# Watermarking Protein Design: How AI-Generated Biology Can Be Traced Back to Its Source
## Introduction
As artificial intelligence becomes increasingly capable of designing novel proteins with therapeutic, industrial, and research applications, a critical question has emerged: how can we verify whether a given protein sequence or structure was generated by an AI model or derived from natural sources? This concern is not merely academic. AI-designed proteins are already being used in drug discovery, enzyme engineering, and synthetic biology. Without a reliable method of attribution, it becomes difficult to distinguish between naturally occurring biology and computationally designed molecules — raising issues around intellectual property, biosafety, and scientific reproducibility.
A team of researchers has developed a dual-purpose watermarking framework called SynthIDBio that addresses both protein sequence design and protein structure prediction. The system embeds imperceptible, cryptographically secured signatures into AI-generated outputs, allowing downstream users to determine whether a given protein was produced by a specific model. Two complementary approaches form the backbone of this framework: one that operates on amino acid sequences and another that works on three-dimensional atomic coordinates.
## Understanding the Challenge of Watermarking Protein Design
Watermarking in the context of protein design presents unique challenges that distinguish it from text-based AI watermarking. Large language models, which generate human-readable text, have relatively high entropy during the sampling process — meaning there are many possible next words at each step. This natural randomness provides a generous canvas for embedding a watermark without distorting the output distribution in a noticeable way.
Protein design models, however, operate under very different conditions. These models typically sample at low temperatures, which sharply limits the entropy of the generation process. At low temperatures, the model becomes highly confident in its predictions, producing sequences that closely resemble a single most-likely output. This reduced randomness makes it significantly harder to insert a detectable watermark without either distorting the output or rendering the watermark undetectable.
Furthermore, protein design involves additional downstream filtering steps. Sequences must pass quality checks related to stability, foldability, and binding affinity before they are considered viable candidates. Any watermarking scheme must survive these filters and remain detectable even after the sequences have been subjected to experimental validation.
## SynthIDBio-Sequence: Watermarking at the Amino Acid Level
### The Foundation: Tournament Sampling
The sequence-level watermarking component, SynthIDBio-sequence, builds upon ProteinMPNN, a widely used model for conditional protein sequence design. Rather than altering the model’s weights or the final output, SynthIDBio-sequence intervenes at the sampling stage — the moment when the model generates its amino acid sequence, one residue at a time.
The core mechanism is a technique called tournament sampling. At each position in the sequence, the model produces a probability distribution over the twenty standard amino acids. Tournament sampling modifies this distribution through a competitive process: multiple candidate amino acids are drawn, each is assigned a binary score (0 or 1) by a scoring function, and the candidate with the higher score wins the “tournament.” This scoring function is deterministic but secret — it depends on a cryptographic key known only to the watermark issuer.
This process is repeated across multiple layers, each using a different secret key derived from the original. With enough layers, the cumulative effect is that the final sequence carries a subtle but detectable statistical bias — a signature that aligns with the secret keys used during generation. Crucially, the distortion introduced is bounded: in expectation, the distribution of watermarked sequences does not differ from the distribution of non-watermarked sequences, preserving the scientific utility of the designed proteins.
### Two Variants: Distortionary and Non-Distortionary
To address the low-entropy challenge inherent in protein design, SynthIDBio-sequence offers two variants. The non-distortionary variant adheres strictly to the principle of expectation-preserving watermarking, making it suitable for scenarios where maintaining the original output distribution is paramount. However, in low-entropy regimes, this variant may produce a watermark signal that is too weak to detect reliably.
The distortionary variant deliberately introduces a stronger bias by increasing the number of tournament layers or reusing keys across layers. This amplifies the watermark signal at the cost of a small distributional shift. In practice, the distortionary approach can use up to twenty-five layers, all sharing the same secret key, which produces a robust and highly detectable signature. For protein design applications, this trade-off is generally acceptable: the structural and functional properties of the designed proteins remain largely unaffected, while the watermark becomes far more resilient to detection challenges.
### Integration Into the Design Pipeline
Watermarking is not applied in isolation. SynthIDBio-sequence integrates into the full protein design pipeline, which typically includes sequence generation, quality filtering, and experimental selection. A critical addition is a second-stage filter based on the watermark signal itself. After initial quality filtering removes designs that fail structural and energetic criteria, a g-value threshold is applied to ensure that only sequences carrying a sufficiently strong watermark signal pass through.
This g-value filter trades computational resources for detectability. By setting a stringent false positive rate (for example, 0.1%), the filter ensures that watermarked designs are reliably identified while non-watermarked designs are excluded — but it also means that many more candidates must be generated to produce a comparable number of final designs. The thresholds are calibrated using large reference datasets of both natural protein sequences and experimentally validated designed binders, covering sequence lengths relevant to real-world applications.
## SynthIDBio-Structure: Watermarking at the 3D Coordinate Level
While sequence watermarking addresses AI-generated amino acid chains, it does not cover protein structures predicted directly from structure prediction models. SynthIDBio-structure fills this gap by embedding watermarks into the three-dimensional atomic coordinates produced by a structure prediction model.
### Fine-Tuning the Diffusion Process
SynthIDBio-structure targets models that generate protein structures through iterative denoising — a process that starts from random noise and gradually refines it into a physically plausible three-dimensional arrangement. The key insight is that the watermark can be embedded directly into the model’s training process by fine-tuning the denoising module alongside a companion detector network.
During fine-tuning, two versions of the denoiser are used: the original, frozen model that produces standard (non-watermarked) structures, and a copy with trainable weights that learns to produce watermarked structures. The detector network is trained simultaneously to distinguish between the two, learning to recognize the subtle fingerprints left by the modified denoiser in the final coordinates.
The training objective combines two terms: the standard diffusion loss, which ensures that the watermarked model still produces accurate structures, and a watermarking loss, which forces the detector to correctly classify watermarked versus non-watermarked outputs. This dual objective ensures that the watermark is embedded without compromising the model’s primary function of predicting correct protein geometries.
### Robustness Through Transformation
Because protein structures can be represented in many equivalent ways — rotated, translated, or reflected in three-dimensional space — the watermark detector must be invariant to these transformations. The detector achieves this by operating on intra-residue features: pairwise distances between atoms within the same residue, bond angles, and torsion angles computed across sliding windows of consecutive atoms. These features depend only on the internal geometry of each residue and are therefore unaffected by rigid transformations of the whole structure.
Additionally, a small amount of uniform noise is added to the coordinates before they are fed into the detector during training. This augmentation improves robustness against perturbations that might arise from file format conversions, coordinate rounding, or minor structural adjustments — ensuring that the watermark remains detectable even after the structure has been processed through standard bioinformatics workflows.
### Practical Advantages
One of the most compelling features of SynthIDBio-structure is that the watermark is embedded during training rather than applied as a post-processing step. This means the watermark cannot be removed by simply re-running the model or applying a different decoding strategy. Once the model weights are released, the watermark is permanently baked into any structure generated by that model, providing a durable and tamper-resistant attribution mechanism.
The fine-tuning process itself is relatively efficient. Training on a modest GPU cluster for approximately one day is sufficient to achieve strong detectability, a fraction of the cost required to train the original model. Importantly, this fine-tuning introduces no additional computational overhead during inference — the model generates structures at its normal speed with no latency penalty.
## Experimental Validation
### In Vito Testing of Watermarked Protein Binders
The practical effectiveness of SynthIDBio-sequence was validated through in vitro experiments using AI-designed protein binders. Three targets were selected for testing: VEGF-A, a protein involved in angiogenesis; PD-L1, a key immune checkpoint target; and SC2RBD, the receptor-binding domain of a viral spike protein. For each target, parent sequences with experimentally measured binding affinities were used as templates, and thousands of new designs were generated through a resequencing process.
These designs were produced under three conditions: without any watermark, with a distortionary watermark, and with a non-distortionary watermark. After filtering for structural quality and binding potential, the top candidates were selected and synthesized as synthetic gene fragments. Expression in a cell-free transcription-translation system confirmed that watermarked sequences could be successfully translated into functional proteins. Binding kinetics measured using surface plasmon resonance demonstrated that the designed binders interacted with their target proteins as expected.
Crucially, the watermark remained detectable throughout this entire experimental workflow — from digital sequence generation through DNA synthesis, protein expression, and purification. The watermark signal persisted even after sequences were codon-optimized for expression, a step that could theoretically obscure subtle statistical patterns.
### Assessing Resilience Against Rewriting Attacks
A key question for any watermarking system is whether it can withstand attempts to remove the watermark. A common attack vector is resequencing — running a non-watermarked model on a known watermarked binder to generate a new sequence that retains the binding function but loses the watermark. The researchers estimated the hit rate of such attacks by combining their experimental data with historical success rates for the tested targets.
The results showed that the watermark significantly reduced the attacker’s ability to rewrite designs without leaving a trace. When combined with the g-value filtering stage, the combined defense made it substantially more difficult for an adversary to produce functional, non-watermarked designs from watermarked parents. The trade-off was a reduction in the total number of designs that passed all filters, but this was considered an acceptable cost given the security benefits.
### Detecting Watermarks in Predicted Structures
For SynthIDBio-structure, the imperceptibility of the watermark was confirmed through extensive comparison of structural features between watermarked, non-watermarked, and natural protein structures. Standard metrics such as root-mean-square deviation, local distance difference test scores, and template modeling scores showed no statistically significant differences between watermarked and non-watermarked structures. Per-residue feature distributions — including pairwise distances, backbone angles, and torsion angles — were also nearly indistinguishable, confirming that the watermark is embedded without any visible or measurable impact on the predicted structures.
## Frequently Asked Questions
### What is AI watermarking in the context of protein design?
AI watermarking in protein design refers to the embedding of a hidden, cryptographically secured signature into protein sequences or structures generated by machine learning models. This signature allows third parties to determine whether a given protein output was produced by a specific AI system, much like a digital watermark in images or text.
### Why is protein design watermarking more challenging than text watermarking?
Protein design models typically operate at low sampling temperatures, which severely limits the randomness available at each step of sequence generation. In text generation, the high entropy of language provides ample space to embed a watermark without distorting the output. In protein design, the reduced randomness means that any watermark must be carefully engineered to be both detectable and non-distorting, often requiring specialized techniques such as multi-layer tournament sampling.
### Does watermarking affect the quality or function of designed proteins?
No. Both variants of SynthIDBio-sequence are designed to preserve the statistical properties of the output distribution. Experimental validation confirmed that watermarked protein binders retained their binding affinity, expression levels, and structural quality compared to non-watermarked counterparts. Similarly, SynthIDBio-structure produces coordinates that are indistinguishable from non-watermarked predictions across all standard structural metrics.
### Can watermarks be removed once they are embedded?
For SynthIDBio-sequence, the watermark is applied at the sampling stage and is not stored in the model weights. In principle, a sufficiently motivated attacker could attempt to rewrite watermarked sequences using a non-watermarked model, though the g-value filtering stage significantly raises the bar for such attacks. For SynthIDBio-structure, the watermark is embedded directly into the model’s weights during fine-tuning, making it effectively permanent — the watermark cannot be removed without retraining or modifying the model itself.
### What happens if someone tries to forge a watermark?
The watermark relies on a secret cryptographic key known only to the issuer. Without access to this key, it is computationally infeasible to fabricate a convincing watermark signature. The tournament sampling mechanism and the detector network are designed such that false positives (non-watermarked sequences being classified as watermarked) are extremely rare when appropriate thresholds are applied.
### Is this technology intended for open-source models?
Yes. One of the design principles of SynthIDBio-structure is compatibility with open-model contexts. Because the watermark detector is trained as part of the fine-tuning process and the watermark is zero-bit (binary detection rather than message retrieval), the system does not require the model to retain a separate message-encoding capability. This makes it suitable for models that are freely shared with the research community.
### How does the g-value filter improve watermark detection?
The g-value filter acts as a second line of defense applied after standard quality filtering. It sets a threshold on the average watermark score across all sequence positions, ensuring that only sequences with a sufficiently strong signal pass through. This reduces false negatives — watermarked designs that might be missed due to low entropy or short sequence length — at the cost of requiring more candidate designs to be generated to obtain the same number of final results.
## Conclusion
The development of SynthIDBio represents a significant step toward responsible deployment of AI in protein engineering. By providing a robust, experimentally validated framework for tracing AI-generated protein sequences and structures back to their source, the system addresses growing concerns around attribution, biosafety, and intellectual property in computational biology. The dual approach — watermarking both sequences and structures — ensures broad coverage across the most commonly used AI tools in modern protein design.
The practical implications extend beyond simple detection. As AI-generated proteins increasingly enter drug development pipelines and therapeutic markets, the ability to verify their origin becomes essential for regulatory compliance, scientific transparency, and public trust. The trade-offs inherent in watermarking — modest increases in computational cost, the need for careful threshold calibration — are outweighed by the benefits of a traceable and accountable AI ecosystem for biological design.
Looking ahead, the principles established by SynthIDBio may serve as a foundation for watermarking other modalities of AI-generated biomolecular design, including nucleic acid sequences and small molecules. As generative AI continues to accelerate discovery across the life sciences, embedding trust and provenance into the outputs of these systems will remain an essential priority for researchers, regulators, and society alike.
Thank you for reading



