{"id":711260,"date":"2026-06-03T01:58:09","date_gmt":"2026-06-03T01:58:09","guid":{"rendered":"https:\/\/www.newsbeep.com\/ca\/711260\/"},"modified":"2026-06-03T01:58:09","modified_gmt":"2026-06-03T01:58:09","slug":"u-of-t-researchers-demonstrate-ai-worm-could-target-any-online-device","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ca\/711260\/","title":{"rendered":"U of T researchers demonstrate AI worm could target any online device"},"content":{"rendered":"<p>A team of researchers at the University of Toronto has discovered a new class of cyberthreat that gives hackers more power and reach at far less cost. It can be built with free AI models. Every online device is a potential target. And current cyber defences are not yet ready for it.<\/p>\n<p>The researchers, <a href=\"https:\/\/cleverhans.io\/latest-research.html\" rel=\"nofollow noopener\" target=\"_blank\">who released their work June 2<\/a>, are believed to be the first to show that publicly accessible AI models can be used to power a worm that adapts its strategy as it spreads from one device to the next. It can seize control of an entire network and hijack computing power to allow hackers to launch sophisticated attacks at virtually no cost.<\/p>\n<p>Conducted in a secure digital lab walled off from the outside world, the research shows that highly skilled hackers don\u2019t need cutting-edge AI or deep pockets to unleash malware capable of learning, calculating and pivoting in real time \u2013 exploiting known vulnerabilities in each device as it proliferates across a system.<\/p>\n<p>The findings raise profound concerns about the security of our interconnected world \u2013 from financial systems to hospitals to the networks underpinning critical services.\u00a0<\/p>\n<p>\u201cIt was imperative for us to understand this threat in a controlled, academic setting before bad actors figured it out for themselves,\u201d says Nicolas Papernot, who authored the research alongside members of his <a href=\"https:\/\/cleverhans.io\/\" rel=\"nofollow noopener\" target=\"_blank\">CleverHans Lab<\/a> located at U of T and the <a href=\"https:\/\/vectorinstitute.ai\" rel=\"nofollow noopener\" target=\"_blank\">Vector Institute<\/a>, where he is a Canada CIFAR (Canadian Institute for Advanced Research) AI Chair. \u00a0<\/p>\n<p>Papernot \u2013 who is also an associate professor of computer engineering in U of T\u2019s Faculty of Applied Science &amp; Engineering and computer science in the Faculty of Arts &amp; Science \u2013 added that the research was shared only after careful scrutiny to remove any information that could aid threat actors, noting it is well understood that such are efforts are underway behind closed doors. He says he felt compelled to go public as early as possible to give researchers, policymakers and the general public a chance to protect themselves against an emerging threat that stretches from everyday laptops to HVAC systems and the energy grid.<\/p>\n<p>Before publishing, the researchers shared their findings with national science, security and defence bodies and sought advice on how to responsibly release the information.\u00a0<\/p>\n<p>\u201cThe reason we are doing this research is to ensure the security of the digital ecosystem we all rely on \u2013 to keep people safe. This finding catapults us into a new era of cybersecurity,\u201d says Papernot, a faculty affiliate at U of T\u2019s <a href=\"https:\/\/www.google.com\/search?client=safari&amp;rls=en&amp;q=Schwartz+Reisman+Institute+for+Technology+and+Society&amp;ie=UTF-8&amp;oe=UTF-8\" rel=\"nofollow noopener\" target=\"_blank\">Schwartz Reisman Institute for Technology and Society<\/a>, which focuses on ensuring AI is responsible, inclusive and beneficial for everyone.\u00a0<\/p>\n<p>\u201cBy understanding the risks, we are now positioned to develop the countermeasures needed to detect and defend against threats like this.\u201d\u00a0<\/p>\n<p>Underestimated threats<\/p>\n<p>One of the world\u2019s leading cybersecurity experts, Papernot has made it his lab\u2019s mission to anticipate the security concerns that matter most \u2013\u00a0even the ones the cybersecurity community isn\u2019t paying attention to yet.<\/p>\n<p>The rise of the most powerful AI models like Anthropic\u2019s Claude Mythos has sparked widespread alarm over their unprecedented capacity to unearth hidden security flaws, even as big-tech players maintain tight controls to prevent misuse.<\/p>\n<p>Papernot\u2019s team, however, was interested in the potential misuse of smaller, relatively simple models that anyone can download and modify for free. While valuable for researchers and developers,\u00a0these \u201copen-weight\u201d AI models can be stripped of their safety guardrails and, with enough technical knowledge, manipulated to do harm.<\/p>\n<p>This risk is often downplayed on the assumption that these models lack the power to do real damage. So, Papernot\u2019s team decided to put that assumption to the test in a safe, academic setting.<\/p>\n<p>Building a prototype<\/p>\n<p>A worm is a digital invader that crawls through a network, copying itself onto every device it touches \u2013 no clicks required and without users\u2019 knowledge. If it takes root, it can wreak havoc across an entire system. Traditionally, this type of attack follows a fixed script programmed by a human. If it hits a defence it wasn\u2019t programmed to crack, it fails. Cybersecurity experts know this and have built protections to contain such threats.<\/p>\n<p>For their AI-powered version, Papernot\u2019s team built a proof-of-concept prototype in a secure, closed system, taking extensive precautions. Their experiments emulate the capabilities of an AI-driven worm in a simulation of dozens of interconnected devices, including laptops, printers and cameras.\u00a0<\/p>\n<p>The researchers\u2019 work showed that open-weight AI models could be used to engineer a far more sophisticated threat \u2013 one that can scope out each target, tailor its attacks and take over a machine before cloning itself onto the next one. The worm also gathers information as it moves deeper into a network, with every breach revealing passwords and weak points that can unlock another machine. And because it adapts, no single defence can stop it.<\/p>\n<p>The worm extends its reach at its victims\u2019 expense. Once it embeds itself in a machine, the AI worm siphons processing power to fuel its reasoning and launch the next attack. This stolen compute propels its spread, essentially eliminating the cost of each new infection.\u00a0<\/p>\n<p>\u201cHackers have typically had to prioritize the most high-value targets because time and computing resources were limited,\u201d Papernot says. \u201cBut now, once a worm is launched, the cost would drop to nearly zero.\u201d<\/p>\n<p>Unlike prior research on a worm that spreads itself through AI applications, the researchers\u2019 prototype represents a threat that can operate outside AI systems to attack the underlying software, putting a much wider range of devices at risk.<\/p>\n<p>\u201cEvery device connected to the internet \u2013 laptops, cameras, smart thermostats and everything else \u2013 becomes a potential target, if not for the data it holds, then as a foothold to attack more valuable targets.\u201d<\/p>\n<p>A new era of cyberthreat<\/p>\n<p>While the research demonstrates that AI worms don\u2019t require expensive models or computing power, building one still demands technical expertise. Even so, Papernot suspects that the window for defences is rapidly closing \u2013 and that the cybersecurity world isn\u2019t ready for what is coming.<\/p>\n<p>Unlike the powerful, heavily safeguarded Mythos, the prototype does not root out unknown weaknesses. But in an uncontrolled setting, the worm could gain internet access and scan and exploit warning notices about newly discovered vulnerabilities, outpacing the software patches meant to stop them.\u00a0<\/p>\n<p>Some of these can be fixed with software updates. But others are human errors such as weak passwords and sloppy IT setups that can\u2019t be solved by pushing out a patch. That means a hacker doesn\u2019t need the most advanced AI models to cause unprecedented damage. \u00a0<\/p>\n<p>\u201cIn an interconnected world, no system is immune to this threat,\u201d Papernot says. \u201cSharing these findings is the first step in galvanizing researchers, industry leaders and policymakers to take action \u2013 and quickly.\u201d\u00a0<\/p>\n<p>Every device is a potential source of information for the next attack, so locking down your own makes the whole network tougher to crack. Papernot urges IT professionals to shore up any security settings that could leave their systems exposed. Users need to do their part, too.<\/p>\n<p>\u201cEveryone has a role to play in keeping us safe,\u201d Papernot says.<\/p>\n<p>That means practising good security hygiene: Keep your devices patched and up to date. Use strong passwords. Enable multifactor authentication.\u00a0<\/p>\n<p>\u201cWe can no longer afford to hit \u2018ignore\u2019 on software updates,\u201d he says. \u201cEvery door you close is one less way in, so it\u2019s worth taking a few minutes to reboot.\u201d<\/p>\n<p>Disclosure for defence<\/p>\n<p>For Papernot, publishing the findings is itself an act of defence that academic research is uniquely positioned to mount.<\/p>\n<p>He points to the precedent set by <a href=\"https:\/\/www.provost.utoronto.ca\/awards-funding\/university-professors\/\" rel=\"nofollow noopener\" target=\"_blank\">University Professor<\/a> Emeritus Geoffrey Hinton, who <a href=\"https:\/\/www.utoronto.ca\/news\/geoffrey-hinton-wins-nobel-prize\" rel=\"nofollow noopener\" target=\"_blank\">won a Nobel Prize<\/a> for his role in ushering in the AI revolution. \u201cGeoffrey has been vocal about the role academic research plays in shaping decision-making when it comes to regulating AI. This type of collective mobilization by academia, industry and governments is exactly what we need to address this new threat we have identified here with AI-driven computer worms.\u201d \u00a0<\/p>\n<p>It is a well-established practice in cybersecurity research to build proof-of-concept prototypes in controlled environments to better understand emerging threats and evaluate defences against them. Conducting such studies in an academic setting ensures that the research remains independent, upholds ethical and safety standards and is open to review and scrutiny, ultimately benefiting the broader community.<\/p>\n<p>Papernot credits his co-authors and collaborators Jonas Guan, Tom Blanchard, Hanna Foerster, Hengrui Jia\u00a0and Gabriel Huang\u00a0for helping bring this threat to light.<\/p>\n<p>His lab is already hard at work developing countermeasures. And he says U of T is the perfect place to do it. \u201cU of T brings the deep AI expertise, multi-disciplinary talent, safe research environment, infrastructure and institutional scale crucial to solving big problems like this,\u201d he says. \u201cAnd the solutions to this problem will involve the increased availability of open-source AI models of all sizes and transparency from the companies creating the most powerful models.\u201d\u00a0<\/p>\n<p>\u201cWe\u2019re ready to work with the rest of the world to find solutions and build a safer future.\u201d<\/p>\n<p>\u00a0<\/p>\n<p>\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"A team of researchers at the University of Toronto has discovered a new class of cyberthreat that gives&hellip;\n","protected":false},"author":2,"featured_media":711261,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[49,48,61],"class_list":["post-711260","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-ca","tag-canada","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/711260","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/comments?post=711260"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/711260\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media\/711261"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media?parent=711260"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/categories?post=711260"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/tags?post=711260"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}