Retrieved from the Internet https://www.camlis.org/s/harang_CAMLIS17.pdf> Oct. 28, 2017, 31 pages. [cited by applicant]
Huang, L. et al., “Orthogonal Weight Normalization: Solution to Optimization over Multiple Dependent Stiefel Manifolds in Deep Neural Networks,” [Online], Retrieved from the Internet: <URL: https://arxiv.org/pdf/1709.06… [cited by applicant]
International Preliminary Report on Patentability for International Patent Application No. PCT/US2018/054558, dated Apr. 8, 2020, 5 pages. [cited by applicant]
International Search Report and Written Opinion for International Patent Application No. PCT/US2018/054558, mailed Dec. 10, 2018, 6 pages. [cited by applicant]
International Search Report and Written Opinion for International Patent Application No. PCT/GB2019/050199, mailed Mar. 29, 2019, 15 pages. [cited by applicant]
International Search Report and Written Opinion for International Patent Application No. PCT/IB2019/050642, mailed Apr. 12, 2019, 12 pages. [cited by applicant]
International Search Report and Written Opinion for International Patent Application No. PCT/IB2019/051629, mailed Jun. 17, 2019, 14 pages. [cited by applicant]
International Search Report and Written Opinion for International Patent Application No. PCT/GB2019/052222, mailed Nov. 12, 2019, 17 pages. [cited by applicant]
International Search Report and Written Opinion for International Patent Application No. PCT/GB2020/050188, mailed Mar. 31, 2020, 12 pages. [cited by applicant]
Ioffe and Szegedy, “Batch Normalization: Accelerating Deep Network Training by Reducing Internal Covariate Shift.” [Online] Retrieved from the Internet https://arxiv.org/pdf/1502.03167v3.pdf>, Submitted on Feb. 11, 2015… [cited by applicant]
Kang, et al., “Malware Classification Method via Binary Content Comparison”, RACS'12, Oct. 23-26, 2012, San Antonio, TX, USA (2012); 6 pages, https://dl.acm.org/doi/pdf/10.1145/2401603.2401672. [cited by applicant]
Kardan and Stanley, “Fitted Learning: Models with Awareness of their Limits”. [Online] arXiv:1609.02226v4 [cs.AI] Jul. 9, 2018, Retrieved from the Internet https://arxiv.org/pdf/1609.02226.pdf, 19 pages. [cited by applicant]
Kirkpatrick, J. et al., “Overcoming catastrophic forgetting in neural networks,” PNAS (2017); 114 (13): 3521-3526. [cited by applicant]
Liao and Carneiro, “On the Importance of Normalisation Layers in Deep Learning with Piecewise Linear Activation Units.” [Online] Retrieved from the Internet https://arxiv.org/pdf/1508.00330.pdf>, Submitted on Aug. 3, 20… [cited by applicant]
Liao, et al., “Streaming Normalization: Towards Simpler and More Biologically-plausible Normalizations for Online and Recurrent Learning.” Center for Brains, Minds & Machines, Memo No. 057, [Online] Retrieved from the I… [cited by applicant]
Lundberg, S. M. et al., “A Unified Approach to Interpreting Model Predictions,” 31st Conference on Neural Information Processing Systems (NIPS 2017), Long Beach, CA, USA, 10 pages. [cited by applicant]
Montavon, G. et al., “Methods for Interpreting and Understanding Deep Neural Networks,” [Online], Retrieved from the Internet: <URL: https://arxiv.org/pdf/1706.07979.pdf>, Jun. 24, 2017, 14 pages. [cited by applicant]
Narayanan, et al., “A multi-view context-aware approach to Android malware detection and malicious code localization.” Empir Software Eng (2018); 23: 1222-1274. Epub Aug. 30, 2017. [cited by applicant]
Pascanu, R. et al., “Revisiting natural gradient for deep networks,” [Online], Retrieved from the Internet: <URL: https:/arxiv.org/pdf/1301.3584v7.pdf>, Feb. 17, 2014, 18 pages. [cited by applicant]
Ribeiro, M. T. et al., “Model-Agnostic Interpretability of Machine Learning,” [Online], Retrieved from the Internet: <URL: https://arxiv.org/pdf/1606.05386.pdf>, Jun. 16, 2016, 5 pages. [cited by applicant]
Ribeiro, M. T. et al., “‘Why Should I Trust You?’ Explaining the Predictions of Any Classifier,” [Online], Retrieved from the Internet: <URL: https://arxiv.org/pdf/1602.04938v3.pdf>, Aug. 9, 2016, 10 pages. [cited by applicant]
Ribeiro, M. T., “Lime—Local Interpretable Model-Agnostic Explanations,” [Online Blog], Retrieved from the Internet: <URL: https://homes.cs.washington.edu/˜marcotcr/blog/lime/>, Apr. 2, 2016, 7 pages. [cited by applicant]
Rudd, E.R., et al., “MOON: A Mixed Objective Optimization Network for the Recognition of Facial Attributes.” [Online], Retrieved from the Internet: <URL:https://arxiv.org/abs/1603.07027>, arXiv:1603.07027 [cs.CV] , Mar.… [cited by applicant]
Rudd, et al., “MEADE: Towards a Malicious Email Attachment Detection Engine”, 2018 IEEE International Symposium on Technologies for Homeland Security (HST), IEEE, Oct. 23, 2018, pp. 1-7. [cited by applicant]
Rudd, et al., “The Extreme Value Machine”. [Online] arXiv:1506.06112v4 [cs.LG] May 21, 2017, Retrieved from the Internet https://arxiv.org/abs/1506.06112.pdf, 12 pages. [cited by applicant]
Salimans, T. et al., “Weight Normalization: A Simple Reparameterization to Accelerate Training of Deep Neural Networks,” [Online], Retrieved from the Internet: <URL: https://arxiv.org/pdf/1602.07868.pdf>, Jun. 4, 2016, … [cited by applicant]
Sanghani, et al., “Personalized spam filtering using incremental training of support vector machine”. 2016 International Conference on Computing, Analytics and Security Trends (CAST), IEEE Dec. 19, 2016, pp. 323-328, 6 … [cited by applicant]
Santos and Torres, “Macro Malware Detection using Machine Learning Techniques—A New Approach.” In Proceedings of the 3rd International Conference on Information Systems Security and Privacy (ICISSP 2017, SCITEPRESS—Scie… [cited by applicant]
Saxe and Berlin, “Deep Neural Network Based Malware Detection Using Two Dimensional Binary Program Features,” IEEE 2015,10th International Conference on Malicious and Unwanted Software: “Know Your Enemy” (Malware), 2015… [cited by applicant]
Saxe and Berlin, “eXpose: A Character-Level Convolutional Neural Network with Embeddings For Detecting Malicious URLs, File Paths and Registry Keys.” [Online], Retrieved from the Internet: <https://arxiv.org/abs/1702.08… [cited by applicant]
Schultz, et al., “Data Mining Methods for Detection of New Malicious Executables”, Proceedings of the 2001 IEEE Symposium on Security and Privacy (2001); Oakland, CA, May 14-16, 2001; [Proceedings of the IEEE Symposium … [cited by applicant]
Sethi and Kantardzic, “Handling adversarial concept drift in streaming data”. Expert Systems With Applications (May 1, 2018); 97: 18-40. Available online Dec. 11, 2017. [cited by applicant]
Srivastava, et al., “Dropout: A Simple Way to Prevent Neural Networks from Overfitting.” Journal of Machine Learning Research (2014); 15: 1929-1958. Submitted Nov. 2013; Published Jun. 2014, 30 pages. [cited by applicant]
Tahan, G., et al., “Mal:ID: Automatic Malware Detection Using Common Segment Analysis and Meta-Features.” Journal of Machine Learning (2012); (Submitted Aug. 2011; Published Feb. 2012); 1: 1-48, 33 pages. [cited by applicant]
Theis, L. et al., “Faster gaze prediction with dense networks and Fisher pruning,” [Online], Retrieved from the Internet: <URL: https://arxiv.org/pdf/1801.05787.pdf>, Jan. 17, 2018, 10 pages. [cited by applicant]
Tian, et al., “An automated classification system based on the strings of trojan and virus families.” Malicious and Unwanted Software (Malware); 2009 4th International Conference, Piscataway, NJ, USA, Oct. 13, 2009, pp.… [cited by applicant]
Tolomei, G. et al., “Interpretable Predictions of Tree-based Ensembles via Actionable Feature Tweaking,” [Online], Retrieved from the Internet: <URL: https://arxiv.org/pdf/1706.06691.pdf>, Jun. 20, 2017, 10 pages. [cited by applicant]
Tseng, Huihsin et al., U.S. Appl. No. 62/483,102, filed Apr. 7, 2017, 19 pages. [cited by applicant]
Tu, M. et al., “Ranking the parameters of deep neural networks using the Fisher information,” 41st IEEE International Conference on Acoustics, Speech and Signal Processing, ICASSP 2016—Shanghai, China, Institute of Elec… [cited by applicant]
U.S. Appl. No. 15/727,035, Notice of Allowance mailed Dec. 27, 2019, 7 pages. [cited by applicant]
U.S. Appl. No. 15/884,542, Office Action mailed Mar. 4, 2021, 53 pages. [cited by applicant]
U.S. Appl. No. 16/257,749, Notice of Allowance mailed Mar. 1, 2021, 10 pages. [cited by applicant]
U.S. Appl. No. 16/257,749, Office Action mailed Aug. 11, 2020, 14 pages. [cited by applicant]
Velez and Clune, Identifying Core Functional Networks and Functional Modules within Artificial Neural Networks via Subsets Regression, GECCO '16, Proceedings of the Genetic and Evolutionary Computation Conference 2016, … [cited by applicant]
Wu, et al., “L1-Norm Batch Normalization for Efficient Training of Deep Neural Networks.” [Online] Retrieved from the Internet https://arxiv.org/pdf/1802.09769.pdf>, Submitted on Feb. 27, 2018, 8 pages. [cited by applicant]
U.S. Appl. No. 15/884,542, Office Action mailed Apr. 5, 2022, 32 pages. [cited by applicant]
U.S. Appl. No. 16/158,844, Office Action mailed May 24, 2022, 25 pages. [cited by applicant]
U.S. Appl. No. 16/853,803, Office Action mailed May 2, 2022, 9 pages. [cited by applicant]
Xu, K., et al., “DeepRefiner: Multi-layer Android Malware Detection System Applying Deep Neural Networks,” IEEE European Symposium on Security and Privacy, 2018, 15 pages. [cited by applicant]
Chiba, Daiki et al., “Detecting Malicious Websites by Learning IP Address Features”, 2012 IEEE/IPSJ 12th International Symposium on Applications and the Internet, Jul. 16, 2012 (Jul. 16, 2012), pp. 29-39. [cited by applicant]
International Search Report and Written Opinion for International Application No. PCT/GB2022/050681, mailed Jun. 20, 2022, 14 pages. [cited by applicant]
Huang, Y., et al., “Graph neural networks and cross-protocol analysis for detecting malicious IP addresses”, Complex & Intelligent Systems (2023); 9(4): 3857-3869, Published Online Sep. 14, 2022. [cited by applicant]
International Preliminary Report on Patentability for International Application No. PCT/GB2022/050681, mailed Nov. 2, 2023, 7 pages. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 18/186,587 mailed Aug. 15, 2024, 11 pages. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 17/239,128 mailed Jan. 26, 2024, 19 pages. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 16/158,844 mailed Nov. 1, 2023, 11 pages. [cited by applicant]
Corrected Notice of Allowability for U.S. Appl. No. 17/314,625 mailed Oct. 24, 2023, 5 pages. [cited by applicant]
U.S. Appl. No. 16/263,264, Office Action mailed Feb. 22, 2022, 13 pages. [cited by applicant]
Buitinck, L., et al., “API design for machine learning software: experiences from the scikit-learn project”, arXiv preprint (2013); 16 pages. [cited by applicant]
Dai, J., et al., “Efficient Virus Detection Using Dynamic Instruction Sequences”, Journal of Computers (May 2009); 4(5): 405-414. [cited by applicant]
Devi, D., et al., “Detection of packed malware”, SecurIT'12 (Aug. 17-19, 2012); p. 22. [cited by applicant]
Elovici, Y., et al., “Applying machine learning techniques for detection of malicious code in network traffic”, KI 2007: Advances in Artificial Intelligence: 30th Annual German Conference on Al, KI 2007, Osnabrück, Germ… [cited by applicant]
Henchiri, O., et al., “A feature selection and evaluation scheme for computer virus detection”, Proceedings of the Sixth International Conference on Data Mining (ICDM'06), IEEE Computer Society (2006); 5 pages. [cited by applicant]
Joachims, T., “Making large-scale SVM learning practical LS-8 Report 24”, Technical Report, University of Dortmund (1998); 18 pages. [cited by applicant]
Kecman, V., “Support vector machines-an introduction”, StudFuzz, Springer-Verlag Berlin Heidelberg (2005); 177: 1-11. [cited by applicant]
Kolter, J. Z., et al., “Learning to detect and classify malicious executables in the wild”, Journal of Machine Learning Research (2006); 7(12): 2721-2744. [cited by applicant]
Kolter, J. Z., et al., “Learning to detect malicious executables in the wild”, Proceedings of the Tenth ACM SIGKDD International Conference on Knowledge Discovery and Data Mining (2004); 9 pages. [cited by applicant]
Menahem, E., et al., “Improving malware detection by applying multi-inducer ensemble”, Computational Statistics & Data Analysis (2009); 53: 1483-1494. [cited by applicant]
Monnappa, K. A., “Introduction to Malware Analysis”, Learning Malware Analysis: Explore the concepts, tools, and techniques to analyze and investigate Windows malware, Packt Publishing Ltd., Birmingham—Mumbai (2018); Ch… [cited by applicant]
Mukkamala, S., et al., “Intrusion detection using an ensemble of intelligent paradigms”, Journal of Network and Computer Applications (2005); 28(2): 167-182. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 15/884,542 dated Jul. 13, 2023, 13 pages. [cited by applicant]
Russell, S. J., “Kernel Machines”, Artificial Intelligence A Modern Approach, Pearson Education International (2010); Section 20(6): 749-751. [cited by applicant]
Sikorski, M., et al., “Practical malware analysis: the hands-on guide to dissecting malicious software”, No. starch press (2012); pp. 2-3; pp. 11-13; p. 384; 12 pages. [cited by applicant]
Souppaya, M., et al., “Guide to malware incident prevention and handling for desktops and laptops”, NIST Special Publication 800-83 Revision 1 (2013); 47 pages. [cited by applicant]
Tahan, G., et al., “Mal-id: Automatic malware detection using common segment analysis and meta-features”, Journal of Machine Learning Research (2012); 13: 949-979. [cited by applicant]
U.S. Appl. No. 15/727,035, Office Action mailed Aug. 14, 2019, 11 pages. [cited by applicant]
U.S. Appl. No. 15/884,542, Advisory Action mailed Dec. 6, 2022, 3 pages. [cited by applicant]
U.S. Appl. No. 15/884,542, Office Action mailed Jan. 26, 2023, 32 pages. [cited by applicant]
U.S. Appl. No. 15/884,542, Office Action mailed Sep. 21, 2022, 32 pages. [cited by applicant]
U.S. Appl. No. 15/907,807, Notice of Allowance mailed Oct. 20, 2021, 5 pages. [cited by applicant]
U.S. Appl. No. 16/158,844, Advisory Action mailed Jun. 6, 2023, 3 pages. [cited by applicant]
U.S. Appl. No. 16/158,844, Office Action mailed Jan. 4, 2023, 32 pages. [cited by applicant]
U.S. Appl. No. 16/158,844, Office Action mailed Jun. 29, 2023, 35 pages. [cited by applicant]
U.S. Appl. No. 16/263,264, Corrected Notice of Allowability mailed Jan. 5, 2023, 2 pages. [cited by applicant]
U.S. Appl. No. 16/263,264, Notice of Allowance mailed Oct. 4, 2022, 9 pages. [cited by applicant]
U.S. Appl. No. 16/853,803, Notice of Allowance mailed Nov. 30, 2022, 7 pages. [cited by applicant]
U.S. Appl. No. 17/239,128, Office Action mailed Jul. 12, 2023, 33 pages. [cited by applicant]
U.S. Appl. No. 17/314,625, Corrected Notice of Allowability mailed Mar. 29, 2023, 2 pages. [cited by applicant]
U.S. Appl. No. 17/314,625, Notice of Allowance mailed Mar. 7, 2023, 10 pages. [cited by applicant]
Wang, T., et al., “Detecting unknown malicious executables using portable executable headers”, 2009 Fifth International Joint Conference on Inc, IMS and IDC. IEEE (2009); p. 278. [cited by applicant]
Wilding, ED., “The authoritative international publication on computer virus prevention, recognition and removal”, Virus Bulletin (Nov. 1990); 24 pages. [cited by applicant]
Ye, Y., et al., “SBMDS: an interpretable string based malware detection system using SVM ensemble with bagging”, Journal in Computer Virology (2009); 5: 283-293. [cited by applicant]
Ye, Y., et al., “Hierarchical associative classifier (HAC) for malware detection from the large and imbalanced gray list”, Journal of Intelligent Information Systems (2010); 35: 1-20. [cited by applicant]
U.S. Appl. No. 15/884,542, Office Action mailed Sep. 9, 2021, 44 pages. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 18/186,587, by Saxe, Joshua Daniel et al., mailed Oct. 31, 2024, 11 pages. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 18/483,795, by Saxe, Joshua Daniel et al., mailed Feb. 19, 2025, 13 pages. [cited by applicant]
U.S. Appl. No. 19/211,885, inventor Saxe, Joshua Daniel et al., filed May 19, 2025. [cited by applicant]