Pushmeet Kohli & Jeremy Ratcliffe on watermarking proteins, function intact
Google DeepMind's SynthID hides a key-driven signal inside AI output — text, images, and, as a proof of concept, AI-designed proteins — so its AI origin can be detected by anyone holding the key.
Provenance, not a logo
A watermark is not a label stuck on top — it is a signal woven into the content itself, so you can still ask whether something came from a human or an AI model after the file has been edited.
A watermark, not the blocky logo you see on a stock photo, something far more subtle, something mathematical.
Three tests a watermark must pass
A usable watermark has to be imperceptible, robust, and scalable all at once — drop any one and people stop using it or attackers strip it out.
We need three properties. One, it should not degrade the quality otherwise basically the whole point is lost. People will not use it.
From catching fakes to signing originals
Trained detectors get worse as models get better, because the tells they relied on disappear — so the field shifted from spotting fakes after the fact to signing content at the moment it is generated.
the classifier's accuracy goes down over time as the generative AI models become better
Hide a key in the choice of words
When a model has several equally-good next words, a secret key tilts which ones it picks, and a detector holding that key later spots the pattern — even telling which model wrote the text.
if different AI models are using different keys we can sort of check whether this was generated by this model or this other model
Robustness, trained against an attacker
For images the mark is injected by one network and read by another, with an attacker in the middle cropping and distorting the image — all trained together so the signal is harder to shake off.
The watermark generator injects a very small signal which is imperceptible.
The same trick jumps to proteins
Because a protein-design model (ProteinMPNN) generates sequences much like a text model generates words, SynthID's text watermark adapts almost directly to protein sequences, while a separate method marks 3D structures by nudging atom positions.
you can introduce watermarks through the selections of individual amino acids that are likely to have both maintain the same structure and therefore have similar function
The biosecurity hole it could plug
An AI can design a sequence that looks nothing like any known pathogen yet might fold into a dangerous protein, slipping past the databases DNA-synthesis firms screen against — so a watermark could add a second check: was this order AI-made?
you can make something that in sequence space is very different than something that's present in that pathogen database but might fold into the thing that is of concern
They actually made the proteins
The watermarked proteins were built and tested in a lab, not just simulated — the binders bound at near-identical rates whether or not they carried the mark.
we made protein binders. So we made the things that stick.