skip to content

Features Cheap to Rewrite

When the input is a form the adversary fills in, the budget is money and attestation rather than a distance. Interviewers ask because the image threat model gets imported here wholesale.

on this pageshow

explore

questions

4

In a merchant-onboarding risk model, what separates fields an applicant rewrites for free from ones they cannot?

level: juniorimportance: must knowfreq 58%

answer

  1. written by the person being judged
  2. the budget is currency, not distance
  3. some fields cost only a keystroke
  4. some are asserted by a third party
  5. free, costly to make true, or attested

basics

~20 s

Price to the applicant, not distance. Self-declared fields cost only a retype. Fields such as trading tenure cost real money or real waiting. Fields bound to a third-party attestation cost the applicant a fraud against that party.

solid answer

~50 s

When the person being scored also writes the model's input, their budget is denominated in money and effort per field rather than in distance from some original. It splits three ways. Fields set by assertion — stated business category, stated monthly volume, a website registered this morning — cost a retype. Fields that must be made true — incorporation age, a settled trading history, a real customer base — cost money, waiting, or both. Fields bound to a third-party attestation — a bank-verified balance, settled card-network history, a checked identity document — cost an actual fraud against that third party, which many applicants will not commit. A merchant applicant sees only approve, decline or refer, holds no model access at all, and still has complete authorship of the first tier. That authorship, not any query budget, is their vantage.

go deeper

for a junior

Be ready to say who writes each input a decisioning model reads, and to sort a short list of fields into ones the subject types, ones they would have to spend money on, and ones a third party asserts.

for a middle

Explain why the split is about price rather than plausibility, and why a column can look clean and predictive in historical data while still being free for a motivated applicant to set.

for a senior

Show that you would inventory the whole feature set this way before arguing about controls, and that you can say how much of a live model's score currently rests on the free tier.

for a principal

Own the consequence: consuming a highly weighted, free-to-set column is a deliberate risk position, and the alternatives all cost integration, funnel or review hours that somebody has to fund.

## The setting A merchant-onboarding risk model scores a business that wants to accept card payments. Some of what it reads is typed into a form by the applicant: stated business category, stated monthly card volume, a website address, a contact number, a director's address. Some of it arrives from somewhere else: an average balance read from a connected bank account, months of settled history from a card network, an incorporation date from a public registry, an identity document checked by a third party. The adversary in this picture is the applicant. They never see weights, gradients or a score vector; the reply is approve, decline or refer. They cannot poison anything and they are not sending crafted images. What they have is authorship of the record being judged, and the question the threat model has to answer is: for each column the model consumes, who sets its value, and what does setting it differently cost that person? ## Three tiers of price **Free to retype.** A self-declared string or number is set by assertion. Nothing compares it against a truth at decision time, so the applicant types a different value and the model reads an ordinary row. A stated monthly volume, a stated category, a self-reported employee count and a freshly registered domain all sit here. A domain is a useful borderline case: it costs a registration fee and, if the model reads its *age*, it costs waiting — which is exactly the point of pricing per field rather than per record. **Costly to make true.** Some fields can only be changed by changing the world. Incorporation age can be bought only by waiting or by acquiring an older entity. A settled trading history has to be produced by real transactions, which means real counterparties, real settlement and real time. A funded balance means actually holding money. These are not impossible — they are priced, and the price is in currency and calendar time. **Bound to an attestation.** Some fields are asserted by a party other than the applicant: a bank, a card network, a registry, an identity checker. To move one of these the applicant has to defraud that party, which converts a form-filling exercise into a criminal act against an institution that keeps records. Most people who would happily overstate a turnover figure will not do that, and the ones who will leave a much heavier trail. ## Why this is a threat model and not feature engineering The same three-way split, read from the modelling side, is a question about data quality. Read from the adversary's side it is a budget: it says exactly which parts of the input surface an unfunded, unskilled, model-blind adversary controls completely. That is what makes it a vantage statement. The measurement that matters is not how noisy a column is but how much of the decision rests on columns whose author is the subject. ## What an attestation buys, and what it does not Attestation raises the price of a field; it does not make the field mean what you assume. A verified balance is a fact about one account on one day, not about the business's finances. A checked identity says who completed the check, not who will control the account next month. A registry date says when an entity was incorporated, not that it has ever traded. Treating an attested column as ground truth is the mirror-image mistake of treating a self-declared one as evidence. ## What follows for design Once the inventory exists, the design questions are concrete. How much of the score can the free tier move on its own? Is a free field corroborated by a priced one, so that disagreement is itself a signal? Would you refuse to consume a column outright because it is both highly weighted and set by the applicant for nothing? Those are modelling and product decisions, and they are the honest response to this adversary — there is no distance constraint to tighten. ## Where this stops Advising a rejected applicant which change is easiest for them to make is recourse and belongs with counterfactual explanation. Whether a column is a proxy for something you should not decide on is a fairness question. How rules engines and manual review are built is product work. This leaf owns only the pricing of the input surface from the adversary's side.

  • Does requiring an attestation on a field make that field trustworthy?
    It binds the field to a party who keeps records and can be held accountable, and it raises the applicant's cost from a retype to a fraud against that party. It does not make the field mean what you assume: an attested balance is true of one account on one day, and a checked identity says who signed up, not who controls the account later. Attestation prices a field; it does not validate your interpretation of it.
  • If a field is free to retype, do you have to drop it?
    No. You can keep it where it is cheap to cross-check against a priced field, where disagreement between the two is itself a useful signal, or where it can only ever contribute a small share of the score. Dropping is one option; capping its influence, requiring corroboration, or routing disagreement to review are others. The step you cannot skip is making the price explicit before you weight it.
  • Why is this different from asking which features are noisy?
    Noise is accidental and roughly symmetric; a self-declared field under an adversarial author is deliberate and one-directional, pushed toward whichever value the model rewards. A column can be low-noise historically and still be free to set, because the historical population had no reason to lie. The inventory you need is who authors each value and what a change costs them, not how clean the column looks.

A rental application: your stated salary is a sentence you write, your payslips cost you a job, and a landlord reference costs you somebody else's signature.

saying these in an interview costs you the question

  • Treats a self-declared field as evidence about the world
  • Says a capped perturbation budget bounds what an applicant can do
  • Assumes an attested field cannot be influenced at all
  • Confuses cost to change with feature importance
  • Thinks no model access means no reach over the input

context

open as a page

Why does a perturbation radius fail to describe a loan applicant editing their own application?

level: middleimportance: should knowfreq 50%

basics

~20 s

An applicant does not nudge a stated income by a fraction of a percent; they type a different number. A radius assumes a true input to stay near, and a self-authored form has none. The limit is per-field cost.

open as a page

A merchant-risk model's most predictive columns are all self-declared - what do you report?

level: seniorimportance: should knowfreq 40%

basics

~20 s

Accuracy was measured on applicants with no reason to misstate those fields. Report the share of score sitting on columns the subject retypes for free, and what the cheapest application that flips a decline costs.

open as a page

Onboarding wants to drop bank verification to lift signup conversion - what do you own in that call?

level: principalimportance: nice to knowfreq 26%

basics

~20 s

Naming what the step buys: it holds one column the applicant cannot set for free. Removing it moves score mass onto retypeable fields and drops the cheapest successful application to near zero. Price that shift; the conversion appetite is the business's.

open as a page