SK Telecom, Upstage to Pursue AI Security Technology Collaboration With Domestic Security Firms and Universities
TECHWORLD ·
✦ AI Summary
SK Telecom said it will launch a "Sovereign AI Cybersecurity Council" with domestic companies and universities and pursue technology collaboration.
Upstage, six information security companies, and three universities will participate in the council, which was set up to expand the cybersecurity scope of models advancing to the third stage of the Sovereign AI Foundation Model Project.
The security firms will train the two models with on-site data, the universities will verify their safety, and the participating companies will pursue application to security products and services and joint demonstrations.
SK Telecom said on the 8th that it will launch a "Sovereign AI Cybersecurity Council" with domestic companies and universities and pursue related technology collaboration. Upstage, six domestic information security companies, and three domestic universities will take part in the council.
The participating information security companies are SK shieldus, Secui, AhnLab, RaonSecure, Genians, and PIOLINK, while the participating universities are Korea University, Soongsil University, and Pusan National University. The agreement was designed to expand cybersecurity for the government's "Sovereign AI Foundation Model Project" for models advancing to the third stage. The target models are SKT's "A.X K" series and Upstage's "Solar."
The security firms will train the two models with on-site data, while the universities will verify their safety. The participating companies will also take on the role of applying the models to security products and services and confirming the results.
SKT and Upstage plan to train AI models on real security work data provided by participating institutions. The training data will include data generated in security environments, such as malware analysis, vulnerability analysis, and security monitoring. The goal is to improve AI's ability to understand and judge security situations.
AI model training will proceed in two stages: pretraining and post-training. In the pretraining stage, SKT and Upstage will lead efforts to strengthen the models' foundational knowledge based on security data. SKT's next model, "A.X K3," will systematically learn security-related data, and "A.X K3" will also be supplemented with data for the safe operation of the "Everyone's AI" service. Upstage will focus on training its next Solar model with security data for vulnerability detection and analysis, and the next Solar model will be able to analyze large volumes of code and long-term logs at the same time.
In the post-training stage, the company will use on-site security work data from domestic security firms. The goal of post-training is to improve real-world operational capabilities. The main areas are software vulnerability analysis and patching, security operations center incident response, and the safe use of security tools.
The basis for AI security capabilities lies in on-site data accumulated through real-world threat and response experience. The participating information security companies have expertise in their respective fields, including threat intelligence, malware analysis data, and experience operating security solutions, and they will link that expertise to model development and verification.
By company, SK shieldus operates the integrated security monitoring platform "Secudium," which analyzes 17 billion threat events a day in real time. AhnLab holds more than 2.5PB of security data and also has malware and endpoint threat detection technologies. Secui has high-performance firewall solutions. RaonSecure has security data by domain and also has autonomous penetration testing technology. Genians has real-world security solution operation data and also has a post-training dataset. PIOLINK has autonomous attack verification technology and detection rule generation technology.
The council plans to reflect the latest threat data continuously accumulated at monitoring centers in model training.
The participating companies will apply A.X K and Solar to their security products and services. The applications will target zero-day analysis and real-time security monitoring. In addition, the participating companies will pursue joint verification in real operating environments.
During the demonstration process, the companies will verify model performance and safety. They will also work to reflect field analysis and response experience in retraining. Through this, they plan to build a virtuous cycle structure of data acquisition, model training, and performance verification.
The council will apply mutual red-teaming to A.X K and Solar. Mutual red-teaming is a method of attacking and evaluating each other to find vulnerabilities. The discovered vulnerability cases will be used as training data. The purpose is to strengthen the defensive capabilities of both models.
SKT built and operated SERT, or Self-Expanding Red-Teaming, during the development of A.X K2. SERT is SKT's own red-teaming automation system. SKT has experience generating and training on about 15,000 attack response data points. SKT plans to extend this SERT to mutual red-teaming.
The participating universities will take charge of the design and evaluation of red-teaming from a third-party perspective, verifying different security and performance items. Korea University will be responsible for evaluating the AI's executable file analysis capabilities and attack defense capabilities. Soongsil University will be responsible for setting the AI security performance evaluation standard and evaluating its ability to respond to attacks that bypass guardrails. Pusan National University will be responsible for verifying the next model's performance and safety, as well as verifying the lightweight model's performance and safety.
The participating institutions plan to promote regular technology exchanges. Based on this, they are expected to identify joint AI information security research projects. They will also review participation in AI and information security projects.
Yu Kyung-sang, head of SKT AI CIC, said the scope and depth of a model's inference are factors that determine the level of security AI. He also said the verification models from the Sovereign AI Foundation Model Project will be applied in real security settings with domestic information security companies and universities. He added that he aims to prove the practical results of national AI models in the cybersecurity field.
Source: TECHWORLD · Kim Hye-jin
Original: https://www.epnc.co.kr/news/articleView.html?idxno=407940
References
This article was produced with the help of an automated content generation algorithm.
Source: TECHWORLD
View originalThis article was summarized and organized by BizCrush based on the original article from TECHWORLD. For exact quotations and full details, please refer to the original article.