Artificial intelligence experts are cautioning individuals to utilize strong passwords and promptly update their device software to combat the emerging threat of “AI-driven computer worms.” These advanced cyber-threats are capable of launching tailored attacks on devices, draining resources and stealing information as they look for new targets.
Recently, researchers at the University of Toronto, in collaboration with the Vector Institute, revealed that publicly available AI models can power a worm that can dynamically adjust its attack strategy while spreading across internet-connected devices like laptops, printers, and cameras.
Nicolas Papernot, an associate professor at the University of Toronto, emphasized the importance of maintaining cybersecurity hygiene by promptly updating software and regularly changing passwords. He stressed the necessity of implementing multi-factor authentication and ensuring swift deployment of software patches by organizations.
Unlike traditional computer viruses, worms can spread autonomously from one device to another without human intervention. The AI-driven worm developed by the U of T team collects data as it traverses devices, exploiting weak points and passwords to infiltrate new machines.
Papernot highlighted the unprecedented threat posed by these AI-driven worms, which can adapt their attack strategies to each victim device they encounter. Unlike conventional attacks, these worms can learn from their interactions, making them more challenging to defend against.
The cost-effectiveness of building and deploying AI-driven worms makes them a significant cybersecurity risk. Samir Chhabra from Innovation, Science and Economic Development Canada noted that the low costs associated with these worms enable hackers to target a larger number of victims, as the compute power required for attacks is stolen from the infected devices.
A survey by the Communications Security Establishment (CSE) revealed that while a majority of respondents update their software regularly and use complex passwords, there is room for improvement in cybersecurity practices. Papernot emphasized the need for enhanced cybersecurity measures in critical infrastructure sectors to mitigate the risks posed by AI-driven threats.
