Overview
- DeepMind published a proof-of-concept called SynthID Bio on Wednesday that embeds a hidden statistical signature into both amino-acid choices and predicted 3D atomic coordinates so the origin can be detected by holders of a private key.
- Laboratory tests reported by DeepMind show watermarked protein binders for VEGF-A, the SARS-CoV-2 spike RBD, and PD-L1 retained hit rates, binding affinity, and sequence diversity comparable to unwatermarked designs.
- The watermark is added during generation by nudging sequence and folding model outputs and cannot be attached after the fact, which ties provenance to the model that made the design.
- DeepMind is open-sourcing methods, in vitro data and model weights and says the approach can be integrated into DNA-synthesis screening and database submission workflows, but it cautions the technique is one layer in a broader biosecurity strategy.
- Independent experts and the paper note a key limitation: downstream redesign with other tools can obscure or remove the watermark, so work is needed to harden robustness and test genome-scale watermarking demonstrated so far in early bacteriophage culture trials.