Live data from Hacker News

U of T researchers demonstrate AI worm could target any online device

utoronto.ca

11–20 of 53 posts

Re: U of T researchers demonstrate AI worm could target any online device

#11
post #7

Did people doubt that this was theoretically possible? Seems self-evident to me. The interesting thing will be seeing it in the real world rather than in a controlled environment where they deliberately made all devices on the network have a known vulnerability.

There’s a difference between speculation and measurement, especially since you’d have people making arguments like saying that open models aren’t powerful/fast enough to work. Demonstrating this is a useful warning to everyone (most of the industry) who’s been slacking on internal defenses because they don’t think a well-resourced attacker will target them.

Re: U of T researchers demonstrate AI worm could target any online device

#14
post #3

The academic paper is here: https://arxiv.org/abs/2606.03811 It's not fully described how things work exactly, but apparently it does not transfer entire LLMs as part of the worm. Now that would be interesting :)

I think an approach could be to use some engineered security issue or however people build botnets, and give it some AI llm that is small and minimal but comes with instructions to download models from hugging face, and some other minimal prompts and descriptions of tools. Then it could use this to grow in infected computers and try find more capable and vulnerable computers to run better capable models and also devise some minimal communication between the different points of the botnet. Perhaps set itself a goal to dominate the biggest amount of compute and have some other goal. Would be curious to see what happens.

Re: U of T researchers demonstrate AI worm could target any online device

#15
post #10

[flagged]

Acronyms, shorthand etc. are routinely used on here to refer to US states,universities etc.

For those of us outside the US, its a minor pain of using hacker news. Interestingly, this is the first time I've heard complaint about it and its a non-US university.

Re: U of T researchers demonstrate AI worm could target any online device

#17
Next up:

Obvious pattern of using ai to replace human reasoning in a proven methodology of malware distribution, C&C, and network infiltration obviously possible, say researchers.

Researchers use AI to create the torment nexus using commodity hardware, demonstrating the very real threat that AI could enable attackers to create torment nexus nodes using commodity hardware. “It wasn’t even that hard !“ says one researcher. Firmware available to qualified researchers who pinky swear that it will not be leaked.

Researchers set fire to laboratory with gasoline, killing seven volunteer victims, demonstrating that laboratory fires are a real risk and can carry significant consequences, especially when gasoline is involved.

Just because you can, doesn’t mean you should.

Re: U of T researchers demonstrate AI worm could target any online device

#19
post #6

Earlier quoted context omitted.

In the abstract, what does it mean "the attacker's marginal cost per new infection is zero"?

If you infect a machine with GPU enough to run the localLLM needed to steal another machine, you can let it burn tokens all day for free because whoever you stole the first one from will pay the electric bill.

We're getting closer to the Matrix's "We do know it was us who blackened the skies"

Re: U of T researchers demonstrate AI worm could target any online device

#20
post #17

Next up: Obvious pattern of using ai to replace human reasoning in a proven methodology of malware distribution, C&C, and network infiltration obviously possible, say researchers. Researchers use AI to create the torment nexus using commodity hardware, demonstrating the very real threat that AI could enable attackers to create torment nexus nodes using commodity hardware. “It wasn’t even that hard !“ says one researc…

this is part of the pro-active security loop. gotta demonstrate how it can break to figure out how to defend it.

our other choice is to let someone else figure it out in relative secrecy. then theyre able to cause a bunch of damage to a wide range of systems. with no defences for it. everyone would be scrambling around figuring out how to deal with it while the damage is going on. not good.

Post reply on HN