Artificial intelligence experts are cautioning the public to enhance their cybersecurity measures by using robust passwords and promptly updating their device software to combat the emergence of “AI-driven computer worms.” These new cyber threats are capable of launching customized attacks on connected devices, depleting resources and stealing information as they search for new targets.
Recently, a team from the University of Toronto, led by Nicolas Papernot, the Canadian Institute for Advanced Research AI chair, revealed that publicly available AI models can fuel a worm that can adjust its attack strategy on the go while spreading across internet-connected devices like laptops, printers, and cameras. The research, done in partnership with the Vector Institute, was shared with key national bodies before publication.
Papernot, also an associate professor at U of T specializing in computer engineering and computer science, emphasized the importance of promptly updating software and regularly changing passwords to the public during a panel discussion at the university. He stressed the need for multi-factor authentication and swift deployment of software patches by organizations.
Unlike traditional computer viruses, worms move autonomously between devices without human intervention. The U of T researchers noted that the worm they developed in a controlled environment collects data as it traverses devices, exploiting new breaches to uncover passwords and vulnerabilities to access other machines. In uncontrolled scenarios, such worms could gain internet access and learn from warnings about recent vulnerabilities, surpassing efforts to patch vulnerabilities.
Papernot highlighted that these AI-driven worms can create personalized attack strategies for each device they encounter, making them more challenging to combat with conventional security measures. This approach contrasts with previous attacks that followed predefined scripts and were less adaptable to defensive software.
The cost-effectiveness of developing and deploying these AI-driven worms poses a significant cybersecurity risk, according to Papernot. Samir Chhabra from Innovation, Science and Economic Development Canada noted that the low costs associated with these worms allow hackers to target more victims efficiently, as the worm utilizes stolen computing resources, making subsequent attacks virtually cost-free.
Papernot’s research underscores the need for enhanced cybersecurity practices in Canada, especially concerning critical infrastructure exposed to the internet. The findings serve as a call to action for individuals and organizations to bolster their cybersecurity defenses to mitigate the evolving threats posed by AI-driven cyber attacks.
