Datasets
A Device-Level IoT Network Traffic Dataset with Distributed Capture and Non-IID Characteristics
The data was generated in a virtualised smart city environment on the Gotham testbed (GNS3-based), segmented into City, Cloud, and Threat networks connected via 10 routers and 30 switches. The City network itself splits into four operational segments (a museum, a residential neighbourhood, a steel plant, a power network), each hosting a distinct mix of devices and traffic behaviours.
Belarbi et al., “A Device-Level IoT Network Traffic Dataset with Distributed Capture and Non-IID Characteristics” Data, 2026, 11, 207. https://doi.org/10.3390/data11080207
- Generated using a virtualised smart city environment — with 70+ heterogeneous IoT devices using protocols like MQTT, CoAP, and RTSP. 31.8+ million packet-level records, 22 features per packet (frame/network/transport layers)
- Includes both benign and multiple attack classes: Network Scanning, Brute Force, Denial of Service (DoS), and Command and Control (C&C) Communication.
- Devices include: air quality sensors, building monitors, city power meters, cooler motors, hydraulic systems, predictive maintenance units, IP cameras, and combined-cycle industrial controllers. Traffic patterns vary by device type and protocol, reflecting real-world heterogeneity.
- Multiple threat actors were emulated to generate realistic attack chains:
Denial of Service include: UDP Floods, TCP SYN/ACK Floods
Dataset: https://doi.org/10.5281/zenodo.14502760
Code: https://github.com/othmbela/gotham-network-packet-labeller
Jupyter notebooks are provided in the link below + a link to Google CoLab also included in each notebook: https://github.com/othmbela/gotham-network-packet-labeller/tree/main/notebooks