跳到主内容
@wquguru
精选86Google DeepMind(YouTube)产品发布/更新多源精选 ×4

Google DeepMind详解AI水印技术:从数字内容到生物分子

From deepfakes to DNA: the science of watermarking AI

原文
发到 X
推荐理由

深度访谈揭示了SynthID等工业级水印的技术取舍与跨模态落地逻辑,对关注AI治理与安全基础设施的团队极具参考价值。

Welcome back to Google Deep Mind the podcast. I'm Professor Hannah Fry. Picture [music] the scene. You are scrolling through your socials and you see some remarkable footage. The [music] up close slow motion eruption of a volcano or a tornado raging through a village or perhaps some footage of [music] a protest. I think many of us ask the same question. Is that real? Was this made by a human [music] or a machine? Well, as AI gets better at generating texts and images and audio and video, that [music] is becoming one of the most challenging questions of our time.

欢迎回到 Google DeepMind 播客。我是汉娜·弗莱教授。想象一下这个场景:你正在浏览社交媒体,看到一段惊人的视频。[音乐]近距离慢动作拍摄的火山喷发,或者龙卷风肆虐村庄的画面,又或许是抗议活动的录像。我想我们中的许多人都会问同一个问题:这是真的吗?这是人类制作的,还是机器生成的?[音乐]随着 AI 在生成文本、图像、音频和视频方面变得越来越出色,这个问题正成为我们这个时代最具挑战性的问题之一。

Except that now the answer just got a lot more complicated. [music] We are entering a world where AI can design biological molecules and structures that have never existed in [music] nature before, some of which could be designed to cause harm. So, how do you stop something dangerous [music] before it gets made? Well, the answer, it turns out, might be hidden in plain sight, embedded invisibly into the very [music] thing you're looking at or the very molecule you're about to synthesize.

只不过现在答案变得更加复杂了。[音乐]我们正在进入一个 AI 能够设计自然界中从未存在过的生物分子和结构的时代,其中一些可能被设计成造成危害。那么,如何在危险物品被制造出来之前阻止它呢?事实证明,答案可能就隐藏在众目睽睽之下,以不可见的方式嵌入到你正在查看的物体或你即将合成的分子之中。[音乐]

A watermark, not the blocky logo you see on a stock photo, something far more subtle, [music] something mathematical. And today I am joined by two people who are working on this from different angles. Pushmi [music] Kohley is VP of science at Google deep mind and one of the architects of synth ID the watermarking system now being adopted across the AI [music] industry and Jeremy Radcliffe is a biocurity researcher whose team has applied that same technology [music] to biology welcome to the podcast both of you Jeremy let's start with you watermarking anything that AI spits out I mean it sounds like a very good idea but just just break it down for me why is this helpful

一种水印,不是你在库存照片中看到的方块状标志,而是更微妙的东西,[音乐]数学层面的东西。今天我有幸邀请到两位从不同角度从事这项工作的人。普什米·科利是 Google DeepMind 的科学副总裁,也是 SynthID 水印系统的主要架构师之一,该系统目前正在整个 AI 行业得到采用;杰里米·拉德克利夫是一位生物安全研究人员,他的团队已将同样的技术应用于生物学领域。欢迎二位来到播客。杰里米,我们先从你开始。对 AI 生成的任何内容进行水印处理——我的意思是这听起来是个非常好的主意,但请为我简单解释一下,为什么这有帮助?

so for biology sort of the motivation from being able to watermarking is so that we can have provenence and say specifically where did this sequence come from and really what we're trying to differentiate is between sequences that come from things in nature versus sequences that come as products of AI systems. So specifically the the type of risk that we're thinking about in terms of AI systems is sort of an AI generated sequence that can have properties that we know to be problematic but we might not be able to identify from the sequence itself that it has these problematic properties.

对于生物学而言,进行水印处理的动机主要是为了获得溯源能力,明确说明该序列具体来自何处。我们真正试图区分的是来自自然界的序列与作为 AI 系统产物的序列。具体来说,我们在考虑 AI 系统带来的风险类型时,是指那些可能具有已知有害特性的 AI 生成序列,但我们可能无法仅从序列本身识别出这些有害特性。

And what what makes a good watermark? Because I think when people consider the phrase, they sort of think of I don't know like banknotes or like passports. Is there like rules for what counts as a good watermark?

那么,什么是好的水印?因为我认为当人们提到这个词时,他们通常会联想到钞票或护照之类的东西。对于什么样的水印才算好,有没有一些规则?

I think for us in particular, human imperceptibility is one. So making it very difficult for someone to be able to tell what portion of data has been watermarked

我认为对我们来说,人类不可感知性是一个关键因素。也就是说,要让他人很难分辨出数据的哪一部分被添加了水印。

because otherwise it would be really easy to erase.

否则,水印很容易被擦除。

Yeah. Having high detectability, so having some system that can go through and actually identify the watermark with high confidence and then also good generalizability. to being able to have at least a watermarking method that can work across a bunch of different systems rather than having to make bespoke ones for every single data type.

是的。具有高可检测性,即拥有某种系统能够以高置信度准确地识别出水印;同时还需要具备良好的泛化能力,即至少有一种水印方法能够在多种不同的系统中通用,而不是为每种数据类型都定制专属的方法。

What do you think push me? I mean, does that apply beyond biology and more broadly?

你认为这适用于哪些领域?我的意思是,这不仅限于生物学,而是更广泛地适用吗?

Yeah, I think the main uh reason why we started the whole watermarking project at deep mind almost 8 years ago now was to give a sense of uh provenence uh to what users are seeing. If you look at different modalities, whether it's text, whether it's images, whether it's videos, it was hard to imagine 10 years back that we would today be talking about systems that can create images, videos, audio, text, and proteins or enzymes that are indistinguishable from what a human or what exists in nature.

是的,我认为我们大约八年前在 DeepMind 启动整个水印项目的主要原因,是为了让用户对所看到的内容产生一种来源可信感。如果你观察不同的模态,无论是文本、图像还是视频,回想十年前,我们很难想象今天我们会讨论那些能够生成与人类创作或自然界存在的事物无法区分的图像、视频、音频、文本以及蛋白质或酶的系统。

And it it's an important sort of element for users to to give users this idea that you can really uh believe what you are seeing. So what do we need from a watermark? We need three properties. One, it should not degrade the quality otherwise basically the whole point is lost. People will not use it. The second element is robustness against attack or against transformations. If people want to remove it, it's hard to remove in the sense that even if you make changes to the signal, it will persist.

因此,向用户提供这种‘你所见之物真实可信’的概念是一个重要的要素。那么我们需要水印具备哪些特性呢?我们需要三个属性。第一,它不应降低内容质量,否则就失去了根本意义,人们就不会使用它。第二个要素是抗攻击性或抗变换能力。如果人们试图移除水印,它应该难以被移除,即使你对信号进行了修改,水印依然会存在。

And then the third requirement it's that it should be easy to use, right? It should not uh it should be easy to integrate in the signal and it's easy to detect

第三个要求是易于使用,对吧?它应该容易集成到信号中,并且易于检测。

from the signal. So those are the three sort of properties of imperceptibility, robustness and scalability that we have designed all our watermarking systems uh for w with the whole idea that users have more control and have a better view of what they are seeing or what they are sort of using or designing and so on. feels like this subject of automarking has been quite a big deal this summer

从信号中检测。因此,这就是我们在设计所有水印系统时所遵循的不可感知性、鲁棒性和可扩展性这三个属性。我们的整体理念是让用户拥有更多的控制权,并能更好地审视他们所看到、所使用或所设计的内容等。感觉这个关于自动水印(automarking)的话题今年夏天引起了相当大的关注。

but at the same time we're a few years into generative AI being accessible to the public what what's taken so long push me why is it only now that this has become so widespread when image editing software started becoming very sophisticated people were uh sort of uh very concerned about this issue of is this a real image or is has the has this been tampered with and There was a lot of work and specialized systems which could really sort of analyze an image and think and see the tiny differences that uh exist in a tampered image and can say oh yeah this was a fake image or this has been tampered with and so on.

但与此同时,生成式 AI 向公众开放已有几年了。到底是什么原因导致了这么长的延迟?请告诉我为什么直到现在它才变得如此普及?当图像编辑软件开始变得非常复杂时,人们对此问题——即这是否是一张真实图片,或者是否被篡改过——感到相当担忧。当时有许多工作和专用系统能够真正分析图像、进行思考并发现被篡改图像中存在的细微差异,从而判断“是的,这是一张假图”或“这张图已被篡改”等等。

But as generative AI became more sophisticated, those tiny differences went away.

但随着生成式 AI 变得越来越复杂,那些细微的差异消失了。

Mhm.

嗯哼。

And then that naturally sort of resulted in the question is this game over in the sense that uh humans will not have the ability uh to detect whether something is AI generated and this is where watermarking sort of came in. We said the way to sort of make sure that humans always have the ability to understand the origin of where some signal came from is by injecting a signal within it having a bias so it doesn't go away.

随后,这自然引出了一个问题:这是否意味着游戏结束了?也就是说,人类将失去检测某物是否为 AI 生成的能力。正是在这里,水印技术应运而生。我们认为,确保人类始终有能力理解某些信号来源的方法是,在其中注入一个具有偏置的信号,使其不会消失。

Even if the models are perfect

即使模型是完美的

and they have the ability to sort of generate images which are indistinguishable from what a camera would observe or what a text that a human would write. We specifically sort of put in some imperceptible things that can allow users to later detect that this was or this originated from my AI model.

并且它们具备生成与相机观察到的景象或人类撰写的文本无法区分图像的能力。我们特意加入了一些不可察觉的元素,以便用户稍后能够检测到这些内容源自我的 AI 模型。

And when you say we here, Push, I mean, you really do mean we in the literal sense, right? It was you it was you guys that came up with a solution for this one that was was scalable.

当你说‘我们’的时候,Push,你是真的在字面意义上指‘我们’吗?对吗?是你们团队提出了一个可扩展的解决方案。

Yes. So we we our team has been working on this for almost 8 years. We we started with images because people were concerned about uh these images being used for fake news, misinformation and and so on. And uh so there was uh that motivation to solve that problem. At the same time uh although the problem is extremely challenging because of the properties we just mentioned of uh robustness and imperceptibility and efficiency and scalability uh still an image is a very large amount of data.

是的。所以,我们的团队已经为此工作了近 8 年。我们从图像入手,因为人们担心这些图像会被用于虚假新闻、错误信息等等。因此,解决这个问题的动机由此产生。同时,尽管由于我们刚才提到的鲁棒性、不可感知性、效率和可扩展性等特性,这个问题极具挑战性,但图像毕竟包含大量的数据。

A 1 megapixel image has sort of uh 1 million sort of numbers or like three million numbers depending on the on how it's encoded and so on to hide information right and without changing the content. So we developed um watermarking systems for images first. Later on we had to look at the challenge of how do you do this for other modalities like text which are not as highdimensional as images

一张100万像素的图像大致包含一百万个数值,或者根据编码方式不同包含三百万个数值,以便在不改变内容的前提下隐藏信息。因此,我们首先开发了用于图像的 watermarking(水印)系统。后来,我们不得不面对如何将其应用于其他模态的挑战,比如文本,因为文本不像图像那样具有高维特性。

where actually it's a very small amount of uh uh signal right in if you

实际上,其中的信号量非常小。如果你……

it's not a million numbers in a sentence is there. Yeah, exactly. It's a few words. You can't change those sort of few words and you have to be very cautious in terms of not changing the meaning

一句话里并没有一百万个数值。是的,没错。只有几个词。你不能随意更改这些少量的词汇,并且在不能改变原意的情况下必须非常谨慎。

of of the content. And so the approaches that we developed for watermarking text were quite different and distinct from what we use for watermarking highdimensional uh signals like images and videos and and audio even. But this idea of watermarking which you guys pioneered has now been brought into law. It's essential that any generative content within the EU has to have some sort of watermarking.

对于内容的含义。因此,我们为文本水印开发的方法与我们用于高维信号(如图像、视频甚至音频)水印的方法截然不同且独具特色。但你们开创的水印理念现已纳入法律。欧盟规定,任何生成式内容都必须带有某种形式的水印。

I

我

更进一步:量化金融体系

看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力

进入量化体系 →