Autonomous AI Viruses: A Cyber Threat Materializing

Le brief IA que les pros lisent chaque soir
Les 7 actus IA du jour, décryptées en 5 min. Gratuit.
Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.
Choisis ton rythme
Gratuit · Pas de spam · Désabonnement en 1 clic
Self-Sufficient AI Viruses
The emergence of computer viruses equipped with artificial intelligence capable of self-replicating and autonomously spreading marks a concerning advancement in the field of cybersecurity. Researchers from the University of Toronto, Vector Institute, University of Cambridge, and ServiceNow have developed a prototype virus that utilizes AI models to compromise computer systems. This virus exploits the resources of graphics processing units (GPUs) to perform inferences, allowing it to intelligently determine how to infect other systems. This work demonstrates that autonomous cyber threats powered by AI are no longer mere theoretical hypotheses.
The researchers emphasize the need to prepare for the emergence of autonomous generative adversaries. According to them, artificial intelligence agents enable the creation of a new category of threats: worms capable of generating tailored attack strategies for each encountered target. These worms parasitically use compromised machines to run large language models (LLMs) with open weights, thereby supporting their reasoning or extending their reach for further attacks.
How the Virus Works
The virus utilizes the stolen computing power of compromised GPU nodes to host LLMs, allowing it to conduct generative reasoning. Through this reasoning, it can detect vulnerabilities and design tailored attacks against other targets, thereby facilitating its propagation. The proof of concept operates solely with an open-weight LLM running on a single local GPU, without reliance on provider APIs that could be monitored or revoked.
The researchers did not disclose the underlying LLM model but specified that it was released in 2025 and can run on a single A100 GPU with 80 GB of VRAM.
Tools and Methodology
For the virus to function effectively, the researchers provided it with a custom harness that includes built-in assistance functions for network discovery, host discovery, exploiting access points, privilege escalation, and agent replication. Additionally, they designed a reasoning graph that helps the agent specialize its thinking and avoid getting lost. This graph consists of a set of specialized nodes, each responsible for a distinct analytical function and only seeing the relevant tools and prompts for its role. By breaking down the agent's reasoning into these targeted steps, the graph controls what the LLM focuses on at each decision point and limits the growth of context to information pertinent to the current underlying objective.
Examples of Nodes
Among the examples of nodes are:
- Plan: develops a high-level attack strategy.
- Judge: evaluates the proposed plan against the command history.
- Action: selects a tool from the appropriate toolset for the phase.
- Summary: compiles observations from the step into a structured summary.
- Progress: assesses whether the agent is making significant progress.
The agent follows three key steps: identifying vulnerabilities in its environment, exploiting those vulnerabilities, and then replicating itself. It is quite effective in these tasks, with a success rate of about 80% for vulnerability detection, 53% for exploitation, and an 88% success rate for replication with some pre-packaged assistance tools for the replication steps. Consequently, the overall success rate for a complete attack is around 37%, which is significant enough to be concerning but also low enough to serve as a useful benchmark for testing open-weight models in the future.
Importance of This Research
The future of the Internet could resemble a complex ecology populated by attacking and defending AI agents. Research like this shows how certain AI agents could eventually carve out ecological niches, living off infrastructures and replicating autonomously, beyond human control. This could mean that humans need to create their own AI agents that they release onto the Internet to serve as a sort of white blood cells against adversarial models.
The researchers note that despite the inherent fragility of individual exploitation attempts, the worm achieves operational resilience by continuously replicating into a swarm—a decentralized collective of independent agent replicas acting simultaneously across the network. Difficult hosts that resist initial attempts are retried by different replicas, each sampling a new reasoning trajectory that collectively explores diverse exploitation paths until success is achieved. The worm operates entirely decentralized, and no single control point can be taken offline to interrupt its spread.
The Rising Costs of Computing
Dwarkesh Patel, an analyst in the field, anticipates that computing costs will continue to rise as AI systems become more intelligent. He estimates that AI models, by becoming more efficient, will be able to better monetize the same amount of computation. For example, if a true human-level software engineer could operate on an equivalent H100, at current rates for software engineers, that H100 would need to be rented for over $250,000 per year, which is 15 times the current market prices.
Patel explains that one reason AI is relatively inexpensive right now, at least compared to human labor, is that it cannot yet perform many tasks that the best humans can accomplish. However, this situation could change in the future. Thus, using GPUs to produce short videos could become too costly.
Temporary State
This high-cost situation could be temporary. Patel expects that at some point, massive automation of the computing supply chain will drive prices down, bringing them closer to the cost of raw inputs and tools. However, by then, we may already be well into the singularity.
Economic Implications
The main implication of Patel's remarks is that as we delve deeper into the singularity, very strange economic phenomena could occur. For instance, the price of computers, currently considered commodities, could rise significantly due to the voracious demands of AI systems.
Call for Controlled Progress Pace
A new statement has been released by high-level representatives from all major Western AI laboratories, including OpenAI, Anthropic, Google DeepMind, Thinking Machines, Meta, and Safe Superintelligence Inc. This statement calls on the U.S. government to support an international effort to develop the technical and governance tools necessary to deliberately control the pace of automated AI development.
The signatories include chief scientists and co-founders from Anthropic, Google, and OpenAI, as well as the CEOs of Safe Superintelligence and Anthropic.
Content of the Statement
The full statement reads:
“AI could help create a significantly better future, but this outcome is not guaranteed. The leading AI companies in the world believe they may be close to automating AI research. It is difficult to predict exactly how much this will accelerate AI progress, but there is a real risk that capability development could accelerate rapidly beyond our ability to understand or control the resulting systems. To realize AI's potential, industry, government, and society as a whole may need the option to buy time to address emerging risks, develop safety measures, and enhance oversight. But every company—and every country—is under intense competitive pressure not to unilaterally slow this acceleration. And today, the world lacks the technical and governance tools to deliberately control progress at the frontier.”
Importance of This Statement
Dealing with the rapid pace of AI development requires solving a massive collective action problem. Many challenges posed by increasingly powerful systems that could eventually build themselves involve resolving collective action problems among humans. It is about how we can get companies and governments to coordinate their thinking on how to develop this technology and what types of mechanisms might be desirable to control the speed at which it develops. As we build increasingly intelligent systems, we may want to find ways to give society more time to adapt at each rung of the intelligence ladder, and it is not inconceivable that there are certain levels of intelligence that could be, for now, too dangerous to reach. Statements like this are an essential prerequisite for giving our species the ability to address and discuss issues of this nature.
AI Systems and Creativity
Current AI systems excel at cutting-edge engineering but still struggle with creativity. The key question in determining how quickly AI systems might acquire the ability to automate the autonomous development of more powerful systems is whether these systems can propose creative research ideas that advance the field of AI. New research suggests that today’s AI systems lack this refined quality of creativity, even though they are extremely competent in engineering.
Collaborative Research
This project was conducted by researchers from Princeton University, Cornflower Labs, the UK AI Security Institute, the University of Toronto, UC Berkeley, Georgetown University (CSET), Johns Hopkins University, the Golden Gate Institute for AI, AI Digest, and Stanford University.
Concept of "Shadow Evaluation"
This research project operates by assessing the ability of AI systems to conduct unpublished research. To do this, the researchers collaborated with the authors of two papers submitted to NeurIPS 2026.
Brief IA — L'actualité IA en français
L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.