Artificial intelligence experts are cautioning the public to enhance their cybersecurity practices by using strong passwords and promptly updating software on their devices to counter the threat of “AI-driven computer worms.” These new cyber-threats are capable of launching customized attacks on various internet-connected devices, such as laptops, printers, and cameras.
Researchers at the University of Toronto, led by Nicolas Papernot, the Canadian Institute for Advanced Research AI chair, recently demonstrated that publicly available AI models can fuel a worm that adapts its attack strategy as it spreads among connected devices. This research, carried out in partnership with the Vector Institute, was shared with national science, security, and defense authorities before publication.
Papernot emphasized the importance of not neglecting software updates and regularly changing passwords during a panel discussion at the University of Toronto. He stressed the necessity of using multi-factor authentication and ensuring swift deployment of software patches by organizations to enhance cybersecurity.
Unlike traditional computer viruses, worms propagate without human intervention, moving from one device to another. The AI-driven worm developed by the U of T researchers gathers information as it spreads, exploiting vulnerabilities and weak passwords to infiltrate new devices. This worm can even learn from warning alerts about security flaws, surpassing the effectiveness of conventional software patches.
Papernot warned that these AI-driven worms are not only more sophisticated but also more cost-effective to create and deploy compared to previous cyber threats. Samir Chhabra from Innovation, Science and Economic Development Canada highlighted that the low costs associated with these worms enable hackers to target more victims efficiently.
A recent survey by the Communications Security Establishment revealed that while a majority of Canadians update their software regularly and use complex passwords, there is still room for improvement in cybersecurity practices. Papernot underlined the need for stronger cybersecurity measures, especially concerning critical infrastructure vulnerable to cyber-attacks.
The emergence of AI-driven cyber threats underscores the urgency for individuals and organizations to prioritize cybersecurity hygiene to safeguard against evolving digital risks.
