Artificial intelligence experts are cautioning the public to enhance their cybersecurity practices by utilizing strong passwords and promptly updating software on their devices to combat a new type of cyber-threat known as “AI-driven computer worms.” These sophisticated worms can launch tailored attacks on connected devices, compromising processing power and data as they seek out new targets.
Recently, researchers from the University of Toronto, led by Nicolas Papernot, demonstrated that publicly available AI models can power a worm capable of adjusting its attack strategy in real-time as it spreads across internet-connected devices such as laptops, printers, and cameras. This research, conducted in collaboration with the Vector Institute, was shared with national science, security, and defense entities before publication.
Papernot, an associate professor at U of T, emphasized the importance of not ignoring software update notifications and regularly changing passwords during a panel discussion at the university. He stressed the need for multi-factor authentication and prompt deployment of software patches by organizations to mitigate the risks posed by these AI-driven threats.
Unlike traditional computer viruses, these AI-powered worms autonomously spread between devices without human intervention. The researchers highlighted that the worm they developed collects data as it moves through devices, exploiting vulnerabilities and weak passwords to propagate further. These worms can outsmart software patches by learning from warnings about new vulnerabilities, making them difficult to contain.
Papernot warned that these AI-driven worms are more effective and cost-efficient compared to previous threats, enabling hackers to target more victims. The lower costs associated with deploying these worms make subsequent attacks virtually free, posing a significant shift in cybersecurity risk management.
A survey conducted by the Communications Security Establishment (CSE) revealed that while a majority of respondents regularly update their device software and use complex passwords, there is a lack of consistency in using unique passwords. Papernot emphasized the necessity of strengthening cybersecurity measures in critical infrastructure systems such as power grids, hospitals, and schools, which are vulnerable to online threats.
The findings underscore the urgency for individuals and organizations to prioritize cybersecurity hygiene by adopting robust security practices and staying vigilant against evolving cyber threats posed by AI-driven worms.