Skip to main content
Research Paper

Federated IoT Intrusion Detection Dataset - Privacy-Preserving Security

IoT Security & Intrusion Detection Cybersecurity
1,070 views
2 min read
License
Catalog metadata: This page is a discovery record, not publisher documentation. Verify the description, schema, provenance, version, licence, and citation at the linked source before use.

Catalog Summary

"Dataset for evaluating federated learning approaches to IoT intrusion detection published in Nature Scientific Reports January 2026. Features distributed network traffic from multiple IoT deployments with privacy constraints and decentralized learning evaluation metrics."

Catalog Notes

Dataset Overview

This pioneering dataset published in Nature Scientific Reports in January 2026 addresses the critical challenge of IoT security in privacy-sensitive environments. It enables research into federated learning approaches where intrusion detection models are trained across distributed IoT networks without centralizing raw data.

Distributed Network Architecture

The dataset simulates multiple independent IoT deployments:

  • Number of Nodes: 10+ independent IoT network sites
  • Device Diversity: Each site contains different device types and manufacturers
  • Network Topologies: Varied architectures (star, mesh, hierarchical)
  • Geographic Distribution: Simulated sites in different regions with varying threat landscapes

Privacy-Preserving Data Structure

Local Network Traffic

Each site provides:

  • Flow-Based Features: Aggregated traffic statistics without raw packets
  • Attack Labels: Local intrusion detection annotations
  • Site Metadata: Anonymous identifiers and configuration parameters

Federated Learning Metrics

Performance measures for distributed training:

  • Communication Rounds: Number of model update exchanges
  • Model Convergence: Accuracy improvement across federation rounds
  • Data Heterogeneity: Statistical divergence between sites
  • Privacy Budget: Differential privacy parameters (epsilon, delta)

Attack Coverage

Each site contains varying proportions of attack types:

  • DDoS and DoS attacks
  • Port scanning and reconnaissance
  • MITM attacks
  • Botnet command-and-control traffic
  • Data exfiltration attempts

The heterogeneous attack distribution tests federated models' ability to generalize across diverse threat environments.

Research Contributions

Dataset-Centric Evaluation

The publication emphasizes evaluating federated learning algorithms based on data characteristics rather than just model architectures, providing insights into when federated approaches outperform centralized training.

Benchmark Results

Baseline performance for multiple federated learning algorithms:

  • FedAvg (Federated Averaging)
  • FedProx (Federated Proximal)
  • SCAFFOLD (Stochastic Controlled Averaging)
  • FedOpt (Federated Optimization)

Practical Applications

  • Multi-Organization Security: Collaborative threat detection across competing organizations without sharing sensitive data
  • GDPR Compliance: Privacy-preserving security analytics meeting regulatory requirements
  • Edge-Cloud Hybrid: Distributed learning between edge devices and cloud infrastructure
  • Continuous Adaptation: Models improving over time through federated updates without data movement

Academic Significance

Published in Nature with rigorous peer review, this dataset advances both IoT security and privacy-preserving machine learning fields. It provides reproducible benchmarks for evaluating federated learning in real-world IoT security scenarios.

View Data Structure

To explore column names, data types, and sample rows, visit the official dataset page on Research Paper.

Preview on Research Paper

Cite This Dataset

The dataset creators ask users of this dataset to cite the accompanying paper. Use one of the verified formats below.

Al-Essa, M., Andresini, G., Appice, A., & Malerba, D. (2025). Dataset-centric evaluation of federated intrusion detection models in IoT networks. Scientific Reports, 15(1), 2168. https://doi.org/10.1038/s41598-025-32567-w

Source metadata: Nature Publishing Group (2025) · DOI: 10.1038/s41598-025-32567-w

Indexed by IoTDataset.com on Jan 24, 2026

Review the Source Record

Confirm the licence, version, access conditions, file format, and provenance at the source before use.

Open Source Page

Related Topics & Keywords

Browse all IoT Security & Intrusion Detection datasets

Share This Research

More in IoT Security & Intrusion Detection

View All
Cybersecurity Research Paper

MU-IoT - Comprehensive IoT Network Intrusion Dataset 2024

New realistic IoT network intrusion dataset (MU-IoT) with comprehensive attack scenarios for cybersecurity research. Published in IEEE 2024 with 4+ citations. Covers multiple IoT protocols and device types.

Jan 22, 2026
Cybersecurity Frontiers

TRUSTLab: IoT/Edge Intrusion Detection Flow Dataset

About 4.6 million labelled bi-flows with 80 CICFlowMeter features, covering 15 attack families plus benign traffic in 16 single-class files. CC BY 4.0.

Jul 29, 2026
Cybersecurity / IoT Network Security University (Canadian Institute for Cybersecurity)

CICIDS2017 - Comprehensive Network Intrusion Detection Dataset

The most cited cybersecurity dataset worldwide with 2.8+ million network flows capturing 14 types of realistic attack scenarios including DDoS, brute force, botnet, and web attacks alongside benign traffic for advanced intrusion detection systems.

Jan 20, 2026
Cybersecurity Mendeley Data

Smart Home Intrusion Detection Dataset — 7 Attack Scenarios

Smart home traffic captured under normal operation and seven multi-stage attack scenarios across heterogeneous end devices. CC BY 4.0, published 2026.

Jul 29, 2026
Cybersecurity University

MedBIoT — Medium-Sized IoT Botnet IDS Dataset [83 devices]

IoT botnet IDS dataset using 83 real and emulated devices with Mirai, BashLite, and Torii traffic. Raw PCAP files support botnet and anomaly detection research.

Jun 02, 2026
Cybersecurity IoTSyn Generated

Synthetic IoT Intrusion Detection Dataset — 18% Attacks

Free CC0 synthetic dataset: 500 rows of labelled network flows covering DoS, DDoS, botnet and reconnaissance traffic. 18% Attacks.

Apr 04, 2026

Explore other topics

All topics →