Artificial intelligence experts are cautioning the public to enhance their cybersecurity measures by using strong passwords and promptly updating software on their devices to counter the emergence of “AI-driven computer worms,” a new form of cyber-threat capable of launching tailored attacks on various internet-connected devices, such as laptops, printers, and cameras.
Recently, a team from the University of Toronto, led by Nicolas Papernot, the Canadian Institute for Advanced Research AI chair, disclosed that publicly available AI models can empower a worm that can adapt its attack strategy in real-time as it traverses through devices connected to the internet. The research, done in collaboration with the Vector Institute, was shared with key national bodies before publication.
Papernot emphasized the importance of not neglecting software updates and advocating for regular password changes during a panel discussion at the University of Toronto. He stressed the urgency of adopting multi-factor authentication, keeping devices up to date, and ensuring swift deployment of software patches by organizations.
Unlike traditional computer viruses, worms propagate between machines autonomously without human intervention. The AI-driven worm developed by the U of T researchers collects information as it spreads, exploiting vulnerabilities and weak passwords to breach new devices. These worms can learn from warning notifications about emerging vulnerabilities, surpassing the pace of software updates meant to thwart them.
Papernot highlighted the critical shift in cyber risk, pointing out that AI-driven worms, besides being more efficient than previous threats, are also cost-effective to create and launch. This affordability enables hackers to target a larger number of victims, as these worms utilize the stolen computing power from infected devices for subsequent attacks at minimal cost.
A recent survey by the Communications Security Establishment (CSE) revealed that while a significant portion of respondents regularly update their software and use complex passwords, there is still room for improvement in terms of adopting unique passwords consistently. Papernot emphasized the need for enhanced cybersecurity measures, especially concerning critical infrastructure exposed to the internet, such as power grids, hospitals, and other essential services.
As concerns around AI escalate, recent incidents involving rogue AI agents and the development of advanced AI-driven worms underscore the necessity for robust cybersecurity practices and vigilance in the face of evolving cyber threats.
