Assistant Professor of HKUST, previously at Princeton, Harvard, USTC Cofounder and CEO of Scinetics AI4Science, AGI, RSI

Zaixi Zhang retweeted
Really exciting work from the DeepMind team. I work on generative biology and AI safety myself, and I have been following provenance and safeguards for biological generative models for a while. I remember reading FoldMark when it first came out in 2024, so the structural watermarking part of SynthID Bio immediately caught my attention. For anyone interested, this is the FoldMark paper I am referring to: FoldMark: Safeguarding Protein Structure Generative Models with Distributional and Evolutionary Watermarking bioRxiv: 10.1101/2024.10.23.619960 biorxiv.org/content/10.1101/… I think SynthID Bio is an important contribution, particularly in bringing watermarking to biological sequences and experimentally showing that watermarked proteins can retain biological function. This is exactly the kind of safety infrastructure generative biology will increasingly need. That said, as an outside reader, I think the comparison with prior work on structural watermarking deserves a closer look. FoldMark was publicly available in 2024 and was already explicitly formulated around watermarking protein generative models and their generated structures. It was not simply proposing provenance as a future direction. The original work developed an encoder/decoder for embedding and recovering information from protein structures, followed by fine-tuning protein generative models so that the watermark becomes integrated into the generation process. The work has also expanded substantially since then. The current FoldMark reports evaluation across models including AlphaFold3, ESMFold, RFDiffusion, and RFDiffusionAA, multi-bit watermarking up to 32 bits, user tracing at scales up to one million users, and wet-lab validation with EGFP and CRISPR-Cas13. So there is clearly substantial prior work on the structural provenance problem, even though FoldMark and SynthID Bio use different architectures and should not be treated as identical methods. The SynthID Bio paper does cite FoldMark. So, to me, this is not really a citation dispute. The more interesting scientific question is the comparison. SynthID Bio makes comparative statements around the simplicity of its structural watermarking approach and structural accuracy, but does not provide a controlled head-to-head evaluation against FoldMark. The paper also acknowledges that differentiation from structure-based watermarks such as FoldMark has not been studied. That distinction matters because the two systems are not necessarily solving the same problem under the same constraints. A zero-bit watermark answering whether an output is watermarked is fundamentally different in information capacity from a multi-bit watermark intended to identify a particular user or generation source. Likewise, comparing structural quality across different backbone models, datasets, training procedures, payloads, and false-positive thresholds makes it difficult to isolate whether an observed advantage comes from the watermarking algorithm itself or simply from the underlying experimental setup. Given that FoldMark is publicly available, I would really like to see the straightforward experiment: Same backbone. Same data. Same payload requirement. Same false-positive criterion. Same evaluation protocol. Then compare structural fidelity, detection performance, robustness, attribution capacity, and computational cost. That would make the scientific distinction between the two approaches much clearer.But precisely because this is becoming an important research direction, comparisons with prior methods should be as controlled as possible. This seems like an empirical question that should be relatively easy to settle: run both approaches under matched conditions and let the experiments show where the actual differences are. @pushmeet @GoogleDeepMind Authors of Foldmark: @ZaixiZhang @MengdiWang10 @marinkazitnik @lecong
Very happy to announce that our team @GoogleDeepmind has pushed the boundaries of generative biology, achieving the successful synthesis of AI-designed proteins that are both functional and watermarked. This proof-of-concept watermarking of the building blocks of life is enabled by SynthID Bio, our new protein watermarking method. It is designed to safeguard the new era of AI-powered generative biology and strengthen global biosecurity. You can read my thoughts here on why watermarking AI-designed proteins is an important research breakthrough: x.com/pushmeet/status/210531…
2
3
360
Zaixi Zhang retweeted
Great to see Zaixi Zhang’s @ZaixiZhang FoldMark featured alongside Google DeepMind’s SynthIDBio in Nature today @GoogleDeepMind @davidstutz92 @pushmeet . Protein provenance and attribution are quickly becoming real infrastructure questions for generative biology. Exciting to see both approaches shaping the conversation.
An innovative safeguard could help to flag proteins devised by artificial-intelligence tools such as AlphaFold, but the digital marker can be erased. go.nature.com/4iSk3j5
1
2
3
447
Zaixi Zhang retweeted
Replying to @davidstutz92
We’d welcome the opportunity to explore these questions together. If possible, a clearer head-to-head comparison with FoldMark in the paper would help readers understand the similarities and differences. We’d also be excited to collaborate with DeepMind on future DNA watermarking and related directions, building on work such as our [DNAMark](arxiv.org/abs/2509.18207).
1
1
3
191
Thank you, Prof. Zitnik, for your guidance and support! We began working on protein structure watermarking in early 2024, released the FoldMark preprint that year, and have continued refining it ever since. Beyond watermark detection, FoldMark also enables attribution to specific user IDs, with support for up to 1 million users. We’ve also extended our watermarking research to DNA and RNA, including DNAMark, published at NeurIPS 2025. It’s encouraging to see growing interest in making AI-generated biomolecules traceable!
Exciting new @GoogleDeepMind work on watermarking AI-generated proteins in a way that preserves protein function and the quality of AI designs. Enjoyed discussing watermarking and other strategies for tracking generative AI outputs in biology with @ScienceMagazine: science.org/content/article/… Also glad to see a stellar former student @ZaixiZhang discussing this work and our related approach FoldMark with @Nature
1
4
814
Read DeepMind’s SynthIDBio paper this morning and used ChatGPT to help organize a side-by-side comparison with our FoldMark, particularly the structure watermarking component. Still surprised by how FoldMark is represented. The paper explicitly states: “Finally, differentiability from other structure-based watermarks such as FoldMark¹⁵ has not been studied.” Yet it calls SynthIDBio-structure “considerably simpler” and suggests that directly fine-tuning AF3 is “key” to “state-of-the-art structural accuracy”—without reporting a direct, controlled comparison with FoldMark. FoldMark already embeds structural watermarks through model fine-tuning. At the task level, SynthIDBio-structure addresses the zero-bit special case of the broader detection-and-attribution problem covered by FoldMark. Our method supports multi-bit attribution, evaluated at up to one million users; their reported structural scheme detects watermark presence without identifying users. FoldMark paper: biorxiv.org/content/10.1101/… Github: github.com/zaixizhang/FoldMa… @GoogleDeepMind @demishassabis @pushmeet @davidstutz92
Biosecurity is one of the most urgent challenges for the AI era. Bringing SynthID to biology so AI-generated proteins can be watermarked is a critical step - and we’re open sourcing SynthID Bio tools so the research community can build on this work. Published in @Nature today, congrats to the team! nature.com/articles/s41586-0…
2
5
27
19,484
Read DeepMind’s SynthIDBio paper this morning and used ChatGPT to help organize a side-by-side comparison with our FoldMark, preprinted in 2024, particularly the structure watermarking component. Still surprised by how FoldMark is represented. The paper explicitly states: “Finally, differentiability from other structure-based watermarks such as FoldMark¹⁵ has not been studied.” Yet it calls SynthIDBio-structure “considerably simpler” and suggests that directly fine-tuning AF3 is “key” to “state-of-the-art structural accuracy”—without reporting a direct, controlled comparison with FoldMark. FoldMark already embeds structural watermarks through model fine-tuning. At the task level, SynthIDBio-structure addresses the zero-bit special case of the broader detection-and-attribution problem covered by FoldMark. Our method supports multi-bit attribution, evaluated at up to one million users; their reported structural scheme detects watermark presence without identifying users. FoldMark paper: biorxiv.org/content/10.1101/… Github: github.com/zaixizhang/FoldMa… @GoogleDeepMind @demishassabis @pushmeet @davidstutz92 @Nature
Very happy to announce that our team @GoogleDeepmind has pushed the boundaries of generative biology, achieving the successful synthesis of AI-designed proteins that are both functional and watermarked. This proof-of-concept watermarking of the building blocks of life is enabled by SynthID Bio, our new protein watermarking method. It is designed to safeguard the new era of AI-powered generative biology and strengthen global biosecurity. You can read my thoughts here on why watermarking AI-designed proteins is an important research breakthrough: x.com/pushmeet/status/210531…
3
5
23
3,337
Zaixi Zhang retweeted
DeepMind gave AI-designed proteins a “birth certificate.” But the idea of watermarking biological AI outputs did not start today. A discussion is emerging around SynthID Bio, a new Nature paper from DeepMind, and earlier work such as FoldMark that explored watermarking AI-generated protein structures two years ago. The bigger question goes beyond one paper: In the AI era, how do we preserve credit for original scientific ideas? #AI #Biology #DeepMind #Nature #AIforScience
Very happy to announce that our team @GoogleDeepmind has pushed the boundaries of generative biology, achieving the successful synthesis of AI-designed proteins that are both functional and watermarked. This proof-of-concept watermarking of the building blocks of life is enabled by SynthID Bio, our new protein watermarking method. It is designed to safeguard the new era of AI-powered generative biology and strengthen global biosecurity. You can read my thoughts here on why watermarking AI-designed proteins is an important research breakthrough: x.com/pushmeet/status/210531…
8
17
1,868
Also talked with the author of ProteinWatermark @AFISH0320 ,the sequence watermark part of the nature paper did not compare with the obvious baseline method first preprinted in 2024
1
1
62
Read DeepMind’s SynthIDBio paper this morning and used ChatGPT to help organize a side-by-side comparison with our FoldMark, preprinted in 2024, particularly the structure watermarking component. Still surprised by how FoldMark is represented. The paper explicitly states: “Finally, differentiability from other structure-based watermarks such as FoldMark¹⁵ has not been studied.” Yet it calls SynthIDBio-structure “considerably simpler” and suggests that directly fine-tuning AF3 is “key” to “state-of-the-art structural accuracy”—without reporting a direct, controlled comparison with FoldMark. FoldMark already embeds structural watermarks through model fine-tuning. At the task level, SynthIDBio-structure addresses the zero-bit special case of the broader detection-and-attribution problem covered by FoldMark. Our method supports multi-bit attribution, evaluated at up to one million users; their reported structural scheme detects watermark presence without identifying users. FoldMark paper: biorxiv.org/content/10.110… Github: github.com/zaixizhang/Fol…
1
2
261