Large-scale distributed IoT IDS benchmark with traffic captured at individual device interfaces across 78 heterogeneous smart city IoT devices using the Gotham testbed. PCAP and CSV. Published January 2026 on Zenodo. Designed for federated learning and decentralised IDS research.
Agricultural IoT network intrusion dataset with 1.31 million labeled flow records (532 MB) emulating a real AG-IoT farm environment. Covers crop health, weather, and soil condition data with network attack scenarios. CSV via Zenodo. Used for smart farming security research.
Large-scale IoT cybersecurity dataset with 47M+ labeled network flows from 105 real IoT devices across 33 attack types in 7 categories. PCAP and CSV formats. Built for IDS/IPS development and ML-based IoT traffic classification research.
Heterogeneous IoT/IIoT dataset from UNSW Canberra Cyber Range with network traffic, Windows/Linux OS traces, and IoT sensor telemetry. Labeled for 9 attack types including DoS, DDoS, ransomware, and XSS. CSV and PCAP formats. Benchmark for AI-based IDS evaluation.
Real IoT malware traffic dataset with 325M labeled network flows from 20 malware and 3 benign device captures over 500+ hours. PCAP and Zeek conn.log formats. Used for IoT botnet detection, malware traffic classification, and ML security research.
Real-time IoT network security dataset from a live IoT infrastructure with 41 bidirectional flow features. Includes ThingSpeak-LED, Wipro-Bulb, and MQTT-Temp devices with SSH brute force, DDoS (Hping/Slowloris), and Nmap attack scenarios. CSV format. Used for adaptive IDS development.
Realistic IoT/IIoT cybersecurity dataset supporting centralized and federated learning with 15 attack types across network, application, and protocol layers. CSV and PCAP formats (~12 GB). Available via IEEE Dataport and Kaggle. Designed for edge computing IDS research.
BCCC-IoT-IDS-Zwave-2025 is a behavior-centric cybersecurity dataset focusing on Z-wave protocol vulnerabilities and intrusion detection for modern smart home automation systems.
RT-IoT2022 is a network traffic dataset specifically derived from a real-time IoT testbed containing smart home devices. It includes both normal traffic and various common network attacks.
The Gotham Dataset is a large-scale, reproducible benchmark for evaluating decentralized Intrusion Detection Systems (IDS) and Federated Learning in virtualized smart cities. It captures interface-level network traffic from 78 heterogeneous IoT devices, including complex attack vectors like Mirai botnets, Merlin C2 traffic, and CoAP amplification, preserving the non-IID nature of edge data for realistic AI security training.