Relational Injection Attack Against Relational Deep Learning
Abstract
Relational deep learning (RDL) predicts outcomes for entities using information from database rows connected through foreign-key relationships. This reliance on relational context raises a question: can permitted row insertions manipulate an existing target’s prediction without modifying existing records or the trained model? We formulate Relational Injection Attack (RIA), a test-time attack that inserts linked rows under explicit write permissions. Under a white-box setting, our framework consists of two components: schema-admissible path selection and value optimization. The path selector ranks injection paths using the model’s response and the potential gains from attribute changes. For value optimization, we introduce Relational Projected Gradient Descent (RelPGD), which optimizes continuous weights over discrete candidate values using centered and scaled gradients, followed by multi-start local search on unsuccessful targets. We evaluate twelve binary classification tasks from seven RelBench datasets. Our path selector improves macro-average attack success rate by 10.1 percentage points over the relation-weight-norm heuristic. RelPGD matches or exceeds the mean attack success rates of CAPGD in 21 of 24 task–model settings. These findings demonstrate that permitted row injections can affect predictions, motivating their inclusion in RDL robustness evaluations. For transparency, our source code is available at [https://anonymous.4open.science/r/RIA-DCC0](https://anonymous.4open.science/r/RIA-DCC0).
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.