AI-based tools create security threats partly because identification has lagged behind. Biosecurity presents unique challenges because biological utility goes hand in hand with potential threats. Sophisticated tools now design proteins like plastic-digesting enzymes. However, those same tools could create toxins or alter viral proteins.
Standard DNA identification software does not pick out AI-designed proteins. Nobody has characterized them well enough to recognize them as threats yet. On Wednesday, Google's DeepMind team published a research paper offering a potential solution called protein watermarking. The system watermarks protein sequences without compromising protein function. This allows trusted researchers to identify new AI-designed proteins.
Protein chemistry complicates watermarking
Proteins consist of only 20 amino acids. Some amino acids are chemically similar while others have opposite charges. Many proteins tolerate limited sequence changes in certain regions. Other areas fail with slight deviations.
Proteins are also small compared to images. Proteins containing 500 amino acids are fairly large with limited raw material for hiding signals. It remained unclear whether Google's SynthID tech would work on proteins without rendering them inactive.

SynthIDBio steps into the design process
Google adapted its SynthID tech into a variant called SynthIDBio. The team started with ProteinMPNN, a popular AI protein design tool developed by the Baker Lab. ProteinMPNN first describes an appropriate backbone configuration. Then it places side chains one amino acid at a time.
SynthIDBio uses a cryptographic key and previous amino acid identities to suggest new ones. ProteinMPNN tests if the suggested amino acid forms a functional protein. The system incorporates watermark amino acids only when they remain consistent with protein function. The watermark distributes randomly across the entire protein length.
Read nextGoogle Releases Gemini 4 Argon Frontier Model to Close Gap With RivalsWatermarked proteins prove functional in testing
The team tested watermarked proteins by designing ones that physically interact with key natural proteins. The watermarked versions worked just fine and bound their intended targets. This suggests no serious problems for more complicated design tasks.
Google envisions the system helping DNA synthesizers screen orders. Trusted organizations could use keys to verify that unknown proteins come from trusted AI designs. This lets facilities focus resources on evaluating untrusted sources.
The research team highlighted several potential holes. The system is only as secure as the key distribution and maintenance network. Very short proteins incorporate too few watermark amino acids for identification. Users might also pad sequences with unwatermarked elements to dilute the signal.
Other AI protein design software packages do not rely on ProteinMPNN. Not everyone will be able to watermark designed proteins until Google handles other integrations. Cutoff settings for statistical watermark identification also affect false positives and false negatives.



