MDDI 연설문 · 2025-10-21
천제호 고급정무부장의 싱가포르 AI 캡처 더 플래그 경기 개막 인사말
요점
- • 싱가포르의 두 개 「크라우드소싱」 보안 플랫폼: AI CTF(플래그 탈취 대회) + GBBP(정부 버그 바운티 프로그램). AI CTF는 올해 1,000명 이상의 참여자, 462개 팀을 유치했으며 이 중 1/5는 해외에서 참여했습니다. GBBP는 2018년 이후 64개 기관과 협력하여 115개 시스템을 테스트했고, 586개의 취약점(이 중 11개는 중요)을 발견했으며, 총 약 80만 싱가포르달러의 상금을 지급했습니다.
- • AI CTF는 AI에만 고유한 취약점들(프롬프트 주입, 데이터 포이징, 적대적 머신러닝)을 탐지하며, 공격과 방어 역량을 동시에 단련시킵니다.
- • GBBP는 전 세계 화이트햇 해커들이 정부의 실제 디지털 서비스를 테스트할 수 있도록 합니다. 이렇게 개방적인 국가는 드물며, 지속적으로 이를 진행하는 국가는 더욱 드뭅니다.
- • Tan Kiat How는 또한 이를 통해 다양성과 젊은 세대의 역량을 축하했습니다 — 지난해 「전원 여성 팀」인 「What's AI, 먹을 수 있나?」가 대학 예비 부문에서 2위를 차지했으며, 오늘 수상한 Kevin Pook은 대학 시절부터 버그 바운티를 시작했고 현재는 사이버 보안 컨설턴트입니다.
전체 번역
MDDI 영어 원문의 번역 · 번역일: 2026-05-02
안녕하세요——여러 귀빈, 파트너, 참가자 여러분:
저는 싱가포르 및 해외에서 온 여러분과 함께 올해 「싱가포르 AI 캡처 더 플래그」(AI CTF)와 「정부 취약점 보상금 계획」(GBBP) 시상식에 참석하게 되어 매우 기쁩니다.
인공지능이 빠르게 부상함에 따라 — 우리가 오늘날 직면한 사이버보안 과제가 달라졌습니다. 새로운 기술은 새로운 취약점을 야기하며 — 이는 새로운 사고방식, 새로운 도구, 새로운 기술을 요구합니다. AI CTF는 바로 이러한 AI 고유의 위험을 드러내고 우리의 집단 방어를 강화하기 위해 마련되었습니다.
전 세계에서 — Apple과 같은 선도 기업조차 인식하고 있습니다 — 어떤 조직도 복잡한 시스템의 보안을 혼자서는 보호할 수 없다는 것입니다. 그들의 취약점 보상금 계획은 전 세계 커뮤니티의 창의성을 활용하여 대적이 악용하기 전에 약점을 찾아냅니다.
같은 정신으로 — 싱가포르는 두 개의 기함 플랫폼을 구축했습니다: AI CTF와 GBBP — 커뮤니티의 전문성을 활용하기 위해서입니다. 오늘 저녁 — 우리는 이 두 커뮤니티를 한자리에 모아 — 양쪽 모두에 기여한 수상자들을 축하합니다. 이러한 이니셔티브는 싱가포르의 「주도적」 입장을 반영합니다 — 우리는 사이버보안이 그리고 반드시 항상 「집단적 노력」이어야 한다고 믿습니다.
AI CTF는 인공지능 시스템 고유의 취약점을 탐지하는 것을 목표로 합니다 — 전통적인 테스트로는 감지하지 못할 수 있는 약점들입니다. 참가자들은 AI 시스템의 약점을 발견하고 활용하여 「플래그를 탈취」합니다 — 이 과정에서 여러분은 「적대적 행위가 AI에서 어떻게 나타나고 어떻게 대항하는지」에 대한 직접 경험을 얻게 됩니다.
이러한 훈련은 동시에 공격 및 방어 능력을 강화합니다 — 시뮬레이션된 적대적 공격에서 탄력성 있는 모델 설계에 이르기까지. 이들은 우리 커뮤니티가 차세대 AI 시스템을 지키는 데 필요한 「실무 전문성」을 갖추도록 해줍니다.
GBBP는 전 세계 화이트햇 해커들이 실제 정부 디지털 서비스를 테스트하도록 초대합니다. 전 세계적으로 — 이렇게 자신의 시스템을 개방하는 정부는 드물며 — 지속적으로 그렇게 하는 정부는 더욱 드뭅니다. 보안 테스트를 크라우드소싱함으로써 — 우리는 취약점을 찾을 뿐만 아니라 시민, 전 세계 커뮤니티와의 신뢰와 투명성을 구축합니다.
결과는 명백합니다.
올해 AI CTF는 462개 팀, 총 1000명 이상의 참가자를 유치했습니다 — 그 중 1/5 이상의 팀이 해외에서 참가했습니다. 이는 싱가포르의 노력이 전 세계적으로 공감을 불러일으키고 있음을 보여줍니다. 각 과제의 완수 — 우리의 AI 위협(예: 프롬프트 주입, 데이터 중독, 적대적 기계학습)에 대한 공동 이해를 확대합니다.
2018년 이래 — GBBP는 64개 기관과 협력했고 — 115개 시스템을 테스트했으며 — 공격자에 의해 악용되기 전에 586개의 취약점을 발견했습니다. 그 중 11개는 중요 취약점입니다. 총 약 80만 싱가포르달러의 상금이 지급되었으며 — 각 라운드마다 240명 이상의 화이트햇이 참여했습니다.
발견된 각 취약점, 기여한 각 팀 — 우리가 빠르게 변화하는 디지털 환경에서 한 발 더 나아갈 수 있게 해줍니다.
올해 GovTech와 CSA가 AI CTF를 공동으로 개최했습니다 — 우리가 전달하는 메시지는 명확합니다: 사이버보안은 우리 모두가 필요합니다 — 정부, 산업, 그리고 더 넓은 커뮤니티가 — 지속적으로 진화하는 위협 환경에 공동으로 대항하기 위해.
우리의 성공은 — 싱가포르 내외 커뮤니티의 창의성과 엄밀함을 동원할 수 있는지에 달려있습니다. AI CTF와 GBBP는 이러한 협력을 체현하고 — 또한 「능력 있고 열정적인 사이버 방어자」 생태계가 성장할 수 있도록 도와줍니다.
싱가포르의 활기찬 디지털 환경 — 더 큰 AI 및 사이버보안 인재 풀을 키울 수 있게 해주며 — 공공부문과 여기에 뿌리를 내린 국제 기업이 함께 혜택을 받을 수 있도록 합니다.
저도 — 다양성이 이 분야에 뿌리내리는 것을 보게 되어 기쁩니다. 2024년 Pwn2Own에서 — 여성 연구원들이 세계에서 가장 까다로운 해킹 대회 중 하나에서 「완전 승리」를 거두었습니다. 싱가포르에서 — 지난해 「전원 여학생 팀」「What's AI, 먹을 수 있나요?」이 「대학 예비 부문」에서 2위를 차지했습니다 — 이는 재능이 성별과 무관함을 증명합니다. 이러한 다양성을 계속해서 키워나갑시다 — 왜냐하면 다양성이 바로 혁신의 원동력이기 때문입니다.
우리는 또한 젊은이들을 축하합니다. 오늘의 수상자 중 한 명인 Kevin Pook — 대학 시절부터 취약점 보상금 사냥을 시작했으며, 현재는 사이버보안 고문입니다 — 이는 우리에게 상기시켜줍니다: 초기의 호기심이 평생의 열정과 직업으로 발전할 수 있다는 것을.
싱가포르의 사이버 방어에 대한 접근 — 「주도적 행동」과 「커뮤니티 협력」을 특징으로 합니다. 손을 맞잡고 나아가며 — 우리는 더 안전하고 더 신뢰할 수 있는 디지털 미래를 만들고 있습니다.
모든 참가자, 파트너, 주최자 여러분께 — 여러분의 투입과 탁월함에 감사합니다. 여러분의 기여는 국가 회복력을 강화했으며 — 또한 다른 사람들이 이 중요한 사업에 참여하도록 영감을 주었습니다.
우리의 젊은이, 여성, 전문가, 국제 친구 여러분께 — 여러분이 학생이든, 엔지니어든, 아니면 단지 호기심 있는 사람이든 — 사이버보안은 단순한 기술 경쟁이 아닙니다. 그것은 일종의 소명입니다.
계속해서 배우고, 협력하며, 우리 모두가 마땅히 받아야 할 「안전한 디지털 미래」를 만들어갑시다.
감사합니다.
영어 원문
MDDI 공식 웹사이트 원문 · 수집일: 2026-05-02
Good evening, distinguished guests, partners, and participants.
It is my great pleasure to join all of you, from Singapore and abroad, at this year’s Singapore AI Capture-the-Flag (AI CTF) and Government Bug Bounty Programme (GBBP) Awards Ceremony.
With the rapid rise of artificial intelligence, the cybersecurity challenges that we face today are no longer the same. New technologies bring new vulnerabilities. They demand new ways of thinking, new tools, and new skills. The AI CTF was created precisely to uncover these AI-specific risks and to strengthen our collective defences.
Across the world, even leading firms such as Apple recognise that no single organisation can secure complex systems alone. Their bug bounty programmes tap into the creativity of the global community to uncover weaknesses before adversaries can exploit them.
In that same spirit, Singapore has built two flagship platforms — the AI CTF and the GBBP — to harness community expertise. This evening, we bring these two communities together, celebrating the winners who have contributed to both. These initiatives reflect Singapore’s proactive approach and our belief that cybersecurity is, and must always be, a collective effort.
The AI CTF was designed to probe vulnerabilities unique to artificial intelligence systems, weaknesses that traditional testing may not detect. Participants raced to capture the flag by uncovering and exploiting weaknesses in AI systems. In doing so, you gained first-hand experience of how adversarial behaviour can emerge in AI — and how it can be countered.
These exercises strengthen both offensive and defensive capabilities, from simulating adversarial attacks to designing resilient models. They equip our community with the hands-on expertise needed to safeguard the next generation of AI systems.
The GBBP, meanwhile, invites global ethical hackers to test actual government digital services. Around the world, few governments open their systems in this way, and even fewer do so continuously. By crowdsourcing security testing, we are not only uncovering vulnerabilities but also building trust and transparency with our citizens and the global community.
The results speak for themselves.
This year’s AI CTF drew over 1,000 participants from 462 teams, with more than one in five teams from overseas. This demonstrates that Singapore’s efforts are resonating globally. Each challenge completed expands our shared understanding of AI threats such as prompt injection, data poisoning, and adversarial machine learning.
Since 2018, the GBBP has worked with 64 agencies, testing 115 systems, and uncovering 586 vulnerabilities, including 11 critical issues, before they could be exploited. Nearly S$800,000 has been paid in rewards, and more than 240 ethical hackers participate in each round.
Each vulnerability uncovered, and each team that contributes, strengthens our ability to stay one step ahead in a rapidly changing digital landscape.
This year, as GovTech and CSA join hands for AI CTF, we send a clear message: cybersecurity requires all of us — government, industry, and the wider community — to work together against a constantly evolving threat landscape.
Our success depends on tapping the creativity and rigour of the community, both in Singapore and beyond. The AI CTF and the GBBP exemplify this collaboration, and they help grow our ecosystem of capable, passionate cyber defenders.
Singapore’s vibrant digital environment enables us to develop a larger pool of AI and cybersecurity talent, benefiting both the public sector and the international businesses anchored here.
I am also heartened to see diversity taking root in this space. At Pwn2Own 2024, women researchers achieved full wins in one of the world’s toughest hacking competitions. Here in Singapore, last year’s all-girls team “What’s AI, 可以吃的吗?” clinched second place in the Pre-University category — proof that talent knows no gender. Let us continue to nurture this diversity, for it is diversity that drives innovation.
We also celebrate youth. One of today’s winners, Kevin Pook, began bug-bounty hunting as a university student and is now a cybersecurity consultant — a reminder that early curiosity can grow into lifelong passion and career.
Singapore’s approach to cyber defence is defined by proactive action and community collaboration. Together, we are shaping a safer, more trusted digital future.
To all participants, partners, and organisers — thank you for your dedication and excellence. Your contributions strengthen our national resilience and inspire others to join this important cause.
And to our youth, our women, our professionals, and our international friends: Whether you are a student, an engineer, or simply curious, cybersecurity is more than a contest of skills. It is a calling.
Let us continue to learn, to collaborate, and to build the secure digital future that all of us deserve.
Thank you.