Publication: Publication Date: 2018/11/01 Vol. E101-DNo. 11pp. 2665-2676 Type of Manuscript: Special Section PAPER (Special Section on Information and Communication System Security) Category: Forensics and Risk Analysis Keyword: black box, model inversion, data poisoning, online ML systems,