MDDI 연설문 · 2024-07-03
Janil Puthucheary 선임정무부장관의 AiSP AI 보안 정상회담 개막 연설
요점
- • AI는 새로운 보안 위험을 야기합니다——적대적 머신러닝(MIT가 AI를 오도하여 3D 프린팅 거북이를 소총으로 착각하게 함; McAfee가 제한 속도 표지판을 변경하여 Tesla의 초기 Mobileye 시스템을 오류에 빠뜨림) + 기존 위협(Microsoft 연구원이 개인 키와 30,000+ 개의 Teams 메시지를 포함한 38 TB의 데이터를 실수로 노출함; ChatGPT가 민감한 정보를 포함한 훈련 데이터를 재현하도록 유도됨)。
- • 싱가포르 CSA는 2023년 11월 영국 NCSC, 미국 CISA와 공동으로 《Guidelines for Secure AI System Development》에 서명했습니다; 이번 달에는 《AI 시스템 보호 기술 지침》에 대한 공개 협의를 진행할 예정입니다。
- • 「AI 보안」과 「AI 서비스 네트워크 보안」이 공존합니다: 다크웹식 AI(WormGPT 등)는 고품질 악성 소프트웨어, 개인맞춤형 피싱 이메일, 딥페이크를 생성할 수 있습니다; 마찬가지로 방어 측에서도 AI를 활용하여 이상 탐지와 자동 대응을 수행할 수 있습니다。
- • Deep Instinct 2024년 6월: 미국의 조사 대상 네트워크 보안 전문가 97%가 자신의 조직이 AI의 악용으로 인해 보안 사건을 겪을 것으로 우려하고 있습니다。
- • 오늘 AiSP가 「AI 특별 관심 그룹」(AI SIG)을 출범했습니다——구성원들이 AI 진전을 논의하고 인사이트를 공유합니다。
전체 번역
MDDI 영어 원문의 번역 · 번역일: 2026-05-03
Tam Huynh 보좌 사무총장,
AiSP 회원、
여신사 여러분, 신사 여러분:
좋은 아침입니다. 저는 오늘 AiSP 첫 번째 「AI 안전 정상회담」에 참석하게 되어 매우 기쁩니다.
지난 몇 년 동안—AI가 빠르게 확산되어 광범위한 영역에 배포되었습니다. 이는 위협 환경을 크게 변화시켰습니다. 우리가 알고 있듯이—AI의 빠른 발전과 도입—으로 인해 우리는 많은 새로운 위험에 노출되었습니다.
여기에는 「적대적 기계학습」—공격자들이 이를 통해 모델의 기능을 방해할 수 있습니다.
a. 널리 알려진 예시는—MIT의 연구자들이 AI가 3D 프린팅된 거북이를 소총으로 오인하게 할 수 있었습니다—다양한 각도에서 봐도 마찬가지입니다.
b. McAfee의 연구자들도 「AI가 인식하도록 훈련받은 속도 제한 표지판」을 약간 수정함으로써—테슬라의 초기 AI 시스템 Mobileye를 무력화할 수 있었습니다.
c. 이러한 유형의 위험은 상대적으로 새로운 것입니다—우리는 이들을 더 잘 이해하기 위해 더 많은 노력이 필요합니다. 싱가포르 정부 기술 위원회(GovTech)를 포함한 공공 및 민간 기관들—은 AI 시스템에 대한 이러한 유형의 공격을 시뮬레이션할 수 있는 능력을 개발해왔습니다—이들이 AI 안전에 어떻게 영향을 미치는지 더 잘 이해하기 위해. 이렇게 함으로써—우리는 「올바른 보안 보호장치」를 제자리에 놓도록 도움을 받습니다.
AI는 또한 데이터 프라이버시 위협을 포함한 기존의 사이버 위협에 취약합니다—AI의 광범위한 도입—은 「데이터 노출, 유출, 손상」 위협 범위를 확대합니다.
a. 여러분 중 일부는 들어보셨을 수도 있습니다—38 TB 데이터가 Microsoft AI 연구자들에 의해 실수로 노출되었습니다—그들은 당시 AI 데이터셋을 공유하려고 시도하고 있었습니다. 파일에는 개인 키, 비밀번호 및 30,000개 이상의 Microsoft Teams에서 사용자가 보낸 메시지가 포함되어 있었습니다.
b. 「지속적 공격」에서—ChatGPT도 훈련 데이터를 복원하도록 조작될 수 있습니다—이 데이터는 민감한 정보를 포함할 수 있습니다—예를 들어 이름, 주소, 전화번호.
유사한 사건들—은 「AI 모델의 안전성과 신뢰성」에 대한 공중의 신뢰를 훼손합니다.
a. 신뢰가 없으면—개인과 조직은 우려할 수 있습니다—이 도구들이 오류, 불일치 또는 해로운 결과를 출력할 수 있다고.
b. 이는 역으로—산업이 AI의 이점을 극대화할 수 있는지와—우리가 AI를 활용하여 싱가포르의 디지털 경제와 사회의 추가 성장을 추진할 수 있는지에 영향을 미칩니다.
저는—산업 플레이어들—AiSP 및 그들의 파트너를 포함하여—「AI를 더욱 안전하게 만드는 방법」에 대한 논의를 주도하고 있는 것을 기쁘게 봅니다. 우리 모두는 「사용자와 시스템을 보호하면서 동시에 성장과 혁신을 촉진하는 신뢰할 수 있는 AI 환경을 조성」하는 데 역할을 할 수 있습니다.
정부 차원에서—싱가포르 사이버보안청(CSA)은 산업 파트너 및 국제 동료들과 계속 협력해왔습니다—시스템 관리자가 「AI 도입 방법」 결정에 사용해야 할 명확한 지침을 개발하기 위해.
a. 예를 들어—2023년 11월—CSA는 영국 국가 사이버보안 센터(NCSC)와 미국 사이버보안 및 기반시설 보안청(CISA)과 함께—『Guidelines for Secure AI System Development』에 서명했습니다.
저는 기쁘게 발표합니다—CSA도 이번 달에 『AI 시스템 보호를 위한 기술 지침』(Technical Guidelines for Securing AI Systems)에 대해 공개 의견 수렴을 실시할 예정입니다.
a. 이 「자발적」 지침들—AI 안전에 관한 기존 자원을 보완하기 위한 것입니다—싱가포르의 시스템 관리자들에게 적용 가능한 실질적인 조치를 제공하고—시스템 및 사용자에 대한 잠재적 위험에 대응합니다.
b. 우리는 생태계의 모든 구성원들—AiSP 회원과 국제 파트너를 포함하여—이 지침들을 「어떻게 개선할 수 있을지」에 대한 피드백을 제공할 것을 초대합니다. 우리는 또한 이해합니다—AI가 다양한 맥락과 사용 사례에서 사용된다는 것을. 우리는 바랍니다—이 지침들이 실용적이고 유용하기를.
c. CSA는 앞으로 몇 주 내에 공개 의견 수렴에 대한 더 많은 세부 정보를 공유할 것입니다. 함께—우리는 AI 도구 보안을 강화하려는 보안 전문가들을 위해—유용한 참고자료를 제공할 수 있습니다.
저는 산업 파트너와 전문가들이—자신의 책임을 계속 다하여—AI 도구와 시스템이 악의적 위협에 대해 안전한 상태로 유지되도록 하기를 바랍니다—기술이 계속 진화하더라도.
「AI를 통한 사이버보안」
이러한 노력들과 동시에—많은 조직들도 고심하고 있습니다—「AI 오용으로 인한 공격」으로부터 자신을 어떻게 보호할지.
a. 우리 많은 사람들이 우려합니다—생성형 AI가 오용될 수 있다고—설득력 있고 개인화된 피싱 이메일을 생성하여—사용자가 피싱 링크와 첨부파일을 클릭하도록 유인합니다. 위협 행위자들도 설득력 있는 딥페이크를 만들 수 있으며—사용자가 이를 믿고 속도록 합니다.
b. 사이버보안의 특정 측면에서—우리는 이미 「다크 AI」(dark AI, 예: WormGPT)의 등장과 증가를 목격했습니다—이는 AI가 고도로 정교한 악성코드를 만드는 데 사용될 수 있음을 보여줍니다—이러한 위협들은—기존 시스템이 탐지하기 어려울 수 있습니다.
이는 국제적 우려사항입니다—예를 들어 2024년 6월—Deep Instinct 보고서에 따르면—미국 응답 사이버보안 전문가의 97%가 자신의 조직이 AI의 악의적 사용으로 인한 보안 사건을 겪을까 우려합니다.
「AI 오용」에 대한 우려—는 자연스럽습니다. 하지만 똑같이 중요한 것은—AI가 어떻게 「사이버보안을 위한 선의 힘」이 될 수 있는지 생각하는 것입니다. 위협 행위자들이 이 기술을 자신의 활동에 통합하는 것처럼—방어자들도 AI가 업무에 제공하는 이점을 활용하는 법을 배워야 합니다.
우리 많은 사람들이 이미 봤습니다—AI가 보안 운영의 「가치 배증기」가 될 수 있다는 것을. 적절하게 사용하면—AI는 방어자들이 더 빠르고, 더 광범위하고, 더 정확하게 위험을 식별하도록 도울 수 있습니다—우리가 더 빠르게 대응하도록 돕습니다. 이는 우리 팀이 사이버 위협에 직면할 때—더욱 효율적이고 효과적이 되도록 합니다.
더욱 정교한 위협에 대해서도 AI는 「경기의 판을 평등하게 한다」는 데 도움이 될 수 있습니다. 우리는 이미 기계학습 알고리즘이 「이상 탐지, 잠재적 위협에 대한 자율적 대응 구현」 솔루션에서 점점 더 많이 사용되는 것을 보아왔습니다. 저는 또한 산업이 어떻게 AI를 사용하여 오늘날 우리가 보유한 사이버보안 도구를 강화할 수 있는지, 그리고 어떻게 우리가 「결정적 우위」를 획득할 수 있도록 도움을 줄 수 있는지 기대합니다.
「AI 특별 관심 그룹」 시작
AI는 여전히 진화 중인 신흥 기술입니다. 앞으로 몇 년간 우리는 계속해서 사용 사례 수의 증가를 볼 것입니다. 동시에 우리는 관리해야 할 새로운 위험도 발견하게 될 것입니다. 우리는 이 두 가지 우선순위 사이에서 「미묘한 균형」을 잘 유지해야 「안전한 영역에서의 혁신」을 이룰 수 있습니다.
이를 위해 우리의 기술 전문가들은 이 기술의 발전과 진화를 밀접하게 따라가야 하며, 특히 신뢰, 안전, 사이버보안 업무에 종사하는 동료들이 그러해야 합니다.
가. 이는 우리가 「AI를 어떻게 도입할 것인가, 알려진 위험을 어떻게 관리할 것인가」에 관한 좋은 조언을 제시할 수 있도록 도움을 줄 것입니다.
나. 이는 또한 우리가 「AI는 안전의 원칙에 따라 개발되어야 한다」는 보다 광범위한 대화를 형성하도록 도움을 줄 것입니다.
오늘 AiSP는 「AI 특별 관심 그룹」(AI SIG)을 시작합니다.
가. 이 그룹은 회원들에게 플랫폼을 제공하여 AI의 진전을 논의하고, 주요 통찰력과 경험을 교환하며, 커뮤니티와 그들의 지식을 공유하도록 할 것입니다.
나. 회원들은 이 플랫폼을 사용하여 사이버보안 산업이 「AI와 함께 공존하며 함께 발전하는」 동시에 디지털 영역이 신뢰할 수 있고 안전하게 유지되도록 논의할 수 있습니다.
다. AI가 디지털 기반 시설의 필수적인 구성 요소가 될 때, 이러한 것들은 핵심 의제가 될 것입니다.
관심 있는 회원들은 AiSP 사무국에 연락하여 SIG에 어떻게 가입할 수 있는지 알아볼 수 있습니다. 그들의 향후 대화가 순조로우길 바랍니다.
맺음말
우리 모두는 각자의 역할을 다해 AI가 지속적으로 안전하도록 해야 합니다. 이는 우리의 조직과 사용자들이 AI를 충분히 활용하려고 시도할 때 그들의 신뢰에 영향을 미칠 것입니다.
가. 더 많은 지침이 필요한 사람들을 위해 CSA의 지침은 유용한 출발점이 될 것입니다. 향후 몇 주간 공중이 해당 지침에 어떻게 접근할 수 있는지, 그리고 CSA에 어떻게 피드백을 제공할 수 있는지 주의 깊게 살펴보시기 바랍니다.
동시에 우리는 또한 AI가 사이버보안에 가져오는 기회를 인식할 수 있습니다. 우리는 이 분야의 발전을 밀접하게 따라가야 하며, 「적 대응에서 검증된」 AI 도구의 도입을 옹호해야 합니다.
우리는 또한 전문가와 동료들의 네트워크를 유지할 수 있으며, 위협 환경이 진화할 때 서로 상담할 수 있습니다. AiSP 회원들은 「AI SIG」부터 시작할 수 있으며, 이는 Tam Huynh 씨가 주관할 것입니다.
오늘 회의 토론이 생산적이기를 바랍니다. 감사합니다.
영어 원문
MDDI 공식 웹사이트 원문 · 수집일: 2026-05-02
Assistant Secretary Mr. Tam Huynh,
AiSP Members,
Ladies and gentlemen,
Good morning. I am happy to be joining you today for AiSP’s first AI Security Summit.
Over the past couple of years, AI has proliferated rapidly and been deployed in a wide variety of spaces. This has significantly impacted the threat landscape. We know that this rapid development and adoption of AI has exposed us to many new risks.
This includes adversarial machine learning, which allows attackers to compromise the function of the model.
a. A well-known example is how researchers at MIT were able to trick AI to think that a 3D-printed turtle was a rifle, even if the turtle was viewed from different angles.
b. Researchers at McAfee were also able to compromise Tesla’s former AI system, Mobileye, by making small changes to the speed limit signs that the AI had been taught to recognise.
c. This class of risks is relatively new and we need to do more to understand them better. Both public and private entities, including the Government Technology Agency of Singapore, have been developing capabilities to simulate such attacks on AI systems, to understand better how they can affect the security of AI. And by doing so, this will help us to put the right safeguards in place.
AI is also vulnerable to classic cyber threats, including those to data privacy. In particular, the widespread adoption of AI has led to a growth in the threat surface for data to be exposed, exfiltrated, or damaged.
a. Some of you may have heard how 38 terabytes of data were accidentally exposed by Microsoft AI researchers, who were trying to share an AI dataset. The files included private keys, passwords, and more than 30,000 messages sent by users, on Microsoft Teams.
b. In other types of attacks - persistent attacks - ChatGPT can also be manipulated to reproduce its training data, which may contain sensitive information – like names, addresses, and phone numbers.
Incidents like this undermine public trust and confidence that AI models are safe, secure, and reliable.
a. Without trust, individuals and organisations might fear that tools will produce incorrect, inconsistent, or harmful output.
b. This, in turn, affects whether the industry can maximise the benefits of AI, and whether we can leverage the use of artificial intelligence to drive further growth in the digital economy and society in Singapore.
I am heartened to see that industry players, including AiSP and its partners, are leading discussions on how we can make AI more secure. We can all play a part in fostering a trusted AI environment that protects users and systems, while facilitating growth and innovation.
On the government front, the Cyber Security Agency of Singapore has been working with industry partners and foreign counterparts to develop clear guidelines that system owners should use, when making decisions on the approach to adopt AI.
a. For example, in Nov 2023, CSA co-sealed the “guidelines for secure AI system development”, which was developed with the UK’s National Cyber Security Centre (NCSC) and US’s Cybersecurity and Infrastructure Security Agency (CISA).
I am pleased to announce that CSA will also be releasing its “Technical Guidelines for Securing AI Systems” for public consultation this month.
a. This set of voluntary guidelines are intended to complement existing resources on the security of AI, and provide practical measures that system owners in Singapore can use to address potential risks to systems and users.
b. We invite all members of the ecosystem, including Members of AiSP, and international partners, to provide their feedback on how we can improve the guidelines. We understand that AI is used in a wide range of contexts, and across multiple use-cases. We want to ensure that these guidelines are practical and useful.
c. CSA will release more details on the public consultation in the following weeks. Together, we can provide a useful reference for security professionals looking to enhance the security of their AI tools.
I hope that industry partners and professionals will continue to do their part to ensure that AI tools and systems are kept safe and secure against malicious threats, even as techniques evolve.
AI for Cybersecurity
In parallel to these efforts, many organisations are also thinking about how to secure ourselves against attacks that are driven by the misuse of AI.
a. Many of us are concerned about how generative AI can be misused to generate convincing, personalised emails that trick our users into clicking phishing links and attachments. Threat actors can also create convincing deepfakes and trick our users into believing misinformation and disinformation.
b. Specific to cybersecurity, we have seen the use and the rise of dark AI like WormGPT, which shows that AI can be used to create sophisticated malware. These threats may be difficult for existing systems to detect.
The concern is international – for example, in Jun 2024, Deep Instinct reported that 97% of cybersecurity experts surveyed in the US were concerned that their organisations would suffer a security incident, caused by malicious use of AI.
It is natural that we are concerned about how AI can be misused. However, it is just as important for us to consider how AI can be a force for the good of the cybersecurity sector. Just as threat actors integrate this technology into their operations, defenders need to learn to master the benefits that AI can bring to their work.
Many of us have seen how AI can be a valuable force multiplier for security operations. If used properly, AI can help defenders identify risks at greater speed, scale, and precision, which can help us to address risks more quickly. This can help us to make our teams more efficient, and effective, as we defend against cyber threats.
Even for more sophisticated threats, AI can help to level the playing field. We have already seen an increase in the use of machine-learning algorithms in solutions to detect anomalies, or to mount an autonomous response to potential threats. I look forward to hearing how the industry can use AI to improve the range of cybersecurity tools we have today, and how this can help us to gain a decisive advantage.
Launch of AI Special Interest Group
AI is still an evolving, emerging technology, and we will continue to see a growth in the number of use cases in these next few years. At the same time, we will discover new risks, which will need to be managed. We will need to strike a careful balance between these two priorities, to ensure that we innovate in a safe domain.
And in doing so, our tech professionals need to stay up to date on how this technology develops and evolves – especially for those of us who work in trust, safety and cybersecurity.
a. This will help us to make good recommendations on how AI is adopted, and how we can manage the known risks.
b. It will also help us shape the wider conversation on how AI should be developed, in line with the principles of safety and security.
Today, AiSP will be launching its AI Special Interest Group.
a. This group will provide a platform for members to discuss AI developments, exchange key insights and experiences, and share their knowledge with the community.
b. Members can use this platform to discuss how the cybersecurity sector can continue to ensure the digital domain is trusted, and secure, while co-existing and co-developing with AI.
c. These will be critical topics as AI becomes an integral part of digital infrastructure.
Interested members can reach out to the AiSP Secretariat for details on how to join the SIG. I wish them the best in their future conversations.
Conclusion
We should all play our part in ensuring that AI can continue to be safe, and secure. This will affect the confidence of our organisations and users as they try to make full use of what AI can offer.
a. For those who need more guidance, CSA’s guidelines will be a useful place to start. Please keep an eye out for details on how the public can access the guidelines in the coming weeks, and how to provide your feedback to CSA.
At the same time, we can be aware of the opportunities that AI can bring for cybersecurity. We can keep ourselves abreast of developments in this space, and advocate for the adoption of AI tools that prove to be effective against our adversaries.
We can also maintain a network of experts and peers that we can consult, especially as the threat landscape develops. AiSP members can start with the AI SIG, which will be chaired by Mr. Tam Hyunh.
I wish you a series of fruitful discussions at the conference today. Thank you very much.