From Deepfakes to DNA: The Science of Watermarking AI
打开互动全文版(中英对照 + 朗读 + 问答)→Pushmeet Kohli 与 Jeremy Radcliffe 阐释如何将不可见的数学水印嵌入 AI 生成内容——从图像到 DNA——以保留来源信息并防止滥用。
Pushmeet Kohli and Jeremy Radcliffe explain how invisible, mathematical watermarks embedded in AI outputs—from images to DNA—can preserve provenance and prevent misuse.
欢迎回到 Google DeepMind 播客。我是 Hannah Fry 教授。想象一下这个场景:你正在刷社交媒体,看到一段惊人的视频——火山近距离慢动作喷发,或者龙卷风肆虐村庄,又或者是一些抗议活动的画面。我想我们很多人都会问同一个问题:这是真的吗?这是人做的还是机器做的?随着 AI 在生成文本、图像、音频和视频方面越来越擅长,这正在成为我们时代最具挑战性的问题之一。只不过现在,答案变得更加复杂了。我们正在进入一个 AI 可以设计自然界从未存在过的生物分子和结构的世界,其中一些可能被设计来造成伤害。那么,如何在危险的东西被制造出来之前阻止它?答案可能就隐藏在显而易见的地方,无形地嵌入到你正在看的东西或你即将合成的分子中。一个水印,不是你在库存照片上看到的那种块状标志,而是更微妙、更数学化的东西。今天,我请来了两位从不同角度研究这个问题的人。Pushmeet Kohli 是 Google DeepMind 的科学副总裁,也是 SynthID 的架构师之一,这个水印系统正在被整个 AI 行业采用。Jeremy Radcliffe 是一位生物安全研究员,他的团队将同样的技术应用到了生物学中。欢迎两位来到播客。Jeremy,我们从你开始。给 AI 生成的任何东西加水印,听起来是个非常好的主意,但请给我详细解释一下,为什么这有帮助?
Welcome back to Google DeepMind the podcast. I'm Professor Hannah Fry. Picture the scene. You are scrolling through your socials and you see some remarkable footage. The up close slow motion eruption of a volcano or a tornado raging through a village or perhaps some footage of a protest. I think many of us ask the same question. Is that real? Was this made by a human or a machine? Well, as AI gets better at generating texts and images and audio and video, that is becoming one of the most challenging questions of our time. Except that now the answer just got a lot more complicated. We are entering a world where AI can design biological molecules and structures that have never existed in nature before, some of which could be designed to cause harm. So, how do you stop something dangerous before it gets made? Well, the answer, it turns out, might be hidden in plain sight, embedded invisibly into the very thing you're looking at or the very molecule you're about to synthesize. A watermark, not the blocky logo you see on a stock photo, something far more subtle, something mathematical. And today I am joined by two people who are working on this from different angles. Pushmeet Kohli is VP of science at Google DeepMind and one of the architects of SynthID, the watermarking system now being adopted across the AI industry. And Jeremy Radcliffe is a biosecurity researcher whose team has applied that same technology to biology. Welcome to the podcast, both of you. Jeremy, let's start with you. Watermarking anything that AI spits out, I mean, it sounds like a very good idea, but just break it down for me. Why is this helpful?
所以对于生物学来说,能够加水印的动机是为了让我们能够有溯源,具体说明这个序列来自哪里。我们真正想要区分的是来自自然界的序列和来自 AI 系统产物的序列。具体来说,我们考虑的 AI 系统风险类型是:一个 AI 生成的序列可能具有我们知道有问题的特性,但我们可能无法从序列本身识别出它具有这些有问题的特性。
So for biology, the motivation for being able to watermark is so that we can have provenance and say specifically where did this sequence come from. And really what we're trying to differentiate is between sequences that come from things in nature versus sequences that come as products of AI systems. So specifically, the type of risk that we're thinking about in terms of AI systems is an AI generated sequence that can have properties that we know to be problematic, but we might not be able to identify from the sequence itself that it has these problematic properties.
那么,什么才算是好的水印?因为我觉得当人们想到这个词时,会想到钞票或护照。有没有规则来定义什么是好的水印?
And what makes a good watermark? Because I think when people consider the phrase, they sort of think of banknotes or passports. Is there rules for what counts as a good watermark?
我认为对我们来说,特别是人类不可感知性是一个。所以让人很难分辨出哪部分数据被加了水印。
I think for us in particular, human imperceptibility is one. So making it very difficult for someone to be able to tell what portion of data has been watermarked.
因为否则的话就很容易被抹掉。
Because otherwise it would be really easy to erase.
是的。还要有高可检测性,所以有一个系统可以真正以高置信度识别水印。然后还有良好的泛化性,至少有一种水印方法可以适用于多种不同的系统,而不是必须为每种数据类型定制。
Yeah. Having high detectability, so having some system that can go through and actually identify the watermark with high confidence. And then also good generalizability, to being able to have at least a watermarking method that can work across a bunch of different systems rather than having to make bespoke ones for every single data type.
Pushmeet,你怎么看?我的意思是,这适用于生物学之外更广泛的领域吗?
What do you think, Pushmeet? I mean, does that apply beyond biology and more broadly?
是的,我认为我们在 DeepMind 启动整个水印项目的主要原因,大约 8 年前,是为了给用户所看到的内容提供一种溯源感。如果你看看不同的模态,无论是文本、图像还是视频,10 年前很难想象我们今天会谈论能够创建图像、视频、音频、文本以及蛋白质或酶的系统,这些系统与人类或自然界中存在的东西无法区分。这对用户来说是一个重要的元素,让用户相信你所看到的是真实的。那么,我们需要从水印中得到什么?我们需要三个特性。第一,它不应该降低质量,否则基本上就失去了意义。人们不会使用它。第二个要素是对攻击或变换的鲁棒性。如果人们想移除它,很难移除,因为即使你对信号进行更改,它也会持续存在。第三个要求是它应该易于使用,对吧?它应该易于集成到信号中,并且易于从信号中检测。所以这就是我们设计所有水印系统时所考虑的不可感知性、鲁棒性和可扩展性这三个特性,整个想法是让用户有更多的控制权,更好地了解他们看到的东西或他们正在使用或设计的东西等等。
Yeah, I think the main reason why we started the whole watermarking project at DeepMind almost 8 years ago now was to give a sense of provenance to what users are seeing. If you look at different modalities, whether it's text, whether it's images, whether it's videos, it was hard to imagine 10 years back that we would today be talking about systems that can create images, videos, audio, text, and proteins or enzymes that are indistinguishable from what a human or what exists in nature. And it's an important element for users to give users this idea that you can really believe what you are seeing. So what do we need from a watermark? We need three properties. One, it should not degrade the quality, otherwise basically the whole point is lost. People will not use it. The second element is robustness against attack or against transformations. If people want to remove it, it's hard to remove in the sense that even if you make changes to the signal, it will persist. And then the third requirement is that it should be easy to use, right? It should be easy to integrate in the signal and it's easy to detect from the signal. So those are the three properties of imperceptibility, robustness and scalability that we have designed all our watermarking systems for, with the whole idea that users have more control and have a better view of what they are seeing or what they are using or designing and so on.
感觉这个水印话题今年夏天相当热门。但与此同时,生成式 AI 向公众开放已经好几年了。为什么花了这么长时间,Pushmeet?为什么直到现在才变得如此普遍?
Feels like this subject of watermarking has been quite a big deal this summer. But at the same time, we're a few years into generative AI being accessible to the public. What's taken so long, Pushmeet? Why is it only now that this has become so widespread?
当图像编辑软件开始变得非常复杂时,人们非常担心这个问题:这是真实图像还是被篡改过的?有很多工作和专门的系统可以真正分析图像,看到被篡改图像中存在的微小差异,并说这是假图像或被篡改过等等。但随着生成式 AI 变得更加复杂,那些微小的差异消失了。然后自然就产生了这个问题:是不是游戏结束了,人类将无法检测某物是否是 AI 生成的?这就是水印介入的地方。我们说,确保人类始终有能力理解某个信号的来源的方法是在其中注入一个信号,有一个偏差,这样它就不会消失,即使模型完美,能够生成与相机观察到的或人类写的文本无法区分的图像。我们特意加入了一些不可感知的东西,让用户以后可以检测到这是或源自我的 AI 模型。
When image editing software started becoming very sophisticated, people were very concerned about this issue of is this a real image or has this been tampered with. And there was a lot of work and specialized systems which could really analyze an image and think and see the tiny differences that exist in a tampered image and can say oh yeah this was a fake image or this has been tampered with and so on. But as generative AI became more sophisticated, those tiny differences went away. And then that naturally resulted in the question: is this game over in the sense that humans will not have the ability to detect whether something is AI generated? And this is where watermarking sort of came in. We said the way to make sure that humans always have the ability to understand the origin of where some signal came from is by injecting a signal within it, having a bias so it doesn't go away, even if the models are perfect and they have the ability to generate images which are indistinguishable from what a camera would observe or what a text that a human would write. We specifically put in some imperceptible things that can allow users to later detect that this was or this originated from my AI model.
当你说“我们”时,Pushmeet,我的意思是你真的指的是字面意义上的“我们”,对吧?是你们想出了一个可扩展的解决方案。
And when you say we here, Pushmeet, I mean, you really do mean we in the literal sense, right? It was you guys that came up with a solution for this one that was scalable.
是的。我们,我们的团队已经研究这个近 8 年了。我们从图像开始,因为人们担心这些图像被用于假新闻、虚假信息等。所以有解决这个问题的动机。同时,尽管由于我们刚才提到的鲁棒性、不可感知性、效率和可扩展性等特性,这个问题极具挑战性,但图像仍然是大量的数据。
Yes. So we, our team has been working on this for almost 8 years. We started with images because people were concerned about these images being used for fake news, misinformation and so on. And so there was that motivation to solve that problem. At the same time, although the problem is extremely challenging because of the properties we just mentioned of robustness and imperceptibility and efficiency and scalability, still an image is a very large amount of data.
一张 100 万像素的图像大约有 100 万个数字,或者 300 万个,取决于编码方式,用来在不改变内容的情况下隐藏信息。所以我们先开发了图像水印系统。
A 1 megapixel image has about 1 million numbers, or 3 million depending on how it's encoded, to hide information without changing the content. So we developed watermarking systems for images first.
后来我们不得不面对一个挑战:如何为其他模态做这件事,比如文本,它的维度不像图像那么高。
Later on we had to look at the challenge of how do you do this for other modalities like text which are not as high-dimensional as images.
实际上信号量非常小,对吧?一个句子里并没有 100 万个数字。
Where actually it's a very small amount of signal, right? If in a sentence there aren't a million numbers.
对,没错。就几个词。你不能改变那几个词,而且必须非常小心,不能改变内容的含义。
Yeah, exactly. It's a few words. You can't change those few words and you have to be very cautious in terms of not changing the meaning of the content.
所以我们为文本水印开发的方法,与用于图像、视频甚至音频等高维信号水印的方法相当不同,也截然有别。
And so the approaches that we developed for watermarking text were quite different and distinct from what we use for watermarking high-dimensional signals like images and videos and audio even.
但你们开创的这种水印理念现在已经被写入法律。欧盟境内任何生成式内容都必须带有某种水印。
But this idea of watermarking which you guys pioneered has now been brought into law. It's essential that any generative content within the EU has to have some sort of watermarking.
我认为监管机构和世界各国已经认识到,他们想给用户提供关于所消费内容来源的信息。而一项被视为稳健且可扩展的解决方案的关键技术就是水印。这就是为什么我们不仅看到这个理念在整个行业被采纳,Zid 被 Nvidia 使用,也被 OpenAI 等其他合作伙伴使用,这是件了不起的事:我们在生成式 AI 领域的许多合作伙伴都采用了这项技术。
I think what regulators and countries around the world have recognized is that they want to give us users this information as to the origins of the content that they are consuming. And one key technology that is seen as a robust solution for it that can scale is watermarking. And which is why not only have we seen a take-up of this idea across the industry, the fact that Zid is used by Nvidia, it is used by other partners like with OpenAI and so on, it's a remarkable sort of thing that many of our partners in the generative AI space have adopted this technology.
Jeremy,在本期节目中,我们将讨论水印在 AI 中的两种不同应用。一种是文本、视频、音频等。另一种是生物结构和序列。这两者的解决方案很相似吗?
And Jeremy, in this episode, we're going to be talking about two different applications of watermarking for AI. So, you've got text and video and audio and so on. And then you've also got for biological structures and sequences. Is the solution quite similar between the two?
是的。我会说它们背后的原理相似,我们能够采用许多已经完成的工作,包括使用开源的合成文本库,并直接将其嵌入另一个系统。
Yes. So, I would say they're motivated by similar principles and we were able to adopt a lot of the work that had already been done, including using the open source synthetic text library and just embedding that directly into another system.
对。不仅是同样的技巧,有时甚至是同样的代码,你可以直接拿来用。
Right. The same not just the same tricks but sometimes the actual same code you can sort of pick it up and drop it.
至少从相同的代码开始,然后在其上做一些调整。
At least start from the same code and then make some adaptations on top of it.
好的。好的。我想人们想了解这是如何运作的,因为这听起来几乎像魔法:你可以有一句话,在其中嵌入某种水印,这与空白无关。与在文本中奇怪地放置逗号来隐藏无关,而是词语本身隐藏了它们如何生成以及来自哪里的记录。所以,如果你不介意,Pushmeet,我想我们可以直接走一遍文本水印是如何工作的。我认为这可能是最容易理解的。
Okay. Okay. So I think people want to understand how this works because it sounds almost magical that you could have a single sentence and you have embedded some sort of watermark in there that's nothing to do with whitespace. It's nothing to do with like putting commas in weird hiding them in the text, but that the words themselves are hiding a record of how they were generated and where they came from. So, if it's okay with you, Pushmeet, I thought we might just walk through how this works for text. I think that's probably the easiest one to understand.
好的。但在我们讨论这个之前,网上已经有一些软件声称能够判断你拥有的文本是否由 AI 生成。这与你们创造的有何不同?
Okay. So, before we get to that, there is some software out there already that you can get online that claims to be able to tell whether the text that you have is generated by AI or not. How is that different from what you guys have created?
是的。我认为长期以来的传统方法是训练机器学习模型来解决分类问题,区分模型生成的内容与自然世界捕获的内容。这基本上涉及在大量数据上训练这些机器学习模型。对吧?当早期的大语言模型和这些对话代理出现时,你可以辨认出哦这是大语言模型。它有某些迹象,它有
Yeah. So I think the traditional approach that has been there for a long time is to train machine learning models to solve a classification problem to distinguish between what is generated by a model versus what was captured in the natural world. And this sort of involves basically training these machine learning models over a very large amount of data. Right? When the earlier generations of large language models and these conversational agents came about, you could sort of make out that oh this is a large language model. It has certain tells it has
不是 X,而是 Y,对吧?使用“quietly”这个词有点太多。对。
It's not X, it's Y, right? Uses the word quietly a bit too much. Right.
是的。没错。或者有某些迹象,但随着这些模型变得越来越复杂,那些迹象变得越来越少。所以如果你训练,如果你有这个机器学习分类器试图区分,分类器的准确率会随着时间的推移而下降,因为生成式 AI 模型在复制它们目标实现的内容方面变得越来越好。
Yeah. Exactly. Or there are certain but as these models have become more and more sophisticated those tells have become less frequent. And so if you are train if you have this machine learning classifier which is trying to distinguish the classifier's accuracy goes down over time as the generative AI models become better at replicating what they are targeted to achieve.
好的。那么让我们走一遍这个水印系统是如何工作的。如果可以的话,我们一步一步来。首先,也许我们应该从大语言模型在生成文本时如何选择句子中的下一个词开始。
Okay. Well let's walk through how this the watermarking system works then. So let's do it step by step if we can. So first off, if you could maybe we should start off by how large language models pick the next word in a sentence when it's generating text.
是的。所以,当我们为文本加水印时,思路是这些 token 或词是由大语言模型生成的,而大语言模型本质上有一个分布,决定它可以生成哪些 token 或哪些词。所以,如果我问你,Hannah,你今天早餐吃了什么?你可以说以“我”这个词开始,或者你可以说以“Pushmeet”这个词开始,称呼我。这些是你有的选项。如果它们是同样有效的起点,你就有可选性。
Yes. So, when we are watermarking text, the idea is that these tokens or words are being generated from a large language model and the large language model essentially has a distribution over which tokens it can or which words it can generate. So, if I ask you the question, Hannah, what did you have for breakfast today? You can say start with the word I or you could start with the word Pushmeet, the addressing me. And these are the options that you have. And if they're equally valid starting points, you have optionality.
这就是文本水印利用这种可选性的地方,通过看密钥告诉我们什么。
And this is where text watermarking leverages this optionality by seeing what does the key tell us.
好的,但这就是关键,对吧?有时当你对一个词有选择时,在幕后有一个秘密密钥,它说偏向这些词而不是其他词,然后当你回头看所有文本时,如果你能看到那些词一遍又一遍地出现,你就可以确信这是 AI 生成的。
Okay, so but that's the point, right? is that sometimes when you have an option for a word behind the scenes there is a secret key which says bias these words over others and then when you look back at all of the text together if you can see those words appearing over and over and over again you can be confident that this is AI generated.
所以不是词本身,而是这些词的模式。所以那些词具体来说不需要重复,但模式是检测器所利用的,它们如何一起出现在链中。
So rather than the words it's the patterns of those words. So those words specifically you don't need to be repeated but the patterns is what the detector sort of leverages how they appear in sort of chains together.
没错。
Exactly.
对。是的。好的。所以你是秘密的,对。我的意思是并不是那么秘密。你在播客上谈论它。我们会说但你在后台有一些代码在运行。一些秘密密钥。
Right. Yes. Okay. So you're you're secretly right. So I mean it's not that secretly. You're sort of talking about it on a podcast. We're going to say but you have some code running around in the background. Some some secret key.
是的。
Yes.
然后你可以稍后查看一段文本并说等一下。这看起来像是 AI 生成的。不仅这是 AI 生成的,而且如果不同的 AI 模型使用不同的密钥,我们可以检查这是由这个模型还是另一个模型生成的。
That you can then look at a chunk of text later and say hang on a second. This looks like it was generated by AI. Not only this was generated by AI but if different AI models are using different keys we can sort of check whether this was generated by this model or this other model.
好的。所以你可以分辨这是 Gemini,这是其他任何模型可能有的,但如果你有密钥
Okay. So you can tell this is Gemini this is whatever other whatever other model might have but if you have the key
对,如果你有密钥,好的,我明白了,所以但如果只有很少的词可能,那么你就不能使用它。那么这是否意味着有些文本是无法加水印的?
right if you have the key okay I see okay so so but if there's few words that it could be then you can't use it. So does that mean that some text is unwatermarkable?
是的。所以如果你有一个非常小的、短的文本片段,对吧?比如法国首都是什么?是巴黎。
Yes. So if you have a very a small a short text snippet, right? Like what is the capital of France? It is Paris.
所以那里我们几乎无法改变,因此不会被水印标记。这是这种情况下水印方法的局限性。那么这一切是否意味着学生不能再在论文中作弊了?直白地说,我们现在能够检测任何 AI 生成的内容吗?
So there is very little that we can change there, and so that will not be watermarked. That is a limitation of the watermarking approach in this case. Does all of this mean then that students can't cheat on their essays anymore? Bluntly, are we now able to just detect anything that's AI generated?
我认为整个生态系统整体上正在朝着水印方向发展,正如你看到其他一些实验室发布的公告,但这并不一定意味着他们都会公开他们的检测器。即使你有一个公开可用的检测器,这也可能激励人们学习如何绕过它。就像一些基于机器学习的分类检测系统使用大量已加水印的文本示例一样,如果检测器公开可用,你可以反复查询它,你可能能够逆向工程出绕过公开检测器中特定密钥配置的方法。
I think the whole ecosystem as a whole is moving towards watermarking, as you've seen with some of the other labs making their announcements, but that doesn't necessarily mean that they're all going to make their detectors publicly available. And even if you've got a publicly available detector, that can be motivation for people learning how to get around it. In the same way that some of these machine learning classifying-based detection systems are using a whole bunch of examples of text of things that have been watermarked, were a detector publicly available and you could just query it over and over and over again, you might be able to work back to making something that gets around that specific configuration of keys that is presented in the public detector.
明白了。所以我们还没有一种保证万无一失的方法来检测任何 AI 生成的内容。这只是我们朝着这个方向迈出的一大步。
Got you. So we're not at a sort of guaranteed cast iron way to detect any AI generation whatsoever. It's just we're this is a big step towards that.
至少对于每个公开的密钥版本,还没有一种公开可用的检测系统的方法。
At least not with the method of having a publicly available detection system for every version of keys that is made publicly available.
那么对于图像和视频,是同样的想法吗?如你所述,你有更多的空间来隐藏东西。
Just in terms of images then and video, is it the same idea? You have a lot more space to hide things as you describe.
是的。所以我认为在图像中,方法与我提到的文本水印方法不同。在图像中,我们取未加水印的图像,然后有一个神经网络查看该图像并以非常微妙的方式修改它以嵌入信号。这个嵌入水印的特定模型与检测器神经网络共同训练,它们都试图实现以下目标。你得到一张未加水印的图像。水印生成器注入一个非常小的信号,这是不可察觉的。所以如果它是可察觉的,我们说那不好,因为你的用户会看到它,这会降低图像质量。然后在中间有一个对抗代理,它会尝试对图像进行修改。它可能尝试缩小图像、放大、裁剪、旋转,做许多种变换,如添加噪声等。然后检测器仍然必须检测通过的原始图像是否加水印。
Yes. So I think in images the approach is different from the text watermarking approach that I was mentioning. In images what happens is we take the image which has not been watermarked and then there is a neural network which looks at that image and modifies it in a very subtle way to incorporate the signal. And this particular model which is incorporating the watermark is being co-trained with a detector neural network, and they're both sort of trying to achieve the following. You get an image which is unwatermarked. The watermark generator injects a very small signal which is imperceptible. So if it is perceptible we say that's not great, like your users will see it and that degrades the quality of the image. Then in the middle there is an adversarial agent which is going to try to make modifications to the image. It might try to shrink the image, zoom in, crop it, rotate it, do many kinds of transformations like add noise and so on. And then the detector has to still detect whether the original image that is coming through is watermarked or not.
好的。它们两个是同步训练的,以确保无论中间的对抗者做了什么,水印仍然可检测。那么这对用户意味着什么?
Okay. And both of them are trained in tandem to make sure that regardless of what the adversary in the middle has done, the watermark is still detectable. What does this mean for users then?
我认为主要的是,这不仅仅是关于文本,而是关于所有这些不同的模态。如果你看看人们如何使用 SynthID,就像过去几年 SynthID 推出以来真的很惊人,我会打开我最喜欢的新闻网站,记者会说,这里有一张在媒体上流传的关于这栋在加州大火中神奇未受影响的房子的图像,或者这张来自伊朗战争或其他主题的图像,我们运行了 SynthID 并检测到这是 AI 生成的。
I think the main thing is it's not just about text, it's about all these different modalities. And if you look at how people are using SynthID, like it was really amazing the last few years as SynthID has been launched, I would open my favorite news website and the reporter would say, well here's an image that was circulating in the media about this particular house that magically was untouched in the California fires, or this image that came out from the Iran war or some other sort of topic, and we have run SynthID on it and detected that this was AI generated.
对,所以突然之间……
Right, so all of a sudden...
突然之间,你可以在那些绝对不应该出现 AI 的地方看到 AI。
All of a sudden you can see the AI in places that I mean it definitely shouldn't be basically.
是的,所以 SynthID 被用来实际应对虚假信息。
Yes, and so SynthID being used to actually tackle misinformation.
是的。
Yeah.
实时且大规模地。
In real time and at scale.
那么,任何人都能做你刚才做的事情吗?任何人都可以拿一张图像、一些文本、一些视频,通过 SynthID 运行,并找出它是否是由 AI 模型生成的吗?
So then can anyone do what you just did there? Can anyone take an image, some text, some video, run it through SynthID and find out whether it was generated by an AI model?
例如,我们已经将检测能力嵌入到 Gemini 应用中。所以今天如果你能去 Gemini,如果你问,我正在看这张图像,告诉我它是否是 AI 生成的,它可以运行 SynthID 检测器并说,是的,这是由 Google 图像模型生成的东西,等等。类似的能力现在也被其他采用我们模型的公司所提供。
We have made the detection ability embedded in the Gemini app for instance. So today if you can go to Gemini, if you ask, I'm looking at this image, tell me if it is AI generated, it can run the SynthID detector and say yes, this is something that was generated by a Google image model and so on. And similar sort of abilities now are available by other companies as well who have adopted our models.
每个模型只能检测它是否是由该模型生成的吗?Gemini 只能检测 Gemini 生成的内容吗?
Can each model only detect whether it was generated by that model? Can Gemini only detect Gemini-generated content?
所以那些在内容中注入水印的人,他们必须同意分享密钥。
So people who are injecting the watermark into the content, they have to agree to share the key.
嗯。
Mhm.
对。如果他们分享密钥,那么我们就有能力检测它。对吧?所以可以有一个中心服务。如果你去 SynthID 门户,如果你问某物是由……是 AI 生成的,它可以查看所有合作伙伴机构给我们的密钥,我们也可以为所有那些合作伙伴检测 AI 内容。
Right. If they share the keys, then we have the ability to detect it. Right? So there can be a central service. If you go to the SynthID portal and if you ask something is generated by, is AI generated, it can look at all the keys that have been given to us by partner institutions and we can detect the AI content for all those partners as well.
好的,明白了。但如果某个实验室不想分享他们的密钥,那么你就无法做到。
Okay, got you. But if a certain lab is like doesn't want to share their key then you wouldn't be able to.
是的。
Yeah.
好的。好的。那么,Jeremy,我们现在来谈谈生物学,因为我知道你提出了这个叫做 SynthID Bio 的概念验证系统,它不是对文本、音频和视频进行水印,而是用于生物学,你对 AI 生成的蛋白质序列和 3D 生物分子结构进行水印。请告诉我关于这两个系统的情况。
Okay. Okay. Well, Jeremy, let's talk about biology now because I know that you've come up with this proof of concept system called SynthID Bio, which instead of watermarking, you know, text and audio and video is for biology instead where you are watermarking AI generated protein sequences and 3D biomolecular structures. Just tell me about those two systems.
即将发布的出版物涵盖了合成生物结构,它专门研究对给定序列的预测蛋白质结构进行水印。所以它建立在 AlphaFold 3 之上。第二项技术是合成生物序列。它研究将水印引入蛋白质序列本身。也就是序列中存在的氨基酸字符串。
So the release in the upcoming publication covers synthetic bio structure which is specifically looking at watermarking the predicted protein structures given a sequence. So it builds on top of AlphaFold 3. The second technology is synthetic bio sequence. So which looks at introducing watermarks into protein sequences themselves. So the strings of amino acids that are present for a sequence.
但这两件事是相关的,对吧?我的意思是,每个折叠的蛋白质结构都是一串氨基酸,在……
So but those two things are related right that you have like I mean each folded protein structure is a string of amino acids under
是的。所以我们基本上是在谈论同一类型数据的不同版本,但实际上嵌入水印对两者来说非常不同。所以对于结构水印,我们实际上是在改变单个原子的位置。所以你可以想象两个原子之间的距离稍微改变,或者两个原子之间的角度稍微改变。而对于合成生物序列,我们实际上是在改变单个氨基酸的选择。所以对于结构,仍然是相同的原子。它们只是可能处于稍微不同的配置。而对于序列,我们实际上是在改变内容,但可能不是该内容的实际功能意义。
Yeah. So we're basically talking about different versions maybe of the same type of data but actually embedding the watermark is very different for the two of them. So for the structure watermarking we're actually changing the positions of individual atoms. And so you can think about maybe the distance between two atoms changing slightly or the angle between two atoms changing slightly. Well for synthetic biosequence we're actually changing the selection of an individual amino acid. So for structure it's still the same atoms. They're just maybe in a slightly different configuration. Well, for sequence, we're actually changing the content, but maybe not the actual functional meaning of that content.
那有什么意义?你为什么想要它?
And what's the point? Why do you why do you want it?
是的,你知道,我们想到了一些可能有用的不同用例。
Yeah, you know, we've thought of a couple different use cases that might be useful.
能够说明某个东西是 AI 生成的、有来源可循,以及你如何能够检测出,发往 DNA 合成公司的订单是否来自 AI 系统。
Being able to say that you have provenance of something being AI generated, and how you might be able to detect if an order going to a DNA synthesis company is something that came from an AI system.
因为我觉得这是非生物学家不太了解的事情,对吧?你基本上有——我就叫它们“打印机”吧——你可以把订单发过去,说这是我想要合成的序列,他们就会帮你做出来。但你说的意思是,有可能骗过他们,让他们打印出危险的东西。我这里“打印”这个词用得很宽松。这基本上就是问题所在,对吧?
Because I think that's something that non-biologists aren't really aware of, right? That you essentially have — I'm going to call them printers — but where you can send off and say this is the sequence I want created and they'll do it for you. But what you're saying here is that it's possible to trick them into printing something hazardous. I'm using "printed" very loosely here. That's essentially the problem, right?
这就是担忧所在。是的,这是担忧之一。有很多行业团体和学者专注于如何让这套筛查机制更加稳健,这也是我们希望能有所贡献的方向。但最主要的担忧是:有人能否获取 DNA,从而在实验室里制造出我们不希望他们制造的东西,或者绕过监管。所以,有人能否从公司订购 DNA,然后带到实验室,制造出像已灭绝的流行病那样的东西,比如已灭绝的流感病毒。
That's the concern. Yeah, that's one of the concerns. And there's a large body of industry groups and academics who focus on how to make that screening regimen more robust, and that's something we're interested in being able to contribute to. But the primary concern is: would someone be able to acquire DNA that could give them access to being able to generate something in a lab that we don't want them to be able to do, or maybe gets around regulation. So could someone order DNA from a company and then bring it to a laboratory and make something like an extinct pandemic, like extinct influenza for instance.
好。我得说那会很糟糕——
Okay. Which I would say would be bad —
总的来说。
Generally.
是的。总体上是糟糕的。好。那么至少,如果这些公司能够检测出某个东西是否是 AI 生成的,就相当于多了一道保障,多了一道拦截,在他们继续推进之前。
Yes. Overall bad. Okay. And then at least then if these companies are able to detect whether something is AI, it sort of puts an extra safeguard in place, an extra sort of stop in place before they just can continue on.
而且,如果你检测到水印,你就有信心认为它来自一个内置了安全护栏的系统,而不是可能来自另一个 AI 模型,或者来自自然界的东西。
And something that if you detect the watermark, you have confidence that this was derived from a system that has built-in safety guardrails, versus either maybe another AI model or something that comes from nature.
好。那么这些公司目前有什么样的安全系统,来确保他们不会制造出真正危险的东西?
Okay. And what kind of safety systems do those companies have in place at the moment to make sure that they're not making something really dangerous?
合成公司主要做的是,他们接受个人的订单,但在此之前能够核实其身份的一些信息。所以大多数公司都有一套流程,要求你说明:我是学者,这是我的大学隶属关系,我确实是我所说的那个人,而且你寄送到的具体邮政信箱是属于某个实验室的。我不是地下室里随便一个想要这东西的人。然后他们拿到这些订单,把订单的具体内容与已知危险物品的数据库进行比对,用几种不同的算法将这份提交物与数据库核对。如果匹配,他们要么直接拦截订单,说我们无法合成这个,要么回头找下单的人,试图弄清他们订购的动机,以及他们是否拥有所需的许可。而这些 AI 系统带来的风险,正如其他一些学者所展示的,是你可以制造出在序列空间上与病原体数据库中存在的任何东西都截然不同、但可能折叠成那个令人担忧的东西的序列。
So the synthesis companies largely what they do is they take an order from an individual where they've been able to verify something about their identity. So most of them have a process in place that says I am an academic, this is my university affiliation, I am actually who I say I am, and the specific PO box that you're sending it to is for a laboratory. I'm not just a random person in a basement that wants it. And then they take those orders and they compare the specific content of the order to a database of known hazardous things, and they check that specific submission against that database using a couple different algorithms. And if something matches, then they either just block the order and say we can't synthesize this, or they'll go back to the original individual and try to find out what motivation they have for ordering it and whether they've got, say, requisite licensing. And the risk we have with these AI systems, as shown by some other academics, is that you can make something that in sequence space is very different than something that's present in that pathogen database but might fold into the thing that is of concern.
一串氨基酸看起来人畜无害——
A string of amino acids looks innocent —
但一旦被制造出来,实际的蛋白质可能非常有害。
But once it's created, an actual protein could be really harmful.
是的。而且可能具有与受限数据库中存在的某个东西相同的行为——
Yeah. And could have the same behavior as something that's present in the database of restricted —
而他们当前的系统无法捕捉到它。这确实是担忧所在,尤其是随着这些系统越来越好,你可能得到在序列空间上更远的东西,从而绕过一些现有的防护。
And their current systems wouldn't be able to catch it. Definitely the concern is that, and especially as these systems get better and better, you might be able to get something even further away in sequence space that might get around some of the existing protection.
在这条氨基酸链里弄出非常古怪的东西,却仍能折叠成有害的东西,基本上就是溜过他们的检测系统。
Something really wacky in this ribbon of amino acids that still can fold into something harmful, to basically sneak under their detection system.
正是如此。而且你可以把它剪切粘贴到另一个序列里。所以你可以想象,如果订单中某一部分会被拦截,你可以把某个令人担忧的东西剪切粘贴进去,而它在受限数据库中距离很远,然后在实验室里,你再把它放回原来的位置。
Exactly. And you can cut and paste that into another sequence. So you can imagine like if maybe there's one portion of an order that would be blocked, you could cut and paste something of concern into that that's very far away from the restricted database, and then in the laboratory itself, you just put it back into where it originally came from.
好,我明白了。那么你在这里做水印的想法,并不一定是说你能检测出任何潜在有害的东西,但至少你可以说这是 AI 生成的,要小心,因为当你把它与现有数据库比对时,它可能看起来不像已经在那里的东西——
Okay, I see. And then the idea of what you're doing here with the watermarking is not necessarily to say you're going to be able to detect anything that's potentially harmful, but at the very least you can say this is AI generated, be careful, because when you're comparing it against your existing database, it might not look like something that's already on there —
而且你可以说出它来自哪个系统。而且因为你作为 DNA 合成公司,出于水印之外的原因信任这个 AI 系统,你就可以有信心认为这是通过这种方法生成的。
And you can say which system it came from. And because you as a DNA synthesis company trust this AI system for reasons that go beyond the watermark, you can have confidence that this was generated through this method.
那请给我讲讲这里的蛋白质设计流程。你如何像我们描述文本那样,把水印植入系统?
Talk me through the protein design process then here. So how do you get the watermark into the system in the same way as we described with text?
是的,其实——也许有点偶然,ProteinMPNN 这个从结构到序列的模型所采用的方法,实际上与基于 Transformer 的模型生成文本的方式相当类似。ProteinMPNN 是一个第三方工具,不是 Google 开发的。它已经在世界上发布好几年了,而且它几乎与 AlphaFold 相反。它不是从序列到结构,而是从结构到序列。这在蛋白质设计流程中是很重要的一环,你最初是根据希望它们在三维空间中如何相互作用来选择目标的。这个模型只是接收那个表示,然后生成一个预测序列,以便折叠成那个特定的构型。
Yeah, so it's actually — maybe somewhat fortuitous that the approach that ProteinMPNN, which is this structure-to-sequence model, uses is actually pretty analogous to the way that transformer-based models generate text. So ProteinMPNN is a third-party tool. It's not something that Google developed. It's been released out in the world for a number of years, and it's almost the opposite of AlphaFold. So rather than going from a sequence to a structure, it goes from a structure to a sequence. And that's an important part in a protein design pipeline where you are originally choosing your target based off of how you want them to interact in three-dimensional space. This is a model that just takes that representation and then creates a predicted sequence in order to fold into that specific configuration.
因为这是很重要的一点,对吧?你可能拥有这些极其复杂的折叠结构,但每个蛋白质都是由一条氨基酸链、一串氨基酸构成的。类比就来自这里。一串氨基酸就像一串文本。
Because that's an important point, right? That you might have these extremely complex folded structures, but that each protein is constructed from like a ribbon of amino acids, a string of amino acids. And that's where the analogy comes from. A string of amino acids like a string of text.
是的。所以你几乎可以看到,当你折叠蛋白质时,有些位置可以在单个氨基酸之间进行替换,也许是某些性质相似的氨基酸,比如亮氨酸和异亮氨酸,或者两个非常相似的。所以我们在 SynthID 生物序列中利用的是,你可以通过选择单个氨基酸来引入水印,这些氨基酸很可能既保持相同的结构,因此也具有相似的功能。
Yep. And so what you almost see is that when you're folding a protein, there are locations where there can be swaps between individual amino acids, maybe ones that are similar in certain properties, like leucine and isoleucine, or two that are quite similar. And so what we're taking advantage of within SynthID biosequence is that you can introduce watermarks through the selections of individual amino acids that are likely to both maintain the same structure and therefore have similar function.
但等等,你怎么能确定?我是说,你说你可以做替换,而且没关系。但你能确定这个替换没关系吗?
But hang on, how can you be sure? I mean you said that you can make the swap and it doesn't matter. But can you be sure that the swap doesn't matter?
是的。这正是我们在流程中专门测试的内容。
Yeah. So that's what we specifically test in the process.
所以这项研究的整体思路是注入水印,并确保生成的氨基酸序列——在这个案例中就是构建蛋白质的序列——具有相同的功能,或者说保留我们试图设计的功能。这就是它非常酷的地方:我们现在已经存在带水印的蛋白质。这些是真实的东西。这不是模拟。这些是真实的东西,它们能发挥作用,但带有水印,并且永远可以被检测到。
So the whole idea of this research was to inject the watermark and ensure that the generated amino acid sequence, in this case that builds the protein, has the same function or retains the function that we were trying to design for. And that's what is very cool about it: we have now in existence watermarked proteins. These are real things. This is not in simulation. These are real things which do stuff but which are watermarked and will always be detectable.
而且重要的是,从我们自己的实验室实验来看,它们完全没有改变功能。所以我们制造了蛋白质结合体。也就是制造了那些能粘附的东西。
And importantly from our own laboratory experiments, they don't change the function at all. So we made protein binders. So we made the things that stick.
哦,你们真的把它们做出来了。
Oh, you physically made them.
我们做出来了。我们在实验室里测试了它们。制造蛋白质结合体可以得到的一些测量指标包括命中率。也就是你送进实验室的设计数量中,有多少真正能结合。你还可以看结合得有多好。在这两项指标上,带水印的——而且是在两种不同方案下水印的——与不带水印的蛋白质结合体相比,命中率几乎相同,结合的定量指标也几乎相同。
We made them. We tested them in a laboratory. And some of the measurements you can get from making protein binders are things like hit rates. So of the number of designs that you send in the lab, how many of them actually bind. You can look for how well something binds. And across both those measures, things that were watermarked and watermarked under two different schemes versus protein binders that weren't watermarked had near identical hit rates, near identical quantitative measures of binding.
也许有一点点差别,对吧?
Maybe a tiny bit, right?
有可能。我的意思是,我承认,在我们拿到湿实验数据之前,我对这能有多好地运作有点怀疑,但我觉得它实际上让我们所有人都大吃一惊,竟然这么容易。但在生物学中证明它,我想这让我们所有人都可能有点意外。我知道目前这只是概念验证。你是在展示它可行、有可能,设想是未来任何实验室都能读取你的水印。
Potentially. I mean, I guess admittedly, I think before we got the wet lab data, I was a little bit skeptical about how well this is going to work and I think it blew all of our minds actually just how easy it was. But proving it in biology was like I think something that took us all maybe a little bit by surprise. I know this is proof of concept at the moment. You're sort of demonstrating that it works and that it's possible is the idea that in the future any lab would be able to read your watermark.
是的。我认为这是最终目标,或者我甚至不一定会把它框定为我们的水印。也许这是其他人可以使用的技术。我们知道,必须有许多不同的参与者参与才能真正将其落地。所以模型开发者,那些制造新工具或系统来生成新蛋白质的人,他们必须愿意将水印整合到自己的方案中。因为我们开源了代码,他们甚至不需要与我们协调就能做到这一点。在合成方面,模型提供方和 DNA 合成公司之间必须有能力交换密钥以及关于水印的其他细节。所以从我们这边来说,需要发生几种不同的协调。我们知道还有额外的工程空间可以推进,使水印既可检测又可能更容易嵌入。我们从一些正在进行的工作中知道这一点。这就是我们需要在社区中看到的活动类型,以便让所有相关参与者更容易采用。
Yeah. And I think that's the eventual goal or maybe I wouldn't even necessarily frame it as our watermark. Maybe it's the technology other people can use. We know that there has to be a number of different players who would be part of actually operationalizing this. So model developers, people making either novel tools or systems to be able to generate new proteins, they're going to have to be sort of on board of being able to integrate watermarking within their own schemes. And because we're open sourcing the code, this is something that they can do without even necessarily needing to coordinate with us. And on the synthesis side, there'll have to be some ability to exchange keys and exchange other details about the watermarking between the model providers and the DNA synthesis company themselves. And so these are a couple of different coordinations that need to happen from our side. We know that there is additional engineering headroom that you could move into to make the watermark both detectable and potentially a little bit easier to embed. We know that from some of ongoing work. And this is the type of activities that we would need to see within the community to be able to make this easier to adopt from all the different players who are involved.
文本也是同样的情况吗?这能普遍检测任何东西,还是特定于所使用的密钥?
Is it the same story with the text? Would this be able to detect anything universally or is it specific to the particular key that's used?
如果有人采用我们公开提供的实现并将其集成到他们的系统中,只要他们能够共享密钥以及上下文长度——这是另一个你可以改变前面上下文对水印影响程度的领域。只要你能共享这两个值,你就能检测到来自任何系统的输出。
So if someone were to take the implementation that we're making publicly available and integrated in their system, so long as they're able to share the key as well as the length of context, that's another area that you can change how much of the preceding context matters for watermarking. So long as you can share those two values, you'd be able to detect them coming out of any system.
这个已经在外面运作了吗?你们现在处于什么阶段?
Is this out there working already? What stage are you at right now?
对我们来说,在这篇论文中我们所能做的,或多或少是一个概念验证,我们将开源这项技术,让人们可以进行水印。这与我们对来自 Google 的内容加水印的方式略有不同,因为我们内部不一定有蛋白质设计服务。所以我们开始做的是与领域内和生态系统中的其他人进行大量对话,既包括模型开发方面,也包括合成筛选方面,我们想推动一场关于我们可以把这项技术带到哪里并真正实施的对话。这也不一定是由我们来制定标准,部分原因是我们不是人们订购蛋白质的组织,但至少作为催化剂,让目前世界上的各种服务能够实施这一点。这就是我们目前所看到的自己的角色。
So for us, what we've been able to do within this publication is more or less have a proof of concept that we're going to open source the technology that allows people to do the watermarking. So this is a slightly different one than the way that we can watermark content coming out of Google as we don't have necessarily protein design service internally. So what we've started to do is have a lot of conversations with other people in the field and sort of in the ecosystem both on the model development side as well as on the synthesis screening side and we want to sort of just catalyze a conversation about where we can take this technology and actually do the implementation. It's also not necessarily for us to be able to set the standards on that, partially since we're not the organization that people will be ordering proteins from, but at least being sort of the catalyst so that this can get implemented from the various services that are currently out in the world. That's sort of where we see our role at the moment.
当你和那些真正要打印蛋白质、制造蛋白质的人交谈时,他们的反应是什么?你跟他们谈的时候,他们是什么反应?
And what's their reaction when you talk to the people who are the ones that will be sort of printing the proteins, making the proteins for real? What's their reaction when you talk to them?
是的,你知道,我想这可能只是我个人的反映。我通常对事情相当怀疑,这算是我的天性。他们都非常兴奋。甚至可能超出我们的预期。这对我们来说真的很振奋,因为我们继续走过最后几步,思考将其带入现实世界意味着什么。所以我认为我们对至少可能获得的兴趣持乐观态度。我的意思是,我发现生物社区非常了不起的一点是,他们不仅意识到今天的威胁,还意识到明天的威胁。因此他们对这项技术非常接受,因为他们每天都看到挑战:他们收到可以制造蛋白质的基因合成订单,他们有过滤器可以捕捉有问题的订单。但他们知道这些过滤器并不完美,
Yeah, you know, I think maybe this is just a reflection of who I am. I'm generally quite skeptical of things like that's just sort of in my nature. They've all been so excited. Maybe even more than I think we might have anticipated. Which has been I think really galvanizing for us as we continue to go through sort of the last few steps around what it means to take this out into the real world. So we're I think bullish on the amount of at least interest that we might be able to get. So I mean one thing I found very remarkable about the bio community is how cognizant they are of not just the threats today but the threats of tomorrow. And so they have been extremely receptive of the technology because they see the challenges every day that they are getting these orders for gene synthesis which can create proteins and they have these filters that can catch problematic orders. But they know that those are not imperfect
还需要做更多工作来开发它们,他们希望与领域和 AI 社区合作,找到可行的解决方案,因为随着我们向前发展,生物韧性这个话题真的会越来越受到人们的关注。我的意思是,你们在这个领域还做哪些其他事情?是的,大约两个月前有一份备忘录发布,概述了 Google DeepMind 以及 Isomorphic Labs 在生物韧性方面的整体愿景,这与英国生物安全战略的几个支柱相匹配,即预防、检测和响应。我们团队在这方面有几个不同的努力,广泛来说,我们正在研究如何利用 AI 降低生物风险。它既关注自然威胁,也关注 AI 增强的威胁。我们有一些项目非常具体地对应某一个领域。
and more work needs to be done to develop them and they want to work with the field and the AI community to find solutions that will work because this topic of bio resilience as we go forwards is going to be I mean it's really going to start to become more and more on people's minds. I mean what are the other things that you're doing in this area? Yeah, there was a memo that came out I think it was two months ago or so that sort of laid out Google DeepMind's vision as a whole plus Isomorphic Labs of where we're thinking about bio resilience and that matched a couple different efforts across pillars that are actually rooted in the UK's biological security strategy so on prevent detect and respond. Our team has a couple different efforts under that and broadly we're looking at how we can leverage AI to reduce biological risk. It's focused both on natural threats and on sort of AI enhanced augmented threats. We've got some projects that map really specifically to one area.
所以我认为合成生物学是一个很好的例子,我们真正在思考 AI 增强的 AI 设计,以及这对于模式检测意味着什么。还有一些其他概念更偏向自然威胁领域,然后还有一些介于两者之间。所以我们的变革理论是,如果你让生物学对试图做恶意事情的人变得不那么有用,那么这本身就可以从一开始阻止他们使用它。所以对我们来说,如果我们能够创造新的能力和工具,使我们的整个公共卫生系统更加稳健,或者让流行病学家更容易识别疫情,这本身就可以降低疫情发生的可能性。
So I think this synthetic bio is a good example where we're really thinking about AI-enhanced AI designs and what that might mean for being able to do pattern detection. Got some other concepts that are much more in the natural threat space and then some that sort of map between the both. So our theory of change is that if you make biology less useful for someone who's trying to do something malicious, then that in and of itself can prevent them from using it in the first case. So for us, if we're able to make new capabilities and tools that make our entire public health system more robust or make it easier for epidemiologists to identify an outbreak, that can in and of itself make an outbreak less likely.
因为你想要它好的一面,对吧?你想要它的好处,但你不希望它带来所有潜在的下行风险。
Because you want the good side of this, right? You want the benefits of it, but you don't want it to come along with all of the potential downsides.
绝对如此。绝对如此。我认为 AI 将对人类健康和整体生物学的理解产生巨大的积极影响。我的意思是,这已经在我们身边发生了,对吧?Isomorphic Labs 和许多其他公司正在利用 AI 进行药物发现、理解人类健康等等。但与此同时,也会出现有问题的用例,我们需要所有可以采取的控制措施和手段,确保那些任务变得困难或不可行。
Absolutely. Absolutely. And I think AI will have immense positive impacts in human health and understanding of biology at large. And I mean it's already happening around us, right? Isomorphic Labs and many other companies who are leveraging AI for drug discovery, understanding human health and so on. But at the same time there will be problematic use cases that will be enabled and we need all the controls and all the measures that we can place to make sure that those tasks are difficult or become infeasible.
让我们暂时回到数字媒体的格局,因为目前我认为这些东西相当碎片化。你认为我们会达到一个阶段,有一个中心空间可以去,它会直接告诉你某样东西是否是 AI 生成的?
Just going back to the landscape of digital media for a moment, because at the moment I think this stuff is quite fragmented. Do you think that we will get to a point where there is a central space that you can go to that will just tell you whether something is AI generated or not?
我认为这个领域正在朝这个方向发展。行业总体上一致认为需要溯源解决方案,公司们已经同意了一个标准,确保当有编辑或生成式 AI 时,这些信息会与文件一起放置。问题在于元数据可以被剥离,这就是为什么我们需要强绑定。
I think the field is moving towards that. There is overall industry alignment on the need for provenance solutions, where companies have agreed on a standard of making sure that when there are edits or when there is generative AI, that information is placed alongside the file. The issue with that is that metadata can be stripped off, which is why we need strong binding.
这正是水印所提供的。
Which is what watermarks provide.
所以通过结合这些方法,并构建一个对社区中每个人都有效的解决方案,我认为我们能够达到一个标准。但我认为这方面正在取得进展,只是需要时间。
So by combining these approaches and by building a solution that works for everyone in the community, I think we'll be able to get to a standard. But I think progress is being made on that, but it just takes time.
但这也,我猜同样的问题也适用于生物方面。那么目标是否是在某个时候会有这个行业标准,每个人都在使用?
But this also, I guess same question for the biological side of things. Is that the aim then that there will be this industry standard at some point that everybody is using?
有很多事情,我们甚至在讨论中也注意到,我们知道在计算 G 值和引入水印的方式上都有工程余量可以推进。但表面上看,我们确实相信,以不可察觉的方式嵌入序列本身的水印,可能是识别 AI 生成序列来源的最佳途径之一。
There's a lot of things and we even note this in the discussion where we know that there's engineering headroom to be able to move into both in the way that you're calculating G values and introducing the watermark. But at its surface, we do sort of believe that watermarking embedded in an imperceptible way within the sequences themselves is likely to be one of the best ways forward for being able to identify the provenance of AI generated sequences.
不过我也想知道,这里是否有点猫鼠游戏的味道,对吧?因为一个系统变得越普遍,规则是什么以及如何实施就越清楚。难道不会让其他人更容易带着另一个能够撤销它的系统出现吗?
I do also wonder though whether there's a bit of a game of cat and mouse going on here, right? Because the more universal a system becomes, the more it's clear what the rules are and how it's implemented. Does it not become easier for somebody to come along with another system that is able to undo it?
是的。所以我认为这确实是一个风险,这就是为什么我认为我们采取这些措施非常重要,即拥有这些秘密密钥,我们可以用它们在信号本身中嵌入水印,对吧?无论是蛋白质序列,还是图像等等。而且这些水印很难被去除,理想情况下会难到如果你想要去除检测信号,你就必须改变功能,对吧?并破坏你设计这个东西的原始任务能力。
Yes. So I think this is very much a risk, which is why I think it's really important for us to have these measures where you have these secret keys with which we can embed watermarks in the signal itself, right? Whether it's a protein sequence, whether it's images and so on. And which are hard to take away, like the ideal situation will be hard to take away to an extent that if you want to get rid of the detection signal that you have to change the function, right? And destroy the original capability of the task that you had designed the thing for.
就像它如此嵌入其中,以至于无法撤销。
Like it's so embedded within it that there's no way to undo it.
是的。
Yes.
但我想正如你所说,这不一定是最終的做法。这还处于早期阶段。事实上,你可以拥有一种生物对象,对吧?就像在那个层面上,它内部包含了它来自哪里的故事。
But I guess it is as you said this is not necessarily the final way of doing things. This is sort of early days. The fact that you can have like a sort of biological object, right? Like a sort of right down at that level that contains within it the story of where it came from.
是的,这非常不可思议。我想说,我们不是第一个做水印的,但据我们所知,我们是第一个同时展示不可察觉性和功能保持的,包括体外和实验室结果。
Yeah, it's pretty incredible. And I guess I would say we're not the first ones to do watermarks, but we're the first ones to our knowledge to both show imperceptibility and function preservation, including in vitro and lab-based results.
绝对惊人。真的,真的非常不可思议。非常感谢你们两位加入我。太棒了。
Absolutely amazing. Really, really incredible stuff. Thank you both so much for joining me. That was amazing.
谢谢。
Thank you.
在 AI 领域,像“护栏”和“安全”这样的词经常被提及,但这里,这是这个实验室言行一致的具体证明。他们早在大多数其他实验室考虑之前就开创了为 AI 生成内容添加水印的技术。他们证明了这是可扩展的,不会影响输出的质量或速度。现在他们的想法已经被纳入监管。但他们没有固步自封,而是已经在展望下一个威胁是什么,以及他们如何帮助建立一个能够利用这项技术的力量和潜力、同时不让危害有可乘之机的世界。而且他们是在威胁完全显现之前就这样做了。事实证明,未来将附带真实性证书。你一直在收听 Google DeepMinder 播客,我是 Hannah Fry 教授。本系列还有更多内容,但与此同时,请查看我们的其他剧集,我们很快就会再见。
Words like guard rails and safety, they get thrown around a lot when it comes to AI, but this right here, this is concrete proof of this lab putting its money where its mouth is. They pioneered the technology to watermark AI generated content well before most other labs were thinking about it. They proved it was scalable, that it wouldn't impact on the quality or speed of the output. And now their ideas have been embedded within regulation. But rather than resting on their laurels, they are already looking ahead to what the next threats are and how they can help to build a world that is able to harness the power and potential of this technology without allowing space for the harms to take hold. And they are doing that before the threats fully materialize. The future, as it turns out, will come with the certificate of authenticity. You have been listening to Google DeepMinder podcast with me, Professor Hannah Fry. We have plenty more to come on this series, but in the meantime, check out our other episodes and we will see you very soon.