Vice Prime Minister Bae Kyung-hoon delivers opening remarks at a meeting launching an AI model development project specialised in cybersecurity on Sept. 22. [Photo by DigitalToday reporter Seulgi Son]

The government is developing a "cybersecurity-specialised AI foundation model" aimed at global frontier-level performance.

The government plans to specialise Naver Cloud's HyperCLOVA X and LG AI Research's Exaone for defence and attack, respectively. It aims to improve performance through "adversarial mutual learning" that feeds response results back into training.

The Ministry of Science and ICT held a meeting on Sept. 22 at The Grand Lotte Seoul in Jung-gu, Seoul, and unveiled the development plan of the Naver Cloud consortium.

Vice Prime Minister and Science Minister Bae Kyung-hoon (배경훈) said, "As Mithos has shown, AI is being used for cyberattacks, and even unforeseen threats are becoming reality. Separate from cooperating with overseas frontier models, we also need to quickly secure an independent model specialised in cybersecurity." He added, "Since Naver has come in sharpening its blade after the Dokpamo project, I expect a security-specialised model comparable to frontier-level to emerge."

Exaone for attack, CLOVA X for defence... a 'frontier-level' challenge through head-to-head competition

The security-specialised foundation model will be developed by using different domestic foundation models for attack and defence. The final security-specialised model the two companies develop targets a 700B-class mixture-of-experts structure.

Exaone will be specialised for offensive capabilities. It analyses source code to find types and causes of vulnerabilities and infers pathways that could lead to actual attacks. HyperCLOVA X, as a defensive model, analyses event and threat information scattered across multiple systems to infer attack behaviour and presents risk levels and response measures.

The development process will use the adversarial relationship between red teams and blue teams for learning. Vulnerabilities and attack paths found by the attack model are used to train the defence model, and the defence model's responses become tasks the attack model must overcome in a feedback loop. ThioRI will handle attacker-perspective reinforcement learning in this process.

Performance targets were also set out in detail. Exaone aims first to reach 80 percent of the level of GLM 5.3, a global open-weight frontier model, on the vulnerability discovery benchmark CyberGym, and ultimately to reach a level equivalent to GLM 5.3.

HyperCLOVA X plans first to reach the level of xAI's Grok4 on the incident investigation benchmark ExCyTIn-Bench, and ultimately to raise performance to the level of Anthropic's Claude Opus 4.5. This means it will compete with global frontier models in each security-specialised area, rather than in overall general-purpose performance.

830TB of real data and 4,512 GPUs to be deployed... independent model performance remains a task

To secure frontier-level security performance, about 830TB of foundational security data will be used for training. It includes attack logs and malicious traffic, vulnerabilities, indicators of compromise, and security monitoring data secured from national critical infrastructure such as finance, telecommunications and power, and from sites of domestic security companies.

For computing resources, 4,512 GPUs from the government and private sector will be deployed. The government will support 256 B200 GPUs, while Naver Cloud will add 4,000 of its own B200s and LG AI Research will add 256 H200s.

Naver Cloud has been developing a security-specialised HyperCLOVA X from scratch using 4,000 B200s since August. The two companies will strengthen defence and attack capabilities through continuous pre-training, mid-training, supervised fine-tuning and reinforcement learning using verifiable rewards, among other steps. They will also share training data.

A total of 41 organisations will participate, including 33 participating institutions and 8 cooperating institutions. They will divide roles from data collection and processing to model development, evaluation and verification, and field demonstrations.

Still, choosing a domestic independent model is not necessarily advantageous in pure performance competition. Park Se-jun (박세준), CEO of consortium participant ThioRI, cited as a weakness the inability to use global open-weight models with verified performance. The project period is also only 10 months.

Park said, "It is not easy for research to produce results in a short period of time," adding, "We have GPUs, the team is good, and the goals and concept are good, but the period is the problem."

Even so, the background to developing an independent model is control over sensitive security data. The explanation is that, unlike overseas open-weight models such as Chinese ones where it is difficult to verify the entire training dataset from outside, a domestic independent model allows domestic companies to hold the training data and verify it if necessary.

Naver Cloud CEO Kim Yu-won (김유원) said, "There are aspects where it is extremely difficult to leak our country's important data or information related to communications networks overseas," adding, "If sufficient data is not provided, AI cannot function properly either, so we need a security-specialised model within our control."

Kim Jin-hwi (김진휘), an executive director leading the Naver Cloud consortium project, also cited "availability" as a strength of an independent model that can be used continuously even if access to overseas models is restricted due to export controls. Closed networks in finance, defence and government, where it is difficult to use external AI, are also key targets for application.

Real-world response with security agents... from closed networks to overseas exports

The foundation model developed will be connected to application programming interfaces and software development kits of domestic security companies and to security agents. It will be expanded into services that perform actual security tasks such as AI vulnerability diagnosis, cyberattack response and incident investigation.

Field demonstrations will also be conducted in seven national critical infrastructure and strategic industries: power, finance, science and technology, telecommunications, semiconductors, defence industry and aerospace. New threats and false positive and false negative cases identified in the field will be reflected back into model and service improvements.

The two security-specialised models will be released as open source and commercialised in linkage with products of domestic security companies. It will also push to build closed-network AI security services that can be used without internet connections for national key facilities such as public and defence sites.

Overseas, the plan targets countries with strong data sovereignty and security regulations. It plans to export a full-stack package dubbed "sovereign AI security" that bundles AI infrastructure, models and security services, using Naver Cloud's Global AI Factory and LG CNS hubs in 13 countries.

Kim said, "We are aiming for a country that defends with AI in an era when AI attacks," adding, "We will expand sovereign AI security services to the global market."

Keyword

#HyperCLOVA X #Exaone #Ministry of Science and ICT #CyberGym #ExCyTIn-Bench
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.