Artificial intelligence experts are cautioning the public to strengthen their passwords and promptly update software on their devices to combat a new type of cyber-threat known as “AI-driven computer worms.” These worms are capable of launching tailored attacks on devices, depleting processing power and stealing information as they move between connected devices such as laptops, printers, and cameras.
In a recent study conducted by a University of Toronto team led by Nicolas Papernot, it was revealed that publicly available AI models can be utilized to create a worm that can adapt its attack strategy while spreading across internet-connected devices. This research, done in partnership with the Vector Institute, was shared with national science, security, and defense entities before publication.
Papernot, an associate professor at U of T specializing in computer engineering and computer science, emphasized the importance of not neglecting software updates and regularly changing passwords. He stressed the necessity of using strong passwords, implementing multi-factor authentication, and ensuring timely deployment of software patches within organizations.
Unlike traditional computer viruses, these AI-driven worms can autonomously move from one device to another without human intervention. They collect information as they spread, exploiting vulnerabilities and weak points to infiltrate additional devices. The danger lies in their ability to learn from new vulnerabilities faster than patches can be developed to counteract them.
Papernot highlighted the significant threat posed by these AI-driven worms, mentioning that they are not only more effective than previous cyber threats but are also cheaper to create and deploy. Samir Chhabra from Innovation, Science and Economic Development Canada pointed out that the low cost of executing these attacks allows hackers to target a larger number of victims.
A survey by the Communications Security Establishment found that while a majority of Canadians regularly update their software and use complex passwords, there is still room for improvement in cybersecurity practices. Papernot emphasized the need for enhanced cybersecurity measures, especially in critical infrastructure sectors vulnerable to cyber attacks.
The study underscores the urgency for individuals and organizations to prioritize cybersecurity hygiene by updating software promptly, using strong passwords, and implementing multi-factor authentication to mitigate the risks posed by AI-driven computer worms.
