메뉴
HN
Hacker News 56일 전

토론토 대학 연구진, 모든 온라인 기기를 노릴 수 있는 AI 웜 공개

IMP
9/10
핵심 요약

토론토 대학교 연구진이 공개된 무료 AI 모델을 악용해 감염된 기기의 취약점을 스스로 학습하고 공격 전략을 수정하며 확산하는 '자가 적응형 AI 웜'을 시연했습니다. 이 악성코드는 네트워크를 장악해 사실상 무료로 정교한 해킹 공격을 감행할 수 있으며, 현재 사이버 보안 체계로는 이를 방어할 적절한 대비가 부족한 상태입니다. 연구진은 악의적인 해커들보다 먼저 위협을 파악하고 방어책을 개발하기 위해 외부와 단절된 안전한 환경에서 연구를 수행한 뒤 관계 기관과 공유하며 공개했습니다.

번역된 본문

토론토 대학(U of T) 연구진, 모든 온라인 기기를 표적으로 삼을 수 있는 AI 웜 시연

이 연구는 사이버 보안 커뮤니티가 다가오는 위협에 대비할 수 있도록 지원하기 위해 외부와 차단된 안전한 디지털 실험실에서 수행되었습니다.

연구원 니콜라스 파퍼노(Nicolas Papernot)와 그의 공동 연구진은 공개 접근 가능한 AI 모델이 기기에서 기기로 확산되면서 스스로 전략을 수정 및 적응하는 웜(Worm)을 구동하는 데 사용될 수 있음을 입증했습니다. (사진: Nick Iwanyshyn)

게재일: 2026년 6월 2일 작성자: Adina Bresge

토론토 대학교 연구진은 해커들에게 훨씬 적은 비용으로 더 큰 권한과 도달 범위를 제공하는 새로운 종류의 사이버 위협을 발견했습니다. 이 위협은 무료 AI 모델을 사용해 구축될 수 있습니다. 모든 온라인 기기가 잠재적인 표적이 될 수 있으며, 현재의 사이버 보안 방어 체계는 이에 대한 대비가 아직 갖춰지지 않은 상태입니다.

지난 6월 2일 연구 결과를 공개한 이 연구진은 공개 접근 가능한 AI 모델이 기기 간에 확산되면서 스스로 전략을 수정하는 웜(Worm)을 작동시키는 데 사용될 수 있음을 세계 최초로 입증한 것으로 알려졌습니다. 이 웜은 전체 네트워크를 장악하고 컴퓨팅 파워를 가로채 해커가 사실상 비용 없이 정교한 공격을 감행할 수 있게 합니다.

외부와 완전히 차단된 안전한 디지털 실험실에서 수행된 이번 연구는, 고도로 숙련된 해커도 실시간으로 학습, 계산 및 전략을 수정하고 시스템 전체에 확산되면서 각 기기의 알려진 취약점을 악용할 수 있는 멀웨어(Malware)를 배포하는 데 최첨단 AI나 막대한 자본이 필요하지 않다는 사실을 보여줍니다.

이러한 발견은 금융 시스템부터 병원, 핵심 서비스를 지탱하는 네트워크에 이르기까지 우리의 상호 연결된 세계의 보안에 대한 깊은 우려를 낳고 있습니다.

토론토 대학에 위치한 그의 CleverHans Lab과 Vector Institute(캐나다 CIFAR AI 의장을 역임 중)의 연구진들과 함께 이 연구를 수행한 니콜라스 파퍼노는 “악의적인 행위자가 스스로 이 위협을 깨닫기 전에 통제되고 학술적인 환경에서 이 위협을 이해하는 것이 우리에게 필수적이었다”고 밝혔습니다.

토론토 대학교 응용과학공학부(컴퓨터 공학)와 예술과학부(컴퓨터 과학)의 부교수이기도 한 파퍼노는 위협 행위자를 도울 수 있는 모든 정보를 제거하기 위해 면밀한 검토를 거친 후에만 연구 결과가 공유되었으며, 이러한 노력이 비밀리에 진행되고 있다는 점은 잘 알려져 있다고 덧붙였습니다. 그는 일상적인 노트북부터 난방, 환기 및 냉방(HVAC) 시스템, 전력망에 이르기까지 광범위한 새로운 위협으로부터 연구자, 정책 입안자 및 일반 대중이 스스로를 보호할 수 있는 기회를 주기 위해 가능한 한 빨리 결과를 공개할 의무감을 느꼈다고 말했습니다.

연구진은 출판 전에 국가 과학, 안보 및 국방 기관에 연구 결과를 공유하고 정보를 책임감 있게 공개하는 방법에 대한 조언을 구했습니다.

모든 사람을 위해 AI가 책임감 있고 포용적이며 유익하도록 보장하는 데 중점을 두는 토론토 대학의 Schwartz Reisman Institute for Technology and Society의 소속 교수인 파퍼노는 “우리가 이 연구를 수행하는 이유는 우리 모두가 의존하는 디지털 생태계의 보안을 보장하고 사람들을 안전하게 지키기 위해서입니다. 이번 발견은 우리를 사이버 보안의 새로운 시대로 이끕니다.”라고 말했습니다. 그는 “위험을 이해함으로써 우리는 이제 이러한 위협을 탐지하고 방어하는 데 필요한 대응책을 개발할 수 있는 위치에 서게 되었습니다.”라고 덧붙였습니다.

과소평가된 위협 세계 최고의 사이버 보안 전문가 중 한 명인 파퍼노는 사이버 보안 커뮤니티가 아직 주목하지 않는 가장 중요한 보안 우려를 예측하는 것을 그의 연구실의 사명으로 삼았습니다.

Anthropic의 Claude Mythos와 같은 가장 강력한 AI 모델의 등장은 빅테크 기업들이 오용을 방지하기 위해 엄격한 통제를 유지하고 있음에도 불구하고 숨겨진 보안 결함을 찾아내는 전례 없는 능력에 대해 광범위한 우려를 촉발했습니다.

그러나 파퍼노의 팀은 누구나 무료로 다운로드하고 수정할 수 있는 더 작고 상대적으로 단순한 모델의 오용 가능성에 관심을 가졌습니다. 연구자와 개발자에게 가치 있지만, 이러한 '오픈 웨이트(Open-weight)' AI 모델은 안전 가드레일(Guardrail)이 제거될 수 있으며, 충분한 기술력만 있다면 악의적으로 변형될 수 있습니다.

원문 보기
원문 보기 (영어)
U of T researchers demonstrate AI worm could target any online device The research was conducted in a secure digital lab with the goal of helping the cybersecurity community prepare for an imminent threat Researcher Nicolas Papernot and his collaborators showed that publicly accessible AI models can be used to power a worm that adapts its strategy as it spreads (photo by Nick Iwanyshyn) Published: June 2, 2026 By Adina Bresge A team of researchers at the University of Toronto has discovered a new class of cyberthreat that gives hackers more power and reach at far less cost. It can be built with free AI models. Every online device is a potential target. And current cyber defences are not yet ready for it. The researchers, who released their work June 2 , are believed to be the first to show that publicly accessible AI models can be used to power a worm that adapts its strategy as it spreads from one device to the next. It can seize control of an entire network and hijack computing power to allow hackers to launch sophisticated attacks at virtually no cost. Conducted in a secure digital lab walled off from the outside world, the research shows that highly skilled hackers don’t need cutting-edge AI or deep pockets to unleash malware capable of learning, calculating and pivoting in real time – exploiting known vulnerabilities in each device as it proliferates across a system. The findings raise profound concerns about the security of our interconnected world – from financial systems to hospitals to the networks underpinning critical services. “It was imperative for us to understand this threat in a controlled, academic setting before bad actors figured it out for themselves,” says Nicolas Papernot , who authored the research alongside members of his CleverHans Lab located at U of T and the Vector Institute , where he is a Canada CIFAR (Canadian Institute for Advanced Research) AI Chair. Papernot – who is also an associate professor of computer engineering in U of T’s Faculty of Applied Science & Engineering and computer science in the Faculty of Arts & Science – added that the research was shared only after careful scrutiny to remove any information that could aid threat actors, noting it is well understood that such are efforts are underway behind closed doors. He says he felt compelled to go public as early as possible to give researchers, policymakers and the general public a chance to protect themselves against an emerging threat that stretches from everyday laptops to HVAC systems and the energy grid. Before publishing, the researchers shared their findings with national science, security and defence bodies and sought advice on how to responsibly release the information. “The reason we are doing this research is to ensure the security of the digital ecosystem we all rely on – to keep people safe. This finding catapults us into a new era of cybersecurity,” says Papernot, a faculty affiliate at U of T’s Schwartz Reisman Institute for Technology and Society , which focuses on ensuring AI is responsible, inclusive and beneficial for everyone. “By understanding the risks, we are now positioned to develop the countermeasures needed to detect and defend against threats like this.” Underestimated threats One of the world’s leading cybersecurity experts, Papernot has made it his lab’s mission to anticipate the security concerns that matter most – even the ones the cybersecurity community isn’t paying attention to yet. The rise of the most powerful AI models like Anthropic’s Claude Mythos has sparked widespread alarm over their unprecedented capacity to unearth hidden security flaws, even as big-tech players maintain tight controls to prevent misuse. Papernot’s team, however, was interested in the potential misuse of smaller, relatively simple models that anyone can download and modify for free. While valuable for researchers and developers, these “open-weight” AI models can be stripped of their safety guardrails and, with enough technical knowledge, manipulated to do harm. This risk is often downplayed on the assumption that these models lack the power to do real damage. So, Papernot’s team decided to put that assumption to the test in a safe, academic setting. Building a prototype A worm is a digital invader that crawls through a network, copying itself onto every device it touches – no clicks required and without users’ knowledge. If it takes root, it can wreak havoc across an entire system. Traditionally, this type of attack follows a fixed script programmed by a human. If it hits a defence it wasn’t programmed to crack, it fails. Cybersecurity experts know this and have built protections to contain such threats. For their AI-powered version, Papernot’s team built a proof-of-concept prototype in a secure, closed system, taking extensive precautions. Their experiments emulate the capabilities of an AI-driven worm in a simulation of dozens of interconnected devices, including laptops, printers and cameras. The researchers’ work showed that open-weight AI models could be used to engineer a far more sophisticated threat – one that can scope out each target, tailor its attacks and take over a machine before cloning itself onto the next one. The worm also gathers information as it moves deeper into a network, with every breach revealing passwords and weak points that can unlock another machine. And because it adapts, no single defence can stop it. The worm extends its reach at its victims’ expense. Once it embeds itself in a machine, the AI worm siphons processing power to fuel its reasoning and launch the next attack. This stolen compute propels its spread, essentially eliminating the cost of each new infection. “Hackers have typically had to prioritize the most high-value targets because time and computing resources were limited,” Papernot says. “But now, once a worm is launched, the cost would drop to nearly zero.” Unlike prior research on a worm that spreads itself through AI applications, the researchers’ prototype represents a threat that can operate outside AI systems to attack the underlying software, putting a much wider range of devices at risk. “Every device connected to the internet – laptops, cameras, smart thermostats and everything else – becomes a potential target, if not for the data it holds, then as a foothold to attack more valuable targets.” A new era of cyberthreat While the research demonstrates that AI worms don’t require expensive models or computing power, building one still demands technical expertise. Even so, Papernot suspects that the window for defences is rapidly closing – and that the cybersecurity world isn’t ready for what is coming. Unlike the powerful, heavily safeguarded Mythos, the prototype does not root out unknown weaknesses. But in an uncontrolled setting, the worm could gain internet access and scan and exploit warning notices about newly discovered vulnerabilities, outpacing the software patches meant to stop them. Some of these can be fixed with software updates. But others are human errors such as weak passwords and sloppy IT setups that can’t be solved by pushing out a patch. That means a hacker doesn’t need the most advanced AI models to cause unprecedented damage. “In an interconnected world, no system is immune to this threat,” Papernot says. “Sharing these findings is the first step in galvanizing researchers, industry leaders and policymakers to take action – and quickly.” Every device is a potential source of information for the next attack, so locking down your own makes the whole network tougher to crack. Papernot urges IT professionals to shore up any security settings that could leave their systems exposed. Users need to do their part, too. “Everyone has a role to play in keeping us safe,” Papernot says. That means practising good security hygiene: Keep your devices patched and up to date. Use strong passwords. Enable multifactor authentication. “We can no longer afford to hit ‘ignore’ on software upda