AI Security Lab인공지능보안 연구실 · 숙명여자대학교Sookmyung Women's University

숙명여자대학교 소프트웨어학부 · 2026년 9월 개설Division of Software · est. September 2026

우리는 AI의 머릿속 구조를
뚫고, 지킵니다.
We break and defend the structure inside an AI.

얼굴·음성 인식과 생성형 AI가 무엇을 흘리고, 어떻게 지킬 수 있는지. 공격과 방어를 함께 다루는 새 연구실입니다. 석사·박사 과정 학생을 모집합니다. What face and speaker recognizers and generative models leak, and how to defend them. A new lab working on both attack and defense. Master's and Ph.D. students are welcome.

우리 연구가 발표된 곳 · 올려 보면 무엇을 했는지 보입니다Where our work appears · hover to see what each paper did

연구 주제Research

하나의 질문에서 다섯 갈래로. One question, five threads.

현대의 인식 모델은 입력을 고차원 공간의 점으로 바꿉니다. 그 점들이 어떻게 놓여 있는지가 공격자가 무엇을 얻을 수 있고 방어자가 무엇을 숨길 수 있는지를 결정합니다. 우리는 이 구조를 연구의 중심에 둡니다. Modern recognizers turn inputs into points in a high-dimensional space. How those points are arranged governs what an attacker can extract and what a defender can hide. We put that structure at the center.

01

공격Attack

인식 시스템이 돌려주는 점수만으로 얼굴을 복원하거나 다른 사람을 사칭할 수 있을까요? 경사하강법 없이, 질문을 미리 다 정해 두는 공격으로 상용 API까지 뚫었습니다. Can the scores a recognizer returns be enough to reconstruct a face or impersonate someone? Without gradient descent, with every query fixed up front, our attacks break commercial APIs.

IEEE S&P 2024 · NeurIPS 2025 · ACM CCS 2026 · BMVC 2023
02

보호Protect

비밀번호는 바꿀 수 있지만 얼굴은 바꿀 수 없습니다. 오차가 있는 생체 정보를 비밀키 없이 안전하게 저장하고 검색하는 방법을 오류정정부호와 동형암호로 만듭니다. You can change a password, not your face. We build ways to store and search noisy biometrics without a secret key, using error-correcting codes and homomorphic encryption.

CVPR 2021 · ICCV 2025 · IEEE TDSC 2025 · IEEE Access 2026
03

보증Certify

"지금 알려진 공격은 막는다"가 아니라 "이 범위 안의 어떤 공격도 못 뚫는다"를 수학적으로 증명합니다. 분류가 아닌 인식 문제에 맞게 증명 도구를 다시 짭니다. Not "we resist known attacks" but "no perturbation within this radius can flip the decision", proven. We rebuild certification tools for recognition rather than classification.

ECCV 2024 · IEEE T-BIOM 2025
04

탐지Detect

딥페이크 탐지기와 vision-language 모델도 인식기와 같은 구조 위에 있습니다. 픽셀을 건드리지 않고 프롬프트만으로 탐지기를 속이는 방법과, 그것을 막는 방법을 함께 봅니다. Deepfake detectors and vision-language models share the recognizer's structure. We study prompt-only evasion that never touches a pixel, and how to close that gap.

arXiv 2025 · 진행 중ongoing
05

프라이버시Privacy

AI는 모든 것을 벡터로 바꿔 비교합니다. 그 비교를 원본을 드러내지 않고 하는 방법, 즉 암호화된 채로 유사도를 계산하는 기술을 만듭니다. 검색, 매칭, 집합 교집합까지. AI turns everything into vectors and compares them. We build ways to do that comparison without revealing the originals: similarity computed on encrypted data, for search, matching, and set intersection.

IEEE Access 2025 · ICCV 2025
06

여섯 번째 갈래는
당신이 만듭니다.
The sixth thread
is yours to start.

석사·박사 과정 학생을 모집합니다.Master's and Ph.D. students welcome.

왜 여기서Why here

작은 연구실이 잘하는 것.What a small lab does well.

수학과 코드, 두 언어Two languages: math and code

문제를 수학으로 정의하고 실험으로 확인합니다. 선형대수·확률·정수론이 도구이고, 어느 한쪽만으로는 보안 연구가 완성되지 않습니다.Problems are defined in math and confirmed by experiment. Linear algebra, probability, and number theory are the tools; neither side alone completes security research.

교수와 직접Directly with the PI

신생 연구실이라 모든 학생이 교수와 매주 직접 만납니다. 연구 주제를 정하는 단계부터 학회 발표까지 직접 지도합니다.A new lab means every student meets the PI directly, every week. Guidance is hands-on from choosing a topic to presenting at a conference.

최고 학회에서 검증된 방법Methods proven at top venues

IEEE S&P, ACM CCS, NeurIPS, ICCV, ECCV, CVPR. 보안과 AI 양쪽의 최상위 학회에 발표해 온 연구 흐름을 그대로 잇습니다.IEEE S&P, ACM CCS, NeurIPS, ICCV, ECCV, CVPR. You join a line of work that publishes at the top of both security and AI.

국경 없는 협업Collaboration across borders

국내외 대학·연구기관과 공동 연구를 이어갑니다. 해외 파견과 국제 공동연구의 기회가 열려 있습니다.Ongoing joint work with universities and research institutes at home and abroad. Research visits and international collaboration are real options.

소식News

최근 소식Recent news

전체 보기 →All news →

연구실의 문은 열려 있습니다.The door is open.

석사·박사 과정 학생을 모집합니다. 보안을 몰라도 괜찮습니다. 궁금한 것이 많은 사람이면 충분합니다. Master's and Ph.D. students are welcome. No security background required. Curiosity is the prerequisite.

지원 안내 보기How to apply