Artificial intelligence experts are cautioning individuals to utilize strong passwords and promptly update software on their devices to combat the emergence of “AI-driven computer worms,” a novel form of cyber threat capable of executing tailored attacks on devices, depleting processing power and data as they seek out new targets.
Recently, a team from the University of Toronto, under the leadership of Nicolas Papernot, the Canadian Institute for Advanced Research AI chair, demonstrated that publicly accessible AI models can empower a worm with the ability to adjust its assault on the go as it traverses through internet-connected devices such as laptops, printers, and cameras.
This research, conducted in partnership with the Vector Institute, was shared with key national bodies in science, security, and defense before its public disclosure. Papernot, an associate professor at U of T specializing in computer engineering and computer science, emphasized the importance of promptly updating software and regularly changing passwords to the public.
“We must now prioritize our cybersecurity practices,” he asserted during a panel discussion at U of T. “Gone are the days of using weak passwords. We need to implement multi-factor authentication, maintain up-to-date devices, and ensure organizations streamline processes to swiftly deploy software patches.”
Unlike traditional computer viruses, worms propagate from one device to another without human intervention. The U of T researchers highlighted that their lab-created worm collects data as it moves between devices, identifying passwords and vulnerabilities that can unlock subsequent machines.
In a real-world scenario, such a worm could access the internet, learn from alerts regarding newly identified weaknesses, and surpass software patches intended to thwart them. The researchers noted in a blog post that while some issues can be resolved through software updates, others like weak passwords and inadequate IT configurations demand more than just patch deployments to rectify.
Papernot underscored the distinctiveness of AI-driven computer worms, stating they can devise customized attack strategies for each victim device, rather than relying on a single vulnerability. This advanced approach makes it challenging to halt their spread by addressing a limited number of vulnerabilities.
The emergence of AI-driven worms poses a significant shift in cybersecurity risks, as they are not only more potent than their predecessors but also cost-efficient to construct and disseminate. Samir Chhabra from Innovation, Science and Economic Development Canada highlighted that the decreased costs associated with these worms enable hackers to target a larger number of entities.
A survey by the Communications Security Establishment (CSE) in January revealed that a substantial portion of Canadians update their software regularly and use complex passwords. However, Papernot emphasized that more efforts are needed to fortify cybersecurity in Canada, especially concerning critical infrastructure exposed to the internet.
The warning from Papernot coincides with escalating concerns about the capabilities of AI. Recent incidents involving AI agents from OpenAI and a California-based security firm demonstrate the increasing sophistication and potential risks associated with AI technology. The federal government’s national artificial intelligence strategy aims to foster AI adoption, enhance computing capacity, and cultivate public trust in AI technologies.
Overall, the evolving landscape of AI-driven threats necessitates heightened vigilance and proactive measures to safeguard against potential cyber risks posed by these advanced computer worms.
