AI-driven computer worms that adapt attacks on the fly pose new threat, U of T research warns
University of Toronto team shows publicly available AI models can power worms that customize attacks per device—outpacing traditional patches.
The day's top stories, food & events — every morning at 7. Unsubscribe anytime.
A University of Toronto research team has demonstrated that publicly available AI models can power computer worms capable of designing custom attacks on the fly—a departure from traditional malware that relies on fixed scripts and often fails against unexpected defences.
The research, led by Nicolas Papernot, a Canadian Institute for Advanced Research AI chair and U of T associate professor of computer engineering and computer science, was conducted in collaboration with the Vector Institute. The team shared their findings with national science, security and defence bodies before publication.
Unlike the 2017 WannaCry worm, which froze computers and encrypted files across 150 countries but typically followed a pre-programmed script, AI-driven worms gather information as they move between devices and adjust their strategy accordingly. "The difference here is that the AI-driven computer worms are able to design attack strategies that are specific to each victim device that they interact with," Papernot said. "So, rather than use a single vulnerability, they will work and interact with the victim device, and find an attack strategy that's customized and tailored."
Each breach the worm encounters reveals passwords and weak points that unlock another machine. In an uncontrolled setting, the worm could gain internet access, learn from newly discovered vulnerabilities posted in warning notices, and outpace software patches meant to stop it.
Papernot emphasized that the threat is not limited to cutting-edge AI models. "The hacker doesn't need most advanced AI models to cause unprecedented damage," U of T said.
The university stressed that some vulnerabilities can be fixed with software updates, but others stem from human errors—weak passwords and sloppy IT setups—that patches cannot solve. Papernot's recommendations for users: use strong, unique passwords; enable multi-factor authentication; keep devices up to date; and for organizations, deploy software patches as quickly as possible. "We can no longer be sloppy with our cybersecurity hygiene," Papernot said at a U of T panel discussion.
Have any AI-powered worms of this type been detected in the wild, or is this research entirely laboratory-based?
What timeline does U of T estimate before such worms could realistically threaten public infrastructure or critical systems?
We'll update this story as answers emerge.
By the numbers
What makes AI-driven worms different from traditional malware like WannaCry?
AI-driven worms customize attacks for each device by gathering information as they spread, rather than following a single pre-programmed script. They can discover vulnerabilities specific to each victim and adjust their strategy accordingly, whereas the 2017 WannaCry worm used fixed attack methods across all infected machines.
Who led the University of Toronto research on AI-driven worms?
Nicolas Papernot, a Canadian Institute for Advanced Research AI chair and U of T associate professor of computer engineering and computer science, led the research in collaboration with the Vector Institute.