Sep 4, 2018 · 1 min read
This will be very difficult. First of all the model (functional class) and the feature space are very hard to reverse engineer, when they are not known. I doubt any company would reveal this: do you know what features do Google use to rank your results if you are outside Google’s search team? Second, when someone start to tamper with the features, then the joint distribution of the input distribution shifted. This is very easy to detect and will be fixed simply by retraining a model on the newly collected data. In fact, many companies used online learning so the model can pick up these shifts automatically from streaming data.
