IoT-23: A labeled dataset with malicious and benign IoT network traffic
IoT-23 provides labeled IoT network-traffic captures, including 20 malware scenarios and 3 benign IoT captures, intended to support machine-learning research on IoT security.
Labelled attack traffic for intrusion detection research: DDoS and botnet captures, MQTT and protocol abuse, malware traces and federated IDS benchmarks.
IoT-23 provides labeled IoT network-traffic captures, including 20 malware scenarios and 3 benign IoT captures, intended to support machine-learning research on IoT security.
A real-world cybersecurity dataset capturing MQTT-based IoT network traffic with live attacks and anomalous behavior. Collected from an active deployment with multiple attack types including DoS, SlowITe, and malformed injections. Provides both raw and preprocessed CSV files with rich metadata for intrusion detection and anomaly classification research.
RT-IoT2022 is a network traffic dataset specifically derived from a real-time IoT testbed containing smart home devices. It includes both normal traffic and various common network attacks.
CICIoT2023 is a large-scale, flow-based network traffic dataset capturing real-time benign and malicious communications in an IoT environment composed of 105 physical devices. The dataset captures traffic traces for 33 attack scenarios grouped into seven categories: DDoS, DoS, Reconnaissance, web-based attacks, brute-force attempts, spoofing, and Mirai malware.
The Gotham Dataset is a large-scale, reproducible benchmark for evaluating decentralized Intrusion Detection Systems (IDS) and Federated Learning in virtualized smart cities. It captures interface-level network traffic from 78 heterogeneous IoT devices, including complex attack vectors like Mirai botnets, Merlin C2 traffic, and CoAP amplification, preserving the non-IID nature of edge data for realistic AI security training.
An MQTT DoS and DDoS IoT attack dataset collected on a Raspberry Pi 3B+ Mosquitto broker over 12 sessions, including three days of normal traffic and several minutes of attack traffic, totaling 424,716 labeled entries for machine learning-based IDS and IPS research.
A federated learning evaluation across several contemporary IoT and IIoT intrusion detection datasets, benchmarking algorithms such as FedAvg, FedProx, and FedNova with LSTM and Transformer models in in-domain, cross-dataset, and multi-dataset federation scenarios.
A merged and optimized dataset combining N-BaIoT (IoT-specific traffic) and UNSW-NB15 (general network threats) with feature engineering, dimensionality reduction, and benchmarked ML models (Decision Tree, SVM, Random Forest, Neural Network) for IoT anomaly detection, published in Scientific Reports.
A real-world MQTT-based IoT cybersecurity dataset collected from the MQTTEEB testbed at the International University of Rabat, with benign traffic and five attack types (DoS, SlowITe, Malformed Data Injection, Brute Force, Publish Flooding), provided in multiple processed forms (raw, cleaned, normalized, standardized, SMOTE) for AI-driven intrusion detection research.
Large-scale reproducible IoT network dataset with traffic from 100+ diverse IoT devices including smart home, wearable, and industrial sensors, featuring multiple attack scenarios and benign behavior for intrusion detection research.
Real-time network traffic dataset from diverse IoT devices including normal behavior and various attacks (DDoS, brute-force, scans) for developing intrusion detection systems.
Infrared survey data from the reactivated NEOWISE mission with >20 million calibrated FITS images in two bands (W1, W2). Essential for asteroid and comet discovery and thermal modeling.
Dataset for evaluating federated learning approaches to IoT intrusion detection published in Nature Scientific Reports January 2026. Features distributed network traffic from multiple IoT deployments with privacy constraints and decentralized learning evaluation metrics.
Comprehensive large-scale IoT botnet dataset combining legitimate IoT network traffic with realistic botnet attack scenarios. Features full packet captures (PCAP) and extracted flow features for diverse attack types including DDoS, reconnaissance, theft, and DoS attacks.
Specialized dataset for detecting IoT botnet attacks using network traffic analysis. Captures behavior of 9 real IoT devices infected with Mirai and BASHLITE malware variants. Ideal for training ML models to identify compromised IoT devices through traffic patterns.
Comprehensive large-scale IoT intrusion detection dataset from Canadian Institute for Cybersecurity with 33 attack types across 105 real IoT devices. Includes 8.94 GB of network traffic data covering DDoS, DoS, Mirai, MITM, and reconnaissance attacks.
New realistic IoT network intrusion dataset (MU-IoT) with comprehensive attack scenarios for cybersecurity research. Published in IEEE 2024 with 4+ citations. Covers multiple IoT protocols and device types.
Curated IoT network traffic dataset for intelligent network management and resource allocation research. Features diverse device types, traffic patterns, and quality-of-service metrics for ML-based optimization.
Comprehensive network traffic dataset from UNSW Canberra Cyber Range Lab capturing benign and malicious flows in simulated IoT/IIoT smart environments using Argus and Zeek (Bro) tools.
1,191,264 network intrusion instances with 47 features. Large-scale dataset for training predictive models to detect IoT network attacks and anomalies.
Comprehensive real-time IoT infrastructure dataset from UCI. Captures bidirectional network traffic using Zeek monitoring tool. Ideal for IDS development.
1,000 records of simulated IoT network activity with blockchain-based security. Covers DDoS, malware, MITM attacks across device, network, and application layers.
Large-scale labeled network traffic captures (PCAPs) from IoT devices. Based on Stratosphere Laboratory's famous IoT-23 dataset with botnet and normal traffic patterns.
Industry-standard dataset for prognostics research with simulated run-to-failure data from 100 turbofan engines including 21 sensor readings and remaining useful life (RUL) labels for predictive maintenance algorithms.