Artificial intelligence experts are cautioning the public to enhance their cybersecurity practices by using strong passwords and promptly updating software on their devices to combat the emerging threat of “AI-driven computer worms.” These sophisticated cyber-threats can launch customized attacks on various internet-connected devices, such as laptops, printers, and cameras, depleting processing power and extracting information as they seek out new targets.
Research led by the University of Toronto, in collaboration with the Vector Institute, revealed that publicly available AI models can empower a worm capable of adjusting its attack strategies in real-time as it traverses through internet-connected devices. This groundbreaking discovery, shared with national science and security bodies, underscores the importance of proactive cybersecurity measures.
Nicolas Papernot, an associate professor at U of T, emphasized the critical need for individuals and organizations to prioritize cybersecurity hygiene. He stressed the significance of regularly updating software, using multi-factor authentication, and refraining from password reuse to mitigate the risk posed by AI-driven worms.
Unlike traditional computer viruses, worms autonomously spread from one machine to another without human intervention. The researchers highlighted that their experimental worm gathers intelligence as it propagates, exploiting vulnerabilities and weak passwords to infiltrate new devices. This adaptive behavior poses a significant challenge, as conventional software patches may not effectively counter these dynamic threats.
The rise of AI-driven worms signals a paradigm shift in cybersecurity risk, as they are not only more potent but also cost-effective to develop and deploy. The lower costs associated with these worms enable hackers to target a larger number of victims, utilizing stolen computing resources to launch successive attacks at minimal expense.
Papernot’s research findings underscore the pressing need to fortify cybersecurity measures in Canada, especially concerning critical infrastructure vulnerable to cyber threats. Strengthening cybersecurity practices, such as regular software updates and robust password management, is crucial to safeguarding against the evolving landscape of AI-driven cyber threats.

