Ian J. Goodfellow (born 1987) is an American computer scientist best known for inventing the generative adversarial network (GAN), the framework in which a generator network and a discriminator network are trained against each other until the generator's output is indistinguishable from real data.1 Introduced at NeurIPS in 2014 while he was a doctoral student at the Université de Montréal, the GAN became one of the defining generative modeling ideas of the deep learning era and the basis of a large fraction of photorealistic image synthesis before diffusion models took over that role.2 He is also the first author of Deep Learning (2016), the field's standard textbook, written with Yoshua Bengio and Aaron Courville.3

His other major line of work is the security of machine learning systems: with Jonathon Shlens and Christian Szegedy he introduced the fast gradient sign method and the linearity account of adversarial examples, showing that state-of-the-art classifiers could be reliably fooled by imperceptible input perturbations.4 Across a career at Google Brain, OpenAI, Apple, and Google DeepMind, he has worked mostly outside the public eye since 2019, and his public record rests on the pre-2017 research and the textbook.1

Career

Goodfellow completed bachelor's and master's degrees in computer science at Stanford University, where he worked with Andrew Ng, and received his PhD in machine learning from the Université de Montréal in February 2015, supervised by Yoshua Bengio and Aaron Courville; his thesis studied deep learning of representations for computer vision.1 Work he had done with Google colleagues during his studies produced a Street View transcription system that read multi-digit address numbers from photographs and, according to the paper, solved the hardest category of Google's reCAPTCHA at better than 99 percent accuracy.5

He joined Google Brain full-time after the doctorate, left in March 2016 as one of the first research hires of the newly founded OpenAI, where he overlapped with chief scientist Ilya Sutskever, and returned to Google a year later.1 In 2019 he moved to Apple as director of machine learning in the Special Projects Group. He resigned in 2022 after Apple ordered corporate staff back to the office, a departure first reported by The Verge as a protest of the return-to-work policy, and joined Google DeepMind as a research scientist shortly afterward.6 He left Google in 2025; as of June 2026, his LinkedIn profile indicated he was co-founding a startup.1

YearsRoleOrganization
2015-2016Research scientistGoogle Brain
2016-2017Research scientistOpenAI
2017-2019Staff research scientistGoogle
2019-2022Director of machine learning, Special Projects GroupApple
2022-2025Research scientistGoogle DeepMind

Research contributions

Generative adversarial networks

The GAN paper framed generative modeling as a two-player game: a discriminator is trained as a binary classifier between real and generated samples under a cross-entropy objective, while the generator is trained, by backpropagation through the discriminator, to maximize the discriminator's error.2 Goodfellow has recounted that the idea came to him in a single evening at a Montreal bar in 2014, in argument with fellow students about how to generate images, and that he coded the first working version that night; the account comes from a 2018 MIT Technology Review profile.7 The framework powered the subsequent image-synthesis lineage, from BigGAN's high-resolution ImageNet samples in 2018 to NVIDIA's StyleGAN family,8 while also enabling deepfakes, a misuse Goodfellow himself flagged early.1 Image generation has since migrated largely to diffusion models such as Stable Diffusion and Imagen, but adversarial training of this form remains a standard tool across domains. Related contributions from his doctoral years include the maxout activation, designed to pair with dropout,9 and, at OpenAI, the practical training improvements of the 2016 "Improved Techniques" paper and his widely used NeurIPS 2016 GAN tutorial.10

Adversarial examples

With Shlens and Szegedy at Google, Goodfellow showed in 2015 that the vulnerability of deep classifiers to small, worst-case perturbations stems largely from their excessive linearity rather than from overfitting, and derived the fast gradient sign method, a one-step attack that remains the baseline for the field of adversarial robustness.4 A follow-up with Alexey Kurakin and Samy Bengio demonstrated that adversarial perturbations survive printing and rephotographing, moving the problem from a numerical curiosity to a physical security concern.11

Textbook and synthesis

Deep Learning (MIT Press, 2016), written with Bengio and Courville and freely readable online, became the default graduate text for the field, and Goodfellow wrote the deep learning chapter of the fourth edition of Russell and Norvig's Artificial Intelligence: A Modern Approach (2020).13

Selected publications

  1. Goodfellow, I. J., Warde-Farley, D., Mirza, M., Courville, A., and Bengio, Y., "Maxout Networks," arXiv:1302.4389, ICML 2013. An activation function built to exploit dropout's model-averaging behavior.
  2. Goodfellow, I. J., Bulatov, Y., Ibarz, J., Arnoud, S., and Shet, V., "Multi-digit Number Recognition from Street View Imagery using Deep Convolutional Neural Networks," arXiv:1312.6082, ICLR 2014. The Street View transcription system.
  3. Goodfellow, I. J., et al., "Generative Adversarial Nets," arXiv:1406.2661, NeurIPS 2014. Introduced the GAN framework.
  4. Goodfellow, I. J., Shlens, J., and Szegedy, C., "Explaining and Harnessing Adversarial Examples," arXiv:1412.6572, ICLR 2015. The fast gradient sign method and the linearity hypothesis.
  5. Salimans, T., Goodfellow, I., et al., "Improved Techniques for Training GANs," arXiv:1606.03498, NeurIPS 2016. Feature matching, minibatch discrimination, and other stabilizations.
  6. Goodfellow, I., Bengio, Y., and Courville, A., "Deep Learning," MIT Press, 2016. The standard graduate textbook of the field.
  7. Goodfellow, I., "NIPS 2016 Tutorial: Generative Adversarial Networks," arXiv:1701.00160, 2017. The reference tutorial on GAN theory and practice.
  8. Kurakin, A., Goodfellow, I., and Bengio, S., "Adversarial Examples in the Physical World," arXiv:1607.02533, 2017. Showed adversarial examples persist through printing and photography.

See also

References


  1. "Ian Goodfellow," Wikipedia, accessed July 2026. 

  2. Goodfellow, I. J., Pouget-Abadie, J., Mirza, M., Xu, B., Warde-Farley, D., Ozair, S., Courville, A., and Bengio, Y., "Generative Adversarial Nets," arXiv:1406.2661, NeurIPS 2014. 

  3. Goodfellow, I., Bengio, Y., and Courville, A., "Deep Learning," MIT Press, November 2016. 

  4. Goodfellow, I. J., Shlens, J., and Szegedy, C., "Explaining and Harnessing Adversarial Examples," arXiv:1412.6572, ICLR 2015. 

  5. Goodfellow, I. J., Bulatov, Y., Ibarz, J., Arnoud, S., and Shet, V., "Multi-digit Number Recognition from Street View Imagery using Deep Convolutional Neural Networks," arXiv:1312.6082, ICLR 2014. 

  6. The Verge, report on Goodfellow's departure from Apple over its return-to-office policy, May 2022; "Ian Goodfellow," Wikipedia, accessed July 2026. 

  7. Giles, M., "The GANfather: The Man Who's Given Machines the Gift of Imagination," MIT Technology Review, February 2018. 

  8. Karras, T., Laine, S., and Aila, T., "A Style-Based Generator Architecture for Generative Adversarial Networks," arXiv:1812.04948, December 2018. 

  9. Goodfellow, I. J., Warde-Farley, D., Mirza, M., Courville, A., and Bengio, Y., "Maxout Networks," arXiv:1302.4389, ICML 2013. 

  10. Salimans, T., Goodfellow, I., et al., "Improved Techniques for Training GANs," arXiv:1606.03498, NeurIPS 2016. 

  11. Kurakin, A., Goodfellow, I., and Bengio, S., "Adversarial Examples in the Physical World," arXiv:1607.02533, 2017.