A survey of text adversarial attack and defense techniques

Guojun Zhang et al.

International Journal of Web Information Systems2026https://doi.org/10.1108/ijwis-10-2025-0359article
AJG 1
Weight
0.50

What the paper says

Purpose Text adversarial techniques are a key research area in natural language processing (NLP). With the widespread application of deep learning-driven NLP in sentiment analysis and machine translation, the lack of robustness against adversarial attacks has become increasingly evident. Adversarial samples in the text domain can mislead models and the discrete nature of text distinguishes adversarial techniques in this field from others. To outline recent progress, this paper aims to review relevant studies from the past decade, summarizing advancements in adversarial attack, defense and detection methods. Design/methodology/approach This paper conducts a systematic literature review of text adversarial attacks and defenses. The review begins with an analysis of attack methods, then discusses text adversarial defense and detection methods and finally points out the challenges in both attack and defense. Findings The authors provide a clear classification of attack methods based on specific criteria, followed by an overview of defense and detection techniques, highlighting their respective strengths and limitations. Originality/value This review systematically classifies and analyzes text adversarial attack, defense and detection techniques and thoroughly explores the challenges and future development directions in this field, providing valuable reference information for researchers in this area.

Open paper page →

Cite this paper

https://doi.org/https://doi.org/10.1108/ijwis-10-2025-0359

Or copy a formatted citation

@article{guojun2026,
  title        = {{A survey of text adversarial attack and defense techniques}},
  author       = {Guojun Zhang et al.},
  journal      = {International Journal of Web Information Systems},
  year         = {2026},
  doi          = {https://doi.org/https://doi.org/10.1108/ijwis-10-2025-0359},
}

Paste directly into BibTeX, Zotero, or your reference manager.

Flag this paper

A survey of text adversarial attack and defense techniques

Flags are reviewed by the Arbiter methodology team within 5 business days.


Evidence weight

0.50

Balanced mode · F 0.40 / M 0.15 / V 0.05 / R 0.40

F · citation impact0.50 × 0.4 = 0.20
M · momentum0.50 × 0.15 = 0.07
V · venue signal0.50 × 0.05 = 0.03
R · text relevance †0.50 × 0.4 = 0.20

† Text relevance is estimated at 0.50 on the detail page — for your query’s actual relevance score, open this paper from a search result.