Researchers warn adaptive AI worms could target connected devices
University of Toronto researchers led by Nicolas Papernot say publicly available AI models can power computer worms that adapt their attacks as they move across internet-connected devices such as laptops, printers and cameras. The lab-built worm gathered information from each compromised device, using newly exposed passwords and weaknesses to look for the next target.
Papernot said the threat changes the defensive playbook because AI-driven worms can tailor strategies to each victim instead of relying on a fixed script or one vulnerability. In an uncontrolled setting, researchers warned, a worm could learn from public notices about newly discovered flaws and spread before patches are deployed.
Researchers and federal officials warned that weak passwords, reused credentials and delayed updates create openings that software patches alone cannot close. Papernot urged regular password changes, multi-factor authentication and faster patch deployment, while Samir Chhabra of Innovation, Science and Economic Development Canada said worms that steal victims’ computing power could make future attacks far cheaper.