
ULSAN — A project to develop multilayered security technology that prevents data leaks and malfunctions in "agentic AI" — systems built on large language models that make decisions and carry out tasks on their own — is getting under way.
Ulsan National Institute of Science and Technology (UNIST) said on the 18th that it had been selected for the interdisciplinary track of the 2026 AI Star Fellowship, a program for top early-career AI researchers run by the Ministry of Science and ICT and the Institute of Information & Communications Technology Planning & Evaluation (IITP).
The research team, working in a consortium with Sungkyunkwan University, will receive a total of 11 billion won ($7.9 million) in government funding over five and a half years through December 2031. With this selection, UNIST is now running two projects simultaneously under the AI Star Fellowship program, which the ministry is pursuing to cultivate next-generation core researchers.
Moon Hyun-gon, a professor of computer science and engineering at UNIST, will serve as principal investigator. Also participating are UNIST professors Wi Seong-il, Park Min-kyung, Park Sae-rom and Na Hyung-ho, along with Sungkyunkwan University professors Park Eun-il, Hwang Sung-jae and Kim Hyoung-shick. SecuLayer, S2W and Raon Data, companies specializing in security and AI, have joined as industry-academia partners.
Agentic AI searches the web on its own, controls various work tools and handles complex tasks. But if malicious external attacks distort the model's decision-making, there is a significant risk of serious malfunctions or data breaches in live service environments. Existing approaches have been limited to piecemeal defenses at each stage, such as threat detection at the input layer or isolation of execution environments, leaving them unable to block chained, compound attacks.
To address this, the team will apply a "cross-layer safety co-design" approach that integrates the model, the user interface and the execution environment. It plans to establish standard safety criteria so that threats are blocked sequentially at the next stage even if one line of defense is breached, and to resolve technical challenges at each layer through three subprojects. The completed security technology will be applied directly to the partner companies' commercial services to verify its effectiveness.
Moon's team has conducted research in systems security, including building trusted execution environments (TEE) and formal verification of system safety, and has published numerous papers at the world's most prestigious security conferences, including USENIX Security and IEEE S&P. The team plans to complete the security framework by combining that work with its AI research capabilities in areas such as knowledge distillation and deepfake detection verification.
"To guarantee the security of agentic AI, we have to protect not only the model itself but also the channels through which data moves and the system environment where it actually runs, all in an integrated way," Moon said. "By completing a fundamental security framework spanning multiple layers, we want to ease the anxiety of industries that have hesitated to adopt AI over security concerns, and we will also work to train the next generation of specialist researchers."







