Skip to content
Open access

A Device-Level IoT Network Traffic Dataset with Distributed Capture and Non-IID Characteristics

Aug 2026 · International Conference on Data Technologies and Applications · 0 citations · 8 references

TL;DR

The Gotham testbed dataset is presented, a device-level IoT network dataset generated using the open-source Gotham testbed, a virtualised smart city environment that preserves device-level traffic distributions and captures non-IID characteristics without artificial partitioning.

Abstract

The development of intrusion detection and network security solutions for securing Internet of Things (IoT) networks is constrained by the limited availability of representative network security datasets. Many existing datasets rely on centralised traffic collection and do not capture the non-Independent and Identically Distributed (non-IID) characteristics inherent to edge environments. To address this limitation, this work presents a device-level IoT network dataset generated using the open-source Gotham testbed, a virtualised smart city environment. Network traffic is collected in a distributed manner at the interfaces of 78 heterogeneous IoT devices operating across multiple protocols, including MQTT, CoAP, and RTSP. The dataset comprises over 31.8 million packet-level records, each described by 22 features. It includes both benign traffic and multiple attack classes, namely Network Scanning, Brute Force, Infection, Denial of Service (DoS), and Command and Control (C&C) Communication. Ground-truth labels are assigned using a deterministic process based on orchestration logs. The dataset preserves device-level traffic distributions and captures non-IID characteristics without artificial partitioning. It is publicly available and can be used to support reproducible evaluation of intrusion detection approaches and network analysis tasks in both centralised and distributed learning settings.

Read PDF

Similar papers

Open access 2026

Data-Driven Detection of Multi-vector IoT DDoS Attacks across Network Layers

—As cyberattacks targeting Internet of Things (IoT) networks grow more sophisticated, the demand for models capable of accurately detecting and mitigating these threats becomes increasingly urgent existing detection systems often concentrate on a single attack surface which leads to critical blind spots in IoT network...

Rania A. Al-Ali, Mohammad M. Alnabhan, Q. A. Al-Haija · 0 citations
#edge computing Open access Sep 2026

Real‐Time Anomaly Detection Using Federated Learning in Edge Devices

This work shows that production‐grade, privacy‐preserving intrusion detection is feasible in IoT networks at the edge, and addresses the concerns of data privacy and non‐IID data distribution inherent to distributed IoT networks.

Vaibhav Joshi, Abishi Chowdhury, Amrit Pal et al. · 0 citations
Conference Jul 2026

ShadowNet: A Multi-Protocol IoT Honeypot for Attack Detection and Behavior Analysis

The rapid growth of Internet of Things (IoT) devices in smart homes, industries, and urban infrastructure has increased the global cyber-attack surface. Many IoT devices use lightweight communication protocols and often lack strong authentication, making them easy targets for automated cyberattacks. This paper introduc...

Mahesh S. Shinde, Vijendra Sarode, Harsh Sarulkar et al. · 0 citations
Open access Aug 2026

Zero-Trust Architecture for Securing IoT Edge Networks Against Advanced Persistent Threats

These findings demonstrate that Edge-ZTA provides an efficient, privacy-preserving, and scalable cybersecurity framework capable of mitigating sophisticated multi-stage cyberattacks while satisfying the stringent performance requirements of next-generation Industrial IoT infrastructures.

Ahmed Ramzi Rashid, Zaydon L. Ali, Ahmed Sedeeq Baker Al-doori · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.