"Before artificial intelligence (AI) arrived, in cyberspace an attacker only had to find a single vulnerability, while a defender had to consider every possibility, putting the defender at a disadvantage. As AI advances, it is becoming realistically possible for defenders to review every possibility, and in the future defenders will have the upper hand."

Kim Tae-su, Microsoft (MS) corporate vice president for security (professor, School of Computer Science, Georgia Institute of Technology), said this in an interview with ChosunBiz right after his keynote at the SMARTCLOUD SHOW 2026, held at the Westin Josun Hotel in Sogong-dong, Seoul, on the 26th. He said that attackers had held the edge in the race to find vulnerabilities, but with AI's advancement allowing defenders to check every possibility ahead of attacks, the balance will flip.

Kim Tae-soo, MS security vice president (professor, School of Computer Science, Georgia Tech), gives an interview with ChosunBiz at the Westin Josun Hotel in Jung-gu, Seoul, on the 26th./Courtesy of ChosunBiz

Kim said, "In the AI era, attacking and defending are not fundamentally different tasks," adding, "But for now, attackers are adopting AI quickly, while defenders must weigh regulation, compliance, and expense, so the attack side currently has the advantage." He continued, "Defenders can decide whether to release code, so they hold more information than attackers," and said, "In particular, as AI enables checking all possibilities in advance, defenders will have the advantage in the long run."

In 2021, at age 36, Kim was tapped as an executive director at Samsung Research and led AI and cybersecurity research for four years. Last year, in the AI Cyber Challenge (AIxCC) hosted by the Defense Advanced Research Projects Agency (DARPA), he led Team Atlanta to victory. AIxCC is a competition where teams use AI to automatically analyze, detect, and fix vulnerabilities. Team Atlanta scored a total of 392.76 points in the finals, opening an overwhelming gap over second place. Earlier this year, after moving to the role of MS corporate vice president for security, he led development of MDASH, an AI-based vulnerability detection system.

Kim pointed to MDASH's core as combining different AI agents according to task stages and roles. MDASH builds a threat model based on software architecture and past vulnerability data, then more than 100 sub-agents search for weaknesses. Discovered vulnerabilities are cross-validated by agents in the roles of hacker, developer, and defender, and it generates proof-of-concept (PoC) code to confirm real exploitability as well as fix patches. This structure reduces individual model bias and verifies vulnerabilities from diverse perspectives to improve accuracy.

Kim said, "If you have the AI model that found a vulnerability participate again in verification and discussion, it can repeat similar conclusions due to the same bias," adding, "To prevent this, we apply different AI models to agents in the developer and attacker roles to reflect diverse viewpoints." He continued, "If the agents cannot reach consensus at the end, three models vote, and we report it as a vulnerability only when two or more judge it to be a real bug," adding, "It is a structure that cross-checks the judgments of multiple models to filter out a specific model's bias and raise accuracy."

MDASH is currently applied to the MS Windows organization's CI/CD pipeline and is mandatory in development. Within four months of adoption, it found vulnerabilities equivalent to 66% of all vulnerabilities discovered in Windows last year. Kim said, "Windows undergoes continuous penetration testing, yet MDASH finds new bugs in the same code," adding, "It is recognized for discovering highly complex vulnerabilities, beyond human hackers, in a short time." He added, "On the back of these results, it was quickly productized, and multiple corporations at home and abroad are adopting it."

Kim said Korea's security workforce is world-class, but the industrial base to support it has not grown sufficiently. In fact, the Team Atlanta he led to the AIxCC win last year included researchers from Georgia Institute of Technology, KAIST, and Pohang University of Science and Technology POSTECH, and 80% to 90% of the team members were Korean.

Kim said, "Korea is exposed to cyber threats such as North Korea, so geopolitically it must take cybersecurity seriously, but the related industry is not providing enough support," adding, "The wage gap between U.S. and Korean security personnel is severe, and in Korea, security workers are often paid less than general (software) developers." He continued, "The reason domestic security personnel go abroad in search of higher compensation is that Korean society does not sufficiently value the security industry and its workforce," adding, "If the industry does not change, no matter how much the government supports it, it could be like pouring water into a bottomless jar."

Kim said that as AI takes over the role of junior staff, the traditional entry path for security experts may narrow, but new opportunities will open. He said, "Even compared with six months ago, AI's pace of progress is frightening," adding, "The code that underpins security work is text, so AI's reasoning ability is being applied quickly, and technically AI is superior to human hackers."

However, he said, "As AI-generated code increases, the scope of security work is actually expanding," and forecast, "Generalists who understand AI, development, and security broadly and work flexibly across multiple areas will become more important."

※ This article has been translated by AI. Share your feedback here.