ARCHIVES

Original Article

HAT-D: Lightweight Embedding-Space Adversarial Training with a Compact Denoiser for Robust Sentiment Analysis

Wonder Kudzo Ekpe1

South Africa

Published Online: March-April 2026

Pages: 153-164

Abstract

Adversarial perturbations, including synonym substitutions, character-level edits, and token insertions, can significantly degrade the performance of modern sentiment-analysis models. Although adversarial training is widely regarded as one of the most effective defences against such attacks, it typically incurs sub- stantial computational cost and training complexity, which can limit its practicality in resource-constrained deployment settings. This work investigates whether meaningful robustness improvements can be achieved through a lightweight hybrid defence that balances robustness, accuracy, and efficiency. We propose HAT-D, a lightweight hybrid robustness framework that combines TRADES-style embedding-space adversarial training with a compact denoising module (and optional smoothing), and evaluate it under synonym, character, insertion, and mixed attack settings. The design aims to improve robustness against discrete text perturbations without the full computational cost of end-to-end adversarial fine-tuning. The framework is evaluated on the SST-2 sentiment classification benchmark under multiple adversarial attack families, including synonym substitution, character-level perturbations, token insertions, and mixed strategies. Experimental results show that full adversarial training achieves the highest overall robustness under our multi-attack evaluation, while ensemble-based defences remain competitive but incur substantial deployment overhead. HAT-D provides a single-model hybrid alternative that preserves essentially unchanged clean inference latency (at the reported precision) and avoids the multiplicative adaptation cost and footprint of ensembles. Overall, the results emphasize that robustness is attack-family dependent, motivating joint reporting of robustness, clean performance, and efficiency when selecting practical defences. These results highlight the importance of evaluating robustness methods not only by adversarial accuracy but also by their computational efficiency. By explicitly characterizing the robustness–accuracy–efficiency trade-off, this work demonstrates that lightweight hybrid defences can provide a practical operating point for robust NLP deployment in resource-constrained environments.

Related Articles

2026

Fake Currency Detection Using Deep Learning

2026

Smart E-Commerce System with Dynamic Pricing

2026

Personal Expense Tracker with Currency Converter

2026

Paw Safe: An Extensive Technology-Driven Framework for Stray Dog Rescue, Healthcare Management, Community Engagement, and Smart Urban Governance

2026

Design and Development of a Full-Stack E-Commerce Website

2026

Power quality improvement techniques from a topological perspective: An overview

2026

The Rust Tax: Measuring the Cost of Memory Safety and Safely Recovering What You Can

2026

Determination of Spectral Source Parameters from Broadband Earthquake Records in Western Anatolia (Türkiye)

2026

Spatial Damage Pattern and Structural Vulnerability Assessment of Moderate Magnitude Earthquakes: The 2017–2019 Ayvacık Case Study, Western Anatolia

2026

Integrated Rainwater Harvesting In a 10.1 Km Urban Elevated Corridor: Hydrological Performance, Urban Climate Resilience and Infrastructure Sustainability Implications