Skip to main content
Kaggle

Gotham Dataset 2025: Large-Scale Federated IoT IDS Benchmark

IoT Security & Intrusion Detection Cybersecurity
607 views
1 min read
License
Catalog metadata: This page is a discovery record, not publisher documentation. Verify the description, schema, provenance, version, licence, and citation at the linked source before use.

Catalog Summary

"The Gotham Dataset is a large-scale, reproducible benchmark for evaluating decentralized Intrusion Detection Systems (IDS) and Federated Learning in virtualized smart cities. It captures interface-level network traffic from 78 heterogeneous IoT devices, including complex attack vectors like Mirai botnets, Merlin C2 traffic, and CoAP amplification, preserving the non-IID nature of edge data for realistic AI security training."

Catalog Notes

Overview

The Gotham Dataset 2025 is designed to move beyond centralized security models by providing granular, device-level traffic captures from a virtualized urban IoT infrastructure. It is specifically structured to support Federated Learning (FL) research where data remains local to each node.

What’s inside

  • Data modalities: Structured CSV files containing extracted network features from packet captures.
  • Scale: 78 unique IoT devices including sensors, actuators, and controllers.
  • Metadata: Device IDs, interface identifiers, and detailed attack timestamps.

Collection / Setup

  • Generated using the open-source Gotham testbed for high reproducibility.
  • Captures traffic at the individual node interface level to maintain data skew (non-IID).

Labels / Targets

  • Attack types: Mirai Botnet, Merlin C2 (HTTP/1-3/QUIC), Masscan, Nmap, CoAP reflection, and various UDP/TCP Floods.

Recommended tasks

  • Federated Learning benchmarking
  • Anonymized intrusion detection
  • Distributed anomaly detection
  • Privacy-preserving AI validation

Limitations

  • Data is synthetic/simulated via a testbed rather than physical urban sensors.
  • Requires concatenation for centralized learning tasks.

Access & License

Official page

View Data Structure

To explore column names, data types, and sample rows, visit the official dataset page on Kaggle.

Preview on Kaggle

Cite This Dataset

Belarbi, O., Spyridopoulos, T., Anthi, E., Rana, O., Carnelli, P., & Khan, A. (2025). Gotham Dataset 2025: A Reproducible Large-Scale IoT Network Dataset for Intrusion Detection and Security Research. [Dataset]. Zenodo. https://doi.org/10.5281/zenodo.14502760

Source metadata: Zenodo (2025) · DOI: 10.5281/zenodo.14502760

Indexed by IoTDataset.com on Feb 05, 2026

Review the Source Record

Confirm the licence, version, access conditions, file format, and provenance at the source before use.

Open Source Page

Related Topics & Keywords

Browse all IoT Security & Intrusion Detection datasets

Share This Research

More in IoT Security & Intrusion Detection

View All
Cybersecurity Zenodo

IoT-23; Labeled IoT Malware & Benign Traffic [325M Flows, 500+ Hours]

Real IoT malware traffic dataset with 325M labeled network flows from 20 malware and 3 benign device captures over 500+ hours. PCAP and Zeek conn.log formats. Used for IoT botnet detection, malware traffic classification, and ML security research.

Apr 13, 2026
Network Security Kaggle

IoTID20: IoT Network Intrusion Dataset [625K Flows, 4 Attack Types, 83 Features]

Smart-home-derived IoT botnet dataset with 625,783 labeled flow records and 83 network features. Covers DoS, Mirai, MITM, and Scan attacks from EZVIZ and SKT NGU Wi-Fi cameras. CSV format. Supports binary, category, and sub-category IDS classification tasks.

Apr 13, 2026
Network Security University

CICIoT2023: Real-Time IoT Attack Dataset [47M+ Labeled Flows, 33 Attack Types]

Large-scale IoT cybersecurity dataset with 47M+ labeled network flows from 105 real IoT devices across 33 attack types in 7 categories. PCAP and CSV formats. Built for IDS/IPS development and ML-based IoT traffic classification research.

Apr 13, 2026
Cybersecurity University

MedBIoT — Medium-Sized IoT Botnet IDS Dataset [83 devices]

IoT botnet IDS dataset using 83 real and emulated devices with Mirai, BashLite, and Torii traffic. Raw PCAP files support botnet and anomaly detection research.

Jun 02, 2026
Cybersecurity / IoT Network Security University (Canadian Institute for Cybersecurity)

CICIDS2017 - Comprehensive Network Intrusion Detection Dataset

The most cited cybersecurity dataset worldwide with 2.8+ million network flows capturing 14 types of realistic attack scenarios including DDoS, brute force, botnet, and web attacks alongside benign traffic for advanced intrusion detection systems.

Jan 20, 2026
Cybersecurity Kaggle

Edge-IIoTset: Comprehensive IoT & IIoT Cyber Security Dataset [~12 GB, 15 Attack Types]

Realistic IoT/IIoT cybersecurity dataset supporting centralized and federated learning with 15 attack types across network, application, and protocol layers. CSV and PCAP formats (~12 GB). Available via IEEE Dataport and Kaggle. Designed for edge computing IDS research.

Apr 13, 2026

Explore other topics

All topics →