Security

Domestic AI Supply Chain Security ‘Gap’... Professor Lee Man-hee Says, “We Need to Start by Securing Visibility”

TECHWORLD ·

Professor Lee Man-hee of Hannam University. [Photo: Reporter Kim Hye-jin]

✦ AI Summary

Domestic AI supply chain security was raised as an issue, with criticism that institutional and response frameworks have not adequately reflected the need to begin with securing visibility.

While recommendations and standardization for AI BOM are progressing overseas, Korea was contrasted as lagging in related progress.

Professor Lee Man-hee said it is necessary to identify the sources of data and models and the paths through which they enter, and that securing visibility against AI supply chain attacks is a condition for both defense and traceability.

A gap in domestic AI supply chain security has been raised, along with the point that visibility must come first. As AI spreads, the need to extend the scope of supply chain security across AI systems is growing, but there is concern that domestic systems and response frameworks have not kept pace.

While efforts are under way overseas to establish recommendations for AI BOM(AI Bill of Maerials), the lack of related progress in Korea was also contrasted. Lee Man-hee, a professor at Hannam University and chair of the Supply Chain Security Research Committee, participated as a session speaker at the Private AI Tech Summit on the 4th and introduced global trends in AI supply chain security, explaining AI BOM as an emerging response tool based on his presentation, “Supply Chain Security in the Era of AI Transformation.”

Professor Lee said the AI system process spans everything from data collection to service operation. He then suggested that the scope of supply chain security should be expanded beyond source code to include data, models, infrastructure, hardware, and third-party services.

He pointed out the need to guard against malicious data infiltration. The scope in question is AI systems, including both internal and external models. He explained that if malicious data enters and there is no audit trail, it is difficult to identify the source of the infection and also difficult to assess the impact.

The reason, he said, is the growing importance of visibility in supply chain security across AI systems. In this context, global research trends are focusing on AI BOM for AI supply chain security.

AI BOM refers to a specification for recording information about the models used in an AI system, as well as datasets, training configurations, evaluation metrics, SW dependencies, framework information, license information, and legal requirements. AI BOM has the character of extending the SBOM concept to AI systems.

According to the speaker’s summary, AI BOM is currently being standardized. Examples of standardization include CucloneDX v1.5 and SPDX 3.0. In May this year, a document titled “SBOM for AI: Minimum Elements” was prepared with participation from the U.S., Germany, France, Italy, Canada, the U.K., Japan, and the EU executive branch.

The AI BOM minimum requirements guidance suggests including in AI BOM the SBOM document itself, overall properties of the AI system, information on the models used, datasets across the full lifecycle, physical and virtual infrastructure, cybersecurity measures, and KPI. However, it is not a mandatory legal standard.

He went on to say that, unlike overseas, Korea’s preparation for AI supply chain security is insufficient. He noted that the AI Framework Act enforcement decree does not mention the AI supply chain, and that the roadmap for strengthening supply chain security also omits AI-related content such as AI vulnerability handling. He also said that next year’s software informatization projects will introduce SBOM submission and vulnerability response procedures, but since AI systems are also SW, SBOM submission is necessary. He added that there are questions because related matters have not been clearly specified.

The AI Framework Act includes the need for AI safety and a management framework for high-impact AI. However, it does not contain an AI supply chain transparency item. The supply chain security strengthening roadmap released in June this year mentioned the start of standardizing SBOM management systems in the public sector and the building of an integrated SBOM management system, but it does not include AI-specific content.

For these reasons, the domestic situation is summarized as one in which preparation for AI supply chain security is generally insufficient.

He explained that the government is pushing to strengthen AI reliability for AI supply chain security and is also moving ahead with SBOM mandates.

He said that, accordingly, AI Cyber Shield Dome will move ahead next year with 55 billion KRW for key technology initiation, and that AI supply chain security and AI BOM technology development have been selected as candidate tasks within the project. He said the AI Cyber Shield Dome project is an AI technology-based national cyber defense system R&D initiative led by the Ministry of Science and ICT and IITP over 5 years, covering threat detection, analysis, inference, and autonomous response.

On the governance side, he said, the AI Supply Chain Security Forum has begun, and on the research side, studies are under way on AI BOM formats and items tailored to the domestic environment. He explained that the forum’s goal is to establish minimum requirements for a Korean-style AI BOM, and that foundational research to define the forum’s minimum requirements is also in progress, with the goal of reflecting security suitability verification in the 2027 guidelines.

The speaker began by assuming that AI supply chain attacks have already become a reality, and contrasted the fact that recommendations are under way overseas while domestic progress is close to a gap compared with abroad. He then said that the absence of systems and technology is not a basis for inaction, and that the starting point for response is securing visibility. He explained that it is necessary to identify the sources of data and models and the paths through which they enter, and that understanding these processes is both a condition for defense and a condition for traceability.

Source: TECHWORLD · Kim Hye-jin
Original: https://www.epnc.co.kr/news/articleView.html?idxno=406570

References

This article was produced with the help of an automated content generation algorithm.


Source: TECHWORLD

View original

This article was summarized and organized by BizCrush based on the original article from TECHWORLD. For exact quotations and full details, please refer to the original article.