Cardiff University | Prifysgol Caerdydd ORCA
Online Research @ Cardiff 
WelshClear Cookie - decide language by browser settings

A device-level IoT network traffic dataset with distributed capture and non-IID characteristics

Belarbi, Othmane ORCID: https://orcid.org/0000-0002-6106-7669, Spyridopoulos, Theodoros ORCID: https://orcid.org/0000-0001-7575-9909, Anthi, Eirini, Rana, Omer ORCID: https://orcid.org/0000-0003-3597-2646, Carnelli, Pietro and Khan, Aftab 2026. A device-level IoT network traffic dataset with distributed capture and non-IID characteristics. Data 11 (8) , 207. 10.3390/data11080207

[thumbnail of data-11-00207-v2.pdf] PDF - Published Version
Available under License Creative Commons Attribution.

Download (4MB)

Abstract

The development of intrusion detection and network security solutions for securing Internet of Things (IoT) networks is constrained by the limited availability of representative network security datasets. Many existing datasets rely on centralised traffic collection and do not capture the non-Independent and Identically Distributed (non-IID) characteristics inherent to edge environments. To address this limitation, this work presents a device-level IoT network dataset generated using the open-source Gotham testbed, a virtualised smart city environment. Network traffic is collected in a distributed manner at the interfaces of 78 heterogeneous IoT devices operating across multiple protocols, including MQTT, CoAP, and RTSP. The dataset comprises over 31.8 million packet-level records, each described by 22 features. It includes both benign traffic and multiple attack classes, namely Network Scanning, Brute Force, Infection, Denial of Service (DoS), and Command and Control (C&C) Communication. Ground-truth labels are assigned using a deterministic process based on orchestration logs. The dataset preserves device-level traffic distributions and captures non-IID characteristics without artificial partitioning. It is publicly available and can be used to support reproducible evaluation of intrusion detection approaches and network analysis tasks in both centralised and distributed learning settings.

Item Type: Article
Date Type: Publication
Status: Published
Schools: Schools > Computational & Mathematical Sciences
Schools > Computer Science & Informatics
Publisher: MDPI
Date of First Compliant Deposit: 20 August 2026
Date of Acceptance: 21 July 2026
Last Modified: 20 Aug 2026 10:15
URI: https://orca.cardiff.ac.uk/id/eprint/189102

Actions (repository staff only)

Edit Item Edit Item

Downloads

Downloads per month over past year

View more statistics