Home · Science · Oct 1 archive
Google DeepMind Develops Watermarking Tech for AI-Designed Proteins
Confirmed
In Short: Google DeepMind has developed SynthID Bio, a watermarking technology for AI-designed proteins, which allows identification without compromising their function, according to a research paper published Wednesday.

The technology, an extension of Google's SynthID, which watermarks digital content, now applies to biological sequences. It subtly influences the selection of amino acids, the building blocks of proteins, to embed a watermark.
This development addresses the growing concern over the potential misuse of AI-designed proteins. While these proteins can be used for beneficial purposes, such as creating enzymes to digest plastics or blocking venom proteins, they could also be used to create toxins or alter viral proteins.
The current challenge lies in identifying potentially threatening proteins, as existing software cannot detect AI-generated proteins due to a lack of characterized data.
SynthID Bio was tested on protein binders, which are molecules designed to latch onto specific target proteins. The tests showed that watermarked proteins matched their unwatermarked counterparts in hit rate, binding affinity, and natural sequence diversity.
The team fine-tuned a small part of AlphaFold 3’s diffusion network to incorporate the watermarking ability into the model’s weights, ensuring the watermark does not affect the protein’s function.
Sarah Carter, a biosecurity policy expert, praised the watermarking technology, saying it empowers developers to lead on safety and helps synthesis providers streamline screening for customers who use trusted models.
James Diggans of Twist Bioscience also noted that watermarking is a promising addition to the biosecurity toolbox, potentially helping to focus resources on sequences that require closer review.
Despite these advancements, the main challenge remains making the watermark robust against deliberate tampering. Early tests on a watermarked bacteriophage genome suggest the watermark remains functional.
Google DeepMind's SynthID Bio is the first successful attempt to watermark AI-designed proteins without affecting their function, marking a significant step in biosecurity and synthetic biology.
What this adds
The technology's robustness against deliberate tampering remains a challenge.
The watermarking technology could help streamline screening processes for synthesis providers.
What's confirmed
- Google DeepMind has built SynthID Bio, a watermark for AI-designed proteins, and shown in wet-lab tests on protein binders that it leaves their function intact.
- On all three, watermarked designs matched unwatermarked versions on hit rate, binding affinity and natural sequence diversity.
What's still developing
- On Wednesday, the DeepMind team at Google published a research paper offering a potential solution: protein watermarking.
- This allows new proteins designed by trusted researchers to be identified, opening everything else up to closer scrutiny.
- We’ve developed increasingly sophisticated tools for designing proteins and seen some major successes, such as AI-designed enzymes that can digest plastics or block venom proteins.
- And the software we use to identify DNA sequences that encode potentially threatening proteins doesn’t pick out AI-designed proteins, since nobody has characterized them well enough to know that they’re threats.
- It suggests pairing the watermark with provenance metadata or central repositories of AI-generated biological data, and describes SynthID Bio as one layer next to model-level mitigations and customer vetting, each with potential gaps.
- A watermark would give screeners an automated signal that an order came from a trusted model, one with safeguards built in.
- Hit rate is the share of designs that bind their target, so a match means the watermark did not cost researchers working binders on these three targets.
- Kohli also said SynthID has already been used to watermark more than 100 billion images and videos and over 60,000 years of audio, and is used by partners including OpenAI, NVIDIA and Kakao.
- The team watermarked the genome of an Evo 2-designed bacteriophage, a virus that infects bacteria, and early testing in bacterial cultures suggests the watermarked phages remain functional.
- Unlike a watermark on a picture, though, a biological watermark has to survive inside a physical molecule that must fold, bind and behave exactly as its unmarked equivalent would.
- Image: Generated via ChatGPT Google DeepMind has found a way to stamp a secret signature into AI-designed proteins, and the proteins still do their jobs.
- Laboratory tests found that watermarked protein binders retained their function, while the structural approach largely preserved prediction accuracy.
