Naver Cloud and LG CNS announced on August 27 that they would jointly form a consortium to participate in the cybersecurity track of the “Specialized AI Foundation Model Development” project led by the Ministry of Science and ICT and the National IT Industry Promotion Agency (NIPA). The consortium was selected as the final project operator on September 3 and is scheduled to begin full-scale development on September 18.
What stands out is that the project is not limited to building defensive AI. Naver Cloud will focus on strengthening defensive capabilities based on HyperCLOVA X, while a model based on LG AI Research’s EXAONE will concentrate on offensive capabilities. The two models will be developed separately for attack and defense, then cross-validated to improve each other’s performance.
Both models are ultimately expected to reach roughly 700 billion parameters and adopt a Mixture-of-Experts, or MoE, architecture that selectively activates specialized components depending on the input. Their training approaches will also differ. HyperCLOVA X will incorporate cybersecurity data from the pretraining stage to strengthen defensive capabilities, while the EXAONE-based model will undergo continual pretraining with additional security data to enhance its offensive capabilities. Rather than assigning both roles to a single general-purpose model, the project is designed from the outset to separate attack and defense and deepen the expertise required for each.

The scale of the data and infrastructure being投入 into the project is also substantial. The consortium plans to use approximately 831.59TB of cybersecurity data across 126 categories secured from 21 institutions. Collected threat intelligence will be labeled, standardized, and validated before being refined into training data. In addition to government-provided GPUs, both Naver Cloud and LG are contributing their own infrastructure, and Naver Cloud had already begun relevant pretraining before the project’s official launch.
A total of 33 institutions are participating in the consortium, led by Naver Cloud and including LG CNS, LG AI Research, LG Uplus, cybersecurity companies, universities and research institutes, and organizations related to national critical infrastructure. The project also extends beyond model development itself. It covers the full process from data acquisition and preprocessing to model development, evaluation and validation, real-world deployment, and commercialization.
The completed models are expected to be tested across seven sectors: energy, finance, science and technology, telecommunications, semiconductors, defense, and aerospace. They are also being designed for use in closed networks and on-premises environments with restricted external internet access, allowing deployment in national critical infrastructure. The longer-term goal is to expand their use through APIs, SDKs, and security agents so that they can be applied across Korea’s cybersecurity ecosystem.
This development structure recalls the long-standing relationship between red teams and blue teams in cybersecurity. Just as red teams probe systems from an attacker’s perspective while blue teams defend against those attempts, part of that role will now be assigned to AI within this project.
That does not mean the two AI systems will autonomously attack and defend against each other indefinitely and somehow evolve on their own. Based on the plans disclosed so far, the more accurate description is that separate offensive and defensive models will be developed and then repeatedly evaluated using each other’s outputs. Whereas conventional security AI has largely focused on detecting and responding to attacks that have already occurred, this project differs in one important respect: it is developing offensive AI specifically to strengthen defense.
Not Bigger AI, but Deeper AI
Generative AI competition has so far been driven largely by general-purpose capability. The ability to absorb more knowledge, answer more complex questions, and perform a wider range of tasks within a single model has been a key benchmark. Model size, performance, and breadth of capability have therefore often been treated as indicators of competitiveness.
Cybersecurity, however, demands a somewhat different set of capabilities. In environments where attacks actually occur, broad general knowledge or generic reasoning matters less than the ability to accurately understand vulnerabilities and attack patterns and respond quickly. Even within AI, summarizing documents or generating code requires a very different mix of data and training from analyzing real network attacks or malicious behavior.

Attackers, meanwhile, are increasingly using AI themselves. Tasks that once required significant time—such as writing phishing messages, analyzing malicious code, identifying vulnerabilities, and exploring attack paths—can now be accelerated with AI, reducing the time needed to prepare an attack. If attack methods change more frequently and variants can be produced more quickly, the traditional approach of having humans analyze an attack first and then add new defensive rules may eventually reach its limits.
That is why the goal of this project is not simply to build “a bigger AI.” Instead, it is to concentrate training on the data required for the narrow and sensitive domain of cybersecurity, while separately training offensive and defensive capabilities to improve their effectiveness in real-world conditions.
If general-purpose AI competition has focused on expanding the range of tasks a single model can perform, this project places greater emphasis on deepening expertise within a specific domain.
More Important Than Being “Domestic”: Controllability
Another concept worth examining here is sovereign AI. Sovereign AI does not simply mean building a “domestic AI.” It refers to a strategy in which a country develops AI using its own data and infrastructure, reduces dependence on external technologies, and secures control over the operation of critical systems.
This idea takes on a more direct meaning in cybersecurity. When AI is deployed in critical infrastructure such as energy, finance, telecommunications, semiconductors, and defense, model performance alone is not enough. The data used for training, whether sensitive information can leave the system, who can access the model, and whether problems can be fixed and addressed internally all become part of the security question.

For ordinary AI services, relying on external cloud infrastructure or calling overseas models may not pose a major problem. But the same approach is difficult to apply when dealing with sensitive information such as critical infrastructure logs, vulnerability data, and attack patterns. This is also why such models may need to be operated directly in closed networks or on-premises environments with limited external connectivity.
The Naver Cloud–LG CNS project is being designed with these conditions in mind. Its goal is not only to develop the models, but also to secure the training data, GPU infrastructure, and operating environment domestically so that the systems can be deployed within national critical infrastructure. The aim is to build not just a high-performing security AI, but a system that can be operated, modified, and maintained directly when necessary.
Ultimately, what matters in sovereign AI is not the label “domestic,” but whether meaningful control can actually be maintained. Even when some technologies are sourced externally, the more important question is whether core data and operational authority remain under domestic control and whether critical systems can avoid total dependence on outside providers.
Validating Defense Through Attack
Cybersecurity has long been described as a contest between the sword and the shield. Attackers find new methods, defenders block them, and attackers then search for another opening. This project assigns part of that cycle to AI.
There is an obvious paradox here. To improve the performance of defensive AI, the offensive AI acting as its counterpart must also be sufficiently capable. The better it becomes at identifying vulnerabilities and proposing new attack paths, the more difficult the challenges faced by the defensive model become—and the closer the evaluation can move toward real-world conditions.

At the same time, stronger offensive capabilities create greater risks that must be managed. A model that is highly capable of identifying vulnerabilities or analyzing attack paths can be a valuable defensive tool, but it can also become an offensive instrument if misused. As a result, access control, operating environments, and decisions over how much offensive functionality should be exposed become just as important as improving model performance itself.
For that reason, the success of this project cannot be judged by benchmark scores alone. It will also need to demonstrate how effectively the offensive and defensive models operate in real environments, and how safely the offensive capabilities themselves can be controlled.
Cybersecurity has always evolved through the interaction between attack and defense. With AI now entering that process, the way attacks are simulated and defenses are tested is beginning to change.
To build the strongest shield, first build a strong sword.
Perhaps that paradox is becoming one of the starting points for cybersecurity in the AI era.
