“Experts Warn of AI-Driven Computer Worm Threat”

Artificial intelligence experts are cautioning individuals to utilize strong passwords and promptly update their software on devices to counteract the emergence of “AI-driven computer worms,” a novel type of cyber-threat capable of launching tailored attacks on devices, draining computing resources and data while searching for new targets.

A recent study by a team at the University of Toronto, led by Nicolas Papernot, the Canadian Institute for Advanced Research AI chair, disclosed that publicly accessible AI models can empower a worm that can adjust its attack strategies dynamically as it traverses various internet-connected devices like laptops, printers, and cameras.

The research, done in partnership with the Vector Institute, was shared with various national science, security, and defense entities before publication, the university confirmed.

Papernot, an associate professor of computer engineering and computer science at U of T, is urging the public to heed software update alerts and alter passwords regularly, stressing the importance of robust cybersecurity practices.

“We must no longer be lax with our cybersecurity habits,” he stated during a panel discussion at U of T. “We must refrain from reusing passwords, adopt multi-factor authentication, ensure devices are up to date, and organizations must streamline processes to swiftly deploy software patches.”

Unlike traditional computer viruses, worms propagate between machines autonomously without human intervention. The U of T researchers revealed that the worm they engineered in a controlled setting acquires data as it moves between devices, leveraging each breach to uncover passwords and vulnerabilities that can facilitate access to other machines.

In an unregulated environment, such a worm could exploit internet access to learn from alerts regarding newly identified vulnerabilities, outpacing the deployment of software patches designed to counter them.

Papernot underscored the significance of addressing human errors such as weak passwords and inadequate IT configurations, which cannot be rectified solely by issuing patches, in combating these threats.

The emergence of AI-powered computer worms represents a substantial shift in the cybersecurity landscape, as they can craft customized attack strategies for individual devices they encounter, unlike conventional attacks that follow predetermined scripts.

The advent of these AI-driven worms not only enhances their efficacy compared to predecessors but also reduces the costs associated with constructing and launching them, enabling hackers to target a broader range of victims.

A survey conducted by the Communications Security Establishment in January revealed that a significant majority of respondents regularly update their software and use complex passwords. However, there is room for improvement in terms of using unique passwords consistently, highlighting the need to bolster cybersecurity measures in Canada.

Papernot emphasized the vulnerability of critical infrastructure exposed to the internet, including power grids, hospitals, and schools, underscoring the imperative of enhancing cybersecurity practices nationwide.