S2W said on the 30th it will expand its vulnerability assessment business to support corporations in the safe adoption and use of artificial intelligence (AI).
According to S2W, the project is based on the S2W research team's offensive security expertise, which allows immediate application in the assessment process of real large language model (LLM) attack techniques collected from the dark web, Telegram, and hacking forums.
It will also secure domain suitability by applying items that consider industry-specific characteristics, based on the LLM security vulnerability standard "OWASP Top 10 for LLM" established by the international nonprofit in software and web application security, "OWASP."
Through this, the company plans to precisely diagnose security vulnerabilities inherent in various components of AI services—such as models, prompts, data, and agents—verify the potential for attacker exploitation from multiple angles, and present specific remediation measures, thereby helping corporations establish internal inspection systems for the security of AI services.
S2W is expanding its AI service vulnerability assessment business based on the view that new threats that are difficult to counter with existing security frameworks alone have recently increased.
Meanwhile, S2W said it recently won a contract to assess vulnerabilities in the AI services of a major domestic financial company. It is conducting assessments that take into account the strict security standards and regulatory environment of the financial sector, and it plans to expand into various industries to provide vulnerability assessments that comprehensively reflect each industry's AI utilization methods, service structures, and security requirements.
Yang Jong-heon, head of integrated analysis at S2W, said, "To identify the potential risks of AI services in advance, sophisticated assessments using AI and expert validation from an attacker's perspective must go hand in hand," adding, "S2W combines offensive security experts' know-how with our self-developed AI-based tools to provide highly effective assessments that help corporations adopt and operate AI services more safely."