Two Watermarks, One Protein: How DeepMind Hid a Signature Inside Both Sequence and Shape
Most watermarking lives on the surface of a file - a few altered pixels, a biased token in a sentence. SynthID Bio marks a physical molecule instead, using two separate mechanisms stacked on top of each other. For sequences, the system nudges which amino acid gets chosen at each position using a cryptographic key, while a tool called ProteinMPNN rejects any substitution that would break the fold; for structures, DeepMind fine-tuned part of AlphaFold 3's own diffusion network so the watermark is baked directly into the model's weights rather than added after the fact [1]. The method, and the validation behind it, was published as a peer-reviewed methods paper in Nature, with code and model weights open-sourced alongside it [2].
What makes this more than a lab curiosity is that DeepMind tested it on physically synthesized proteins, not simulations alone. Across three different binder targets - VEGF-A, the SARS-CoV-2 spike protein's receptor-binding domain, and PD-L1 - watermarked designs matched the hit rate, binding affinity, and natural sequence diversity of unwatermarked versions in wet-lab testing [3]. That result extends a watermarking program DeepMind has been building since 2023, when SynthID first shipped for AI-generated images before expanding into video and, by late 2024, open-sourced text watermarking [4]. The broader SynthID family has already watermarked more than 100 billion images and videos and over 60,000 years of audio, with partners including OpenAI, NVIDIA, and Kakao [5]- scale that made biology, with its much harder physics-constrained 'file format,' the obvious next target.


