Source: H3C |Original Link


On July 26, the inaugural Zhongguancun Cyberspace Security Academic Annual Conference was held in Beijing. Themed "AI + Cyberspace Security: New Challenges, New Opportunities," the conference focused on frontier trends and strategic directions in cyberspace security within the era of artificial intelligence. H3C Group, a subsidiary of Unisplendor Corporation, was invited to attend the event, joining experts and scholars from industry, academia, and research institutions to conduct in-depth discussions on technological transformations and evolutionary pathways in cyberspace security in the AI era.

AI Reshapes the Security Landscape: Traditional Defense Faces New Challenges Amid Paradigm Shifts

Liang Liwen, Director of the H3C Group Offensive and Defensive Laboratory, delivered a keynote speech titled "From Empirical Defense to Structured Resilience: A Paradigm Leap." She noted that global technology giants are currently accelerating the commercial deployment of agents, expanding the boundaries of internet infrastructure from traditional network foundations to trusted intelligent infrastructures that support autonomous collaboration between models and agents, intent-based interaction, and computing power scheduling. Amid this transformation, security risks have not merely shifted but have instead manifested as a superimposed landscape characterized by "multiple battlefields and multiple domains."

On one hand, mature attack vectors such as ransomware, data breaches, cryptojacking, and DDoS attacks remain core threats to traditional infrastructure; on the other hand, security for AI-native infrastructure—centered on large models and agents and oriented toward intent-based interaction—has emerged as an entirely new incremental challenge. Liang Liwen characterized this shift as an evolution from "deterministic threat models" to "probabilistic threat models" and further to "non-deterministic intent threat models." The essence of attacks has escalated from unauthorized deviations in code paths to probabilistic manipulation at the semantic layer, and even to the hijacking of decision-making logic.

Of greater concern is the fact that AI is intensifying full-domain dimension-reduction attacks. Transitioning from "elite-driven" to "industrialized" operations, AI-powered attacks have achieved orders-of-magnitude leaps in terms of actors, efficiency, and scale. Attack methods now transcend code boundaries, extending from cognitive manipulation to physical safety, exhibiting characteristics of full-domain integration and cross-domain propagation.

Paradigm Leap: Building a Structured Resilience Protection System with Spatiotemporal Hierarchical Evolution

Addressing emerging security challenges in the AI era, Liang Liwen systematically articulated H3C's structured resilience protection philosophy. Spatially, it establishes multi-layered defense-in-depth domains covering traditional infrastructure, large models, agents, and application ecosystems; temporally, it integrates security governance throughout the entire AI lifecycle. This system possesses four key resilience capabilities: "attack radius constraint, survivability under partial compromise, graceful degradation during failures, and real-time perception with self-healing." Through continuous adversarial engagement, the system enables iterative policy evolution, achieving comprehensive defense and governance spanning code-level risks, content security, and intent-based risks.

Within this framework, specific implementation pathways encompass three phases: pre-event defense, in-event monitoring, and post-event response.

  • Pre-event: Admission control based on prior trustworthiness constitutes the fundamental prerequisite for resilience. Addressing challenges such as highly open AI infrastructure boundaries and complex sources of open-source components and third-party agents, H3C proposes a dual-engine governance paradigm driven by "Sec for AI + AI for Sec." On one hand, it establishes a multi-dimensional admission assessment system covering infrastructure, models, and agents, mandating upfront security verification; on the other hand, through automated red teaming and adversarial generation technologies, it employs high-intensity adversarial testing to compel convergence of model security boundaries.
  • In-event: Dynamic intrinsic security represents the core battleground for resilience. Addressing the probabilistic nature and context dependency of LLM and Agent outputs, H3C introduces a layered "Decision + Verification" protection architecture grounded in Zero Trust principles, enabling minimized dynamic authorization and behavioral interception. Liang Liwen specifically highlighted H3C's exploration in the field of "Neuro-Symbolic AI": utilizing Neural Networks (N) to perceive semantic deviations and attack variations within high-dimensional continuous spaces, while employing Symbolic Engines (S) to perform anchored mapping of neural network outputs followed by logical matching, thereby enforcing hard logic to maintain security baselines. This agent governance philosophy—characterized by "flexible cognition and rigorous execution"—offers a novel technical paradigm for balancing detection flexibility with security certainty.
  • Post-Event: Continuous operations driven by game-theoretic evolution represent the closed-loop manifestation of resilience. Liang Liwen noted that market access is not the end goal; as attacks continuously evolve and models and businesses are dynamically updated, defense systems must possess sustained operational capabilities. H3C leverages measures such as global deployment of AI honeypots, AI threat hunting, and AI vulnerability management to detect adversaries. Concurrently, the company proposes causal reasoning and proactive defense based on Bayesian games to anticipate adversary identities and predict risk propagation pathways in advance, thereby facilitating a transformation from passive response to proactive defense deployment.

In concluding his speech, Liang Liwen stated: "Previously, competition occurred among peers with cognitive parity; today, it involves cross-dimensional gaming characterized by cognitive asymmetry. The transition from experience-based defense to structured resilience entails not only technological upgrades and conceptual reconstruction but also requires consensus-building, deep integration, and collaborative development across industry, academia, and research institutions."

In the face of rapidly evolving AI technologies and escalating demands for AI security, H3C will continue to deepen collaborative innovation with an open approach, promote a paradigm shift in security from passive defense to proactive resilience, and work with the industry to establish a trusted foundation for the digital era while safeguarding the security and prosperity of cyberspace.