MARCO: The Radioactive Watermark for Protein Generative Models

šŸ“… 2026-10-06
šŸ“ˆ Citations: 0
✨ Influential: 0
šŸ“„ PDF
šŸ¤– AI Summary
This study addresses the risks of intellectual property theft and biosafety misuse in protein generative models by proposing the first radioactive watermarking framework. Methodologically, watermarks are embedded via an auxiliary codec during diffusion denoising, while a dual-layer defense mechanism is constructed through adversarial training on Cα distances and dihedral angles combined with random attack simulation. The core innovation lies in its radioactivity, enabling automatic watermark transfer to pirated models trained on protected data, thereby effectively mitigating model extraction attacks. Experimental results demonstrate that this framework preserves high generation fidelity and strong robustness while successfully validating cross-model transferability, achieving efficient and secure active protection for protein generative models.
šŸ“ Abstract
Protein Generative Models (PGMs) have revolutionized structural biology by enabling the design of complex 3D protein structures from sequence data. However, this breakthrough introduces a dual-use challenge, exposing high-value PGMs to economic risks like unauthorized model extraction and biosecurity threats such as biohazard synthesis. To mitigate these threats, we propose \textbf{MARCO} (\textsc{COnformation waterMARk}), the first radioactive watermarking framework specifically tailored for PGMs. MARCO establishes a Dual-Layer defense that simultaneously protects intellectual property and ensures the forensic traceability of potential biosecurity misuses. (i) To preserve efficiency, MARCO iteratively embeds watermarks during diffusion reverse denoising via an auxiliary encoder-decoder, allowing the original PGM parameters to remain frozen for broad compatibility. (ii) To preserve biophysical fidelity and maximize robustness, we employ specialized loss functions targeting $C_α$-atom pairwise distances and torsion angles ($ψ, φ$) within an adversarial training framework integrated with stochastic attack simulations. (iii) Crucially, MARCO exhibits ``radioactivity'' where the watermark automatically transfers to the outputs of any pirate models trained on the watermarked data, effectively countering model extraction attacks. Comprehensive experiments demonstrate that MARCO achieves superior fidelity and robustness while successfully validating watermark transferability.
Problem

Research questions and friction points this paper is trying to address.

Protein Generative Models
Watermarking
Intellectual Property Protection
Biosecurity
Model Extraction
Innovation

Methods, ideas, or system contributions that make the work stand out.

Radioactive Watermarking
Protein Generative Models
Diffusion Models
Adversarial Training
Model Extraction Defense
šŸ”Ž Similar Papers
No similar papers found.