Invalidity dossier

US 12003529

Techniques for detecting artificial intelligence model cybersecurity risk in a computing environment

Current assignee: Wiz Inc

Added 5/14/2026, 6:01:43 AM

At a glancePTAB challenged2 lawsuits on fileHigh-Tech (T)

Active provider: DeepSeek · deepseek-v4-flash

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

Here's a concise summary of US patent 12003529:

US Patent 12003529

  • Title: Techniques for detecting artificial intelligence model cybersecurity risk in a computing environment
  • Assignee: Wiz Inc
  • Inventors: Amitai Cohen, Barak Sharoni, Shir Tamari, George PISHA, Itay Arbel, Daniel Velikanski, Yaniv Shaked
  • Filing Date: 2024-02-22
  • Issue Date (Publication Date): 2024-06-04
  • Abstract: A system and method for detecting a cybersecurity risk of an artificial intelligence (AI), is presented. The method includes: inspecting a computing environment for an AI model deployed therein; generating a representation of the AI model in a security database, the security database including a representation of the computing environment; inspecting the AI model for a cybersecurity risk; generating a representation of the cybersecurity risk in the security database, the representation of the cybersecurity risk connected to the representation of the AI model in response to detecting the cybersecurity risk; and initiating a mitigation action based on the cybersecurity risk.

Plain-Language Overview of Independent Claims:

  • Independent Claim 1 (Method): This claim describes a computer-implemented method for identifying and addressing cybersecurity risks in AI models. It involves:

    1. Scanning a computing environment to find an AI model.
    2. Creating a digital record (representation) of this AI model within a security database, which also holds a record of the computing environment itself.
    3. Examining the AI model for any cybersecurity risks.
    4. If a risk is found, creating a record of that risk in the security database and linking it to the AI model's record.
    5. Taking a corrective action (mitigation) based on the identified cybersecurity risk.
  • Independent Claim 11 (Non-Transitory Computer-Readable Medium): This claim covers a computer storage device that holds instructions. When a computer's processors execute these instructions, the computer performs the same steps outlined in Independent Claim 1 for detecting AI model cybersecurity risks and initiating mitigation.

  • Independent Claim 12 (System): This claim describes a system designed to detect AI model cybersecurity risks. The system includes processing circuitry and memory. The memory contains instructions that, when executed by the processing circuitry, enable the system to carry out the identical steps detailed in Independent Claim 1, from inspecting the computing environment for an AI model to initiating a mitigation action.

Generated 5/16/2026, 12:48:55 PM

Cases on file (2)

Group view →

Specific litigation cases in our database that name US patent 12003529. The free-form analysis below may also discuss cases beyond this list.

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

Based on the information available, there is known litigation involving US patent 12003529.

Here are the details of the known litigation:

  1. First Worldwide Family Litigation:

    • Plaintiff(s): Not specified in the immediate link, but typically the patent holder or licensee would initiate. To determine the specific plaintiff(s), further investigation on Darts-IP would be required.
    • Defendant(s): Not specified in the immediate link. To determine the specific defendant(s), further investigation on Darts-IP would be required.
    • Jurisdiction: Not specified directly, but "worldwide family litigation" suggests multiple jurisdictions may be involved or an initial filing that covers a family of patents.
    • Case Number: Not explicitly listed at this top level.
    • Filing Date: Not explicitly listed at this top level.
    • Outcome or Current Status: Listed as "First worldwide family litigation filed" and "Critical".
  2. PTAB Case IPR2025-01087:

To get more precise details for the "First worldwide family litigation" (e.g., specific plaintiff(s), defendant(s), case number, and filing date), one would need to access the Darts-IP link provided (https://patents.darts-ip.com/?family=91325466&utm_source=google_patent&utm_medium=platform_link&utm_campaign=public_patent_search&patent=[US12003529](/patent/US12003529)(B1)) and investigate further. Similarly, for the IPR case, while "Settlement" is noted, further details on the filing date or specific parties might be available by accessing the Unified Patents portal link (https://portal.unifiedpatents.com/ptab/case/IPR2025-01087).

Since the direct links were given on the patent page itself, I did not need to perform additional broad web searches.Known litigation involving US patent 12003529 includes the following:

  1. PTAB Case IPR2025-01087

    • Plaintiff(s): Petitioner (specific name not publicly available in search snippets).
    • Defendant(s): Wiz, Inc. (Patent Owner).
    • Jurisdiction: Patent Trial and Appeal Board (PTAB).
    • Case Number: IPR2025-01087.
    • Filing Date: The parties requested authorization to file a joint motion to terminate and keep the settlement agreement confidential on January 8, 2026. The actual filing date of the IPR petition would precede this, but is not explicitly stated in the provided snippets.
    • Outcome or Current Status: Settlement.
  2. First Worldwide Family Litigation

    • Plaintiff(s): Not publicly available in search snippets.
    • Defendant(s): Not publicly available in search snippets.
    • Jurisdiction: Not publicly available in search snippets.
    • Case Number: Not publicly available in search snippets.
    • Filing Date: Not publicly available in search snippets.
    • Outcome or Current Status: "First worldwide family litigation filed" and "Critical" (as indicated on the Google Patents page for US12003529, referencing Darts-IP). Specific details such as parties, jurisdiction, case number, and filing date require access to the Darts-IP database, which is a subscription-based service.

Generated 5/16/2026, 12:49:05 PM

Proceedings on file (1)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

1 settled
Terminated-Settled
Filed
Jun 4, 2025
Last modified
Jan 14, 2026
Petitioner
Orca Security Ltd.
Inventor
Amitai COHEN et al

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

Proceedings overview

One Inter Partes Review (IPR) proceeding has been filed against US12003529, which was terminated due to settlement. This means no claims of the patent have been invalidated or sustained by the PTAB, leaving the patent's validity largely untested by the IPR process.

IPR2025-01087 — Orca Security Ltd. v. Wiz Inc.

  • Type: Inter Partes Review
  • Filed: 2025-06-04
  • Status: Terminated-Settled – The parties reached a settlement agreement and requested to terminate the proceeding.
  • Judge panel: Not publicly available in the provided search results.
  • Petition grounds: Specific claims challenged, prior art, and statutory basis are not publicly available from the provided search results.
  • Institution decision: An institution decision was not rendered as the parties settled the dispute and filed a joint motion to terminate the proceeding on January 8, 2026.
  • Final Written Decision: Not issued, as the proceeding was terminated due to settlement.
  • Settlement / termination: The parties executed a settlement agreement resolving all disputes and were granted authorization to file a joint motion to terminate and a joint motion to keep the settlement agreement confidential on January 8, 2026. The specific terms of the settlement are confidential. The last modification date for the proceeding was 2026-01-14.
  • Appeal: Not applicable, as no Final Written Decision was issued.
  • Defensive value: This proceeding concluded without a PTAB decision on the merits, meaning the patent's claims were neither invalidated nor confirmed as patentable through this IPR. For a defendant, this means the patent has not been "hardened" by surviving an IPR challenge, but also that no claims have been canceled.

Strategic summary

Only one IPR proceeding, IPR2025-01087, has been filed against US12003529. This proceeding was terminated due to a confidential settlement between the petitioner, Orca Security Ltd., and the patent owner, Wiz Inc., before any institution decision or final written decision was issued. As such, all claims of US12003529 remain untested by the PTAB. There are no canceled, sustained, or unpatentable claims on record from PTAB proceedings.

Regarding estoppel, since IPR2025-01087 was terminated prior to institution, the statutory estoppel provisions of 35 U.S.C. § 315(e)(2) do not apply. This means that Orca Security Ltd. (and its privies) would not be estopped from raising invalidity grounds in future litigation that they raised or reasonably could have raised in the IPR petition. For a defendant facing assertion of this patent today, all prior-art grounds remain available for challenge, as no PTAB trial has concluded with a final written decision.

There is no discernible pattern signal from this single settled proceeding. There have not been multiple IPRs filed on this patent, nor has the patent owner pursued PTAB appeals aggressively. There is no indication of a defensive aggregator like Unified Patents directly in this specific proceeding for US12003529, although Unified Patents does track PTAB cases in general.

Recommended next steps

Since there are no active PTAB proceedings and the sole filed IPR was settled before institution, there are no upcoming trial-stage milestones to monitor. The absence of PTAB activity is a notable signal; for a patent recently granted in June 2024, the filing of one IPR and its subsequent settlement suggests some early engagement but no definitive PTAB ruling on patentability. Defendants facing assertion of US12003529 would need to initiate their own IPRs if they wish to challenge the patent's validity before the PTAB.

Generated 5/16/2026, 12:49:04 PM

Ownership chain (1)

Asserters network →

Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.

  1. 2024-02-22 · recorded 2024-02-26 · reel 063344/0046 · Assignment

    Amitai Cohen, George Pisha, Barak Sharoni, Shir Tamari, Itay Arbel, Yaniv Shaked, Daniel VelikanskiWiz Inc.

    Correspondent: Jeffrey M. Brown · Kory & Partners

    Original assignment from inventors to the filing company

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

Inventors

  • Amitai Cohen (Wiz Inc)
  • Barak Sharoni (Wiz Inc)
  • Shir Tamari (Wiz Inc)
  • George PISHA (Wiz Inc)
  • Itay Arbel (Wiz Inc)
  • Daniel Velikanski (Wiz Inc)
  • Yaniv Shaked (Wiz Inc)

All inventors were employed by Wiz Inc. at the time of filing, which is also the original assignee. No unusual patterns are noted regarding inventor departures.

Original assignee

The entity named on the issued patent is Wiz Inc. Wiz Inc. is a cybersecurity company that provides cloud security platforms and likely ships products embodying the claims related to detecting AI model cybersecurity risks in cloud environments. Wiz Inc. is currently an operating company.

Assignment timeline

  • 2024-02-22 (executed) / recorded 2024-02-26 — Reel 063344/0046
    • Conveyance: Assignment
    • Assignor: Amitai Cohen, George Pisha, Barak Sharoni, Shir Tamari, Itay Arbel, Yaniv Shaked, Daniel Velikanski
    • Assignee: Wiz Inc.
    • Correspondent: Jeffrey M. Brown, Kory & Partners LLP, 1600 Broadway, Suite 1600, Denver, CO, 80202
    • Context: Original assignment from inventors to the filing company.

The USPTO Assignment Center has only one record for this patent, the initial assignment from the inventors to Wiz Inc.

Timeline diagram

timeline
    title Ownership of US 12003529
    2024 : Filed by Wiz Inc
         : Inventors assigned to Wiz Inc
    2024 : Issued

NPE / troll-pattern signals

  1. Shell-entity transfer — not present. The sole assignee is Wiz Inc., an operating company.
  2. Known asserter in the chain — not present. The sole assignee is Wiz Inc., which is not a known NPE.
  3. Repeat correspondent across the chain — not present. There is only one assignment record.
  4. Cascading transfers — not present. There is only one assignment record.
  5. Pre-litigation transfer — unclear. While the Google Patents record indicates litigation filed (referencing Darts-ip and Unified Patents), the assignment record does not show a transfer within 6 months of this litigation. The PTAB case IPR2025-01087 was filed in 2025, well after the initial assignment.
  6. Bankruptcy fire-sale — not present. Wiz Inc. is an active operating company.
  7. Privateering — not present. There is no indication of a transfer to an NPE for assertion on behalf of Wiz Inc.
  8. Defensive aggregator (anti-NPE) — not present. The patent is currently assigned to Wiz Inc.

Verdict

Operating-company assertion

The patent is currently assigned to Wiz Inc., an active cybersecurity company that develops and markets cloud security platforms. The only recorded assignment is from the inventors to Wiz Inc. (Reel 063344/0046, recorded 2024-02-26), indicating direct ownership by an operating company. While there are mentions of litigation in Google Patents, this does not contradict Wiz Inc. being an operating company asserting its own intellectual property.

Generated 5/16/2026, 12:49:04 PM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

I'll search for US patent 12003529 and its cited prior art references.

Let me fetch the detailed citation lists from Justia and Google Patents.

Let me retrieve the full citation lists and details on the key references.

I've hit my search-step budget, so I'll report what I was able to verify, and clearly flag what I could not.

Prior-Art Analysis — US 12003529 B1

A. The patent under analysis (confirmed)

Field Value
Patent number US 12003529 B1
Title Techniques for detecting artificial intelligence model cybersecurity risk in a computing environment
Application US 18/584,659
Filed 2024-02-22
Granted / published 2024-06-04
Assignee Wiz Inc.
Inventors Amitai Cohen, Barak Sharoni, Shir Tamari, George Pisha, Itay Arbel, Daniel Velikanski, Yaniv Shaked
CPC H04L63/1433 (vulnerability analysis); H04L63/1441 (countermeasures)

Note on dates used below: the face of the patent records no earlier priority claim — the copy I have states the priority date is an assumption equal to the filing date (2024-02-22). So the §102 critical date is 2024-02-22, and AIA §§102(a)(1)/(a)(2) apply.

B. Important scope/verification caveat

I must be explicit per my operating rules: I could not retrieve the full "References Cited" front-page list directly from USPTO Patent Center within the search budget. The citation list below is taken from third-party mirrors of the USPTO front page (Justia's "Referenced Cited" and Google Patents), which is the same data but not the authoritative USPTO record. Two consequences:

  1. The list may be incomplete (Justia's snippet was truncated mid-list).
  2. For all but one reference I could not verify the reference's subject matter text, so I can state the citation and dates but I cannot responsibly map claim elements to them. Producing a §102 element-by-element anticipation chart requires the full text of each reference, which I do not have here. I will not invent descriptions.

C. Cited U.S. documents on the face of US 12003529 (as reported by the mirrors)

Dates shown are the grant date for issued patents and the publication date for pre-grant publications, as listed.

# Citation Date Inventor (as listed)
1 US 10,558,823 B2 2020-02-11 Schroeder et al.
2 US 11,935,416 B2 2024-03-19 Motamedi
3 US 11,936,622 B2 2024-03-19 Gonshorowitz
4 US 11,936,785 B2 2024-03-19 Shemesh
5 US 11,941,054 B2 2024-03-26 Shu
6 US 11,947,698 B2 2024-04-02 Struttmann
7 US 11,949,690 B2 2024-04-02 Lichtenstein
8 US 2019/0050683 A1 2019-02-14 Gupta / Hyde
9 US 2021/0258160 A1 2021-08-19 Kannan
10 US 2022/0030009 A1 2022-01-27 Hasan
11 US 2022/0345457 A1 2022-10-27 Jeffords
12 US 2023/0269272 A1 2023-08-24 Dambrot
13 US 2023/0289604 A1 2023-09-14 Chan
14 US 2023/0351026 A1 2023-11-02 Cross
15 US 2024/0064159 A1 2024-02-22 Crabtree
16 US 2024/0080329 A1 2024-03-07 Reed
17 US 2024/0080338 A1 2024-03-07 Crabtree
18 US 2024/0089272 A1 2024-03-14 Gilad
19 US 2024/0098072 A1 2024-03-21 Verzun
20 US 2024/0104118 A1 2024-03-28 Herzberg
21 US 2024/0104235 A1 2024-03-28 Herzberg
22 US 2024/0104240 A1 2024-03-28 Herzberg
23 US 2024/0106846 A1 2024-03-28 Kapoor
24 US 2024/0106847 A1 2024-03-28 Yadav

The one reference I verified in substance

US 10,558,823 B2 — Schroeder, Kristopher Paul; Underwood, Timothy Ryan. "Systems and methods for controlling data exposure using artificial-intelligence-based modeling." Assignee Grey Market Labs, PBC. Application 16/273,877, filed 2019-02-12; granted 2020-02-11.

  • Description (verified): Generates an "artificial profile model" containing constraints for producing new artificial profiles; receives a signal that a computing device is requesting access to a network location; detects data-privacy elements associated with the device; determines and modifies an artificial profile per the model's constraint so the device is masked from identification.
  • §102 relevance: This is a data-exposure / privacy-masking reference using AI modeling — it is not directed to inspecting a computing environment for an AI model, representing the model in a security database, or inspecting the model for a cybersecurity risk. It does not appear to anticipate any claim of US 12003529 under §102. Its citation is most plausibly a generic "AI + data exposure" art citation by the examiner. (Confidence: moderate — based on the verified abstract.)

References I could not verify — and why I am not assigning §102 claim mappings

For items #2–#24 above I do not have the reference text, so I will not write "anticipates claim X" statements, because the dates alone in several cases suggest a §102(a)(2) posture rather than §102(a)(1), and that distinction is decisive:

  • Items #2–#7 (issued 2024-03-19 through 2024-04-02) and #16–#24 (published 2024-03-07 through 2024-03-28) all post-date the 2024-02-22 critical date. They can only be prior art if they were "effectively filed" (i.e., their earliest US filing/priority date) before 2024-02-22, under §102(a)(2). Whether that is true for each is exactly the fact I could not confirm.
  • Items #8–#15 have publication dates before 2024-02-22 (#8–#14) or on 2024-02-22 (#15) and therefore potentially qualify under §102(a)(1) on their face.

Bottom line on §102: On the record I could verify, no cited reference is a demonstrated anticipatory reference for independent claims 1, 11, or 12. There is no single reference I can point to that discloses all of: (a) inspecting a computing environment for a deployed AI model; (b) generating a representation of that AI model in a security database that also contains a representation of the environment; (c) inspecting the AI model for a cybersecurity risk; (d) generating a linked representation of the risk; and (e) initiating a mitigation action. An anticipation rejection under §102 requires one reference to disclose each element, and the artwork I saw (data-exposure masking, cloud graph modeling generally) addresses different problems.

D. What is needed to complete a proper, defensible prior-art analysis

To finish the task you asked for — a per-reference "which claim(s) it potentially anticipates" mapping — someone with USPTO Patent Center / full-text access needs to pull, for each of #2–#24:

  1. The full text or at least the abstract + independent claim, to test each claim element of '529 claims 1/11/12.
  2. Each reference's earliest effective filing date (to settle §102(a)(2) vs. §102(a)(1) status relative to 2024-02-22).
  3. Confirmation of whether each is a third-party reference or an applicant's own Wiz-family document (relevant to §102(b)(2)(C) common-ownership exception and to double-patenting rather than anticipation).

E. Where the real invalidity fight is on this patent

The citation list is not the whole story. From the litigation record surfaced during searching:

  • IPR2025-01087, Orca Security Ltd. v. Wiz Inc. (filed 2025-06-04; terminated by settlement, last modified 2026-01-14) was filed against this patent. Its petition grounds were not published in the sources I could reach. Because it settled pre-institution, no statutory estoppel under 35 U.S.C. §315(e)(2) attached, and no claim was canceled or sustained.
  • The related district-court case is Orca Security Ltd. v. Wiz, Inc., No. 1:23-cv-00758 (D. Del.), in which '529 is among the asserted patents (per the Joint Claim Construction Chart reference). Orca's invalidity contentions there (Exhibit 2016) would be the single richest source of actual asserted prior-art combinations (§§102/103) against '529 — far more probative than the front-page citations. That document is the artifact I would pull next.

F. Sources used

Flagged limitation: I could not complete the requested element-by-element §102 chart because I could not obtain the full text/abstracts and effective filing dates of references #2–#24 within the available search budget. I have deliberately declined to fabricate those mappings. If you can supply the front-page PDF or Patent Center "References Cited" text for US 12,003,529, I can complete the anticipation mapping reference-by-reference.

Generated 9/23/2026, 11:21:09 AM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

The provided patent text for US12003529 includes a "Prior art keywords" section and a "BACKGROUND" section that describes the general challenges and known issues in AI cybersecurity as of the prior art date (2024-02-22). However, the provided information does not include any specific prior art references (e.g., other patent numbers, scientific publications, or specific systems) that could be combined to analyze the obviousness of the claims under 35 U.S.C. § 103.

Without specific prior art references, it is not possible to:

  1. Identify combinations of prior art references that would render the claims obvious.
  2. Explain why a person having ordinary skill in the art would have been motivated to combine them, as such motivation relies on the specific disclosures of particular prior art documents.

Therefore, I cannot perform an obviousness analysis as requested based solely on the information provided in the patent text's "Prior Art section."

Generated 5/16/2026, 12:49:08 PM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

✓ Generated

For US Patent 12003529, titled "Techniques for detecting artificial intelligence model cybersecurity risk in a computing environment," the following details regarding its term and related applications can be derived from the provided patent information and general USPTO procedures:

Patent Term Adjustment (PTA):
The exact Patent Term Adjustment (PTA) amount for US12003529 cannot be definitively determined without accessing its official prosecution history in the USPTO's Patent Center. PTA is calculated by the USPTO to compensate for certain administrative delays during the examination of a patent application. The calculation is automatically performed by the USPTO and typically included in the Issue Notification Letter. Given the patent's filing date of 2024-02-22 and publication date of 2024-06-04, the relatively short period between filing and issuance suggests that any PTA might be minimal, but a precise figure requires official USPTO records.

Patent Term Extension (PTE):
Patent Term Extension (PTE) is highly unlikely to apply to US12003529. PTE is granted under specific circumstances, primarily for patents covering pharmaceutical drugs, medical devices, food additives, or color additives to compensate for delays incurred during regulatory review processes, such as by the Food and Drug Administration (FDA) or Department of Agriculture. The subject matter of US12003529, concerning artificial intelligence model cybersecurity risk, does not fall within these categories.

Continuation Applications, Divisional Applications, and Related Family Members:
The patent document for US12003529 indicates several priority applications, which are typically precursors or related applications in a patent family:

  • US18/584,659 (Filing Date: 2024-02-22) – This is the application number directly associated with US12003529B1.
  • US18/647,876 (Priority Date: 2024-04-26) – This application is explicitly linked to US12401683B1.
  • US18/888,967 (Priority Date: 2024-09-18) – This application is explicitly linked to US12273372B1.
  • US19/071,373 (Priority Date: 2025-03-05) – This application is explicitly linked to US20250274484A1.

These "Priority to" entries suggest that US12003529 is part of a larger patent family, and these other listed application numbers represent related filings, such as continuation applications, continuation-in-part applications, or divisional applications. The exact nature of their relationship (e.g., whether they are continuations or divisionals) would typically be detailed in their respective application file histories within the USPTO's Patent Center.

Projected Expiration Date:
The patent document for US12003529 explicitly lists an "Anticipated expiration" date of 2044-02-22. This date is typically calculated as 20 years from the earliest effective filing date, plus any applicable Patent Term Adjustment (PTA), and minus any disclaimed term due to a terminal disclaimer. Given the filing date of 2024-02-22, a standard 20-year term would end on 2044-02-22, implying either no PTA or that the PTA calculation leads to this specific date.

Generated 5/16/2026, 12:49:19 PM

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

✓ Generated

Defensive Disclosure Document: US Patent 12003529 Derivatives

This document describes derivative variations and combinations for the subject matter of US Patent 12003529, "Techniques for detecting artificial intelligence model cybersecurity risk in a computing environment," for the purpose of establishing prior art and rendering future incremental improvements obvious or non-novel. The derivations focus on expanding the scope and application of the core inventive concepts, particularly those outlined in Independent Claim 1.

Core Claim 1: Method for Detecting AI Cybersecurity Risk

Independent Claim 1: A computer-implemented method for detecting a cybersecurity risk of an artificial intelligence (AI), the method comprising:
a. inspecting a computing environment for an AI model deployed therein;
b. generating a representation of the AI model in a security database, the security database including a representation of the computing environment;
c. inspecting the AI model for a cybersecurity risk;
d. generating a representation of the cybersecurity risk in the security database, the representation of the cybersecurity risk connected to the representation of the AI model in response to detecting the cybersecurity risk; and
e. initiating a mitigation action based on the cybersecurity risk.


Derivative Variations

1. Material & Component Substitution: Neuromorphic Computing Environment and Analog AI Models

Enabling Description:
This derivative implements the method of US12003529 within a neuromorphic computing environment, utilizing analog AI models instead of conventional digital AI models. The "computing environment" inspection (Claim 1a) would involve monitoring the state and connectivity of spiking neural networks (SNNs) on specialized neuromorphic hardware (e.g., Intel Loihi, IBM TrueNorth). The "AI model" itself (Claim 1b) would be an analog neural network, with its representation capturing network topology, synapse weights, and neuron firing characteristics. Inspection for cybersecurity risks (Claim 1c) would focus on anomalies in synaptic plasticity, unexpected neuron firing patterns, or deviations in analog signal processing indicative of data poisoning through analog noise injection, adversarial analog input perturbation, or malicious modification of physical resistance states representing weights. The security database (Claim 1d) would store representations of these analog states and their historical deviations. Mitigation actions (Claim 1e) could include dynamically reconfiguring neuromorphic hardware routing, resetting synaptic weights from a trusted baseline, or physically isolating compromised neuromorphic processing units to prevent further propagation of analog malfeasance.

graph TD
    A[Neuromorphic Compute Environment] -- Inspect (SNNs, Hardware State) --> B(Analog AI Model Detection)
    B -- Generate Representation --> C{Security Database (Analog States, Topology)}
    C -- Inspect for Risk (Synaptic Anomalies, Firing Patterns) --> D(Cybersecurity Risk Detection)
    D -- Generate Risk Representation --> C
    D -- Initiate Mitigation --> E[Neuromorphic Reconfiguration / Isolation]

2. Material & Component Substitution: Quantum Computing Environment and Quantum AI Models

Enabling Description:
This derivative applies the cybersecurity risk detection framework to quantum computing environments hosting quantum AI models. The "computing environment" (Claim 1a) would be a quantum processor unit (QPU) or a quantum annealer. "AI models" (Claim 1b) would be represented as quantum circuits (e.g., parameterized quantum circuits for variational quantum algorithms, quantum neural networks) or problem Hamiltonians for quantum annealing. The representation in the security database would include quantum circuit diagrams, qubit entanglement maps, gate sequences, and the coherence properties of the qubits. Inspection for cybersecurity risks (Claim 1c) would involve analyzing quantum circuit injection attacks, adversarial quantum samples, or decoherence-induced errors that are statistically significant beyond expected noise. This would necessitate monitoring gate fidelity, entanglement entropy, and quantum state tomography results. Risks detected (Claim 1d) would include backdoored quantum circuits or altered training Hamiltonians. Mitigation actions (Claim 1e) could involve rolling back to a known-good quantum circuit state, re-initializing qubits, or pausing execution on compromised QPUs, potentially leveraging quantum error correction codes for specific threat remediations.

graph TD
    A[Quantum Compute Environment (QPU)] -- Inspect (Circuit States, Qubit Coherence) --> B(Quantum AI Model Detection)
    B -- Generate Representation --> C{Security Database (Quantum Circuits, Entanglement)}
    C -- Inspect for Risk (Adversarial Samples, Decoherence Anomaly) --> D(Cybersecurity Risk Detection)
    D -- Generate Risk Representation --> C
    D -- Initiate Mitigation --> E[Quantum Circuit Rollback / Qubit Re-init]

3. Operational Parameter Expansion: Ultra-Low Latency Edge AI Risk Detection

Enabling Description:
This derivative focuses on detecting cybersecurity risks in AI models deployed on edge devices requiring ultra-low latency inference and real-time mitigation. The "computing environment" (Claim 1a) would encompass a fleet of heterogeneous edge devices (e.g., IoT gateways, smart cameras, industrial controllers) operating with limited resources. "AI models" (Claim 1b) would be highly optimized, lightweight models (e.g., TinyML, quantized neural networks) embedded directly on microcontrollers or specialized edge ASICs. Inspection (Claim 1c) would occur continuously, potentially leveraging hardware-level performance monitoring units (PMUs) and on-device Trusted Execution Environments (TEEs) to detect subtle deviations in inference results, power consumption, or memory access patterns at microsecond granularity. The "security database" (Claim 1d) could be a distributed ledger or a highly optimized time-series database running on a local edge aggregator, focused on storing only critical, actionable risk indicators. Mitigation actions (Claim 1e) would be pre-programmed, hardware-accelerated responses such as immediate model disabling, fail-safe mode activation, or local network isolation (e.g., disabling specific network interfaces on the edge device) within milliseconds of detection.

sequenceDiagram
    participant EdgeDevice
    participant OnDeviceInspector
    participant EdgeAggregator/DB
    participant CloudSecurityPlatform

    EdgeDevice->>OnDeviceInspector: Real-time AI Inference Data
    OnDeviceInspector->>OnDeviceInspector: Inspect AI Model (PMU, TEE)
    alt Anomalous Behavior Detected
        OnDeviceInspector-->>EdgeAggregator/DB: (Ultra-low Latency) Send Risk Indicator
        EdgeAggregator/DB-->>EdgeAggregator/DB: Generate Risk Representation
        EdgeAggregator/DB-->>EdgeDevice: Initiate Mitigation (Hardware-accel)
        EdgeDevice->>EdgeDevice: Apply Mitigation (Disable Model, Fail-Safe)
    else No Anomaly
        OnDeviceInspector-->>EdgeAggregator/DB: (Periodic) Send Heartbeat/Summary
    end
    EdgeAggregator/DB-->>CloudSecurityPlatform: (Batch/Async) Send Aggregate Risk Data

4. Operational Parameter Expansion: Planetary-Scale Federate Learning (FL) Risk Monitoring

Enabling Description:
This derivative extends the patent's methodology to monitor AI models in planetary-scale federated learning (FL) environments, where models are trained collaboratively across vast numbers of distributed clients without centralizing data. The "computing environment" (Claim 1a) is effectively a global mesh of client devices (e.g., smartphones, IoT devices, medical imaging machines). "AI models" (Claim 1b) are the local model weights or gradients contributed by each client to a global model. The "security database" (Claim 1d) must be a highly distributed, eventually consistent ledger or graph database capable of representing millions or billions of individual client model states and their aggregation history. Inspection for cybersecurity risks (Claim 1c) involves detecting adversarial contributions (e.g., data poisoning on client devices, model inversion attacks on shared gradients), model leakage, or backdoor insertions within aggregated model updates. This would require sophisticated differential privacy analysis, anomaly detection on aggregated gradients, and cryptographic proofs of training data integrity from client devices. Mitigation actions (Claim 1e) would include isolating malicious clients, rejecting suspicious model updates, or rolling back the global model to a previous verified state, implemented through a distributed consensus mechanism.

graph LR
    subgraph Client Fleet (Global)
        C1(Client 1)
        C2(Client 2)
        ...
        CN(Client N)
    end

    C1 -- Local AI Model / Gradients --> Aggregator[Federated Aggregator]
    C2 -- Local AI Model / Gradients --> Aggregator
    CN -- Local AI Model / Gradients --> Aggregator

    Aggregator -- Inspect (Gradient Anomaly, Data Leakage, Backdoors) --> RiskDetector(FL Risk Detector)
    RiskDetector -- Generate Representation --> SecurityDB(Distributed Security Database)
    SecurityDB -- Connect Risk to Model Rep --> SecurityDB
    RiskDetector -- Initiate Mitigation --> Aggregator
    Aggregator -- Mitigation Action --> C1, C2, CN (Isolate Client, Reject Update)

5. Cross-Domain Application: Cybersecurity Risk Detection for Autonomous Vehicle AI

Enabling Description:
This derivative applies the core method to AI models governing critical functions in autonomous vehicles (AVs). The "computing environment" (Claim 1a) is the vehicle's onboard computational platform, including its various Electronic Control Units (ECUs) and domain controllers. The "AI model" (Claim 1b) refers to perception models (e.g., object detection, lane keeping), prediction models, planning models, and control models embedded within the AV's software stack. The security database (Claim 1d) would maintain representations of these models, their training datasets, and their operational parameters in various driving scenarios. Inspection for cybersecurity risks (Claim 1c) would involve real-time monitoring of AI model outputs against expected behavior, detecting adversarial attacks on sensor inputs (e.g., LiDAR spoofing, camera pixel manipulation), unexpected decision-making patterns, or deviations in model confidence scores. This would also include analyzing model updates for unauthorized modifications or embedded backdoors. Mitigation actions (Claim 1e) could range from engaging a minimum risk maneuver (MRM), transferring control to a human driver, isolating compromised ECUs, or triggering a diagnostic and lockdown procedure for the affected AI module.

flowchart TD
    A[AV Onboard Platform] --> B{Inspect Vehicle ECUs for AI Models}
    B --> C[Detect Perception, Prediction, Planning AI Models]
    C --> D{Generate AI Model Representation in Security DB}
    D --> E{Inspect AI Models for Cybersecurity Risk (Adversarial Input, Malicious Updates)}
    E --> F{Detect Risk (e.g., Perception Anomaly, Control Deviation)}
    F --> G[Generate Risk Representation in Security DB, Link to AI Model]
    G --> H[Initiate Mitigation Action (MRM, Human Takeover, ECU Isolation)]

6. Cross-Domain Application: Cybersecurity Risk Detection for AI in Drug Discovery and Genomics

Enabling Description:
This derivative applies the patent's method to AI models used in sensitive drug discovery and genomic analysis platforms. The "computing environment" (Claim 1a) would be a high-performance computing (HPC) cluster, cloud environment, or specialized bioinformatics workstation used for drug design, protein folding, or genomic sequencing analysis. The "AI model" (Claim 1b) would include models for molecular docking, de novo drug design (e.g., generative models), predictive toxicology, or disease diagnosis from genomic data. The security database (Claim 1d) would store representations of these models, their proprietary training datasets (e.g., chemical compound libraries, patient genomic data), and provenance metadata. Inspection for cybersecurity risks (Claim 1c) would involve detecting model inversion attacks to reconstruct sensitive training data (e.g., patient genomes, proprietary molecular structures), adversarial perturbations to drug candidates, or manipulation of predictive models to bias research outcomes. This also includes verifying the integrity of AI-generated molecular structures or genomic insights. Mitigation actions (Claim 1e) could involve revoking model access for specific users, quarantining potentially compromised research results, invalidating AI-generated designs, or initiating a full audit of the affected model and its associated data.

graph TD
    A[HPC Cluster/Cloud for Drug Discovery] -- Inspect --> B(Detect Molecular Docking, Generative AI Models)
    B -- Generate Representation (Model, Training Data) --> C{Security Database (Proprietary Data, Provenance)}
    C -- Inspect for Risk (Model Inversion, Adversarial Perturbations) --> D(Cybersecurity Risk Detection)
    D -- Generate Risk Representation --> C
    D -- Initiate Mitigation --> E[Quarantine Results / Invalidate Designs / Access Revocation]

7. Cross-Domain Application: Cybersecurity Risk Detection for AI in Smart Grid and Industrial Control Systems (ICS)

Enabling Description:
This derivative targets AI models deployed within critical infrastructure, specifically smart grid and ICS environments. The "computing environment" (Claim 1a) comprises a distributed network of SCADA systems, RTUs (Remote Terminal Units), PLCs (Programmable Logic Controllers), and cloud-connected operational technology (OT) components. The "AI model" (Claim 1b) would include predictive maintenance models, demand forecasting models, anomaly detection systems for grid stability, or optimization models for energy distribution. The security database (Claim 1d) would represent these AI models, their connections to physical assets, and their operational impact on the grid. Inspection for cybersecurity risks (Claim 1c) would focus on detecting adversarial attacks designed to disrupt grid operations (e.g., false data injection to manipulate forecasts, model degradation to hide equipment failures, or control command manipulation). This includes real-time analysis of model inputs from OT sensors, outputs sent to actuators, and internal model states for deviations. Mitigation actions (Claim 1e) would prioritize grid stability and safety, including activating emergency shutdown procedures for specific components, isolating compromised control loops, switching to manual control, or triggering predefined "black start" or "island mode" protocols for affected segments of the smart grid.

flowchart LR
    A[Smart Grid / ICS Environment] --> B{Inspect SCADA/OT for AI Models}
    B --> C[Detect Predictive Maint, Demand Forecast AI Models]
    C --> D{Generate AI Model Representation in Security DB}
    D --> E{Inspect AI Models for Cybersecurity Risk (False Data Injection, Model Degradation)}
    E --> F{Detect Risk (e.g., Grid Instability Prediction, Actuator Anomaly)}
    F --> G[Generate Risk Representation in Security DB, Link to AI Model]
    G --> H[Initiate Mitigation Action (Emergency Shutdown, Isolate Control Loop, Manual Control)]

8. Integration with Emerging Tech: AI-Driven Optimization of Risk Inspection and Mitigation

Enabling Description:
This derivative enhances the patent's method by introducing an AI-driven optimization layer for the inspection and mitigation processes. A meta-AI model (e.g., a reinforcement learning agent or an expert system) continuously analyzes the effectiveness of different inspection techniques (Claim 1c) and mitigation actions (Claim 1e) across various detected AI models (Claim 1b) and computing environments (Claim 1a), using historical risk data and mitigation outcomes stored in the security database (Claim 1d). The meta-AI dynamically adjusts inspection parameters (e.g., scan frequency, depth of analysis, specific anomaly detection algorithms) and mitigation strategies (e.g., choosing between soft quarantine vs. hard shutdown, selecting the optimal remediation script) to maximize security posture while minimizing operational disruption. This includes predicting emergent threat vectors against AI models and proactively adapting inspection profiles. The system learns which inspection heuristics are most effective for specific AI model types or deployment contexts and prioritizes resources accordingly.

graph TD
    subgraph Core Patent Method
        A(Inspect Environment for AI Model) --> B(Generate AI Model Representation)
        B --> C(Inspect AI Model for Risk)
        C --> D(Detect Cybersecurity Risk)
        D --> E(Generate Risk Representation)
        E --> F(Initiate Mitigation Action)
    end

    G[Meta-AI Optimization Engine] -- Analyze DB Feedback (Risk/Mitigation Outcomes) --> G
    G -- Dynamically Adjust --> C
    G -- Select Optimal --> F
    F --> B

9. Integration with Emerging Tech: IoT Sensor-Driven Real-time AI Model Monitoring

Enabling Description:
This derivative integrates real-time data from a pervasive network of IoT sensors to enrich the cybersecurity risk detection for AI models. The "computing environment" (Claim 1a) includes not only traditional IT/cloud infrastructure but also the physical IoT deployments from which AI models derive their inputs or influence outputs. The "AI model" (Claim 1b) is inspected for risks based on its internal state AND the integrity and contextual relevance of its real-time input data streams from IoT sensors. The security database (Claim 1d) is enhanced to include representations of IoT sensor networks, their data provenance, calibration states, and observed environmental conditions. Inspection for cybersecurity risks (Claim 1c) involves cross-referencing AI model performance and outputs with anomalous patterns detected by redundant IoT sensors, detecting sensor spoofing, data corruption at the edge, or environmental factors that could lead to AI model misbehavior or exploitation. Mitigation actions (Claim 1e) can be triggered not only by AI model anomalies but also by suspicious IoT sensor readings, leading to actions like isolating specific sensor feeds, requesting re-calibration, or temporarily switching the AI model to a more robust, less data-dependent mode.

flowchart LR
    subgraph IoT Sensor Network
        S1[Sensor 1 (Temp)]
        S2[Sensor 2 (Pressure)]
        S3[Sensor 3 (Video)]
    end

    S1 -- Real-time Data --> A[Computing Environment]
    S2 -- Real-time Data --> A
    S3 -- Real-time Data --> A

    A -- Inspect Env for AI Model --> B(Detect AI Model)
    B -- Generate AI Model Representation --> C{Security Database (AI Models, IoT Context, Sensor Data)}
    C -- Inspect AI Model & IoT Data for Risk --> D(Cybersecurity Risk Detection)
    D -- Generate Risk Representation --> C
    D -- Initiate Mitigation --> E[Isolate Sensor Feed / Model Fallback]

10. Integration with Emerging Tech: Blockchain-Verified AI Model Supply Chain and Provenance

Enabling Description:
This derivative incorporates blockchain technology to establish an immutable and verifiable supply chain for AI models and their components, significantly strengthening the "inspection" and "representation" steps. When "inspecting a computing environment for an AI model" (Claim 1a) and "generating a representation of the AI model" (Claim 1b), the system queries a distributed ledger (e.g., using Hyperledger Fabric or Ethereum) to verify the provenance of the AI model, its training data, version history, and associated code dependencies. Each significant event in the AI lifecycle (training completion, version release, deployment, data augmentation) is hashed and recorded on the blockchain. Inspection for cybersecurity risks (Claim 1c) now explicitly includes verifying the integrity and authenticity of the AI model against its recorded blockchain hash. Discrepancies indicate tampering or unauthorized modification. The "security database" (Claim 1d) links its internal representation to these blockchain records. Risks detected could include unverified model versions, unauthorized training data deviations, or compromised model weights not matching blockchain-registered hashes. Mitigation actions (Claim 1e) could include automatic rollback to a blockchain-verified model version, flagging the model as untrustworthy, or initiating a forensic audit using the immutable blockchain history.

graph TD
    subgraph AI Model Lifecycle
        TD[Training Data] -- HASH & Register --> BC(Blockchain Ledger)
        M_Train[Trained Model Version 1] -- HASH & Register --> BC
        M_Deploy[Deployed Model Version 1.1] -- HASH & Register --> BC
    end

    A[Computing Environment] -- Inspect AI Model (Local) --> B(Local AI Model Detected)
    B -- Generate Representation & Query BC --> C{Security Database (Local Rep, BC Hash Link)}
    C -- Inspect AI Model for Risk (Compare Local Hash to BC) --> D(Cybersecurity Risk Detection)
    D -- Detect Risk (Hash Mismatch, Unverified Provenance) --> E[Generate Risk Representation & Link to BC Record]
    E -- Initiate Mitigation --> F[Rollback to BC-Verified Version / Flag Untrustworthy]

11. The "Inverse" or Failure Mode: Fail-Safe AI Risk Detection with Graceful Degradation

Enabling Description:
This derivative describes a fail-safe mode for the AI cybersecurity risk detection system, enabling graceful degradation of service rather than catastrophic failure. In scenarios where the core inspection environment (130 in US12003529) experiences resource constraints or partial compromise, the system enters a "limited-functionality mode." "Inspecting a computing environment" (Claim 1a) and "inspecting the AI model" (Claim 1c) would be automatically scaled back. For example, instead of deep dynamic analysis, only static analysis of critical AI model binaries and configuration files occurs at reduced frequency. The "security database" (Claim 1d) might only store aggregated, high-level risk indicators, reducing data ingestion and processing load. "Generating a representation of the cybersecurity risk" (Claim 1d) would prioritize only high-severity, directly exploitable vulnerabilities. Mitigation actions (Claim 1e) would default to pre-approved, lowest-impact interventions, such as generating alerts to human operators for manual review rather than automated actions like model shutdowns. The system would continuously monitor its own health and resource availability, dynamically adjusting its operational mode (e.g., from full inspection to limited-functionality, or to "alert-only" mode) to maintain a minimal level of cybersecurity coverage under duress.

stateDiagram
    [*] --> Healthy
    Healthy --> ResourceConstraint: System Overload
    Healthy --> PartialCompromise: Inspector Failure

    ResourceConstraint --> DegradedMode: Auto-Scale Back
    PartialCompromise --> DegradedMode: Fail-Safe Activation

    DegradedMode --> LimitedInspection: Reduced Freq/Depth
    DegradedMode --> BasicRiskReporting: High-Severity Only
    DegradedMode --> ManualMitigationPrompt: Human Intervention

    LimitedInspection --> Healthy: Resources Restored
    BasicRiskReporting --> Healthy: All Systems Online
    ManualMitigationPrompt --> Healthy: Issue Resolved

    DegradedMode --> AlertOnlyMode: Severe Failure
    AlertOnlyMode --> Healthy: Critical Systems Restored

Combination Prior Art Scenarios

  1. Combination with Open Policy Agent (OPA) for Policy-Driven Mitigation:
    The core method of US12003529 (inspecting AI models, detecting risks, generating representations) can be combined with the Open Policy Agent (OPA) framework (an open-source, general-purpose policy engine). The "security database" (Claim 1b, 1d) would export its graph-based representations of AI models and detected risks to OPA's data plane. OPA would then evaluate these representations against predefined security policies (e.g., "AI models with detected secrets must not be public-facing," "models trained on sensitive data must not have lateral movement paths to production resources"). The "initiating a mitigation action" step (Claim 1e) would be directly managed by OPA, which could enforce policy decisions by calling appropriate remediation APIs (e.g., modifying network security groups, revoking access permissions, or triggering CI/CD pipeline rollbacks) based on its policy evaluation results. This provides a standardized, declarative approach to automating mitigation.

  2. Combination with OWASP Top 10 for Large Language Models (LLMs) as Risk Inspection Criteria:
    The "inspecting the AI model for a cybersecurity risk" step (Claim 1c) can be explicitly structured around the publicly available OWASP Top 10 for LLMs. This open-source standard provides a widely recognized list of common vulnerabilities and attack vectors specific to LLMs (e.g., Prompt Injection, Insecure Output Handling, Training Data Poisoning, Model Denial of Service). The AI detector's inspection heuristics would directly map to these OWASP categories. For instance, detecting prompt injection risk might involve analyzing input sanitization routines, while training data poisoning detection would involve inspecting the provenance and integrity of the training dataset for anomalies as per OWASP guidance. The "generating a representation of the cybersecurity risk" (Claim 1d) would categorize detected risks according to the OWASP Top 10 for LLMs taxonomy, providing a standardized, openly understood framework for risk reporting and prioritization.

  3. Combination with Cloud Native Computing Foundation (CNCF) projects like Falco (Runtime Security) and OpenTelemetry (Observability):
    The "inspecting a computing environment" (Claim 1a) and "inspecting the AI model" (Claim 1c) steps can be augmented by integrating with Falco for real-time runtime security and OpenTelemetry for comprehensive observability. Falco (an open-source project for cloud-native runtime security) would monitor AI model containers or serverless functions for suspicious system calls, file access patterns (e.g., unexpected access to training data during inference), or network activity that deviates from established baselines, directly contributing to risk detection. OpenTelemetry (an open-source observability framework) would collect and export AI model telemetry data (e.g., inference latency, resource utilization, API calls made by the AI model) alongside contextual traces and logs. This data, stored or referenced in the "security database" (Claim 1b, 1d), would provide enriched context for anomaly detection in AI model behavior, allowing for more precise identification of cybersecurity risks beyond just static code analysis or metadata inspection. The collected data would feed into AI model risk analysis and provide detailed insights for automated or human-driven mitigation actions.

Generated 5/16/2026, 12:49:45 PM

Keep exploring

More patents asserted by Petitioner

Other patents in High-Tech (T)

See all High-Tech (T) patents →

This patent in court (2)

2 tracked lawsuits name US 12003529.