
AI-generated summary
Gong Huazhong, director of the National Information Security Research Institute, took office on August 1, two months after his appointment. Faced with the new information security threats brought about by the rapid development of AI, he held a media exchange meeting to explain the response strategies.
The Institute of Information Security held a media exchange meeting today (5th). Director of the Institute of Information Security Cai Fulong (front 2 from left), Director of the Institute of Information Security Gong Huazhong (front 2 from right) and relevant colleagues attended to explain the information security threats and defense layout in the AI era. (Photo by reporter Qiu Qiaozhen)
[Reporter Qiu Qiaozhen/Reporting from Taipei] Gong Huazhong, director of the National Institute of Information Security (Information Security Institute), took office on August 1 this year. Two months after his expiration, the Institute held a media exchange meeting today (5th) to face the rapid development of AI. Gong Huazhong admitted that he could not sleep well when he first took over the new information security threats brought by the development of the company. He even described the current AI security attacks as "really like heavy rain." As long as the protection is not done well, loopholes may appear.
Gong Huazhong pointed out that with the assistance of AI, attackers can automatically target a large number of targets in a very short period of time and continue to deeply search for system vulnerabilities. In the face of national hacker threats, traditional defense methods that rely on manual monitoring and established standard operating procedures are no longer enough to cope with the speed and scale of attacks in the AI era.
Please read on...
Therefore, the Institute of Information Security will next use "AI versus AI" as its core strategy, combining actual combat defense experience and AI security technology to simultaneously advance from threat intelligence analysis, independent technology research and development, product and supply chain security to talent cultivation, hoping to establish a national security protection system with "quick response, wide coverage, and deep detection."
Gong Huazhong said that one of the keys to introducing AI is to expand the scope of protection at a lower cost. Instead of only focusing on a few key institutions and key targets, it can also conduct deeper detection and find more potential threats. To put it simply, it is hoped that the entire set of information security protection can be renovated and strengthened through AI.
The Information Security Institute is currently planning four key tasks. The first item is "AI automated source code detection and repair." The Information Security Institute will introduce generative AI to go deep into the system's bottom layer, giving priority to government agencies and key infrastructure cores for "source code detection" and "patch recommendations" to reduce vulnerability risks from the source of software development.
Gong Huazhong revealed that the Institute of Information Security has currently cooperated directly with several internationally renowned AI companies, and has access to relevant advanced systems and technologies for information security testing, and has launched a number of preliminary tests.
He said that in the future, we will combine the AI systems of partners and the local security model established by the Institute of Information Security to prioritize the source code testing of core software of government agencies and critical infrastructure, identify potential vulnerabilities and provide repair suggestions, and improve system security from the source.
Gong Huazhong emphasized that the focus of this work is not to make the product better, but to find loopholes first to make the entire system safer. This is also a task that the Information Security Institute has a technical perspective, is unshirkable and should be promoted as a priority. Relevant work has been started. The Institute of Information Security has invested a lot of manpower in testing and development since last month. Since there are many AI industry players participating in the cooperation, resources will continue to be invested in the future to accelerate the introduction of relevant technologies.
The second item is "Using AI to strengthen penetration testing and offensive and defensive drills." The Information Security Institute plans to use AI models, AI agents, and different self-developed skills to simulate attacker thinking, conduct automated black box penetration testing and red and blue team attack and defense drills on important online services and systems, and continuously verify the resilience of actual defenses.
Gong Huazhong said that in the past, information security attack and defense drills mostly relied on human execution. After the introduction of AI in the future, he hopes to make the drills "faster, broader, and more in-depth." The Institute of Information Security is currently collecting different attack methods and is expected to start relevant drills in April next year.
He likened this approach to "vaccination." Since hackers will also use these methods to launch attacks, if government agencies can simulate attacks on their own and identify weaknesses in advance, they will have the opportunity to strengthen their overall defense resilience.
The third task is to establish an "AI automated threat intelligence system." Gong Huazhong pointed out that the Information Security Institute currently collects a large amount of global threat intelligence, including dark web, global networks and relevant information about various countries, and also cooperates with many countries. However, if the huge data continues to rely on manual processing, the burden will be quite heavy.
Therefore, the Information Security Institute plans to introduce large-scale language models to instantly digest and compare large amounts of domestic and foreign threat information, improve analysis efficiency and accuracy, and further integrate analysis results with enterprises and industries.
Gong Huazhong said that in the AI era, network attacks are getting faster and faster. After a risk is discovered in one place, another place may soon be attacked. If the threat can be identified in advance through AI and intelligence information can be quickly shared, there is a chance to block the attack before it spreads.
The fourth item is to create a “national-level AI security attack and defense sandbox.” Gong Huazhong pointed out that many government agencies and enterprises are still unfamiliar with how AI attacks are actually carried out. Therefore, the Information Security Institute is planning to establish a safe and controlled verification environment to allow government and industry teams to get used to high-intensity and fast-paced AI attack methods in advance, establish contingency defense muscle memory, and at the same time work with the information security industry to verify new technologies.
Gong Huazhong said that the above four tasks are the priority directions listed by the Information Security Administration based on the threat information and technical capabilities currently grasped in the past two months. The ultimate goal is to strengthen the in-depth defense of national information security, that is, extending from the management, technology, and network boundaries to internal systems. Only by establishing defense lines layer by layer can a more complete defense system be used to withstand the rapidly rising AI security threats.
As for the promotion schedule of the four major tasks, the Institute of Information Security stated that the first "AI automated source code detection and repair" and the second "AI penetration testing and actual attack and defense drills" have now entered testing and verification, and the second one is expected to be officially launched in April next year.
The third and fourth "AI Threat Intelligence System" and "AI Security Attack and Defense Sandbox" are still in the development stage. The target is to launch preliminary results and the first version of the system next year, and continue to evolve and strengthen them in the future.
In the more than three years since its establishment, the Institute of Information Security has gone through three presidents. In this regard, Gong Huazhong said that based on the foundation laid by the previous two presidents, his next most important thing is how to further "integrate" the existing research and development and protection energy.
He emphasized that R&D units cannot just produce good technologies, but must also think about how to further implement and even industrialize them; units originally responsible for protection must also continue to improve their capabilities, so that R&D and practical protection form a continuous cycle of operation, cooperate with each other, give back to each other, and further introduce more AI technologies. These are the focus of the next promotion.
Grasp the economic pulse with one hand. Click here to subscribe to Free Finance Youtube channel
AI outlook — possibilities, not facts
The Information Security Agency will begin AI-enhanced penetration testing and offensive and defensive drills in April next year.
Very likely · Within months
The third and fourth "AI Threat Intelligence System" and "AI Security Attack and Defense Sandbox" will launch preliminary results and the first version of the system next year
Likely · Within months

U.S. President Trump continuously posted on Truth Social calling AI risks a scam, and called Nvidia CEO Jen-Hsun Huang to emphasize that whoever wins AI will win. Huang Jen-Hsun said that all industries and people in the United States should become winners in the AI competition. Experts point out that competition between the United States and China and the lack of AI security governance may put Taiwan under the dual pressure of chip supply and compliance costs. Taiwan needs to strive for verifiable acceleration guardrails and a voice in common governance.

Hong Kong has introduced a four-step AI talent ladder strategy to counter entry-level job disruption from automation, with officials stating AI is a catalyst, not a threat, and emphasizing population-scale investment in digital literacy rather than shielding youth from the technology.

Hong Kong has introduced a four-step AI talent ladder strategy to address entry-level job disruption from automation, aiming to build digital literacy and develop industry leaders rather than shield youth from AI, according to Permanent Secretary for Innovation Kevin Choi.

Chinese researchers have developed a stable co-production system that extracts hydrogen and fresh water from seawater while recovering uranium and bromine, improving electricity efficiency by about 15 percent over existing methods, according to a study in Nature Energy.

Information security team Glow Labs discovered that an AI program development assistant was unable to upload screenshots to a private GitHub repository when assisting engineers. Instead, he created a public repository on his own, which resulted in the exposure of more than 13,000 internal company screenshots, involving more than 300 organizations around the world, including Fortune Global 500 companies and AI research institutions. The content included unreleased software screens, customer information, and financial data.

U.S. President Trump announced the formation of a "Superintelligence Working Group" to coordinate the federal government's work in the field of artificial intelligence, appointing Director of National Intelligence Jay Clayton and others as members, and said that the working group will report directly to him and the White House Chief of Staff.