[Information Security Solutions Conference] 'AIDC environments must be segmented and protected more tightly'
IT DAILY ·
✦ AI Summary
Daegu University professor Kim Chang-hoon gave a keynote speech at the '2026 Information Security Solutions Conference' on AI-specific services for securing AI data centers (AIDC).
He explained that improving AI performance requires collecting and connecting distributed data at high speed, but security centers on distinguishing protected areas and restricting access and movement, creating tension between the two needs.
He also pointed out the absence of a security framework across AIDC and AI services, and proposed a new cybersecurity framework (CSF) for AIDC as well as the need to establish a national threat framework.
Kim Chang-hoon, a professor in the Cybersecurity major at Daegu University, delivered a keynote speech at the '2026 Information Security Solutions Conference' held on the 9th at El Tower in Yangjae-dong, Seoul, on the topic of 'AI-specific services for securing AI data centers (AIDC).' Kim is also the head of the N2SF Research Group of the Korean Association for Cybersecurity.
Kim explained that improving AI performance requires collecting data distributed across multiple systems and connecting it at high speed. He then said that the starting point of cybersecurity is distinguishing the protected area and restricting access and movement. He pointed out that a tension arises as the need to integrate and connect data for more advanced AI performance intersects with the principles of separation and control in security.
Kim said that as AI spreads, the difficulty of security challenges rises. He also stressed the need to establish a national threat framework suited to the AI era. In the photo, Kim is seen delivering a presentation at the event, and the photographer is Kim Ho-jun.
As AI spreads, AIDC, as the infrastructure that operates it, is drawing attention across industries, and interest in AIDC is also rising. Accordingly, moves to build AIDC facilities have begun across the country, and the budget for AIDC construction is estimated at several trillion won or more. Institutional reforms are also under way, and the Special Act on Promotion of the AIDC Industry is scheduled to take effect in March next year.
However, because AIDC is tied to the connected and integrated architecture of AI, tensions with traditional security approaches are expected to grow. Kim said that, as technology becomes concentrated in AIDC, security will become an even more difficult task. He also forecast that in AIDC environments, the asymmetry between AI sharing and separation and isolation will widen. Security becomes stronger as the level of asset and domain separation increases, but because AI relies on a connected and integrated structure, risk rises and the attack surface expands.
One new threat factor in AIDC is communication between graphics processing units (GPU). A representative example is Remote Direct Memory Access (RDMA), a GPU data transmission and reception technology that transfers data in GPU memory without going through the CPU or the OS. RDMA reduces CPU involvement and provides low latency, but from a security standpoint it may be exposed to additional threats.
Kim pointed out that the absence of a security framework across AIDC, AI services, and infrastructure is a problem. He said there is a lack of a system for identifying the location of an organization's IT assets, and also a lack of a system for predicting threats based on asset information.
In response, Kim proposed a new cybersecurity framework (CSF) for AIDC. The framework is based on three-axis threat modeling: axis 1 is the protected target, axis 2 is the target's location, and axis 3 is the security attributes that can be attacked. Location attributes are classified into three layers: infrastructure, cloud, and AI, and the analysis criteria for compromised security attributes are based on the CIA principle. The detailed elements of CIA are confidentiality (C), integrity (I), and availability (A).
Kim said he conducted 87 threat-modeling cases using an AIDC CSF draft, and the results showed that many AI-related threats were concentrated in the data domain. Going forward, he plans to set priorities using scores derived from the modeling results and, through that, improve the level of protection.
He also advised that the SOC needs to change. He noted that AIDC remains limited to rule-based threat detection set by public security monitoring, and said it must shift toward analyzing information from multiple layers and deriving correlations among attack behaviors.
Kim then predicted that the connected domain will expand through AI. He said this would lead to the spread of damage within internal networks, and noted that in the AI era, security needs to become more tightly woven. He also said that, unlike the growing attention on AIDC, cybersecurity is not getting the spotlight, and added that he hopes awareness of these issues will be reflected in future national policy.
Source: IT DAILY · Kim Ho-jun
Original: https://www.itdaily.kr/news/articleView.html?idxno=241492
References
This article was produced with the help of an automated content generation algorithm.
Source: IT DAILY
View originalThis article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.