"Before artificial intelligence (AI) emerged, in the cyber world an attacker only had to find a single vulnerability, while a defender had to consider every possibility and was at a disadvantage. As AI advances, it is becoming realistically possible for defenders to examine all possibilities, and going forward defenders will have the upper hand."

Kim Tae-su, Microsoft (MS) corporate vice president for security (professor of computer engineering at Georgia Tech), said this on Aug. 26 after his keynote at SMARTCLOUD SHOW 2026, held at the Westin Josun Hotel in Sogong-dong, Seoul, in an interview with ChosunBiz. He said that attackers had held the edge in the race to find vulnerabilities, but as AI develops and allows defenders to check every possibility ahead of attacks, the balance will flip.

Kim Taesu, Microsoft (MS) Corporate Vice President for Security and professor of computer engineering at Georgia Tech, gives an interview with ChosunBiz at the Westin Josun Hotel in Jung-gu, Seoul, on the 26th. /Courtesy of ChosunBiz

Kim said, "In the AI era, attack and defense are not fundamentally different tasks," adding, "For now, attackers are adopting AI quickly, while defenders must consider regulation, compliance, and expense, so the offensive side currently has the advantage." He continued, "Defenders can decide whether to release code and therefore hold more information than attackers," and said, "In particular, as AI advances and enables all possibilities to be checked in advance, defenders will have the advantage in the long run."

Kim was tapped in 2021 as an executive director at Samsung Research at age 36 and led AI and cybersecurity research for four years. Last year, he led Team Atlanta to victory in the AI Cyber Challenge (AIxCC), hosted by the U.S. Defense Advanced Research Projects Agency (DARPA). AIxCC is a competition that tests the ability to automatically analyze, detect, and fix vulnerabilities using AI. Team Atlanta scored a total of 392.76 points in the finals, opening a commanding gap over second place. Early this year, after moving to MS as corporate vice president for security, he led development of MDASH, an AI-based vulnerability detection system.

Kim pointed to MDASH's core as a method that combines different AI agents by work stage and role. MDASH builds a threat model based on software architecture and historical vulnerability information, then more than 100 sub-agents search for vulnerabilities. Agents in hacker, developer, and defender roles cross-validate the discovered vulnerabilities and even generate proof-of-concept (PoC) code to verify real attack feasibility as well as patches to fix them. This structure reduces individual model bias and verifies vulnerabilities from diverse perspectives to improve accuracy.

Kim said, "If you bring the AI model that found a vulnerability back into verification and discussion, it can repeat similar conclusions due to the same bias," adding, "To prevent this, we apply different AI models to agents in developer and attacker roles to reflect diverse viewpoints." He continued, "If the agents fail to reach agreement at the end, three models vote, and a vulnerability is reported only when at least two of them judge it to be a real bug," adding, "It is a structure that cross-validates the judgments of multiple models to filter out a particular model's bias and raise accuracy."

MDASH is currently applied to the MS Windows organization's CI/CD pipeline and is mandatory in the development process. Within four months of adoption, it found vulnerabilities equivalent to 66% of all vulnerabilities discovered in Windows last year. Kim said, "Windows undergoes continuous penetration testing, yet MDASH finds new bugs in the same code," adding, "It is recognized for discovering complex vulnerabilities more advanced than those found by human hackers in a short time." He added, "On the back of these results, it was quickly commercialized, and many corporations at home and abroad are adopting it."

Kim assessed that while Korea's security workforce has world-class capabilities, the industrial base to support it has not grown sufficiently. In fact, Team Atlanta, which he led to the AIxCC win last year, included researchers from Georgia Tech, KAIST, and Pohang University of Science and Technology POSTECH, and 80% to 90% of the members were Korean.

Kim said, "Korea is exposed to cyber threats from North Korea and others and, geopolitically, must place importance on cybersecurity, but the related industry is not providing sufficient support," adding, "The wage gap between U.S. and Korean security personnel is severe, and in Korea security personnel are often paid less than general (software) developers." He continued, "The reason domestic security personnel go abroad in search of higher compensation is that Korean society is not adequately valuing the security industry and its workforce," adding, "If the industry does not change, no matter how much support the government provides, it could be like pouring water into a bottomless jar."

Kim predicted that as AI replaces the roles of junior staff, the traditional entry path for security experts may narrow, but new opportunities will open. He said, "Even compared with six months ago, the pace of AI's development is frightening," adding, "Code, the foundation of security work, is text, so AI's reasoning ability is being applied rapidly, and technically AI is superior to human hackers."

However, "as AI-generated code increases, the scope of security work is actually expanding," and he predicted, "In the future, generalists who understand AI, development, and security broadly and work flexibly across multiple domains will become more important."

※ This article has been translated by AI. Share your feedback here.