For Nicolas Papernot (ECE), the secret to strengthening cybersecurity in the age of AI is transparency — sharing information about threats and allowing researchers to probe these systems before attackers do.
He practises what he preaches. Papernot, an associate professor of electrical and computer engineering at the University of Toronto’s Faculty of Applied Science & Engineering and a faculty affiliate at the Schwartz Reisman Institute for Technology and Society, drew global headlines in June when his lab demonstrated how to use free models to build an AI-powered worm that adapts its strategy as it spreads from one device to the next, taking over machines and stealing their computing power along the way.
After careful review, Papernot’s team decided to go public with their findings to give defenders a head start to build safeguards against such threats, which are believed to be in development behind closed doors.
Papernot — who is also a faculty member at the Vector Institute, where he holds a Canada CIFAR AI Chair — will discuss what AI-powered threats mean for critical infrastructure, the economy and national security at a Schwartz Reisman Institute event on Sept. 10, which will be livestreamed on YouTube.
He spoke to U of T News reporter Adina Bresge ahead of the talk about the state of cybersecurity, the role universities can play and how everyday users can protect themselves.
How worried should we be about cybersecurity in the age of AI?
We should be concerned, but not just because AI suddenly created an entirely new class of threats. What AI is really doing is exposing how weak our existing cybersecurity already is.
Right now, we live in a precarious balance between attackers and defenders. Systems are protected just enough that it’s not always worth it for attackers to target them. But with AI, the cost of mounting an attack drops dramatically, and that balance starts to tip.
The upside is that we already know many of the steps we need to take. It would actually be easier to invest in basic cybersecurity — things like stronger authentication and better protection of critical systems — than to hope a super-sophisticated AI defence system will magically fix everything for us.
Why do you place such an emphasis on transparency in AI?
People often describe AI as a “black box,” and that’s part of the problem. If nobody outside a company can see what these systems are doing, it’s very hard to tell whether they’re safe.
In an ideal world, we wouldn’t need to take companies at their word. They’d show us evidence of how their systems work and what data they use. There are methods — like cryptography — that would allow them to do that without revealing trade secrets, but right now, they’re too expensive to implement at scale.
That leaves us in a situation where we’re relying on trust instead of proof. Transparency is how we bridge that gap: independent evaluations, clearer testing methods and more openness about how models are built and deployed.
How can universities help solve this problem?
Universities are well positioned to act as a transparency bridge between companies, governments and the public.
We already operate under strict ethical and security guidelines, and our work is designed to be publicly shared and scrutinized. That makes universities a natural place to test powerful AI systems in contained environments, stress-test their safeguards and report honestly on what we find.
That independence benefits everyone. Companies gain credibility that is hard to achieve on their own. Governments can rely on the findings without raising concerns about interference. And the public knows these systems have been tested by experts with no stake in the results.
The goal isn’t to criticize anyone. It’s to help everyone understand the risks and how to manage them. We often hear promises about how AI is going to cure diseases or solve climate change if we just make it powerful enough. But we may never reach that optimistic future if, along the way, we suffer major security failures and large-scale attacks.
A prosperous AI future is a safe AI future. Strengthening cybersecurity isn’t an obstacle to progress — it’s what allows us to roll out AI systems widely and responsibly, so they can actually deliver the benefits we’re hoping for.
How are the risks your research highlighted playing out in the real world?
We’re seeing that some companies are running extremely powerful models with surprisingly weak safety measures around them. These companies should adopt today’s cybersecurity practices to contain their experiments appropriately, even if it comes at the cost of decreased model performance.
Our team — Jonas Guan, Tom Blanchard, Hanna Foerster, Hengrui Jia and Gabriel Huang — built an AI-powered worm in a controlled environment to study how an autonomous system might move across a network and what it takes to keep one in check. That work showed us where things could go wrong if you weren’t careful. We’ve now seen it happen.
I wouldn’t say we had a crystal ball. But it does show the value of doing this kind of work at universities. By building and containing these systems carefully, we can find weak points and tell companies and regulators where to strengthen their defences — before something goes wrong.
How can people protect themselves today?
The cybersecurity hygiene we’ve been talking about for years matters more than ever — and we can’t afford to put it off. Strong passwords, multi-factor authentication and up-to-date software are still your first line of defence.
What’s changed is we’re giving AI tools a lot of control over our digital lives, and we don’t always know what they’ll do with it. We have to think carefully about what we’re handing over, and how that information can be passed between tools. If you give an AI agent access to your email and your calendar, for example, there’s nothing to stop it from pulling a private message about your manager and attaching it to the invite for your next one-on-one.
On top of that, attackers can manipulate AI systems to act against you. An AI agent reading your email can’t always tell the difference between a message from a colleague and malicious instructions that someone planted inside it. That command could tell the agent to comb through your inbox and send what it finds to your contact list.
Once you’ve given that access, you can’t really take it back. So be cautious about which AI tools you use, what you share with them and what other services you let them control.
A team of researchers from U of T Engineering has created a new type of dye-sensitized nanoparticle that can detect target chemicals at very low concentrations, while also distinguishing between molecules with very similar shapes.
When bound to their target molecules, the nanoparticles absorb light in the form of low-energy photons and use it to emit a high-energy photon. This chemical sensing ability could help pharmaceutical manufacturers detect impurities or enable researchers to find tiny traces of chemical pollutants in groundwater.
“Organic molecules called flurophores have been used for decades to absorb light and convert it into colorful emissions, but the process only works in one direction,” says Professor Kai Huang (MSE), senior author on a paper published in Journal of the American Chemical Society that describes the new particles.
“With fluorophores, the excitation frequency has to be higher than the emission frequency, which means that they convert high-energy photons into low-energy photons. What makes our dye-sensitized nanoparticles special is that they are capable of upconversion, meaning that they can absorb light in the form of low-energy photons and emit higher-energy ones.
“For example, you could excite them with near-infrared light, which can easily be produced with low-cost lasers, and they would glow bright green in response.”

Huang says that the difference between the excitation and emission frequencies makes it easier to sort the signal from the noise.
“It’s like the difference between stargazing at night versus the daytime,” he says.
“The stars shine the same brightness all the time, but during the day the sun is so powerful that it overwhelms them. Shifting the excitation frequency lower produces zero-autofluorescence background in the samples you are analyzing, while the luminescent nanoprobes keep shining; it is like turning off the sun, so you can see the stars better.”
In the nanoparticles, the upconversion is made possible by ions of ytterbium and erbium, part of the chemical family of elements known lanthanides.
Previously, the typical approach to making these chemical-sensing agents resulted in nanoparticles shaped like flat hexagons. In these particles, ytterbium and erbium ions were embedded in a host matrix made of sodium, yttrium and fluorine, like chocolate chips in a cookie. The dyes are organic molecules coated on the outside, analogous to the icing.
When infrared light is shined on the particles, the dyes absorb the light energy and pass it on to the ytterbium ions, which act as an energy relay to pass it on to the erbium ions. The erbium ions do the upconversion, with the energy then getting re-emitted as green light.
“But there’s a problem: if you pack the ytterbium atoms in too densely, they start to absorb not only the energy coming in, but also the energy coming out,” says Jiaze Wu, a PhD student in Huang’s lab and lead author on the new paper.
“This is called back-energy transfer: it means that the energy that would have been emitted by the erbium ions as green light instead gets bounced back to the ytterbium relay and never reaches the surface.”
Wu, Huang and the team overcame this trade-off by changing the recipe. Instead of using sodium, yttrium and fluorine for the host matrix, they design a new matrix made of lithium, lutetium and fluorine.
They also altered the shape of the particles, from flat hexagons to a more diamond-shaped 3D structure, and gave them multiple layers: a dense core, surrounded by an inner shell, which in turn is surrounded by an outer shell.

“We were able to create nice gradient: the concentration of embedded ytterbium ions gets denser as you go through each layer, with the core being the most dense,” says Wu.
“This arrangement enabled us to pack in much more ytterbium. In our particles, the light energy coming in flows almost entirely in one direction, inward toward the erbium ions.”
These design changes were not simply lucky guesses; the team arrived at them after doing extensive computer simulations. In this way, they were able to virtually test out dozens of formulations and geometries before actually manufacturing the nanoparticles in the lab.
“We used Monte Carlo simulations and density functional theory to simulate how the energy would interact between different parts of the nanoparticle, right down to the atomic or even subatomic level,” says undergraduate student Weixiang Ben (Year 3 MSE), who led the computational work.
“That’s how we showed that this core-shell-shell structure could actually function as a one-directional energy tunnel for incoming light.”
Wu says that the new nanoparticles are much brighter than what came before; he estimates that the light being emitted is roughly 150 times brighter than upconversion nanoparticles that haven’t been dye-sensitized, and about 50 times brighter than some of the most optimized conventional structures previously reported under same excitation condition.
This high sensitivity enables the nanoparticles to detect target molecules at very low concentrations — even a small number of bonded nanoparticles will glow brightly enough to be detected.
They are also able to easily distinguish between molecules that are structural isomers of each other, that is, that they are made of the exact same set of atoms, but arranged slightly differently.
“Let’s say you’re making a drug molecule, and your manufacturing process works fine, except that 10% of the batch is the wrong structural isomer,” says Wu.
“That’s a huge problem: it can make the drug less effective, or worse, lead to side effects that you definitely don’t want. The current process for detecting this relies on very expensive analytical tests, but with these nanoparticles, you could do it using low-cost lasers and a very small sample.”
Huang says that the next step toward commercial development will be work out a technique for mass-producing the nanoparticles.
“We’re working on this already, in fact. We think it’s feasible, but it requires a very long roadmap,” says Huang.
“In the meantime, this model serves as proof-of-concept; with this technique, we can produce a very high-performance upconversion nanoparticle that could be customized to any molecule you might want to detect. That’s something entirely new.”
University Professor Elizabeth Edwards (ChemE) is the 2026 recipient of the Royal Society of Canada’s Miroslaw Romanowski Medal, for scientific work related to environmental problems. The medal is awarded for significant contributions to the resolution of scientific aspects of environmental issues or for important improvements to the quality of an ecosystem brought about by scientific means.
Throughout her career, Edwards has conducted groundbreaking research on the remediation of contaminated groundwater, wastewater treatment and anaerobic digestion. Perhaps her most significant contribution is her work on anaerobic bioremediation of pollutants. Edwards demonstrated that certain petroleum hydrocarbons and common chlorinated industrial solvents can be degraded by microbes in oxygen-free (anaerobic) environments. Her documentation of anaerobic degradation of benzene in sediment from sites across North America made it possible for government bodies to accept this method as a tool to manage benzene contamination in groundwater, leading to enormous cost and time savings over previous methods.
One of the microbial cultures developed by the Edwards lab, called KB-1, is dominated by unusual bacteria that are very effective at dechlorinating chlorinated solvents, among the most prevalent contaminants in groundwater. KB-1 proved capable of complete dechlorination of chlorinated ethenes without the accumulation of the carcinogenic byproduct vinyl chloride. This discovery led to the further scale up and commercialization of KB-1 and the founding of a spin-off company, SIREM, in 2002, with her partners at Geosyntec consultants. KB-1 and derivative cultures developed through SiREM and the Edwards lab have now been used at more than 900 sites worldwide.
Edwards has directed several large multidisciplinary research networks focusing on microbes and enzymes to address a variety of challenges, from waste-to-energy to renewable plastics to biomining. Most notably, she served as founding director of BioZone, a major research centre at U of T fostering open collaboration between academia and industry to tackle environmental challenges at the interface of biology and engineering. It has a strong mandate to promote research excellence and transparency, equity and open science.
Edwards’ research accomplishments have been recognized with many prestigious awards, including an NSERC Synergy Award for Innovation with Geosyntec Consultants, the Kalev Pugi Award from the Society of Chemical Industry Canada, and the Killam Prize in Engineering – Canada’s most prestigious engineering award. She is a fellow of the American Association for the Advancement of Science, the Canadian Academy of Engineering and the Royal Society of Canada. In 2019, she was named a University Professor, a title reserved to the top 2% of tenured faculty within the University of Toronto. In 2020, she was appointed an officer of the Order of Canada.
“Professor Edwards’ pioneering research and leadership in the field of bioremediation of contaminated groundwater has resulted in groundbreaking methods and tools for restoring this essential resource,” says Chris Yip, Dean of the Faculty of Applied Science & Engineering.
“On behalf of the faculty, my warmest congratulations to her on this well-deserved honour.”
MIE professor Mark Fox has been elected a 2026 fellow of the Royal Society of Canada (RSC). The RSC’s mission is to advance knowledge, encourage integrated interdisciplinary understanding and address issues that are critical to Canada and Canadians. Fellowship in the RSC is one of the highest honours a Canadian scholar can achieve.
Fox was one of the first researchers to explore the use of artificial intelligence in industrial systems. In his early work at Carnegie Mellon University, he developed the concept of constraint directed scheduling, which is used in many modern scheduling systems today. He also pioneered the application of artificial intelligence to project management, simulation and engineering design. In 1984, Fox co-founded Carnegie Group Inc., a software company that specialized in AI-based systems for solving engineering, manufacturing and telecommunications problems. In 1991, he joined the faculty at U of T Engineering, where he was appointed the NSERC Research Chairholder in Enterprise Integration. And in 1994, Fox co-founded Novator Systems Ltd., one of the first companies to provide outsourced software and services for the then brand-new field of online retailing.
Fox’s more recent research has focused on developing ontologies — a shared vocabulary for systems to understand, communicate and reason about data — for enterprise modelling and applying them to Smart Cities. His ontologies for the representation of municipal information and knowledge have been adopted by cities around the world and have formed the basis of several ISO/IEC Smart City data standards. Fox co-initiated, with Professor Richard Florida, the creation of the School of Cities at U of T in 2015. That same year, he was named U of T Distinguished Professor of Urban Systems Engineering.
In 2014, Fox founded the Centre for Social Services Engineering, with a mandate to apply engineering principles to the design and delivery of social services to our society’s most vulnerable. To that end, he led the development of an ontology for impact measurement of social services: the Common Impact Data Standard (CIDS). Over 800 agencies across Canada are now using CIDS to report on their impact.
Fox is a fellow of the Association for the Advancement of Artificial Intelligence (AAAI), as well as a past AAAI councilor and co-founder of the AAAI Special Interest Group in AI in Manufacturing. He was elected a fellow of the Engineering Institute of Canada (EIC) in 2009 and garnered the EIC’s CP Rail Medal in 2011. In 2019, he was named a fellow of the Institute of Electrical and Electronics Engineers.
“Professor Fox’s groundbreaking research has advanced several applications in artificial intelligence, made our cities ‘smarter’ and more livable, and enhanced the ability of various agencies to deliver key social services,” says Chris Yip, Dean of the Faculty of Applied Science & Engineering.
“On behalf of the faculty, I congratulate him on this prestigious recognition and on his exceptional contributions.”
As an undergraduate, Connor Isaac (MechE 2T5 + PEY, MIE PhD student) brought his engineering expertise back to his home community on Walpole Island First Nation — now as a graduate student, he’s exploring how to conduct similar work with First Nations across Ontario.
Isaac, who is Chippewa (Ojibwe) and Potawatomi, graduated in June and then became a direct-entry PhD student under the supervision of Professor David Sinton (MIE). He’ll be working on a project known as CANSTOREnergy, which brings together researchers from 11 Canadian universities, along with community, utility and industry partners.
Together, the team plans to re-envision energy systems and storage technologies to address the diverse needs and perspectives of urban and rural communities in Canada.
“I’ve always been interested in new forms of energy; before I went into engineering, I even considered theoretical physics so that I could work on nuclear fusion,” says Isaac.
“But it was during an NSERC-funded summer research placement in Professor Sinton’s lab, just after my third year, where I really got to dive into the details of energy research.”
In that placement, Isaac helped design a machine that focused on repeatability and small-scale fabrication of the catalyst layer for an electrolyzer, a device that uses electricity to drive forward a chemical reaction that wouldn’t happen otherwise.
By converting electricity — including that generated from solar or wind installations — into chemical fuels, electrolyzers can provide new ways to store energy for months or years at a time.
“In industry, electrolyzers are used to split water into hydrogen and oxygen, and you can later react the hydrogen in a chemical fuel cell to get the electricity back,” says Isaac.
“Professor Sinton and his team use electrolyzers to convert captured carbon into carbon-based fuels such as ethanol. You can react those chemical fuels in a fuel cell as well, but you can also feed them directly into existing devices. For example, if you make ethanol and mix it with gasoline, you can run it in a regular internal combustion engine.”
“Either way, generating your own chemical fuel that you can store in huge tanks opens up new possibilities beyond what you could get with batteries.”
Isaac’s role in the CANSTOREnergy program will attempt to address the gaps associated with talking to members of the communities about their energy needs and how these emerging technologies might apply to them. The project is placing a strong emphasis on engaging in these conversations early on, in ways that can help inform the development of the technology itself.
In his new position, Isaac will be drawing on the experience of his PEY Co-op internship. He spent 12 months working for the Walpole Island First Nation Government on a range of engineering-related issues — everything from landfill improvements to new housing builds to estimating land area required for a solar installation.
“Until now, this has been a big gap that affects a lot of engineering projects relating to First Nations,” says Isaac.
“It’s been hard to find people who understand the technical side of things, but who are also able to relate to the chiefs and councils. You can send in an engineer, but they may not really understand the local issues, or how they play out in the community. There’s been a disconnect, and so I’m hoping to kind of become that bridge.”
Isaac’s PhD will be supported by the Indigenous and Black Engineering and Technology (IBET) Momentum Fellowship, which aims to foster equitable and inclusive research environments to increase the presence of Indigenous and Black academics in STEM.
As an IBET Momentum Fellow, Isaac will receive financial support, mentorship, training and networking opportunities throughout his graduate program.
“I needed a lot of help to pay for my undergraduate degree, and while I did get funding from the government for tuition, living expenses in a costly city like Toronto was something that wasn’t really on the table,” says Isaac.
“The IBET scholarship allows me to focus more on school, as opposed to having to work part-time just to meet my daily needs.”
Isaac sees getting a PhD in engineering as one of the most powerful things he can do to strengthen communities like the one he comes from.
“I want to help as many First Nation communities as I can,” he says.
“And that’s really the scope of my PhD: going across Ontario, interviewing either the chief and council or the main technical staff, seeing what energy issues they have, what capacity they have, and kind of working from there.”
“It’s not about prescribing what they need to do, but rather about generating a large system map to understand the social, technical, and environmental needs that exist and then developing the technology with those in mind. It’s whole new approach, and I’m very excited to get started.”
Artificial intelligence (AI) scribes can reduce the time physicians spend documenting patient visits by 69.1% during simulated primary care appointments, according to new research led by LaShawn Murray (MIE PhD Candidate).
The study — published in the journal JAMIA Open, and co-authored with Professor Enid Montague (MIE) and Dr. Onil Bhattacharyya of Women’s College Hospital — involved nine physicians completing simulated patient encounters both with and without the use of AI scribes. These digital tools are capable of recording audio and using it to generate structured, regulatory-compliant clinical notes for a patient’s medical chart — the record physicians use to document their care.
The researchers used video recordings of each appointment to analyze how physicians spent their time. They found that when the scribes were in use, the doctors spent significantly less time documenting.
“We know healthcare workers are experiencing burnout, which is associated with compromised patient safety and increased potential for errors, and can contribute to physician turnover,” says Murray.
“We also know that administrative tasks contribute to said burnout, so we want to find ways to reduce that strain.”
The study is part of a multi-phase project between U of T’s Wellness and Health Enhancement Engineering Lab and the Centre for Digital Health Evaluation, Women’s College Hospital Institute for Health System Solutions and Virtual Care. The team’s previous research compared the usability and performance of six AI scribe products; only the three performing tools were then used in this subsequent study.
Without the AI scribes, physicians spent more than one-third of each simulated patient encounter on note taking. In addition to saving time during the patient interaction, Murray hopes incorporating AI will lead to more timely documentation.
“Documentation often gets delayed because there’s just so much to do and the days are so busy; this can make it less accurate,” says Murray.
“I hope with this technology we see a reduction in things like charting being done after hours or days later. That would also create a reduction in cognitive labour with physicians having to remember what happened during appointments that occurred days prior.”
Researchers also observed an unexpected change in how some physicians kept track of their thoughts during appointments where AI scribes were used. The shift in workflow highlighted the role note taking can play in diagnosis.
“The most interesting finding for me was seeing how physically creating the charts throughout the appointment prompted thinking and more clinical decision-making questions from the doctors,” says Murray.
“When the scribes were in use, we saw the adoption of scratch pads for note taking to help physicians remember to ask follow-up questions.”
With the scribes, instead of spending appointments switching between the patient and typing on the computer, physicians documented differently. Rather than charting throughout, physicians shifted toward reviewing and editing the AI-generated documentation after it had been produced. This resulted in fewer interruptions during the simulated encounters.
One of the overarching goals of the project is to generate Ontario-specific research around AI technology in healthcare as Ontario physicians operate within different privacy regulations than their U.S. counterparts, which could affect how AI scribes are integrated into clinical practice.
“When the studies were first coming out, we were seeing them come from these large U.S.-based hospital systems,” says Murray.
“So for us, it was really about focusing on the Canadian context and, even more specifically, within Ontario. It’s not to say that we were the only ones in the space, but there was a gap in the literature looking at how AI impacts primary care delivery and what that means for Canadian healthcare.”
Murray, who has been studying AI scribes since 2023, has seen changes to the technology itself, with more customizable features and better integration into existing platforms but also in the conversations around the technology’s potential. As the technology has become more widely adopted, expectations have also begun to change.
“When the technology was new, the conversation was very much that this would solve all our problems,” says Murray.
“Now that’s shifted to, ‘hey maybe this is just one piece of the overall documentation burden that we’re seeing,’ because charts are not the only administrative burden facing physicians. We’re also thinking about things like referrals, prescription orders, billing and regulatory expectations that are contributing to administrative work.”
While the study relied on simulated patient encounters, more research will be needed to understand how AI scribes perform in everyday clinical practice.
For example, as the technology is more widely adopted, Murray wants to know how receptive patients will be to the use of AI scribes in the course of their care.
“Are they appreciative of the differences in communication? Are there hesitancies in terms of being recorded and who has access to these recordings,” says Murray.
“I wonder about the impact for different patient populations as well. What happens when physicians who are almost always using AI scribes suddenly have one patient that doesn’t consent to it being used in their care? This research has opened a lot more discussions and possibilities to consider.”