SK Telecom said on Wednesday it has launched a sovereign AI cybersecurity council involving Upstage, South Korean security companies and universities, and signed a business agreement to cooperate on AI information security technology.
The agreement is designed to expand SKT’s A.X K series and Upstage’s Solar, which advanced to stage 3 of the government’s sovereign AI foundation model project, into the cybersecurity field. Among the security companies joining the council are SK Shieldus, AhnLab and Secui.
The council will train the two models using on-site data from security companies, have universities verify safety and apply the models to participating companies’ security products and services.
SKT and Upstage plan to train their AI models on security work data generated in real security settings, such as malware analysis, vulnerability analysis and security monitoring, provided by participating organisations. They aim to improve the AI’s ability to understand and judge security situations.
Training will take place in two stages. In the pre-training stage, models will strengthen foundational knowledge based on security data. SKT’s next model, A.X K3, will systematically learn data in the security field and reinforce data needed to operate safely its AI-for-everyone service for the entire population. Upstage will intensively train security data for vulnerability detection and analysis on the next Solar model, which can analyse large volumes of code and long-term logs at once.
In the post-training stage, the models will use on-site security work data to improve real-world task performance. Key targets include software vulnerability analysis and patching, incident response at security operations centres and safe use of security tools.
Participating security companies will link expertise by area, including threat intelligence, malware analysis data and experience operating security solutions, to model development and validation. SK Shieldus analyses threat events totalling 17 billion per day in real time through its integrated security monitoring platform Secudium. AhnLab has more than 2.5 petabytes of security data and malware and endpoint threat detection technology.
Secui has a high-performance firewall solution, RaonSecure has domain-specific security data and autonomous penetration testing technology, Genians has operational data for real-world security solutions and a post-training dataset, and Piolink has autonomous attack verification and detection-rule generation technology.
Participating companies will apply A.X K and Solar to their security products and services, including zero-day vulnerability analysis and real-time security monitoring, and pursue joint proof-of-concept tests in actual operating environments. During the process, they will confirm the models’ performance and safety and feed analysis and response experience gained in the field back into training. They plan to build a virtuous cycle from data acquisition to model training and performance validation.
The council will apply mutual red-teaming, in which A.X K and Solar attack and evaluate each other to find vulnerabilities. Vulnerability cases found in this process will be used as training data to strengthen the defensive capabilities of both models.
Participating universities will handle red-teaming design and evaluation as third parties. Korea University will assess AI executable file analysis capability and defence against attacks, Soongsil University will assess AI security performance evaluation criteria and the ability to respond to guardrail bypass attacks, and Pusan National University will verify the performance and safety of next-generation and lightweight models.
Kyeong-sang Yoo (유경상), head of SKT AI CIC, said, "The level of security AI ultimately depends on how broadly and deeply the model can reason." He said, "Models verified in the sovereign AI foundation model project will prove their effectiveness in real security settings together with leading domestic information security companies and universities, and we will show achievements from using national representative AI models in the cybersecurity field as well."