EPSRC FUNDED PROGRAMME hub@edgeaihub.co.uk +44 (191) 208 6000

Datasets

A Device-Level IoT Network Traffic Dataset with Distributed Capture and Non-IID Characteristics

The data was generated in a virtualised smart city environment on the Gotham testbed (GNS3-based), segmented into City, Cloud, and Threat networks connected via 10 routers and 30 switches. The City network itself splits into four operational segments (a museum, a residential neighbourhood, a steel plant, a power network), each hosting a distinct mix of devices and traffic behaviours.

Belarbi et al., “A Device-Level IoT Network Traffic Dataset with Distributed Capture and Non-IID Characteristics” Data, 2026, 11, 207. https://doi.org/10.3390/data11080207

  1. Generated using a virtualised smart city environment — with 70+ heterogeneous IoT devices using protocols like MQTT, CoAP, and RTSP. 31.8+ million packet-level records, 22 features per packet (frame/network/transport layers)
  2. Includes both benign and multiple attack classes: Network Scanning, Brute Force, Denial of Service (DoS), and Command and Control (C&C) Communication.
  3. Devices include: air quality sensors, building monitors, city power meters, cooler motors, hydraulic systems, predictive maintenance units, IP cameras, and combined-cycle industrial controllers. Traffic patterns vary by device type and protocol, reflecting real-world heterogeneity.
  4. Multiple threat actors were emulated to generate realistic attack chains:

Denial of Service include: UDP Floods, TCP SYN/ACK Floods

Dataset: https://doi.org/10.5281/zenodo.14502760

Code: https://github.com/othmbela/gotham-network-packet-labeller

Jupyter notebooks are provided in the link below + a link to Google CoLab also included in each notebook: https://github.com/othmbela/gotham-network-packet-labeller/tree/main/notebooks