arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

MARCO:蛋白质生成模型的放射性水印

MARCO: The Radioactive Watermark for Protein Generative Models

Huajie Chen, Xin Guo, Yuchen Shi, Yuchen Zhong, Minhui Xue, Chi Liu, Congcong Zhu, Kun Gao, Minfeng Qi, Tianqing Zhu

arXiv 2610.08316首次发表:更新:

发表机构

Faculty of Data Science, City University of Macau; CSIRO; Responsible AI Research (RAIR) Centre, Adelaide University(澳门城市大学数据科学学院; 澳大利亚联邦科学与工业研究组织; 阿德莱德大学负责任人工智能研究(RAIR)中心)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对蛋白质生成模型的双重用途风险,提出首个放射性水印框架MARCO,通过双层防御在扩散过程中嵌入水印,实现知识产权保护和生物安全溯源,并验证了水印可转移性。

AI 中文摘要

蛋白质生成模型(PGMs)通过从序列数据设计复杂的3D蛋白质结构,彻底改变了结构生物学。然而,这一突破带来了双重用途的挑战,使高价值的PGM面临经济风险(如未经授权的模型提取)和生物安全威胁(如生物危害合成)。为缓解这些威胁,我们提出了MARCO(构象水印),这是首个专门针对PGM的放射性水印框架。MARCO建立了双层防御,同时保护知识产权并确保潜在生物安全滥用的取证可追溯性。(i)为保持效率,MARCO通过辅助编码器-解码器在扩散反向去噪过程中迭代嵌入水印,使原始PGM参数保持冻结以实现广泛兼容性。(ii)为保持生物物理保真度并最大化鲁棒性,我们在集成随机攻击模拟的对抗训练框架中,采用针对Cα原子对距离和二面角(ψ, φ)的专用损失函数。(iii)关键的是,MARCO表现出“放射性”,即水印自动转移到任何基于带水印数据训练的盗版模型的输出上,有效抵御模型提取攻击。综合实验表明,MARCO在实现优越保真度和鲁棒性的同时,成功验证了水印的可转移性。

英文摘要

Protein Generative Models (PGMs) have revolutionized structural biology by enabling the design of complex 3D protein structures from sequence data. However, this breakthrough introduces a dual-use challenge, exposing high-value PGMs to economic risks like unauthorized model extraction and biosecurity threats such as biohazard synthesis. To mitigate these threats, we propose \textbf{MARCO} (\textsc{COnformation waterMARk}), the first radioactive watermarking framework specifically tailored for PGMs. MARCO establishes a Dual-Layer defense that simultaneously protects intellectual property and ensures the forensic traceability of potential biosecurity misuses. (i) To preserve efficiency, MARCO iteratively embeds watermarks during diffusion reverse denoising via an auxiliary encoder-decoder, allowing the original PGM parameters to remain frozen for broad compatibility. (ii) To preserve biophysical fidelity and maximize robustness, we employ specialized loss functions targeting $C_α$-atom pairwise distances and torsion angles ($ψ, ϕ$) within an adversarial training framework integrated with stochastic attack simulations. (iii) Crucially, MARCO exhibits ``radioactivity'' where the watermark automatically transfers to the outputs of any pirate models trained on the watermarked data, effectively countering model extraction attacks. Comprehensive experiments demonstrate that MARCO achieves superior fidelity and robustness while successfully validating watermark transferability.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑