Really exciting work from the DeepMind team. I work on generative biology and AI safety myself, and I have been following provenance and safeguards for biological generative models for a while.
I remember reading FoldMark when it first came out in 2024, so the structural watermarking part of SynthID Bio immediately caught my attention.
For anyone interested, this is the FoldMark paper I am referring to: FoldMark: Safeguarding Protein Structure Generative Models with Distributional and Evolutionary Watermarking
bioRxiv: 10.1101/2024.10.23.619960
biorxiv.org/content/10.1101/…
I think SynthID Bio is an important contribution, particularly in bringing watermarking to biological sequences and experimentally showing that watermarked proteins can retain biological function. This is exactly the kind of safety infrastructure generative biology will increasingly need.
That said, as an outside reader, I think the comparison with prior work on structural watermarking deserves a closer look.
FoldMark was publicly available in 2024 and was already explicitly formulated around watermarking protein generative models and their generated structures. It was not simply proposing provenance as a future direction. The original work developed an encoder/decoder for embedding and recovering information from protein structures, followed by fine-tuning protein generative models so that the watermark becomes integrated into the generation process.
The work has also expanded substantially since then. The current FoldMark reports evaluation across models including AlphaFold3, ESMFold, RFDiffusion, and RFDiffusionAA, multi-bit watermarking up to 32 bits, user tracing at scales up to one million users, and wet-lab validation with EGFP and CRISPR-Cas13.
So there is clearly substantial prior work on the structural provenance problem, even though FoldMark and SynthID Bio use different architectures and should not be treated as identical methods.
The SynthID Bio paper does cite FoldMark. So, to me, this is not really a citation dispute.
The more interesting scientific question is the comparison.
SynthID Bio makes comparative statements around the simplicity of its structural watermarking approach and structural accuracy, but does not provide a controlled head-to-head evaluation against FoldMark. The paper also acknowledges that differentiation from structure-based watermarks such as FoldMark has not been studied.
That distinction matters because the two systems are not necessarily solving the same problem under the same constraints.
A zero-bit watermark answering whether an output is watermarked is fundamentally different in information capacity from a multi-bit watermark intended to identify a particular user or generation source. Likewise, comparing structural quality across different backbone models, datasets, training procedures, payloads, and false-positive thresholds makes it difficult to isolate whether an observed advantage comes from the watermarking algorithm itself or simply from the underlying experimental setup.
Given that FoldMark is publicly available, I would really like to see the straightforward experiment:
Same backbone. Same data. Same payload requirement. Same false-positive criterion. Same evaluation protocol.
Then compare structural fidelity, detection performance, robustness, attribution capacity, and computational cost.
That would make the scientific distinction between the two approaches much clearer.But precisely because this is becoming an important research direction, comparisons with prior methods should be as controlled as possible.
This seems like an empirical question that should be relatively easy to settle: run both approaches under matched conditions and let the experiments show where the actual differences are.
@pushmeet @GoogleDeepMind
Authors of Foldmark:
@ZaixiZhang @MengdiWang10 @marinkazitnik @lecong
Very happy to announce that our team
@GoogleDeepmind has pushed the boundaries of generative biology, achieving the successful synthesis of AI-designed proteins that are both functional and watermarked.
This proof-of-concept watermarking of the building blocks of life is enabled by SynthID Bio, our new protein watermarking method. It is designed to safeguard the new era of AI-powered generative biology and strengthen global biosecurity.
You can read my thoughts here on why watermarking AI-designed proteins is an important research breakthrough:
x.com/pushmeet/status/210531…