Skip to main content
University

MQTT-IoT-IDS2020 — MQTT Internet of Things IDS Dataset

IoT Security & Intrusion Detection Network Security
171 views
2 min read
Licence not recorded — verify at source
Catalog metadata: This page is a discovery record, not publisher documentation. Verify the description, schema, provenance, version, licence, and citation at the linked source before use.

Catalog Summary

"MQTT IoT IDS dataset from a simulated network with 12 sensors, broker, camera, and attacker. PCAP and CSV features support MQTT intrusion detection research."

Catalog Notes

Overview

MQTT-IoT-IDS2020 is a public dataset for intrusion detection in MQTT-based Internet of Things networks. MQTT is a common machine-to-machine communication protocol in IoT, and the dataset was created because general-purpose IDS datasets do not always represent MQTT traffic well.

The dataset was generated using a simulated MQTT architecture containing twelve sensors, a broker, a simulated camera, and an attacker. Five scenarios were recorded: normal operation, aggressive scan, UDP scan, Sparta SSH brute-force, and MQTT brute-force attack.

Raw PCAP files are saved and feature files are extracted at three abstraction levels: packet features, unidirectional flow features, and bidirectional flow features. The CSV files are intended for machine-learning usage.

Column Schema

ColumnDescription
packet_featuresPacket-level features extracted from raw PCAP files.
unidirectional_flow_featuresFeatures describing one-way network flows.
bidirectional_flow_featuresFeatures describing bidirectional communication flows.
scenarioRecorded scenario such as normal operation, aggressive scan, UDP scan, SSH brute-force, or MQTT brute-force.
labelNormal or attack class used for IDS modelling.
pcap_fileRaw packet-capture file for deeper traffic inspection.

Key Statistics

  • Total Records: Multiple PCAP and CSV feature files
  • Features: Packet, unidirectional-flow, and bidirectional-flow feature sets
  • File Format: PCAP, CSV
  • File Size: Not specified on the public metadata page
  • Time Period: Data produced June 23, 2020; made available February 2, 2021
  • Scenarios: 5 traffic scenarios

Use Cases

  • MQTT-specific IoT intrusion detection
  • Brute-force and scanning attack classification
  • Packet-level versus flow-level feature comparison
  • Lightweight protocol security analysis for IoT networks

Source & Attribution

Created by Hanan Hindy and Xavier Bellekens, with Christos Tachtatzis, Robert Atkinson, and Ethan Bayne listed in the dataset metadata. Published through IEEE DataPort and indexed by the University of Strathclyde with DOI 10.21227/bhxy-ep04.

View Data Structure

To explore column names, data types, and sample rows, visit the official dataset page on University.

Preview on University

Cite This Dataset

Hindy, H., Bellekens, X., Tachtatzis, C., Atkinson, R., & Bayne, E. (2021). MQTT-IoT-IDS2020: MQTT Internet of Things Intrusion Detection Dataset. [Dataset]. IEEE DataPort. https://doi.org/10.21227/bhxy-ep04

Source metadata: IEEE DataPort (2021) · DOI: 10.21227/bhxy-ep04

Indexed by IoTDataset.com on Jun 02, 2026

Review the Source Record

Confirm the licence, version, access conditions, file format, and provenance at the source before use.

Open Source Page

Related Topics & Keywords

Browse all IoT Security & Intrusion Detection datasets

Share This Research

More in IoT Security & Intrusion Detection

View All
Network Security Zenodo

IoT Emulated ICMP/Ping Dataset — Normal and Malicious Traffic [3.2 GB PCAP]

IoT IDS dataset for distinguishing normal and malicious ICMP/Ping traffic generated from an ESP-01s embedded device. PCAP, Zeek logs, and labelled CSV files.

Jun 02, 2026
Cybersecurity University

MedBIoT — Medium-Sized IoT Botnet IDS Dataset [83 devices]

IoT botnet IDS dataset using 83 real and emulated devices with Mirai, BashLite, and Torii traffic. Raw PCAP files support botnet and anomaly detection research.

Jun 02, 2026
Cybersecurity Kaggle

Edge-IIoTset: Comprehensive IoT & IIoT Cyber Security Dataset [~12 GB, 15 Attack Types]

Realistic IoT/IIoT cybersecurity dataset supporting centralized and federated learning with 15 attack types across network, application, and protocol layers. CSV and PCAP formats (~12 GB). Available via IEEE Dataport and Kaggle. Designed for edge computing IDS research.

Apr 13, 2026
Cybersecurity Kaggle

RT-IoT2022 - Real-Time IoT Infrastructure Intrusion Detection

A comprehensive dataset derived from real-time IoT infrastructure, designed for intrusion detection research and network security analysis.

Feb 19, 2026
Cybersecurity Mendeley Data

MQTTEEB-D: Real-World IoT Cybersecurity Dataset for AI-Powered Threat Detection in MQTT Networks

A real-world cybersecurity dataset capturing MQTT-based IoT network traffic with live attacks and anomalous behavior. Collected from an active deployment with multiple attack types including DoS, SlowITe, and malformed injections. Provides both raw and preprocessed CSV files with rich metadata for intrusion detection and anomaly classification research.

Feb 07, 2026
Cybersecurity Kaggle

TON_IoT Network Dataset - UNSW Cyber Range Lab Collection

Comprehensive network traffic dataset from UNSW Canberra Cyber Range Lab capturing benign and malicious flows in simulated IoT/IIoT smart environments using Argus and Zeek (Bro) tools.

Jan 22, 2026

Explore other topics

All topics →