Cambridge University Researchers Build AI Worm That Adapts Across Networks
Key point
Successfully demonstrated a proof-of-concept for an autonomous AI worm that formulates its own attack strategies and propagates using open-weight LLMs.
Details
Researchers from the University of Toronto, Vector Institute, and Cambridge University have successfully demonstrated a proof-of-concept (PoC) for an autonomous AI-based worm that analyzes targets and formulates attack strategies on its own, without relying on a fixed list of vulnerabilities.
This worm utilizes open-weight small language models (LLMs) running directly on infected devices. A key feature is its ability to intelligently exploit existing known vulnerabilities or misconfigurations in real-world scenarios, rather than needing to discover new zero-day vulnerabilities.
Key Features and Performance:
- Autonomous Reasoning and Response: It reads security advisories at runtime to craft exploits for the latest vulnerabilities. Upon failure, it modifies its own source code (e.g., removing IP blocklists, fixing VM detection logic) to retry the attack.
- Resource Hijacking: It seizes computational resources from GPU-equipped devices among the infected machines to run LLMs locally. For low-spec IoT devices, it routes queries to upstream GPU nodes on the network for processing.
- Experimental Results: In a test environment consisting of 33 hosts, it achieved an infection and propagation rate of approximately 62%.
Recognizing the risks associated with this technology, the researchers excluded specific operational details from the paper. They emphasized the use of AI-based automated penetration testing tools for defense, as well as network segmentation based on Zero-trust and Micro-segmentation.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.