acceptodds
Under review as a conference paper at ICLR 2027

Relational Injection Attack Against Relational Deep Learning

Abstract

Relational deep learning (RDL) predicts outcomes for entities using information from database rows connected through foreign-key relationships. This reliance on relational context raises a question: can permitted row insertions manipulate an existing target’s prediction without modifying existing records or the trained model? We formulate Relational Injection Attack (RIA), a test-time attack that inserts linked rows under explicit write permissions. Under a white-box setting, our framework consists of two components: schema-admissible path selection and value optimization. The path selector ranks injection paths using the model’s response and the potential gains from attribute changes. For value optimization, we introduce Relational Projected Gradient Descent (RelPGD), which optimizes continuous weights over discrete candidate values using centered and scaled gradients, followed by multi-start local search on unsuccessful targets. We evaluate twelve binary classification tasks from seven RelBench datasets. Our path selector improves macro-average attack success rate by 10.1 percentage points over the relation-weight-norm heuristic. RelPGD matches or exceeds the mean attack success rates of CAPGD in 21 of 24 task–model settings. These findings demonstrate that permitted row injections can affect predictions, motivating their inclusion in RDL robustness evaluations. For transparency, our source code is available at [https://anonymous.4open.science/r/RIA-DCC0](https://anonymous.4open.science/r/RIA-DCC0).

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.