SlovakNews

Science & Tech · United States of America

Google DeepMind proposes watermarking system for AI-designed proteins

SynthIDBio embeds detectable signals during protein design while seeking to preserve function. Its usefulness depends on protein length, compatible design tools and secure management of detection keys.

Live Version: 1Sources: 2Perspectives: 1Updated:
Foto: Ars Technica · source

What's new

  • DeepMind researchers proposed SynthIDBio for watermarking AI-designed proteins. [s1]
  • The method was integrated into the ProteinMPNN design process. [s1]
  • Researchers reported that watermarked proteins still bound their intended targets. [s1]
  • Detection software scans complete sequences using the watermarking key. [s1]

Google’s DeepMind team has proposed a method at Google for placing detectable watermarks in AI-designed proteins without impairing their intended activity, Ars Technica reported on Sept. 30, 2026. The research presents the system, called SynthIDBio, as a possible biosecurity tool for distinguishing designs from trusted organizations during DNA-order screening.1

A signal embedded during design

Proteins are chains assembled from 20 amino acids, with their sequence influencing how they fold and function. According to Ars Technica, SynthIDBio uses a cryptographic key and the amino acids already selected for a sequence to recommend the next building block. Those recommendations collectively create a signal spread across the protein rather than placing a single identifying tag at one position.1

The researchers incorporated SynthIDBio into ProteinMPNN, an AI protein-design tool developed by the Baker Lab. ProteinMPNN places amino acids along a specified protein backbone while assessing whether the resulting sequence should remain functional. If a watermark-related suggestion is incompatible with that requirement, the design tool rejects it, according to Ars Technica.1

This arrangement is intended to give protein function priority over the watermark. The watermark therefore emerges only from suggested amino acids that ProteinMPNN accepts as compatible with the design. Google’s team used the combined system to create proteins intended to interact physically with particular natural proteins and reported that the watermarked designs bound their targets.1

How detection works

Identifying the watermark requires possession of the relevant key. Detection software examines the full amino-acid sequence and measures how frequently the choices associated with SynthIDBio appear. The result is statistical: a sequence is classified by comparing the strength of the detected pattern with a chosen cutoff.1

That statistical approach creates trade-offs. Changing the cutoff affects the rates of false positives and false negatives, Ars Technica reported. Sequence length also matters because very short proteins may contain too few watermark-related amino acids to produce an identifiable signal. The report said detection can work once a protein is sufficiently long, but the dossier provides no universal minimum length.1

The signal may also be weakened if someone attaches a watermarked sequence to an unwatermarked protein, diluting its frequency across the combined chain. In addition, not every AI protein-design package uses a process into which SynthIDBio can be inserted. The proposed method therefore does not automatically cover all proteins created with AI tools.1

A proposed aid to DNA screening

DNA synthesizers screen orders for sequences that encode potentially threatening proteins, including viral proteins and toxins. AI-designed proteins may be harder for existing screening software to assess. Ars Technica reported that the proposed watermark could allow synthesizers to recognise designs produced by trusted organizations and concentrate additional scrutiny on untrusted designs.1

The proposal is not a complete security system. Its effectiveness would depend on how cryptographic keys are issued, shared and protected, as well as whether relevant protein-design tools adopt the method. Ars Technica concluded that the approach “it doesn’t guarantee the security of DNA orders, but it simplifies the threat-screening process.” Its practical value in the form described remains unclear.1

Phys.org framed the development as an extension of the broader role of watermarks, which have been used with bank notes, fine art, digital photographs and software. Such marks can help establish authenticity and trace origin. SynthIDBio applies that general purpose to amino-acid sequences rather than to physical objects or digital media.2

Why it matters

For readers in Europe, the proposal is relevant as a potential method for helping DNA synthesizers distinguish AI-designed proteins associated with trusted sources from designs requiring closer review. It may support biosecurity screening, but the reported limitations mean it cannot by itself secure DNA orders or cover every protein-design system.12

Videos

SynthID Bio: The Invisible Signature Inside AI Generated Proteins · Binary Verse AI
From deepfakes to DNA: the science of watermarking AI · Google DeepMind

Related stories

Version history

  1. version 1 ·