Artificial intelligence experts are cautioning the public to enhance their online security by using strong passwords and promptly updating software on their devices to combat the emergence of “AI-driven computer worms.” These new cyber-threats are capable of launching customized attacks on devices, draining processing power and stealing information as they propagate in search of new targets.
Recently, researchers at the University of Toronto, led by Nicolas Papernot, the Canadian Institute for Advanced Research AI chair, disclosed that publicly available AI models could fuel a worm that adjusts its attack strategy dynamically while spreading across internet-connected devices like laptops, printers, and cameras. This research, conducted in partnership with the Vector Institute, was shared with national science, security, and defense entities before publication.
Papernot, an associate professor at the University of Toronto specializing in computer engineering and computer science, emphasized the importance of not neglecting software updates and regular password changes to combat these evolving threats. He stressed the necessity of multi-factor authentication and swift deployment of software patches by organizations.
Unlike traditional computer viruses, worms can spread autonomously from one machine to another without human intervention. The worm developed by the U of T researchers is designed to gather information as it traverses devices, exploiting vulnerabilities and weak passwords to access new machines. This dynamic nature poses challenges for traditional defense mechanisms that rely on fixed scripts against human-programmed attacks.
The rise of AI-driven worms poses a significant cybersecurity risk, as they are not only more effective but also cheaper to develop and deploy compared to their predecessors. The lower cost of launching these worms allows hackers to target a larger number of victims, leveraging stolen computing resources to propagate further attacks at minimal additional cost.
Papernot’s research underscores the need for enhanced cybersecurity measures in Canada, particularly in critical infrastructure sectors like power grids, healthcare facilities, and essential services that are increasingly connected to the internet. Strengthening cybersecurity hygiene, including regular software updates, robust password practices, and proactive defense strategies, is crucial in mitigating the evolving threat landscape posed by AI-driven cyber-attacks.
