Skip to main content
Data in Brief (Elsevier) + Mendeley Data

MQTTEEB-D: A Real-World IoT Cybersecurity Dataset for AI-Powered Threat Detection in MQTT Networks

IoT Security & Intrusion Detection IoT Security / MQTT Intrusion Detection
461 views
2 min read
License
Catalog metadata: This page is a discovery record, not publisher documentation. Verify the description, schema, provenance, version, licence, and citation at the linked source before use.

Catalog Summary

"A real-world MQTT-based IoT cybersecurity dataset collected from the MQTTEEB testbed at the International University of Rabat, with benign traffic and five attack types (DoS, SlowITe, Malformed Data Injection, Brute Force, Publish Flooding), provided in multiple processed forms (raw, cleaned, normalized, standardized, SMOTE) for AI-driven intrusion detection research."

Catalog Notes

Overview

MQTTEEB-D is a practical real-world IoT cybersecurity dataset designed for intrusion detection in MQTT-based networks. It is captured from a live IoT deployment called MQTTEEB at the International University of Rabat (UIR), Morocco, and supports AI-powered threat detection in MQTT-based IoT environments.

Testbed and Data Collection

  • IoT testbed composed of MySignals IoT health sensors, a Raspberry Pi 4 gateway, and an MQTT broker server, representing realistic health-related IoT communication.
  • Network traffic captured in real time using PyShark (Python wrapper for tshark) while executing benign scenarios and multiple cyberattacks.
  • Captured traffic is organized into multiple CSV files, and several processed versions are provided: raw, cleaned, normalized, standardized, and SMOTE-balanced datasets.

Attack Types

  • Denial of Service (DoS): high-rate flooding of MQTT messages to overwhelm the broker or clients.
  • SlowITe (Slow DoS against IoT Environments): low-rate, slow-paced attack targeting MQTT communication.
  • Malformed Data Injection: insertion of incorrectly structured or corrupted MQTT payloads.
  • Brute Force: repeated unauthorized connection or login attempts against MQTT services.
  • MQTT Publish Flooding: excessive publication of MQTT messages to specific topics to cause congestion.

Dataset Contents

  • Multiple CSV files representing different preprocessing stages: raw, cleaned, normalized, standardized, and SMOTE-augmented data.
  • Each record includes MQTT-related traffic features extracted from packet captures (e.g., packet length, inter-arrival times, flags, topics, QoS levels) along with labels indicating benign or specific attack type.
  • Detailed metadata is provided in the Mendeley repository, describing file structure, feature descriptions, and preprocessing steps.

Use Cases

  • Training and evaluating machine learning and deep learning intrusion detection systems for MQTT-based IoT networks.
  • Benchmarking models across different preprocessing strategies (raw versus normalized versus SMOTE-balanced).
  • Studying the impact of diverse real-time attack types on MQTT traffic patterns.

Access and License

The dataset is hosted on Mendeley Data and is intended for public use in cybersecurity research. Users should consult the Mendeley page for the exact license terms and citation instructions.

View Data Structure

To explore column names, data types, and sample rows, visit the official dataset page on Data in Brief (Elsevier) + Mendeley Data.

Preview on Data in Brief (Elsevier) + Mendeley Data

Cite This Dataset

The dataset creators ask users of this dataset to cite the accompanying paper. Use one of the verified formats below.

Aqachtoul, A., Najib, M., & others (2025). MQTTEEB-D: A Real-World IoT Cybersecurity Dataset for AI-Powered Threat Detection in MQTT Networks. Data in Brief, 62, 111897. https://doi.org/10.1016/j.dib.2025.111897

Source metadata: Data in Brief (Elsevier) + Mendeley Data (2025) · DOI: 10.1016/j.dib.2025.111897

Indexed by IoTDataset.com on Feb 03, 2026

Review the Source Record

Confirm the licence, version, access conditions, file format, and provenance at the source before use.

Open Source Page

Related Topics & Keywords

Browse all IoT Security & Intrusion Detection datasets

Share This Research

More in IoT Security & Intrusion Detection

View All
Cybersecurity Zenodo

Gotham Dataset 2025 - Large-Scale IoT Network Intrusion Detection

Reproducible large-scale IoT network dataset from 78 emulated devices using MQTT, CoAP, and RTSP protocols. Includes benign and malicious traffic with DoS, brute force, scanning, and C&C attacks in PCAP and CSV formats.

Mar 20, 2026
IoT Security / MQTT DoS and DDoS Mendeley Data

MQTT DoS DDoS IoT Attack Dataset

An MQTT DoS and DDoS IoT attack dataset collected on a Raspberry Pi 3B+ Mosquitto broker over 12 sessions, including three days of normal traffic and several minutes of attack traffic, totaling 424,716 labeled entries for machine learning-based IDS and IPS research.

Feb 03, 2026
Network Security University

MQTT-IoT-IDS2020 — MQTT Internet of Things IDS Dataset

MQTT IoT IDS dataset from a simulated network with 12 sensors, broker, camera, and attacker. PCAP and CSV features support MQTT intrusion detection research.

Jun 02, 2026
Cybersecurity IoTSyn Generated

Synthetic IoT Intrusion Detection Dataset — 18% Attacks

Free CC0 synthetic dataset: 500 rows of labelled network flows covering DoS, DDoS, botnet and reconnaissance traffic. 18% Attacks.

Apr 04, 2026
IoT Security / Machine Learning Intrusion Detection Scientific Reports (Nature Publishing Group)

Securing IoT Networks: A Machine Learning Approach for Detecting Unusual Traffic Patterns

A merged and optimized dataset combining N-BaIoT (IoT-specific traffic) and UNSW-NB15 (general network threats) with feature engineering, dimensionality reduction, and benchmarked ML models (Decision Tree, SVM, Random Forest, Neural Network) for IoT anomaly detection, published in Scientific Reports.

Feb 03, 2026
IoT Network Security Zenodo / ArXiv

Gotham Dataset 2025: A Reproducible Large-Scale IoT Network Dataset for Intrusion Detection

Large-scale reproducible IoT network dataset with traffic from 100+ diverse IoT devices including smart home, wearable, and industrial sensors, featuring multiple attack scenarios and benign behavior for intrusion detection research.

Jan 30, 2026

Explore other topics

All topics →