Google DeepMind has brought its SynthID watermarking technology to synthetic biology. The new tool, SynthID Bio, hides a signature in the amino acid sequence or predicted 3D structure of a protein. The lab announced it on Wednesday in a blog post and a paper in Nature.
Google DeepMind says a test can find the signature in the physical protein as well as in the digital design. In lab tests, it did not change how the proteins worked.
“SynthID Bio is an important piece of the puzzle for tracking the provenance of biological designs,” said Sarah Carter, a biosecurity policy expert at Science Policy Consulting who reviewed the work.
How the mark works
For sequences, SynthID Bio nudges the choice of amino acids. For 3D structures, it adjusts atomic coordinates.
The tool works inside ProteinMPNN, a popular protein design tool from the Baker Lab, John Timmer reported for Ars Technica. It uses a key, similar to a cryptographic key, to suggest each next amino acid. ProteinMPNN rejects any suggestion that does not fit a working protein. To detect the mark, software scans the whole sequence with the key. It measures how often the suggested amino acids appear.
The team tested binders, which are proteins built to latch onto other proteins. It designed them with AlphaProteo and a SynthID Bio version of ProteinMPNN. The tests covered three targets: VEGF-A, the SARS-CoV-2 spike protein RBD and PD-L1. The watermarked designs matched unmarked ones on hit rate, binding affinity and sequence diversity. Adaptyv Bio helped with the lab tests. In August, Anthropic said Claude had designed working binders.
For structures, SynthID Bio fine-tunes a small part of AlphaFold 3’s diffusion network. The watermark then sits in the model’s weights. Google DeepMind says AlphaFold 3 keeps its accuracy, and detection is near-perfect. In July, TNW reported that DeepMind had broken up the team behind AlphaFold.
A check on DNA orders
To make a designed protein, a lab orders DNA from a synthesis company. These companies screen orders against databases of known threats. AI can now design sequences that look little like any known hazard, Google DeepMind says. Unfamiliar orders can then need slow manual reviews. A watermark could show that an order came from a trusted model.
“For Twist, watermarking offers a promising new addition to the biosecurity toolbox that could strengthen screening, focus resources on sequences that warrant closer review and make biosecurity more efficient as AI-designed biology continues to advance,” said James Diggans, vice president of policy and biosecurity at Twist Bioscience.
Google DeepMind says the mark could also help label AI-made entries in public databases. It names the Protein Data Bank, UniProt and GenBank. OpenAI-backed Red Queen Bio is using AI to design antibodies for future viruses.
Known gaps
The team has flagged several limits, according to Ars Technica. The system is only as secure as the process that shares and stores its keys. Very short proteins may carry too few marked amino acids to detect. Fusing a marked protein with an unmarked one could dilute the signal. Detection is statistical, so the cut-off sets the rate of false positives and false negatives.
Many AI protein design tools do not use ProteinMPNN. Google DeepMind says it still needs to make the mark harder to remove on purpose.
Next, viruses that infect bacteria
Google DeepMind has also added SynthID Bio to Evo 2, a genomic model, with the Hie lab at Stanford University and Arc Institute. Together they watermarked the genome of a bacteriophage that Evo 2 designed. A bacteriophage is a virus that infects bacteria. Early tests in bacteria cultures show the watermarked phages work, the lab says. It plans to publish a technical paper.
Google DeepMind has made the code and lab data open source. It is also releasing the model weights to researchers.
SynthID in a microscopy dispute
Google’s SynthID mark for images and video is also at the centre of a separate dispute. Nikon is re-reviewing the winning video in its Small World in Motion contest, Alex Blake reported for TechRadar. The video, by Dr Ning Xu of Tsinghua University, shows airway cilia from a child with a rare genetic disorder. Its caption reads “AI-assisted in post-processing”.
Ian Donovan, a PhD student at UT Southwestern Medical Center, said he had found an embedded SynthID watermark in the video, according to TechRadar. Nikon said on LinkedIn that Xu had provided detailed technical documentation.
“AI was not used to generate the experimental movie, the cilia, or their motion,” Xu said on LinkedIn, according to TechRadar.
Xu said he had used AI to distinguish and visualise features in the reconstructed greyscale images.
Get the TNW newsletter
Get the most important tech news in your inbox each week.