#14ON THE AI 30
From deepfakes to DNA: the science of watermarking AI thumbnail

GOOGLE DEEPMIND · LATEST VIDEO

From deepfakes to DNA: the science of watermarking AI — Transcript

WATCH ON YOUTUBE 38m 6,952 words

Full Timestamped Transcript

00:00:00

Welcome back to Google DeepMind, the podcast. I'm Professor Hannah Fry. Picture the scene You are scrolling through your socials and you see some remarkable footage, the up close, slow motion eruption of a volcano or a tornado raging through a village, or perhaps some footage of a protest. I think many of us ask the same question, is that real? Was this made by a human or a machine? Well as AI gets better at generating text and images and audio and video, that is becoming one of the most challenging questions of our time.

00:00:31

Except that now the answer just got a lot more complicated. We are entering a world where AI can design biological molecules and structures that have never existed in nature before, some of which could be designed to cause harm. So how do you stop something dangerous before it gets made? Well the answer, it turns out, might be hidden in plain sight, embedded invisibly into the very thing you're looking at, or the very molecule you're about to synthesize. A watermark, not the blocky logo you see on a stock photo.

00:01:04

Something far more subtle, something mathematical. And today I am joined by two people who are working on this from different angles. Pushmeet Kohli is VP of Science at Google DeepMind and one of the architects of SynthID, the watermarking system now being adopted across the AI industry. And Jeremy Ratcliffe is a biosecurity researcher whose team has applied that same technology to biology. Welcome to the podcast, both of you. Jeremy, let's start with you watermarking anything that AI spits out, I mean, it sounds like a very good idea, but just just break it down for me. Why is this helpful?

00:01:38

So for biology, sort of the motivation for being able to do watermarking is so that we can have provenance and say specifically where did this sequence come from? And really what we're trying to differentiate is between sequences that come from things in nature versus sequences that come as products of AI systems. So specifically, the type of risks that we're thinking about in terms of AI systems is sort of an AI generated sequence that can have properties that we know to be problematic. We might not be able to identify from the sequence itself that it has these problematic properties. And what makes a good watermark, because I think when people consider the phrase, they sort of think of, I don't know, like banknotes or like passports, is there like rules for what counts as a good watermark?

00:02:18

The thing for us in particular, human imperceptibility, is one. So making it very difficult for someone to be able to tell what portion of data has been watermarked. Because otherwise it would be really easy to erase. Yeah, having high detectability. So having some system that can go through and actually identify the watermark with high confidence and then also good generalizability. So being able to have at least a watermarking method that can work across a bunch of different systems rather than having to make bespoke ones for every single data type. What do you think, Pushmeet? I mean, does that apply beyond biology and more broadly? Yeah, I think the main reason why we started the whole watermarking project at DeepMind almost eight years ago now was to give a sense of provenance to what users are seeing.

00:03:05

If you look at different modalities, whether it's text, whether it's images, whether it's videos, it was hard to imagine ten years back that we would today be talking about systems that can create images, videos, audio, text and proteins or enzymes that are indistinguishable from what a human or what exist in nature. And it's an important element for users to to give users this idea that you can really believe what you are seeing.

00:03:39

So what do we need from a watermark? We need three properties. One, it should not degrade the quality otherwise basically the whole point is lost. People will not use it. The second element is robustness against attack or against transformations. If people want to remove it, it's hard to remove in the sense that even if you make changes to the signal, it will persist. Then the third requirement is that it should be easy to use, right? It should not it should be easy to integrate in the signal, and easy to detect from the signal.

00:04:12

So those are the three sort of properties of imperceptibly, robustness and scalability that we have designed all our watermarking systems for, with the whole idea that users have more control and have a better view of what they are seeing or what they are sort of using or designing and so on. It feels like this subject of watermarking has been quite a big deal this summer, but at the same time, we're a few years into generative AI being accessible to the public. What's taken so long, Pushmeet?

00:04:47

Why is it only now that this has become so widespread? When image editing software started becoming very sophisticated, people were sort of very concerned about this issue of is this a real image or it has the, has this been tampered with? And there was a lot of work and specialized systems which could really sort of analyze an image and think and see the tiny differences that exist in a tampered image and can say, oh, yeah, this was a fake image, or this has been tampered with, and so on.

00:05:21

But as generative AI became more sophisticated, those tiny differences went away. And then that naturally sort of resulted in the question, is this game over in the sense that humans will not have the ability to detect whether something is AI generated? And this is where watermarking sort of came in. We said the way to sort of make sure that humans always have the ability to understand the origin of where some signal came from is by injecting a signal within it, having a bias so it doesn't go away.

00:06:01

Even if the models are perfect and they have the ability to sort of generate images which are indistinguishable from what a camera would observe or what a text that human would write. We specifically sort of put in some imperceptible things that can allow users to later detect that this was originated from an AI model. And when you say we here, Pushmeet, when you really do mean we in the literal sense, right? It was you was you guys that came up with a solution for this one that was was scalable.

00:06:33

Yes, so our team has been working on this for almost eight years. We we started with images because people were concerned about these images being used for fake news, misinformation and so on. And so there was that motivation to solve that problem. At the same time, although the problem is extremely challenging because of the properties we just mentioned of robustness and imperceptibly and efficiency and scalability. Still, an image is a very large amount of data.

00:07:07

A one megapixel mage has sort of a 1 million sort of numbers, or like 3 million numbers, depending on the on how it's encoded and so on to hide information. Right? And without changing the content. So we developed a watermarking systems for images first. Later on we had to look at the challenge of how do you do this for other modalities like text which are not as high dimensional as images, where actually it's a very small amount of signal, right?

00:07:40

It’s not a million numbers in a sentence, is there? Yeah, exactly. It's a few words. You can't change those sort of few words. And you have to be very cautious in terms of not changing the meaning of, of the content. And so the approaches that we developed for watermarking text were quite different and distinct from what we use for watermarking high dimensional signals like images and videos and, and audio even. But this idea of watermarking, which you guys pioneered, has now been brought into law. It's essential that any generative content within the EU has to have some sort of watermarking.

00:08:15

I think what regulators and countries around the world have recognized that they want to give users this information as to the origins of the content that they are consuming, and one sort of key technology that is seen as a robust solution for it that can scale is watermarking, which is why not only have we seen a take up of these of this idea across the industry, the fact that SynthID is used by Nvidia, is used by other partners like with OpenAI and so on.

00:08:50

It's a remarkable sort of thing that many of our partners in the generative AI space have adopted this technology. And Jeremy, in this episode, we're going to be talking about two different applications of watermarking for AI. So you've got text and video and audio and so on. And then you've also got for biological structures and sequences. Is the solution quite similar between the two? Yes, I'd say they're motivated by similar principles. And we were able to adopt a lot of the work that had already been done, including using the open source SynthID text library and just embedding that directly into another system.

00:09:25

Right. The same, not just the same tricks, but sometimes the actual same code. You can sort of pick it up and drop it? . At least start from the same code and then make some adaptations on top of it. Okay, so I think, I think people want to sort of understand how this works, because it sounds almost magical that you could have a single sentence and you have embedded some sort of watermark in there that's nothing to do with white space. That's nothing to do with like putting commas in weird hiding them in the text, but the words themselves are hiding a record of of how they were generated and where they came from.

00:09:58

So if it's okay with you, Pushmeet I thought we might just walk through how this works for text. I think that's probably the easiest one to understand. Okay, so before we get to that, there is some software out there already that you can get online that claims to be able to tell whether the text that you have is generated by AI or not. How is that different from from what you guys have created? So I think the traditional approach that has been there for a long time is to train machine learning models to solve a classification problem, to distinguish between what is generated by a model versus what was captured in the natural world.

00:10:37

And this sort of involves basically training this machine learning models over, very large amount of data, right? When the earlier generations of large language models and these conversational agents came about, you could sort of make out that, oh, this is a large language model. It has certain tells, it has It's not X, it's Y. It uses the word quietly a bit too much. Yeah, exactly. But as these models have become more and more sophisticated, those tells have become less frequent.

00:11:08

And so if you are, if you have this machine learning classifier which is trying to distinguish the classifiers accuracy goes down over time as the generative AI models become better at replicating what they are targeted to achieve. Okay. Well, let's walk through how the watermarking system works. So let's do it sort of step by step. So first off, if you could maybe we should start off by how large language models pick the next word in a sentence when it's generating text.

00:11:38

Yes. So when we are watermarking text, the idea is that these tokens or words are being generated from a large language model. And the large language model essentially has a distribution over which tokens it can or which words it can generate. So if I ask you the question, Hannah, what did you have for breakfast today? You can start with the word I, or you could start with the word Pushmeet, adressing me.

00:12:10

And these are the options that you have. And if they're equally valid starting points, you have optionality. And this is where text watermarking leverages this optionality by seeing what does the key tell us. Okay. So but that's the point right? Is that sometimes when you have an option for a word, behind the scenes, there is a secret key which says bias these words over others. And then when you look back at all of the text together, if you can see those words appearing over and over and over again, you can be confident that this is AI generated.

00:12:47

So, rather than the words. It's the patterns of those words. So those words specifically, don't need to be repeated, but the patterns is what the the detector sort of leverages. How they appear in sort of change together? Exactly. Yes. Okay. So you're you're secretly right. I mean, it's not that secret. You're sort of talking about it on a podcast, but you have some code running around in the background, some some secret key that you can then look at a chunk of text later and say, hang on a second, this looks like it was generated by AI.

00:13:19

Not only this was generated by AI, but if different AI models are using different keys, we can sort of check whether this was generated by this model or this other model. Okay, so you can tell this is Gemini, this is whatever other whatever other model might have. But if you have the key, right? If you have the key okay I see. Okay, so but if there's few words that it could be then you can't use it. So does that mean that some text is unwatermarketable?

00:13:50

Yes. So if you have a very a small a short text snippet, right? Like, what is the capital of France? It is Paris. So there is very little that we can change there. And so that will not be watermarked. That is a limitation of the watermarking approach in this case. Does all this mean then, that students can't cheat on their essays anymore? Bluntly, I mean, are we now able to just detect anything that's AI generated?

00:14:22

I think there's a whole ecosystem as a whole is moving towards watermarking, as you've seen with some of the other labs making their announcements. But that doesn't necessarily mean that they're all going to make their detectors publicly available. And even if you've got a publicly available detector, that can be motivation for people learning how to get around it in the same way that some of these machine learning classifying based detection systems, or using a whole bunch of examples of texts of things that have been watermarked were a detector publicly available, and you could just query it over and over and over again you might be able to work back to making something that gets around that specific configuration of keys that is presented in the public detector.

00:15:00

Got you. So we're not at sort of guaranteed cast iron way to detect any AI generation whatsoever is just we’re this is a big step towards that. At least not with the method of having a publicly available detection system for every version of keys that is made publicly available. Just in terms of images then, and video, is it the same idea? You have a lot more space to hide things as you describe. So I think in images the approach is different from the text watermarking approach that I was mentioning. In images what happens is we take the image which has not been watermarked, and then there is a, a neural network which looks at that image and modifies it in a very subtle way to incorporate the signal.

00:15:50

And this particular model, which is incorporating the watermark, is being cotrained with a detector neural network. And they are both sort of trying to achieve the following. You get an image which is unwatermarked, the watermark generator injects a very small signal which is imperceptible. So if it is perceptible we say that's not great, like your users will see it. And that degrades the quality of the image. Then in the middle there is an adversarial agent which is going to try to make modifications to the image, might try to shrink the image zoom in, crop it, rotate it, do many kinds of transformations like add noise and so on.

00:16:39

And then the detector has to still detect whether the original image that is coming through is watermarked or not. Okay. And both of them are trained in tandem to make sure that regardless of what the adversary in the middle has done, the water marks is still detectable. What does this mean for users then? I think the main thing is it's not just about text, it's about all these different modalities. And if you look at how people are using SynthID like, it was really amazing the last few years has SynthID has been launched, I would open my favorite news website and the reporter would say, well, here's the an image that was circulating in the media about this particular house that magically was untouched in the California, California fires, or this image that came out from the Iran war or some other sort of topic.

00:17:41

And we have run SynthID on it and detected that this was AI generated. Right. So all of a sudden, you can see the AI in places that I mean, it definitely shouldn't be, basically. Yes, and SynthID being used to actually tackle misinformation. Yeah. In real time and at scale. So then can anyone do what you just did there? Can anyone take an image, some text and video, run it through synth ID and find out whether it was generated by an AI model?

00:18:16

We have made the detection ability embedded in the Gemini app, for instance. So today if you can go to Gemini, if you ask, I'm looking at this image. Tell me if it is a generated, it can run the SynthID detector and say, yes, this this is something that was generated by a Google image model and so on. And similar sort of abilities now are available by other companies as well who have adopted our our models.

00:18:48

Can each model only detect whether it was generated by that model? Can Gemini only detect Gemini generated content? So people who are injecting the watermark into the content, they have to agree to share the key, right? If they share the keys, then we have the ability to detect it, right? So there can be a central service if you go to the SynthID portal and if you ask if something is AI generated it can look at all the keys that have been given to us by partner institutions.

00:19:21

And we can detect the AI content for all those partners as well. Okay. Got you. But if a certain lab is like doesn't want to share their key, then you wouldn't be able to? Yeah. Okay, well, Jeremy, let's talk about biology now because I know that you've come up with this proof of concept system called SynthID Bio, which instead of watermarking, you know, text and audio and video is for biology instead, where you are watermarking AI generated protein sequences and 3D biomolecular structures. Just tell me about those two systems.

00:19:53

So the release in the upcoming publication covers SynthID Bio structure, which is specifically looking at watermarking the predicted protein structure is given a sequence, so it builds on top of AlphaFold 3. The second technology is SynthID Bio Sequence, which looks at introducing watermarks into protein sequences themselves. So the strings of amino acids that are present for a sequence. So those two things are related, right, that you have like I mean, each folded protein structure is a string of amino acids. So we're basically talking about different versions maybe of the same type of data, but actually embedding the watermark is very different for the two of them.

00:20:27

So for the structure watermarking we're actually changing the positions of individual atoms. And so you can think about maybe the distance between two atoms changing slightly or the angle between two atoms changing slightly. Well for SynthID Bio Sequence, we're actually changing the selection of an individual amino acid. So for Structure it's still the same atoms. They're just maybe in a slightly different configuration. While for Sequence we're actually changing the content, but maybe not the actual functional meaning of that content. And what's the point? Why do you want it? Yeah, you know, we've thought of a couple different use cases that might be useful.

00:21:00

Being able to say that you have provenance of something being AI generated and how you might be able to detect if an order going to a DNA synthesis company is something that came from an AI system. Because I think that's something that non-biologists aren't really aware of, right, that you essentially have I'm going to call them printers. But where you can send off and say, this is the sequence that I want created and they'll do it for you. But I mean, what you're saying here is that it's possible to trick them into printing something hazardous. I'm using printed very loosely here. And that's essentially the problem, right?

00:21:31

That's the concern. Yeah. That's one of the concerns. And there's a large body of industry groups and academics who focus on how to make the screening regimen more robust, and that's something that we're interested in being able to contribute to. But the primary concern is would someone be able to acquire, DNA that could give them access to being able to generate something in a lab that we don't want them to be able to do, or maybe gets around regulation? So could someone order DNA from a company and then bring it to a laboratory and make something like an extinct pandemic, like extinct influenza, for instance.

00:22:04

Which I would say would be bad. Generally. Overall bad. Okay. And then at least then if these companies are able to detect whether something is AI, it sort of puts an extra safeguard in place, an extra sort of stop in place before they just can continue on. It's something that if you detect the watermark, you have confidence that this was derived from a system that has built in safety guardrails versus either maybe another AI model or something that comes from nature. Okay, and what kind of safety systems did those companies have in place at the moment to make sure that they're not making something really dangerous?

00:22:36

So the synthesis companies, largely what they do is they take an order from an individual where they've been able to verify something about their identity. So most of them have a process in place that says, I am an academic. This is my university affiliation. I am actually who I say I am, and the specific PO box that you're sending it to is for a laboratory. I'm not just a random person in a basement Joe Bloggs Okay. And then they take those orders and they compare the specific content of the order to a database of known hazardous things, and they check that specific submission against that database using a couple of different algorithms.

00:23:08

And if something matches, then they either just block the order and say, we can't synthesize this, or they'll go back to the original individual and try to find out what motivation they have for ordering it and whether they've got, say, requisite licensing and the risk we have with these AI systems, as shown by some other academics, is that you can make something that in sequence space is very different than something that's present in that pathogen database, but might fold into the thing that is of concern. The string of amino acids looks innocent, but once it's created, an actual protein could be really harmful. Yeah.

00:23:40

And it could have the same behavior as something that's present in the database of restricted orders And their current systems wouldn't be able to catch it. It’s definitily a concern is that and especially as these systems get better and better, you might be able to get something even further away in sequence space that might get around some of the existing protections. Something really wacky in the ribbon of amino acids that still can fold into something harmful, to like to basically sneak under their detection system. Exactly. And you can cut and paste that into another sequence. So you can imagine, like if maybe there's one portion of an order that would be blocked, you could cut and paste something of concern into that that's very far away from the restricted database.

00:24:20

And then in the laboratory yourself, you just put it back into where it originally came from. Okay, I see and then the idea of what what you're doing here with the watermarking is not necessarily to say you're going to be able to detect anything that's potentially harmful, but the very least you can say this is AI generated. Be careful, because when you're comparing it against your existing database, it might not look like something that's already on there. And you can say which system it came from. And because you as a DNA synthesis company, trust this AI system for reasons that go beyond the watermark, you can have confidence that this was generated through this method.

00:24:53

Talk me through the protein design process in here. So how do you how do you get the watermark into the system in the same way as we'd describe with text and images? So it actually, maybe somewhat fortuitous that the approach that Protein NPNN, which is this structure to sequence model uses is actually pretty analogous to the way that transformer based models generate text. So protein NPNN is a third party tool. It's not something that Google developed, it has been released out in the world for a number of years. And it's almost the opposite of AlphaFold. So rather than going from a sequence to a structure, it goes from a structure to a sequence.

00:25:24

And that's an important part in a protein design pipeline, where you are originally choosing your target based off of how you want them to interact in three dimensional space. This is a model that just takes that representation and then creates a predicted sequence in order to fold into that specific configuration. Because that's an important point, right? That you might have these extremely complex folded structures, but that each protein is constructed from like a ribbon of amino acids, a string of amino acids. And that's where the analogy comes from. String of amino acids like a string of text.

00:25:55

And so what you almost see is that the when you're folding a protein, there are locations where there can be swaps between individual amino acids, maybe ones that are similar in certain properties, like leucine and isoleucine or two that are quite similar. And so what we're taking advantage of within SynthDI Bio Sequence is that you can introduce watermarks through the selections of individual amino acids that are likely to have both maintain the same structure and therefore have similar function. But hang on, how can you be sure? I mean, you said that you could make the swap and it doesn't matter, but can you be sure that the swap doesn't matter? So that's what we specifically test in the process.

00:26:29

So the whole idea of this research was to inject the watermark and ensure that the generated sequence amino acid sequence in this case that builds the protein, has the same function or retains the function that it, that we were trying to design for. And that's what is very cool about it that we have now in existence, watermarked proteins, these are real things. This is not in simulation.

00:27:00

These are real things which do stuff, but which are watermarked and will always be detectable. And importantly, from our own laboratory experiments, they don't change the function at all. So we made protein binders. So we made the things that stick. Oh you physically made them. Yes. We test them in a laboratory. And some of the measurements you can get from making protein binders are things like hit rates. So of the number of designs that you send in the lab, how many of them actually bind. You can look for how well something binds. And across both those measures, things that were watermarked and watermarked and are two different schemes versus protein binders that weren't watermarked had near-identical hit rates, near-identical quantitative measures of binding.

00:27:39

Because you’d expect to lose maybe a tiny bit, right? Potentially. I mean, I guess admittedly, I think before we got the wet lab data is a little bit skeptical about how well this is going to work. And I think it blew all of our minds, actually, just how how easy it was. But proving it in biology was like, I think something that took us all maybe a little bit by surprise. I know this is proof of concept at the moment. You're sort of demonstrating that it works, and it is possible. Is the idea that in the future, any lab would be able to read your watermark? Yeah, and I think that's the eventual goal. Or maybe I wouldn't even necessarily frame it as our watermark.

00:28:11

Maybe it's the technology other people can use. We know that there has to be a number of different players who would be part of actually operationalizing this. So model developers, people making either novel tools or systems to be able to generate new proteins, they're going to have to be sort of on board of being able to integrate watermarking within their own schemes. And because we're open sourcing the code, this is something that they can do without even necessarily needing to coordinate with us. And in the synthesis side, they'll have to be some ability to exchange keys and exchange other details about the watermarking between the model providers and the DNA synthesis company themselves.

00:28:45

And so these are a couple of different coordination that need to happen. From our side we know that there is additional engineering headroom that you could move into to make the watermark both detectable and potentially a little bit easier to embed. We know that from some of ongoing work, and this is the type of activities that we would need to see within the community to be able to make this easier to adopt from all the different players who are involved. Is it the same story with the text? Would this be able to detect anything universally, or is it is it specific to the particular key that's used?

00:29:16

So if someone were to take the implementation that we're making publicly available and integrated in their system, so long as they're able to share the key as well as the length of context, that's another area that you can change how much of the preceding context matters for watermarking, so long as you can share those two values, you'd be able to detect them coming out of any system. Is this out there working already? What stage are you at right now? So for us, what we've been able to do with this publication is more or less have a proof of concept that we're going to open source the technology that allows people to do the watermarking. So this is a slightly different one than the way that we can watermark content coming out of Google, as we don't have necessarily protein design service internally.

00:29:53

So what we've started to do is have a lot of conversations with other people in the field and sort of in the ecosystem, both on the model development side as well as on the synthesis screening side. And we want to sort of just catalyze a conversation about where we can take this technology and actually do the implementation. It's also not necessarily for us to be able to set the standards on that partially, since we're not the organization that people will be ordering proteins from, but at least being sort of a catalyst so that this can get implemented from the various services that are currently out in the world. That's sort of where we see our role at the moment. And what's their reaction when you talk to the people who who are the ones that are sort of printing the proteins, making the proteins for real?

00:30:29

What's their reaction when you talk to them? Yeah. You know, I think maybe this is just a reflection of who I am. I'm generally quite skeptical of things like that's just sort of in my nature. They've all been so excited, maybe even more than I think we might have anticipated, which has been, I think, really galvanizing for us as we continue to go through sort of the last few steps around what it means to take this out into the real world. So we're, I think, bullish on the amount of at least interest that we might be able to get. So, I mean, one thing to one thing I found very remarkable about, the bio community is how cognizant they are of not just, the threats today, but the threats of tomorrow.

00:31:10

And so, they have been extremely receptive of the technology because they see the challenges every day that they are getting these orders for gene synthesis, which can create proteins. And they have these filters that can catch problematic orders, but they know that those are not perfect. And more work needs to be done to develop them. And they want to work with the field and their community to find solutions that will work.

00:31:46

Because this this topic of bio resilience as we go forward is going to be I mean, it's really going to start to become more and more on people's minds. I mean, what are the other things that you're doing in this area? There was a memo that came out, I think it was two months ago or so that sort of laid out Google DeepMind's vision as a whole. Plus Isomorphic Labs of what we're thinking about bio resilience. And that matched a couple of different efforts across pillars that are actually rooted in the UK's biological security strategy. So on prevent, detect and respond. Our team has a couple of different efforts under that. And broadly, we're looking at how we can leverage AI to reduce biological risk.

00:32:20

It's focused both on natural threats and on sort of AI enhanced augmented threats. We've got some projects that map really specifically to one area. So I think this SynthID Bio is a good example where we're really thinking about AI enhanced AI designs and what that might mean for being able to do pathogen detection. Got some other concepts that are much more in the natural threat space, and then some that sort of map between the both. So sort of our theory of change is that if you make biology less useful for someone who's trying to do something malicious, then that in and of itself can prevent them from using it in the first case. So for us, if we're able to make new capabilities and tools that make our entire public health system more robust, or make it easier for epidemiologists to identify an outbreak that can, in and of itself, make an outbreak less likely.

00:33:02

Because you want the good side of this, right? You want like the benefits of it, but you don't want it to come along with all of the potential downsides. Absolutely. And I think AI will have immense positive impacts in human health and understanding of biology at large. And I mean, it's already happening around us, right? Isomorphic Labs and many other sort of companies who are leveraging AI for drug discovery, understanding human health and so on. But at the same time, there will be problematic use cases that will be enabled.

00:33:37

And we need all the controls and all the sort of measures that we can place to make sure that those tasks are difficult or become infeasible. Just going back to the the the landscape of digital media for a moment, because, I mean, at the moment I think this stuff is, is quite fragmented. Do you think that we will get to a point where there is a central space that you can go to that will just tell you whether something is AI generated or not? I think the field is moving towards that. There is a overall sort of industry alignment on the need for provenance solutions, where companies have agreed on a standard of like, making sure that if, when there are edits or when there is generative AI, like sort of placing that information alongside the file.

00:34:32

The issue with that is that metadata can be sort of stripped off, which is why we need strong binding, which watermarks provide. So by combining these approaches and by building a system, a solution that works for everyone in the community, I think we will be able to get to a standard, but I think like progress is being made on that. But it just takes time. But this also, I guess same question for the biological side of things, is that the aim then, that there will be this industry standard at some point that everybody is using?

00:35:09

There's a lot of things, and we even note this in the discussion, where we know that there's engineering headroom to be able to move into both in the way that you're calculating G values and introducing the watermark. But at its surface, we do sort of believe that watermarking, embedded in an imperceptible way within the sequences themselves, is likely to be one of the best ways forward to being able to identify the provenance of AI generated sequences. I do also wonder, though, whether there's a bit of a game of cat and mouse going on here, right? Because the more universal a system becomes, the more sort of it's like it's clear what the rules are and how it's implemented.

00:35:44

Does it not become easier for somebody to come along with another system that is able to undo it? Yes. So I think this is this is very much a risk, which is why I think it's really important for us to have these measures where you have the secret keys with which we can embed watermarks in the signal itself. Right? Whether it's a protein sequence, whether it's images and so on. And which are hard to take away like and and like the ideal situation will be hard to take away to an extent that if you want to get rid of the detection signal that you have to change the function, right, and destroy the, the original sort of capability of the task that you had designed the thing for.

00:36:30

Like, it's so embedded within it that there's no way to undo it. But I guess it is. As you said, this is not necessarily the final way of doing things. This is sort of early days. The fact that you can have like some biological object. Right, like a sort of write down at that level that contains within it the story of where it came from. Yeah, it's pretty incredible. And I guess I would say we're not the first ones to do watermarks, but we're the first ones to our knowledge to both show imperceptibly and function preservation and including in vitro and sort of lab based results.

00:37:03

Absolutely amazing, really, really incredible stuff. Thank you very much for joining me. That was amazing. Thank you. Words like guardrails and safety. They get thrown around a lot when it comes to AI. But this right here, this is concrete proof of this lab putting its money where its mouth is. They pioneered the technology to watermark AI generated content well before most other labs were thinking about it. They proved it was scalable, that it wouldn't impact on the quality or speed of the output. And now they're ideas have been embedded within regulation.

00:37:34

But rather than resting on their laurels, they are already looking ahead to what the next threats are and how they can help to build a world that is able to harness the power and potential of this technology without allowing space for the harms to take hold. And they are doing that before the threats fully materialize. The future, as it turns out, will come with the certificate of authenticity. You have been listening to Google DeepMind, the podcast with me, Professor Hannah Fry. We have plenty more to come on this series, but in the meantime, check out our other episodes and we will see you very soon.

SHARE THIS TRANSCRIPT

Also on The AI 30

FULL CHART →

Transcript FAQ

Is there a transcript of "From deepfakes to DNA: the science of watermarking AI"?
Yes. This page has the full, timestamped transcript (6,952 words). Read it here or copy it with one click.
Why is this video on The AI 30?
It's the latest upload from Google DeepMind, which is #14 on The AI 30 with 930K subscribers.
Can I download this transcript as TXT or SRT?
Yes. Paste the video link into our free transcript tool to export it as plain text, SRT or VTT subtitles, or JSON.