"Until now, security has basically been a game that favors attackers. But defenders can now, thanks to artificial intelligence (AI), scan massive volumes of attack code tirelessly. For the first time, defenders are beginning to gain capabilities on a similar scale to attackers. In 1 to 2 years, defenders with code will be able to use AI to test attack scenarios and fix vulnerabilities in advance."
The U.S. government recently put a lock on the public release scope of Anthropic's AI model Mythos. The concern is that AI could find software vulnerabilities faster than humans and be abused for cyberattacks. AI is a "double-edged sword" in cybersecurity. Hackers can use AI to find opponents' vulnerabilities faster and escalate attacks, while defenders can use the same technology to find vulnerabilities before attacks and defend against them. Kim Tae-su, a Microsoft (MS) vice president and Georgia Tech School of Computer Engineering professor, a world authority in system security and AI-based cybersecurity, said in a written interview with ChosunBiz on the 7th that AI will change the security paradigm, noting, "An era has opened in which offense and defense move at machine speed."
Until now, attackers only needed to find one weak point in an entire system, but defenders had to protect everything. In the past, it was impossible for a person to examine all of the attack code, but AI has strengthened defenders' capabilities. Kim said, "However, merely finding a lot of candidate vulnerabilities does not constitute defense," adding, "Discovery, verification, proof, and patching (fixes) must be linked in a single loop to reduce false positives. A system is needed that confirms actual exploitability, sets priorities, and takes action." He continued, "Going forward, AI must evolve to a stage where it conducts security research on its own."
Kim is currently on leave from his professorship at Georgia Tech and conducting agent-based security research at MS. In 2025, he led Team Atlanta to win first place worldwide at the AIxCC (AI Cyber Challenge) hosted by the U.S. Defense Advanced Research Projects Agency (DARPA). The competition is the world's most prestigious cybersecurity contest, where teams compete in technologies that automatically detect and patch software vulnerabilities using AI. Kim was also tapped in 2021, at age 36, as an executive (senior vice president) at Samsung Research. At the time, he led AI and cybersecurity research at Samsung Research. He will deliver a keynote at SMARTCLOUD SHOW 2026, Korea's largest tech conference, to be held on the 26th at the Westin Josun Hotel in Sogong-dong, Seoul. The following is a Q&A with him.
◇ "The U.S. is far more closed than China… Code that people can't read is the most dangerous code"
—After Anthropic's Mythos was released in a limited way, the U.S. government blocked further release.
"While attackers will secure AI capabilities one way or another, if only defenders face restricted access, that could create an asymmetry favoring attackers. So rather than blocking releases across the board, we need a sophisticated design that broadly allows verified defensive uses while controlling dangerous functions. The United States tends to be far more closed than China. If there is no company or country with a stable, overwhelming lead, and the U.S. keeps its technology closed while Chinese technology remains open, then in the long term Chinese technology could become the reference point for global research and development. It will also be hard for Korean corporations to secure competitiveness if they stop at simply gaining or not gaining access rights to AI models. If they combine verified defensive use capabilities with global cooperation, independent evaluation ability, and industry-specific security operations experience, they can create a sufficient competitive edge. In the end, what matters is not whether you possess a core model, but whether you have the operational systems and governance to use powerful AI safely."
—Specifically, how should Korea respond to the Mythos situation?
"Code that people can't read is the most dangerous code. In backbone networks, finance, and public systems, there is a lot of old (legacy) code whose developers have already left the company or that lacks sufficient documentation. In that sense, AI can be more than a simple efficiency tool; because it can reanalyze this 'code that has lost its readers,' it can be a tool that restores disappearing expertise. The first thing Korea should do is AI-based pre-audits focused on legacy code. Before attackers analyze systems with AI, defenders must first apply AI to their own code. This means they should actively leverage the information advantage that defenders know both the source code and the operating environment. Second, they must build a closed loop that runs from vulnerability discovery through to fixes. Finding vulnerabilities is half; fixing them is the other half. A system that verifies and actually consolidates through to remediation is more important than one that merely finds many vulnerabilities. Lastly, establish a prioritization framework. AI can find thousands of candidate vulnerabilities, but without a system to decide what to address first, a new bottleneck will emerge. Ultimately, Korea should respond by building an integrated defense system that starts with AI-based pre-audits and extends through verification, patching, and prioritization."
—MS also unveiled the vulnerability detection system M-DASH. What sets it apart?
"M-DASH does not leave decisions to a single model. Instead, multiple models and more than 100 specialized agents divide roles to find vulnerabilities, verify them, and even confirm reproducibility. This compensates for the limitations of a single model and allows us to find more complex structural vulnerabilities. Going forward, the AI security race will be less about securing the largest model and more about how to combine each model's strengths and design systems suited to solving real problems. Korean security corporations should build capabilities not only to develop their own models but also to design efficient security systems using diverse AI models and agents."
◇ "Korean talent work overseas due to differences in treatment and environment"
—The Korean government is pushing an independent AI foundation model project.
"I agree on the need to develop an independent model. But from a security perspective, building one model does not solve the problem. Before attackers analyze our systems with AI, defenders must first use AI to find, verify, and address vulnerabilities by establishing a defensive system. I believe building a defense system that uses AI is the most realistic way to respond to future cyberattacks."
—The Korean government aims to be No. 3 in AI globally. How realistic is that?
"I believe the capabilities of Korean-born security talent do not fall behind anywhere in the world. In fact, there are many Korean security experts who are active and recognized on the global stage. Realistically, however, many move overseas—especially to the United States, where AI frontier models are being developed—because compensation and research environments are better than in Korea. These environmental differences exist when trying to research and advance AI and security together. Therefore, when assessing Korea's AI competitiveness, we should not focus only on which model has been developed or what rank a country holds. What matters is how fast the research and industrial ecosystem that can advance AI and security together is growing. Government-level drives are needed, but ultimately the security industry itself must grow larger. Only when corporations and markets form that can rapidly adopt the latest security technologies and use them in real industrial settings will outstanding talent remain in the country, and research expand to tackle more complex and important problems."
—What policy efforts are needed for Korea to boost AI competitiveness?
"We must create an environment where Korean AI talent can continue to grow domestically and be used to solve real industrial problems. Corporations and markets must form that can quickly adopt the latest AI and security technologies and apply them on the ground. It is important, in my view, to craft policies that create demand for the public and private sectors to verify and adopt new security technologies and that expand opportunities for security corporations and researchers to solve real problems. It is also important to create an environment where talent can research and experiment freely. Whether in industry or academia, they must be able to handle real systems and verify new technologies to build capabilities. Ultimately, I think policy should be oriented toward creating a virtuous cycle in which talent grows and industry quickly absorbs those results."