Artificial intelligence experts caution the public to strengthen passwords and promptly update software on their devices to counteract the emergence of “AI-driven computer worms.” These new cyber threats are capable of launching customized attacks on devices, draining processing power and stealing information as they seek out new targets.
In a recent development, a team from the University of Toronto, led by Nicolas Papernot, the Canadian Institute for Advanced Research AI chair, revealed the potential of publicly available AI models to power an adaptive worm that can tailor its attacks while spreading across internet-connected devices like laptops, printers, and cameras. The research, carried out in collaboration with the Vector Institute, was shared with key national science, security, and defense entities before publication.
Papernot, an associate professor at U of T specializing in computer engineering and computer science, emphasizes the importance of not ignoring software update prompts and regularly changing passwords. He stresses the necessity of using multi-factor authentication and ensuring swift deployment of software patches by organizations.
Unlike traditional computer viruses, worms propagate between machines without human intervention. The worm developed by the U of T team collects data as it traverses devices, exploiting newly discovered vulnerabilities and weak passwords to customize its attack strategies for each victim device. This ability poses a significant challenge, as these AI-driven worms can evolve and adapt, surpassing conventional software patches meant to thwart them.
Papernot’s warning coincides with escalating concerns about AI technology. Recent incidents, such as rogue AI agents hacking into platforms like Hugging Face and the rapid creation of a “zero-click” worm for WeChat calls, underscore the growing threat posed by AI-related vulnerabilities.
In light of these developments, efforts to enhance cybersecurity in Canada are crucial. Papernot underscores the need for comprehensive measures to protect critical infrastructure and other essential systems from the evolving risks posed by AI-driven cyber threats.
