Artificial intelligence experts are urging the public to enhance their online security practices by using robust passwords and promptly updating software on their devices to combat the emergence of “AI-driven computer worms,” a novel form of cyber threat capable of launching tailored attacks on various connected devices, compromising processing capabilities and data as they propagate in search of new targets.
Recently, a team from the University of Toronto, led by Nicolas Papernot, the AI chair at the Canadian Institute for Advanced Research, disclosed that publicly accessible AI models could fuel a worm that adapts its assault strategies dynamically while moving across internet-connected devices like laptops, printers, and cameras.
This research, conducted in partnership with the Vector Institute, was shared with key scientific, security, and defense entities before its public release. Papernot, an associate professor at U of T specializing in computer engineering and computer science, emphasized the importance of promptly updating software and regularly changing passwords to mitigate these evolving cyber threats during a panel discussion at U of T.
Unlike traditional computer viruses, worms spread autonomously from one device to another without human intervention. The AI-powered worm developed at U of T collects data as it traverses devices, uncovering passwords and vulnerabilities that enable it to compromise additional machines. This worm’s ability to learn and adapt could enable it to gain internet access, learn from emerging vulnerabilities, and outpace software updates meant to thwart it.
Papernot stressed that the unique danger posed by AI-driven worms lies in their capacity to devise customized attack strategies for each targeted device, unlike conventional attacks that follow fixed scripts. This adaptability makes these worms much more challenging to stop using traditional security measures.
The rise of AI-related security concerns is underscored by recent events, including rogue AI agents infiltrating platforms like Hugging Face and the rapid development of advanced AI-driven malware. The affordability and efficiency of deploying AI-driven worms compared to traditional methods make them a significant cybersecurity risk that organizations and individuals need to address promptly.
A recent survey by the Communications Security Establishment revealed that while most respondents update their software regularly and use complex passwords, there is room for improvement in adopting unique passwords and bolstering overall cybersecurity measures. Papernot emphasized the need for enhanced cybersecurity measures, especially for critical infrastructure systems exposed to online threats like power grids, water supplies, hospitals, schools, and essential services.