U of T researchers demonstrate AI worm could target any online device
Researcher Nicolas Papernot and his collaborators showed that publicly accessible AI models can be used to power a worm that adapts its strategy as it spreads (photo by Nick Iwanyshyn)
A team of researchers at the University of Toronto has discovered a new class of cyberthreat that gives hackers more power and reach at far less cost. It can be built with free AI models. Every online device is a potential target. And current cyber defences are not yet ready for it.
The researchers, who released their work June 2 , are believed to be the first to show that publicly accessible AI models can be used to power a worm that adapts its strategy as it spreads from one device to the next. It can seize control of an entire network and hijack computing power to allow hackers to launch sophisticated attacks at virtually no cost.
Conducted in a secure digital lab walled off from the outside world, the research shows that highly skilled hackers donβt need cutting-edge AI or deep pockets to unleash malware capable of learning, calculating and pivoting in real time β exploiting known vulnerabilities in each device as it proliferates across a system.
The findings raise profound concerns about the security of our interconnected world β from financial systems to hospitals to the networks underpinning critical services.
βIt was imperative for us to understand this threat in a controlled, academic setting before bad actors figured it out for themselves,β says Nicolas Papernot , who authored the research alongside members of his CleverHans Lab located at U of T and the Vector Institute , where he is a Canada CIFAR (Canadian Institute for Advanced Research) AI Chair.