Skip to main content
Kaggle

Edge-IIoTset: Comprehensive IoT & IIoT Cyber Security Dataset [~12 GB, 15 Attack Types]

IoT Security & Intrusion Detection Cybersecurity
1,173 views
2 min read
License
Catalog metadata: This page is a discovery record, not publisher documentation. Verify the description, schema, provenance, version, licence, and citation at the linked source before use.

Catalog Summary

"Realistic IoT/IIoT cybersecurity dataset supporting centralized and federated learning with 15 attack types across network, application, and protocol layers. CSV and PCAP formats (~12 GB). Available via IEEE Dataport and Kaggle. Designed for edge computing IDS research."

Catalog Notes

Overview

Edge-IIoTset is a comprehensive, realistic cybersecurity dataset for Internet of Things (IoT) and Industrial IoT (IIoT) applications, proposed to support both centralized and federated learning approaches. It was designed specifically to address the unique security challenges of edge computing environments, where heterogeneous IoT devices generate distributed traffic that must be secured with constrained resources.

The dataset captures 15 distinct attack types spanning multiple threat layers including network-level attacks (DoS/DDoS), application-layer attacks (MQTT/CoAP protocol abuse, web attacks), and reconnaissance and injection attacks. Traffic was collected from a diverse IoT testbed incorporating temperature sensors, soil moisture sensors, pH sensors, water level detection sensors, ultrasonic sensors, flame sensors, heart rate sensors, IR sensors, pressure sensors, and Raspberry Pi devices.

The raw PCAP files were pre-processed and converted to CSV format. The compressed archive is approximately 1.5 GB, expanding to ~12 GB uncompressed. The dataset is downloadable from IEEE Dataport and mirrored on Kaggle for convenience.

Column Schema

ColumnDescription
frame.timePacket capture timestamp.
ip.src / ip.dstSource and destination IP addresses.
tcp.srcport / tcp.dstportSource and destination TCP port numbers.
http.request.methodHTTP request method where applicable.
mqtt.topicMQTT topic string where applicable.
Attack_labelBinary attack label (0 = normal, 1 = attack).
Attack_typeSpecific attack type label (15 categories).

Key Statistics

  • Attack Types: 15 categories across network, application, and protocol layers
  • IoT Device Types: 12+ sensor types including temperature, pH, soil moisture, heart rate, and Raspberry Pi
  • File Format: CSV (pre-processed from PCAP)
  • Compressed Size: ~1.5 GB; Uncompressed: ~12 GB
  • Supported Tasks: Centralized ML and federated learning IDS
  • Published: 2022

Use Cases

  • Edge-computing-aware IoT intrusion detection and anomaly detection
  • Federated learning model benchmarking for distributed IoT security
  • Multi-layer attack classification across MQTT, CoAP, HTTP, and network protocols
  • IIoT sensor data anomaly and injection attack detection

Source & Attribution

Edge-IIoTset was proposed by Mohamed Amine Ferrag and colleagues and published in IEEE Access (2022). The dataset is officially hosted on IEEE Dataport and is also available via Kaggle. It is one of the most cited recent IoT/IIoT cybersecurity datasets for edge and federated learning research.

Data Preview

ip.srcip.dstmqtt.topicAttack_typeAttack_label
192.168.0.24192.168.0.1home/tempNormal0
192.168.0.24198.51.100.5-DDoS_HTTP1
192.168.0.3110.0.0.2-DoS_TCP1
192.168.0.2810.0.0.9sensor/phMQTT_Publish1
192.168.0.24192.168.0.1home/humidityNormal0

Showing first few rows for preview

Cite This Dataset

Ferrag, Mohamed Amine, Friha, Othmane, Hamouda, Djallel, Maglaras, Leandros, & Janicke, Helge (2022). Edge-IIoTset: A New Comprehensive Realistic Cyber Security Dataset of IoT and IIoT Applications for Centralized and Federated Learning. IEEE Access. [Dataset]. IEEE. https://www.kaggle.com/datasets/mohamedamineferrag/edgeiiotset-cyber-security-dataset-of-iot-iiot

Source metadata: IEEE (2022)

Indexed by IoTDataset.com on Apr 13, 2026

Review the Source Record

Confirm the licence, version, access conditions, file format, and provenance at the source before use.

Open Source Page

Related Topics & Keywords

Browse all IoT Security & Intrusion Detection datasets

Share This Research

More in IoT Security & Intrusion Detection

View All
Network Security University

CICIoT2023: Real-Time IoT Attack Dataset [47M+ Labeled Flows, 33 Attack Types]

Large-scale IoT cybersecurity dataset with 47M+ labeled network flows from 105 real IoT devices across 33 attack types in 7 categories. PCAP and CSV formats. Built for IDS/IPS development and ML-based IoT traffic classification research.

Apr 13, 2026
Network Security Kaggle

IoTID20: IoT Network Intrusion Dataset [625K Flows, 4 Attack Types, 83 Features]

Smart-home-derived IoT botnet dataset with 625,783 labeled flow records and 83 network features. Covers DoS, Mirai, MITM, and Scan attacks from EZVIZ and SKT NGU Wi-Fi cameras. CSV format. Supports binary, category, and sub-category IDS classification tasks.

Apr 13, 2026
Network Security University

TON_IoT: UNSW Telemetry, Network & OS Attack Traces [Multi-Source IIoT]

Heterogeneous IoT/IIoT dataset from UNSW Canberra Cyber Range with network traffic, Windows/Linux OS traces, and IoT sensor telemetry. Labeled for 9 attack types including DoS, DDoS, ransomware, and XSS. CSV and PCAP formats. Benchmark for AI-based IDS evaluation.

Apr 13, 2026
Network Security UCI

RT-IoT2022: Real-Time IoT IDS Dataset [41 Features, Multi-Attack]

Real-time IoT network security dataset from a live IoT infrastructure with 41 bidirectional flow features. Includes ThingSpeak-LED, Wipro-Bulb, and MQTT-Temp devices with SSH brute force, DDoS (Hping/Slowloris), and Nmap attack scenarios. CSV format. Used for adaptive IDS development.

Apr 13, 2026
Cybersecurity Zenodo

IoT-23; Labeled IoT Malware & Benign Traffic [325M Flows, 500+ Hours]

Real IoT malware traffic dataset with 325M labeled network flows from 20 malware and 3 benign device captures over 500+ hours. PCAP and Zeek conn.log formats. Used for IoT botnet detection, malware traffic classification, and ML security research.

Apr 13, 2026
Cybersecurity UCI

N-BaIoT: Real IoT Botnet Traffic from 9 Infected Devices [7M Records, Mirai & BASHLITE]

Real IoT botnet traffic dataset from 9 commercial devices (webcams, routers, thermostats) authentically infected by Mirai and BASHLITE. Over 7M records, 115 statistical features. CSV format. Benchmark for deep-learning-based IoT anomaly and botnet detection.

May 03, 2026

Explore other topics

All topics →