# From deepfakes to DNA: the science of watermarking AI

## Executive summary

This technical deep dive explains watermarking, a mathematical technique used to establish the provenance of AI-generated content. The system, SynthID, is being rapidly adopted across multiple modalities—including text, images, video, and proteins—to combat misinformation and safeguard against the misuse of advanced AI. For build engineers, the key takeaway is the shift from simple detection to robust, scalable, and imperceptible embedding methods that maintain content quality while ensuring traceability, even through adversarial transformations.

## Key takeaways

- Watermarking for Provenance: Watermarking provides a way to prove whether content (text, image, video, or protein) originated from a human or an AI system, addressing the challenge of indistinguishable generative media. (00:34)
- Core Requirements of a Watermark: Effective watermarking requires three properties: 1) Imperceptibility (must not degrade quality); 2) Robustness (must persist even after transformations/attacks); and 3) Scalability (must work across diverse data types). (04:35)
- SynthID Bio for Biology: The technology extends to biology, allowing watermarking of AI-generated protein sequences and 3D biomolecular structures. This safeguards against the synthesis of potentially hazardous molecules. (19:28)
- Detection Mechanism: Detection is not guaranteed for all content; for instance, very short text snippets may be unwatermarkable, and detection requires the sharing of the specific key used to embed the watermark. (28:00)

## Technical details

- Text Watermarking: Text watermarking leverages the optionality inherent in Large Language Models (LLMs). Instead of changing words, the watermark embeds a pattern by biasing the selection of tokens (words) from the model's distribution, allowing detection based on the pattern of word chains. (2200)
- Image/Video Watermarking: The approach involves a neural network that subtly modifies the image to incorporate an imperceptible signal. This generator is co-trained with a detector network, ensuring the watermark remains detectable even after adversarial transformations (e.g., cropping, noise addition). (1516)
- Protein Watermarking (SynthID Bio): Two systems are described: 1) Synthetic Bio Structure (watermarking predicted protein structures built on AlphaFold 3), which involves subtly changing atomic positions; and 2) Synthetic Bio Sequence (watermarking the amino acid sequence itself), which involves changing the selection of individual amino acids while maintaining function. (19:28)

## Practical implications

- The technology is being adopted across the industry, with SynthID used by partners like Nvidia and OpenAI.
- Regulatory bodies, such as those in the EU, are recognizing the need for mandatory watermarking on generative content.
- The system provides an extra safeguard in the biosecurity domain, helping DNA synthesis companies detect if an order originated from an AI system, even if the sequence is designed to bypass existing hazardous material databases.

## Topics

AI Provenance, Watermarking, Bio-security, Generative AI, Deep Learning, SynthID Bio, Google DeepMind Podcast

Source: https://www.youtube.com/watch?v=HIUzrxQxTtw
