Artificial intelligence researchers are warning the public to use strong passwords and promptly install software updates on their devices to combat “AI-driven computer worms,” a new breed of cyber-threat they say can launch custom attacks on devices, sapping processing power and information as they hunt for new victims.
In June, a University of Toronto team led by Canadian Institute for Advanced Research AI chair Nicolas Papernot announced that publicly available AI models can power a worm capable of adapting its attack on the fly as it spreads between devices connected to the internet, including laptops, printers and cameras.
The research, conducted in collaboration with the AI development hub the Vector Institute, was shared with “national science, security and defence bodies” prior to its publication, the university said.
Now Papernot, a U of T associate professor of computer engineering and computer science, is warning the public not to ignore or delay prompts to update software, and to change passwords regularly.
“We can no longer be sloppy with our cybersecurity hygiene,” he said on Thursday at a panel discussion hosted by U of T.
“We can no longer afford to reuse passwords. We have to use multi-factor authentication. We have to keep our devices up to date, and organizations have to change their processes to make sure that these software patches are deployed as quickly as possible.”
WATCH | Nicolas Papernot shares his research on AI worms:
Worms that learn
Unlike other computer viruses, worms spread from machine to machine without human intervention. The U of T researchers said the worm they created in a lab gathers information as it moves between devices. Every new breach reveals passwords and weak points that can unlock another machine.
In an uncontrolled setting, the researchers say, such a worm could gain internet access and learn from warning notices about newly discovered vulnerabilities, outpacing the software patches meant to stop them.
“Some of these [issues] can be fixed with software updates. But others are human errors such as weak passwords and sloppy IT setups that can’t be solved by pushing out a patch,” U of T wrote in a blog post about the discovery.
“That means a hacker doesn’t need the most advanced AI models to cause unprecedented damage.”
In 2017, a worm called “WannaCry” wreaked havoc across 150 countries, freezing computers and encrypting files, while demanding a ransom payment in bitcoin.
Back then, U of T said, this type of attack typically followed a “fixed script” programmed by a human that would often fail when confronted by defensive software it wasn’t designed to crack.
“The difference here is that the AI-driven computer worms are able to design attack strategies that are specific to each victim device that they interact with. So, rather than use a single vulnerability, they will work and interact with the victim device, and find an attack…
Read More: AI-driven ‘worms’ that learn on the fly are the latest potential threat to


