Skip to main content

IoT Security & Intrusion Detection Datasets

Labelled attack traffic for intrusion detection research: DDoS and botnet captures, MQTT and protocol abuse, malware traces and federated IDS benchmarks.

55 datasets Free · citable · CSV

Common tags in this topic

Mendeley Data
Cybersecurity Feb 07, 2026

MQTTEEB-D: Real-World IoT Cybersecurity Dataset for AI-Powered Threat Detection in MQTT Networks

A real-world cybersecurity dataset capturing MQTT-based IoT network traffic with live attacks and anomalous behavior. Collected from an active deployment with multiple attack types including DoS, SlowITe, and malformed injections. Provides both raw and preprocessed CSV files with rich metadata for intrusion detection and anomaly classification research.

CIC Repository
Cybersecurity Feb 05, 2026

CICIoT2023: Large-Scale IoT Attack Traffic Dataset

CICIoT2023 is a large-scale, flow-based network traffic dataset capturing real-time benign and malicious communications in an IoT environment composed of 105 physical devices. The dataset captures traffic traces for 33 attack scenarios grouped into seven categories: DDoS, DoS, Reconnaissance, web-based attacks, brute-force attempts, spoofing, and Mirai malware.

Kaggle
Cybersecurity Feb 05, 2026

Gotham Dataset 2025: Large-Scale Federated IoT IDS Benchmark

The Gotham Dataset is a large-scale, reproducible benchmark for evaluating decentralized Intrusion Detection Systems (IDS) and Federated Learning in virtualized smart cities. It captures interface-level network traffic from 78 heterogeneous IoT devices, including complex attack vectors like Mirai botnets, Merlin C2 traffic, and CoAP amplification, preserving the non-IID nature of edge data for realistic AI security training.

Mendeley Data
IoT Security / MQTT DoS and DDoS Feb 03, 2026

MQTT DoS DDoS IoT Attack Dataset

An MQTT DoS and DDoS IoT attack dataset collected on a Raspberry Pi 3B+ Mosquitto broker over 12 sessions, including three days of normal traffic and several minutes of attack traffic, totaling 424,716 labeled entries for machine learning-based IDS and IPS research.

Scientific Reports (Nature Publishing Group)
IoT Network Security / Federated Learning Feb 03, 2026

Dataset-Centric Evaluation of Federated Intrusion Detection Models in IoT Networks

A federated learning evaluation across several contemporary IoT and IIoT intrusion detection datasets, benchmarking algorithms such as FedAvg, FedProx, and FedNova with LSTM and Transformer models in in-domain, cross-dataset, and multi-dataset federation scenarios.

Scientific Reports (Nature Publishing Group)
IoT Security / Machine Learning Intrusion Detection Feb 03, 2026

Securing IoT Networks: A Machine Learning Approach for Detecting Unusual Traffic Patterns

A merged and optimized dataset combining N-BaIoT (IoT-specific traffic) and UNSW-NB15 (general network threats) with feature engineering, dimensionality reduction, and benchmarked ML models (Decision Tree, SVM, Random Forest, Neural Network) for IoT anomaly detection, published in Scientific Reports.

Data in Brief (Elsevier) + Mendeley Data
IoT Security / MQTT Intrusion Detection Feb 03, 2026

MQTTEEB-D: A Real-World IoT Cybersecurity Dataset for AI-Powered Threat Detection in MQTT Networks

A real-world MQTT-based IoT cybersecurity dataset collected from the MQTTEEB testbed at the International University of Rabat, with benign traffic and five attack types (DoS, SlowITe, Malformed Data Injection, Brute Force, Publish Flooding), provided in multiple processed forms (raw, cleaned, normalized, standardized, SMOTE) for AI-driven intrusion detection research.

Other research topics