Skip to main content
Zenodo / ArXiv

Gotham Dataset 2025: A Reproducible Large-Scale IoT Network Dataset for Intrusion Detection

IoT Security & Intrusion Detection IoT Network Security
1,118 views
2 min read
License
Catalog metadata: This page is a discovery record, not publisher documentation. Verify the description, schema, provenance, version, licence, and citation at the linked source before use.

Catalog Summary

"Large-scale reproducible IoT network dataset with traffic from 100+ diverse IoT devices including smart home, wearable, and industrial sensors, featuring multiple attack scenarios and benign behavior for intrusion detection research."

Catalog Notes

Overview

The Gotham Dataset 2025 is a comprehensive, reproducible IoT network security dataset designed to advance intrusion detection and security research in large-scale heterogeneous IoT environments.

Data Collection

  • Network traffic captured from a testbed containing over 100 diverse IoT devices spanning smart home (cameras, thermostats, lights), wearables (fitness trackers), industrial sensors, and smart appliances.
  • Collected in a distributed manner with traffic captured separately for each device at the IoT gateway interface, enabling device-level analysis.
  • The dataset includes both normal operational behavior across multiple days and various attack scenarios injected into the network.

Attack Scenarios

  • Botnet attacks: Mirai and other IoT botnets performing DDoS, scanning, and propagation.
  • Reconnaissance: Network scanning and device fingerprinting attacks.
  • Man-in-the-Middle: Traffic interception and manipulation between IoT devices and cloud services.
  • Data exfiltration: Unauthorized data transmission from compromised devices.

Dataset Structure

  • Over 23.8 GB of network traffic data in PCAP and processed CSV formats.
  • Per-device traffic captures enabling fine-grained analysis of individual IoT device behavior.
  • Rich flow-based features including packet sizes, inter-arrival times, protocol distributions, and behavioral statistics.
  • Labeled data with attack types, timestamps, and device identifiers.

Use Cases

  • Developing and benchmarking IoT-specific intrusion detection systems at scale.
  • Research on device fingerprinting, behavioral profiling, and anomaly detection in heterogeneous IoT networks.
  • Evaluating machine learning models for IoT security in realistic multi-device environments.

View Data Structure

To explore column names, data types, and sample rows, visit the official dataset page on Zenodo / ArXiv.

Preview on Zenodo / ArXiv

Cite This Dataset

Belarbi, Othmane, & others (2025). Gotham Dataset 2025: A Reproducible Large-Scale IoT Network Dataset for Intrusion Detection and Security Research. [Dataset]. Zenodo. https://doi.org/10.5281/zenodo.14502760

Source metadata: Zenodo (2025) · DOI: 10.5281/zenodo.14502760

Indexed by IoTDataset.com on Jan 30, 2026

Review the Source Record

Confirm the licence, version, access conditions, file format, and provenance at the source before use.

Open Source Page

Related Topics & Keywords

Browse all IoT Security & Intrusion Detection datasets

Share This Research

More in IoT Security & Intrusion Detection

View All
Cybersecurity Mendeley Data

Smart Home Intrusion Detection Dataset — 7 Attack Scenarios

Smart home traffic captured under normal operation and seven multi-stage attack scenarios across heterogeneous end devices. CC BY 4.0, published 2026.

Jul 29, 2026
Cybersecurity IoTSyn Generated

Synthetic IoT Intrusion Detection Dataset — 18% Attacks

Free CC0 synthetic dataset: 500 rows of labelled network flows covering DoS, DDoS, botnet and reconnaissance traffic. 18% Attacks.

Apr 04, 2026
Cybersecurity Kaggle

Bot-IoT Dataset - Large-Scale IoT Botnet Traffic with Full Packet Capture

Comprehensive large-scale IoT botnet dataset combining legitimate IoT network traffic with realistic botnet attack scenarios. Features full packet captures (PCAP) and extracted flow features for diverse attack types including DDoS, reconnaissance, theft, and DoS attacks.

Jan 23, 2026
Cybersecurity / IoT Network Security University (Canadian Institute for Cybersecurity)

CICIDS2017 - Comprehensive Network Intrusion Detection Dataset

The most cited cybersecurity dataset worldwide with 2.8+ million network flows capturing 14 types of realistic attack scenarios including DDoS, brute force, botnet, and web attacks alongside benign traffic for advanced intrusion detection systems.

Jan 20, 2026
Cybersecurity Zenodo

Gotham Dataset 2025 - Large-Scale IoT Network Intrusion Detection

Reproducible large-scale IoT network dataset from 78 emulated devices using MQTT, CoAP, and RTSP protocols. Includes benign and malicious traffic with DoS, brute force, scanning, and C&C attacks in PCAP and CSV formats.

Mar 20, 2026
Cybersecurity CIC Repository

CICIoT2023: Large-Scale IoT Attack Traffic Dataset

CICIoT2023 is a large-scale, flow-based network traffic dataset capturing real-time benign and malicious communications in an IoT environment composed of 105 physical devices. The dataset captures traffic traces for 33 attack scenarios grouped into seven categories: DDoS, DoS, Reconnaissance, web-based attacks, brute-force attempts, spoofing, and Mirai malware.

Feb 05, 2026

Explore other topics

All topics →