The user will be adversarial and probably learn new tricks to trick the machine, this is not solvable (only) via training data.