TRUSTLab: IoT/Edge Intrusion Detection Flow Dataset
Abstract
"About 4.6 million labelled bi-flows with 80 CICFlowMeter features, covering 15 attack families plus benign traffic in 16 single-class files. CC BY 4.0."
Description
Overview
A flow-based traffic collection generated in an operational testbed reproducing enterprise-grade services and modern application interfaces, for evaluating Intrusion Detection Systems in IoT and edge environments.
What makes it different
The dataset follows a single-class session policy: each capture contains exclusively benign traffic or a single attack family. The authors introduce this because existing datasets often mix benign and malicious traffic within the same capture window, producing ambiguous flow labels that may distort model evaluation. Preventing temporal overlap this way preserves label integrity at the bi-flow level.
Composition
- Volume: approximately 4.6 million bi-flows
- Features: 80 per flow, extracted with CICFlowMeter
- Classes: 15 attack families plus benign, in 16 single-class files
- Attack coverage: volumetric flooding, reconnaissance, application-layer exploits, protocol manipulation, evasive techniques and persistence vectors
Reported baselines
The accompanying paper reports a baseline binary classifier reaching a ROC-AUC of 0.9676 and a recall of 0.95. The multiclass benchmark reports per-family precision, recall and F1, with the main residual confusion concentrated in low-and-slow and HTTP-based vectors. Statistical analysis in the paper confirms discriminative signal without requiring payload inspection, which matters for lightweight edge-oriented detection.
Provenance
- Authors: Antonio Villafranca and Maria-Dolores Cano (Universidad Politécnica de Cartagena), Igor Tasic (UCAM Universidad Católica San Antonio de Murcia)
- Published: 5 May 2026, Frontiers in Computer Science, volume 8, article 1803271
- DOI: 10.3389/fcomp.2026.1803271
- Licence: Creative Commons Attribution 4.0 International (CC BY 4.0)
A note on completeness
The row count is given as "approximately 4.6 million" in the source and is therefore not recorded as an exact figure here. The article states the dataset is publicly available; follow the DOI above for the data availability statement and the download location.
View Data Structure
To explore column names, data types, and sample rows, visit the official dataset page on Frontiers.
Preview on FrontiersCite This Dataset
Villafranca, A., Tasic, I., & Cano, M.-D. (2026). TRUSTLab dataset: a real-world CICFlowMeter dataset for IoT/edge intrusion detection. Frontiers in Computer Science. [Dataset]. Frontiers. https://doi.org/10.3389/fcomp.2026.1803271
Source: Frontiers (2026) · DOI: 10.3389/fcomp.2026.1803271
Indexed by IoTDataset.com on Jul 29, 2026
Ready to Start Your Research?
Download this dataset directly from the official repository and start building your next breakthrough project.