Artificial intelligence experts are cautioning the public to enhance their cybersecurity practices by using robust passwords and promptly updating software on their devices to combat the emergence of “AI-driven computer worms,” a novel form of cyber-threat capable of launching tailored attacks on devices, draining processing power and extracting information as they seek out new targets.
Recently, a team from the University of Toronto, led by Nicolas Papernot, the Canadian Institute for Advanced Research AI chair, revealed that publicly accessible AI models can fuel a worm that can adjust its attack strategy in real-time as it spreads among internet-connected devices such as laptops, printers, and cameras.
The research, carried out in partnership with the Vector Institute, was shared with various national science, security, and defense entities before publication. Papernot, an associate professor at U of T specializing in computer engineering and computer science, emphasized the importance of promptly updating software and regularly changing passwords to the public during a panel discussion at the university.
Unlike traditional computer viruses, worms autonomously spread from one machine to another without human intervention. The AI-driven worm developed by the U of T researchers collects data as it traverses devices, identifying passwords and vulnerabilities that enable it to compromise additional machines. This autonomous learning capability poses a significant challenge as the worm can potentially adapt faster than software patches can be deployed to counter it.
Papernot highlighted the critical need to improve cybersecurity practices, emphasizing the importance of multi-factor authentication and timely software updates to mitigate these evolving threats. He underscored that organizations must expedite the deployment of software patches to safeguard against potential attacks.
The increasing prevalence of AI-driven worms signifies a significant shift in cybersecurity risk, as these advanced threats are not only more effective than conventional malware but also more cost-effective to develop and unleash. Samir Chhabra from Innovation, Science and Economic Development Canada noted that the minimal costs associated with deploying these worms allow hackers to target a larger number of victims efficiently.
Papernot’s research underscores the necessity of strengthening cybersecurity measures in Canada to protect critical infrastructure and sensitive systems from potential AI-driven threats. His findings stress the urgency of adopting robust cybersecurity practices to safeguard against evolving cyber threats.


