Skip to main content
UCI

RT-IoT2022: Real-Time IoT IDS Dataset [41 Features, Multi-Attack]

IoT Security & Intrusion Detection Network Security
169 views
2 min read
License
Catalog metadata: This page is a discovery record, not publisher documentation. Verify the description, schema, provenance, version, licence, and citation at the linked source before use.

Catalog Summary

"Real-time IoT network security dataset from a live IoT infrastructure with 41 bidirectional flow features. Includes ThingSpeak-LED, Wipro-Bulb, and MQTT-Temp devices with SSH brute force, DDoS (Hping/Slowloris), and Nmap attack scenarios. CSV format. Used for adaptive IDS development."

Catalog Notes

Overview

RT-IoT2022 is a proprietary-origin dataset derived from a real-time, operational IoT infrastructure, donated to the UCI Machine Learning Repository in January 2024. It integrates traffic from diverse consumer IoT devices — including a ThingSpeak-LED smart bulb, Wipro smart bulb, and an MQTT-based temperature sensor — alongside targeted attack simulations.

Network flows are captured bidirectionally using the Zeek network monitoring tool combined with the Flowmeter plugin, producing a rich tabular feature set of 41 columns per flow record. Attack scenarios include brute-force SSH attacks, volumetric DDoS attacks launched via Hping3 and the Slowloris application-layer tool, and reconnaissance activity using Nmap network scanning patterns.

With approximately 2.09 million total records (1.96M normal, 138K attack), the dataset supports classification, regression, and clustering tasks. Its real-time IoT provenance — rather than purely simulated conditions — makes it particularly valuable for developing robust and adaptive security solutions for production IoT deployments.

Column Schema

ColumnDescription
protoTransport protocol of the flow.
serviceApplication-layer service detected by Zeek.
flow_durationDuration of the bidirectional flow.
fwd_pkts_tot / bwd_pkts_totTotal forward and backward packet counts.
fwd_data_pkts_totForward data packet count.
fwd_pkts_per_sec / bwd_pkts_per_secForward and backward packet rates.
flow_pkts_per_secOverall flow packet rate.
down_up_ratioRatio of download to upload traffic.
Attack_typeLabel: specific attack type or normal traffic class.

Key Statistics

  • Total Records: ~2,095,319 (Normal: ~1,956,847; Attack: ~138,472)
  • Features: 41 columns
  • Attack Types: SSH brute force, DDoS-Hping, DDoS-Slowloris, Nmap scanning
  • IoT Devices: ThingSpeak-LED, Wipro-Bulb, MQTT-Temp
  • File Format: CSV
  • Capture Tool: Zeek + Flowmeter plugin
  • Donated to UCI: January 2024

Use Cases

  • Intrusion detection system development for real-world IoT deployments
  • ML-based attack classification (binary and multi-class)
  • Evaluation of IDS adaptability across volumetric and application-layer attacks
  • Feature selection and dimensionality reduction for IoT network security models

Source & Attribution

RT-IoT2022 was donated to the UCI Machine Learning Repository in January 2024 and is directly available for download from the UCI dataset page. It is maintained as an open academic resource for IoT security and intrusion detection research.

Data Preview

protoserviceflow_durationflow_pkts_per_secAttack_type
tcphttp0.004210473.87Normal
udpdns0.00014214084.50Normal
tcpssh1.2345003.24MQTT_Publish
tcp-0.0000011000000.0DDoS_Hping
tcp-30.123000.43Slowloris

Showing first few rows for preview

Cite This Dataset

RT-IoT2022 Contributors (2024). RT-IoT2022. [Dataset]. UCI Machine Learning Repository. https://archive.ics.uci.edu/dataset/942/rt-iot2022

Source metadata: UCI Machine Learning Repository (2024)

Indexed by IoTDataset.com on Apr 13, 2026

Review the Source Record

Confirm the licence, version, access conditions, file format, and provenance at the source before use.

Open Source Page

Related Topics & Keywords

Browse all IoT Security & Intrusion Detection datasets

Share This Research

More in IoT Security & Intrusion Detection

View All
Network Security University

CICIoT2023: Real-Time IoT Attack Dataset [47M+ Labeled Flows, 33 Attack Types]

Large-scale IoT cybersecurity dataset with 47M+ labeled network flows from 105 real IoT devices across 33 attack types in 7 categories. PCAP and CSV formats. Built for IDS/IPS development and ML-based IoT traffic classification research.

Apr 13, 2026
Network Security University

TON_IoT: UNSW Telemetry, Network & OS Attack Traces [Multi-Source IIoT]

Heterogeneous IoT/IIoT dataset from UNSW Canberra Cyber Range with network traffic, Windows/Linux OS traces, and IoT sensor telemetry. Labeled for 9 attack types including DoS, DDoS, ransomware, and XSS. CSV and PCAP formats. Benchmark for AI-based IDS evaluation.

Apr 13, 2026
Cybersecurity Zenodo

IoT-23; Labeled IoT Malware & Benign Traffic [325M Flows, 500+ Hours]

Real IoT malware traffic dataset with 325M labeled network flows from 20 malware and 3 benign device captures over 500+ hours. PCAP and Zeek conn.log formats. Used for IoT botnet detection, malware traffic classification, and ML security research.

Apr 13, 2026
Cybersecurity Kaggle

Edge-IIoTset: Comprehensive IoT & IIoT Cyber Security Dataset [~12 GB, 15 Attack Types]

Realistic IoT/IIoT cybersecurity dataset supporting centralized and federated learning with 15 attack types across network, application, and protocol layers. CSV and PCAP formats (~12 GB). Available via IEEE Dataport and Kaggle. Designed for edge computing IDS research.

Apr 13, 2026
Network Security Kaggle

IoTID20: IoT Network Intrusion Dataset [625K Flows, 4 Attack Types, 83 Features]

Smart-home-derived IoT botnet dataset with 625,783 labeled flow records and 83 network features. Covers DoS, Mirai, MITM, and Scan attacks from EZVIZ and SKT NGU Wi-Fi cameras. CSV format. Supports binary, category, and sub-category IDS classification tasks.

Apr 13, 2026
Cybersecurity UCI

N-BaIoT: Real IoT Botnet Traffic from 9 Infected Devices [7M Records, Mirai & BASHLITE]

Real IoT botnet traffic dataset from 9 commercial devices (webcams, routers, thermostats) authentically infected by Mirai and BASHLITE. Over 7M records, 115 statistical features. CSV format. Benchmark for deep-learning-based IoT anomaly and botnet detection.

May 03, 2026

Explore other topics

All topics →