Realistic IoT/IIoT cybersecurity dataset supporting centralized and federated learning with 15 attack types across network, application, and protocol layers. CSV and PCAP formats (~12 GB). Available via IEEE Dataport and Kaggle. Designed for edge computing IDS research.
ToN_IoT is a large-scale dataset featuring heterogeneous data from IoT sensors, operating systems, and network traffic for advanced intrusion detection research in Industry 4.0.
pNEUMA is a large-scale dataset of naturalistic vehicle trajectories from half a million vehicles in Athens, Greece, collected via a swarm of drones for traffic congestion research.
A comprehensive and realistic IoT dataset generated by the Canadian Institute for Cybersecurity (CIC) for profiling, detecting, and characterizing multi-vector IoT attacks in a real network topology.
Network-traffic dataset on Mendeley Data documenting DDoS attacks against the Fibaro Home Center 3 smart-home controller; PCAP and CSV formats are provided. [page:4][web:52]
IoT-23 provides labeled IoT network-traffic captures, including 20 malware scenarios and 3 benign IoT captures, intended to support machine-learning research on IoT security.
A real-world cybersecurity dataset capturing MQTT-based IoT network traffic with live attacks and anomalous behavior. Collected from an active deployment with multiple attack types including DoS, SlowITe, and malformed injections. Provides both raw and preprocessed CSV files with rich metadata for intrusion detection and anomaly classification research.
CICIoT2023 is a large-scale, flow-based network traffic dataset capturing real-time benign and malicious communications in an IoT environment composed of 105 physical devices. The dataset captures traffic traces for 33 attack scenarios grouped into seven categories: DDoS, DoS, Reconnaissance, web-based attacks, brute-force attempts, spoofing, and Mirai malware.
IoT-DH is a real-world IoT DDoS honeypot dataset collected from a honeypot deployment and converted from PCAP to CSV with traffic features and labels for DDoS classification, identification, and detection tasks.
Multimodal dataset combining Text-to-SQL natural language queries with IoT network traffic classification, featuring 10,985 SQL training examples and labeled network traffic (benign/malicious) from IoT-23 and Smart Building sensors for NLP and security research.