Artificial intelligence experts are cautioning the public to ensure strong password usage and prompt installation of software updates on their devices to counteract the emergence of “AI-driven computer worms,” a novel type of cyber-threat capable of executing tailored attacks on devices, depleting processing power and data as they seek out new targets.
Recently, a team from the University of Toronto, led by Nicolas Papernot, the Canadian Institute for Advanced Research AI chair, revealed that publicly accessible AI models have the potential to fuel a worm that can adjust its attack strategies dynamically while spreading across internet-connected devices like laptops, printers, and cameras.
This research, carried out in partnership with the Vector Institute, was shared with key entities in science, security, and defense before its public disclosure.
Papernot, an associate professor of computer engineering and computer science at U of T, emphasized the importance of promptly updating software and regularly changing passwords to enhance cybersecurity measures. He stressed the necessity of organizations swiftly deploying software patches to mitigate risks.
Unlike conventional computer viruses, worms self-propagate across machines without human intervention. The U of T researchers noted that their lab-created worm gathers intelligence as it traverses devices, identifying vulnerabilities and weak points to facilitate further infiltration.
In an uncontrolled environment, such a worm could exploit internet access and leverage information from security warnings on newly discovered vulnerabilities, surpassing the effectiveness of software patches designed to thwart them.
Papernot highlighted that while some vulnerabilities can be rectified through software updates, others, such as weak passwords and inadequate IT configurations, require more comprehensive solutions beyond patch deployment.
The threat posed by AI-driven worms is distinct from past attacks, as these worms can customize attack strategies for each victim device, making them more challenging to combat through conventional means.
Papernot’s cautionary message coincides with escalating concerns about AI, exemplified by recent incidents involving rogue AI agents infiltrating online platforms and rapidly developing sophisticated malware.
The emergence of AI-driven worms represents a significant shift in cybersecurity risk, as they are not only more efficient than traditional threats but also cost-effective to develop and deploy, enabling hackers to target a larger number of victims.
According to a survey conducted by the Communications Security Establishment, the majority of respondents regularly update their device software and use complex passwords. However, there is a notable gap in consistently using unique passwords, indicating a need for heightened cybersecurity measures.
Papernot emphasized the imperative for enhanced cybersecurity measures, particularly concerning critical infrastructure systems exposed to the internet, underscoring the importance of proactive security practices in Canada.