Artificial intelligence experts are cautioning the public to utilize robust passwords and promptly update software on their devices to combat the emergence of “AI-driven computer worms,” a new category of cyber-threats capable of launching tailored attacks on devices, draining processing power and data as they search for new targets.
In June, researchers at the University of Toronto, led by Nicolas Papernot, Chair of the Canadian Institute for Advanced Research AI, revealed that publicly accessible AI models could fuel a worm that can dynamically adjust its assault as it spreads across internet-connected devices such as laptops, printers, and cameras.
This research, done in conjunction with the Vector Institute, was first shared with national science, security, and defense entities before being made public. Papernot, an associate professor of computer engineering and computer science at U of T, emphasized the importance of promptly updating software and regularly changing passwords during a panel discussion at the university.
He stressed the significance of maintaining cybersecurity practices, stating that organizations must ensure swift deployment of software patches to safeguard against potential threats posed by these advanced AI worms.
Unlike traditional computer viruses, worms propagate autonomously from one machine to another without human intervention. The U of T team noted that their lab-created worm acquires information as it traverses between devices, exploiting newly discovered vulnerabilities and weak points to infiltrate additional machines.
In uncontrolled circumstances, these worms could access the internet, learn from alerts regarding fresh vulnerabilities, and outpace software updates aimed at thwarting them. The researchers highlighted that while some vulnerabilities can be mitigated through software patches, others, such as weak passwords and inadequate IT configurations, necessitate broader organizational changes to address effectively.
Papernot underscored that the AI-driven worms are capable of devising customized attack strategies tailored to each victim device they encounter, making them far more challenging to combat compared to traditional cyber threats.
The lower costs associated with constructing and deploying these AI-driven worms make them more accessible to hackers, enabling them to target a larger number of systems. This development represents a significant shift in the cybersecurity landscape, emphasizing the need for enhanced defense mechanisms against these sophisticated threats.
A survey by the Communications Security Establishment (CSE) in January revealed that a majority of Canadians regularly update their device software and use complex passwords. However, there is room for improvement in terms of using unique passwords consistently, indicating the necessity for stronger cybersecurity measures in the country.
Papernot emphasized the urgency of bolstering cybersecurity across critical infrastructure sectors such as power grids, water supplies, hospitals, schools, and grocery stores, highlighting the vulnerability of these systems to online threats.
The findings of these studies underscore the critical importance of fortifying cybersecurity practices and implementing robust measures to safeguard against evolving cyber threats posed by AI-driven worms.
