跳到正文
arXiv:cs.AI· Huajie Chen, Xin Guo, Yuchen Shi, Yuchen Zhong, Minhui Xue, Chi Liu, Congcong Zhu, Kun Gao, Minfeng Qi, Tianqing Zhu·· 6 小时前AI 评分38

MARCO:面向蛋白质生成模型的放射性水印框架

MARCO: The Radioactive Watermark for Protein Generative Models

AI 导读

MARCO 是首个专为蛋白质生成模型(PGM)设计的放射性水印框架,通过在扩散逆向去噪过程中迭代嵌入水印,保持原始 PGM 参数冻结以兼容现有模型。针对 Cα 原子对距离和扭转角(ψ, φ)采用专用损失函数,结合对抗训练与随机攻击模拟,兼顾生物物理保真度与鲁棒性。水印具备"放射性",可自动转移至基于水印数据训练的盗版模型输出,有效对抗模型提取攻击,同时实现知识产权保护与生物安全溯源。

正文

View PDF HTML (experimental)

Abstract:Protein Generative Models (PGMs) have revolutionized structural biology by enabling the design of complex 3D protein structures from sequence data. However, this breakthrough introduces a dual-use challenge, exposing high-value PGMs to economic risks like unauthorized model extraction and biosecurity threats such as biohazard synthesis. To mitigate these threats, we propose \textbf{MARCO} (\textsc{COnformation waterMARk}), the first radioactive watermarking framework specifically tailored for PGMs. MARCO establishes a Dual-Layer defense that simultaneously protects intellectual property and ensures the forensic traceability of potential biosecurity misuses. (i) To preserve efficiency, MARCO iteratively embeds watermarks during diffusion reverse denoising via an auxiliary encoder-decoder, allowing the original PGM parameters to remain frozen for broad compatibility. (ii) To preserve biophysical fidelity and maximize robustness, we employ specialized loss functions targeting $C_\alpha$-atom pairwise distances and torsion angles ($\psi, \phi$) within an adversarial training framework integrated with stochastic attack simulations. (iii) Crucially, MARCO exhibits ``radioactivity'' where the watermark automatically transfers to the outputs of any pirate models trained on the watermarked data, effectively countering model extraction attacks. Comprehensive experiments demonstrate that MARCO achieves superior fidelity and robustness while successfully validating watermark transferability.
Subjects: Cryptography and Security (cs.CR); Artificial Intelligence (cs.AI)
Cite as: arXiv:2610.08316 [cs.CR]
  (or arXiv:2610.08316v1 [cs.CR] for this version)
  https://doi.org/10.48550/arXiv.2610.08316

arXiv-issued DOI via DataCite (pending registration)

Submission history

From: Huajie Chen [view email]
[v1] Tue, 6 Oct 2026 13:18:22 UTC (10,011 KB)

来源:arXiv:cs.AI · arxiv.org