Skip to main content
CIC Repository

CICIoT2023: Large-Scale IoT Attack Traffic Dataset

IoT Security & Intrusion Detection Cybersecurity
3,625 views
1 min read
License
Catalog metadata: This page is a discovery record, not publisher documentation. Verify the description, schema, provenance, version, licence, and citation at the linked source before use.

Catalog Summary

"CICIoT2023 is a large-scale, flow-based network traffic dataset capturing real-time benign and malicious communications in an IoT environment composed of 105 physical devices. The dataset captures traffic traces for 33 attack scenarios grouped into seven categories: DDoS, DoS, Reconnaissance, web-based attacks, brute-force attempts, spoofing, and Mirai malware."

Catalog Notes

Overview

CICIoT2023 is a real-time IoT network traffic dataset created to foster the development and evaluation of security analytics applications in realistic IoT environments. It was collected in the Canadian Institute for Cybersecurity (CIC) IoT Lab.

Technical Details

The dataset consists of preprocessed flow-based CSV files derived from raw packet captures. It includes 33 distinct attacks grouped into seven categories (DDoS, DoS, Recon, Web-based, brute force, spoofing, and Mirai).

Collection Setup

The traffic was recorded in an extensive IoT topology composed of 105 real IoT and network devices deployed in a dedicated testbed that emulates operational IoT environments.

Recommended Research Tasks

This dataset is well suited for building and benchmarking intrusion detection systems, evaluating attack classification models, and performing feature selection or representation learning for IoT security.

Access & License

The dataset and related documentation are available from the official CIC IoT dataset page at the University of New Brunswick. Access CICIoT2023

View Data Structure

To explore column names, data types, and sample rows, visit the official dataset page on CIC Repository.

Preview on CIC Repository

Provided Citation

author = {Neto, E. C. P. and Dadkhah, S. and Ferreira, R. and Zohourian, A. and Lu, R. and Ghorbani, A. A.},
title = {{CICIoT2023: A real-time dataset and benchmark for large-scale attacks in IoT environment}},
journal = {Sensors},
year = {2023}

This citation is displayed as supplied. Automatic style conversion is disabled because structured citation metadata is not recorded.

Source metadata: CIC Repository (2023)

Indexed by IoTDataset.com on Feb 05, 2026

Review the Source Record

Confirm the licence, version, access conditions, file format, and provenance at the source before use.

Open Source Page

Related Topics & Keywords

Browse all IoT Security & Intrusion Detection datasets

Share This Research

More in IoT Security & Intrusion Detection

View All
Cybersecurity Kaggle

Bot-IoT Dataset - Large-Scale IoT Botnet Traffic with Full Packet Capture

Comprehensive large-scale IoT botnet dataset combining legitimate IoT network traffic with realistic botnet attack scenarios. Features full packet captures (PCAP) and extracted flow features for diverse attack types including DDoS, reconnaissance, theft, and DoS attacks.

Jan 23, 2026
Cybersecurity Mendeley Data

Smart Home Intrusion Detection Dataset — 7 Attack Scenarios

Smart home traffic captured under normal operation and seven multi-stage attack scenarios across heterogeneous end devices. CC BY 4.0, published 2026.

Jul 29, 2026
Cybersecurity IoTSyn Generated

Synthetic IoT Intrusion Detection Dataset — 18% Attacks

Free CC0 synthetic dataset: 500 rows of labelled network flows covering DoS, DDoS, botnet and reconnaissance traffic. 18% Attacks.

Apr 04, 2026
Cybersecurity Kaggle

N-BaIoT Dataset - IoT Botnet Attack Detection from Network Traffic

Specialized dataset for detecting IoT botnet attacks using network traffic analysis. Captures behavior of 9 real IoT devices infected with Mirai and BASHLITE malware variants. Ideal for training ML models to identify compromised IoT devices through traffic patterns.

Jan 23, 2026
Cybersecurity University

RT-IoT2022: Real-Time IoT Intrusion Detection Dataset

123,117 network flow records with 83 features from real IoT devices (MQTT, ThingSpeak, Wipro) including DDoS, SSH brute-force, and Nmap attacks for IDS model training.

Jan 12, 2026
IoT Network Security Zenodo / ArXiv

Gotham Dataset 2025: A Reproducible Large-Scale IoT Network Dataset for Intrusion Detection

Large-scale reproducible IoT network dataset with traffic from 100+ diverse IoT devices including smart home, wearable, and industrial sensors, featuring multiple attack scenarios and benign behavior for intrusion detection research.

Jan 30, 2026

Explore other topics

All topics →