Artificial intelligence experts are cautioning individuals to utilize strong passwords and promptly update their software to combat the emergence of “AI-driven computer worms,” a new form of cyber threat capable of executing customized attacks on devices, draining processing power and data as they search for new targets.
A team from the University of Toronto, under the leadership of Nicolas Papernot, the Canadian Institute for Advanced Research AI chair, unveiled that publicly accessible AI models have the potential to fuel a worm that can adjust its attack strategy in real-time while spreading across internet-connected devices like laptops, printers, and cameras.
Collaborating with the Vector Institute, the research was shared with key national entities related to science, security, and defense ahead of its public disclosure. Papernot, an associate professor at the U of T specializing in computer engineering and computer science, is emphasizing the importance of promptly updating software and regularly changing passwords to the public.
“We can no longer overlook the importance of cybersecurity practices,” Papernot stated during a panel discussion at the University of Toronto. “It is crucial to avoid password reuse, implement multi-factor authentication, ensure software updates are applied promptly, and organizations need to streamline processes for swift deployment of software patches.”
Unlike traditional computer viruses, worms propagate autonomously from one device to another without human intervention. The worm designed by the U of T researchers collects data as it traverses between devices, exploiting every breach to uncover passwords and vulnerabilities that can be exploited on other machines.
In a real-world scenario, such a worm could gain internet connectivity and learn from alerts regarding newly identified weaknesses, surpassing the software patches intended to thwart them. The researchers highlighted in a blog post that while some issues can be rectified through software updates, others such as weak passwords and inadequate IT configurations cannot be resolved solely by patching.
Papernot underscored the evolving threat landscape posed by AI-driven computer worms, citing their ability to create tailored attack strategies for each victim device encountered. This customization approach makes it challenging to halt their proliferation by addressing individual vulnerabilities.
The warning from Papernot coincides with rising concerns about AI, especially following incidents like the OpenAI agents breaching the Hugging Face platform. Recent advancements in AI have led to the rapid development of sophisticated cyber threats, including a “zero-click” worm capable of spreading through WeChat calls on iOS and Android systems within days.
The emergence of AI-driven worms poses a significant shift in cybersecurity risk, as they are not only more effective but also cost-effective to construct and deploy. Samir Chhabra from Innovation, Science and Economic Development Canada highlighted that the lower costs associated with these worms enable hackers to target a broader range of victims, utilizing stolen computing resources to execute attacks at minimal incremental costs.
A survey by the Communications Security Establishment (CSE) revealed that while a majority of respondents regularly update their device software and use complex passwords, there is room for improvement in adopting unique passwords consistently. Papernot stressed the necessity for enhanced cybersecurity measures in critical sectors like power grids, healthcare facilities, and other essential services that are exposed to internet threats.
The findings indicate the urgency for bolstering cybersecurity practices in Canada to mitigate the evolving threats posed by AI-driven cyber worms.
