ARCHIVES
HAT-D: Lightweight Embedding-Space Adversarial Training with a Compact Denoiser for Robust Sentiment Analysis
South Africa
Published Online: March-April 2026
Pages: 153-164
Cite this article
↗ https://www.doi.org/10.59256/ijsreat.20260602022Adversarial perturbations, including synonym substitutions, character-level edits, and token insertions, can significantly degrade the performance of modern sentiment-analysis models. Although adversarial training is widely regarded as one of the most effective defences against such attacks, it typically incurs sub- stantial computational cost and training complexity, which can limit its practicality in resource-constrained deployment settings. This work investigates whether meaningful robustness improvements can be achieved through a lightweight hybrid defence that balances robustness, accuracy, and efficiency. We propose HAT-D, a lightweight hybrid robustness framework that combines TRADES-style embedding-space adversarial training with a compact denoising module (and optional smoothing), and evaluate it under synonym, character, insertion, and mixed attack settings. The design aims to improve robustness against discrete text perturbations without the full computational cost of end-to-end adversarial fine-tuning. The framework is evaluated on the SST-2 sentiment classification benchmark under multiple adversarial attack families, including synonym substitution, character-level perturbations, token insertions, and mixed strategies. Experimental results show that full adversarial training achieves the highest overall robustness under our multi-attack evaluation, while ensemble-based defences remain competitive but incur substantial deployment overhead. HAT-D provides a single-model hybrid alternative that preserves essentially unchanged clean inference latency (at the reported precision) and avoids the multiplicative adaptation cost and footprint of ensembles. Overall, the results emphasize that robustness is attack-family dependent, motivating joint reporting of robustness, clean performance, and efficiency when selecting practical defences. These results highlight the importance of evaluating robustness methods not only by adversarial accuracy but also by their computational efficiency. By explicitly characterizing the robustness–accuracy–efficiency trade-off, this work demonstrates that lightweight hybrid defences can provide a practical operating point for robust NLP deployment in resource-constrained environments.
Related Articles
2026
Fake Currency Detection Using Deep Learning
2026
Smart E-Commerce System with Dynamic Pricing
2026
Personal Expense Tracker with Currency Converter
2026
Paw Safe: An Extensive Technology-Driven Framework for Stray Dog Rescue, Healthcare Management, Community Engagement, and Smart Urban Governance
2026
Design and Development of a Full-Stack E-Commerce Website
2026
Power quality improvement techniques from a topological perspective: An overview
2026
The Rust Tax: Measuring the Cost of Memory Safety and Safely Recovering What You Can
2026
Determination of Spectral Source Parameters from Broadband Earthquake Records in Western Anatolia (Türkiye)
2026
Spatial Damage Pattern and Structural Vulnerability Assessment of Moderate Magnitude Earthquakes: The 2017–2019 Ayvacık Case Study, Western Anatolia
2026
Integrated Rainwater Harvesting In a 10.1 Km Urban Elevated Corridor: Hydrological Performance, Urban Climate Resilience and Infrastructure Sustainability Implications


