MQTTEEB-D: A Real-World IoT Cybersecurity Dataset for AI-Powered Threat Detection in MQTT Networks
Description
This dataset accompanies the research article on MQTTEEB-D and is intended for public use in cybersecurity research. The MQTTEEB-D dataset is a practical real-world data set for intrusion detection improvement in Message Queuing Telemetry Transport (MQTT)-based Internet of Things (IoT) networks. In contrast to already existing datasets that are constructed on simulated network traffic, MQTTEEB-D is obtained from a real-time IoT deployment at the International University of Rabat (UIR), Morocco. Using MySignals IoT health sensors, Raspberry Pi 4, and an MQTT broker server, this dataset represents the actual complexity of the active IoT communication process, which synthetic data fails to offer. To narrow the gap between simulated and real-world attack scenarios, various cyberattacks including Denial of Service (DoS), Slow DoS against Internet of Things Environments (SlowITe), Malformed Data Injection, Brute Force, and MQTT publish flooding were carried out in real-time, permitting close monitoring of network traffic anomalies. The data was captured using Python wrapper for tshark (PyShark) and organized into multiple Comma-Separated Values (CSV) files. To ensure high data quality, we performed pre-processing steps, such as outlier removal, normalization, standardization, and class balance. Several processed forms (raw, cleaned, normalized, standardized, Synthetic Minority Over-sampling Technique (SMOTE)) applied for this dataset are provided, along with detailed metadata to facilitate ease of use in cybersecurity research. This dataset provides an opportunity for researchers to develop and validate intrusion detection models in a real-world MQTT environment - a critical ingredient in Artificial Intelligence (AI)-driven cybersecurity solutions for IoT networks. The dataset will support future research IoT security and anomaly detection domains. MQTTEEB-D was subsequently used for the development and experimental validation of ISAAF, an AI-driven IoT security and attack prevention framework published in Scientific Reports. The study demonstrates the use of MQTTEEB-D for training, retraining, and evaluating intrusion-detection models under real-world MQTT conditions. Associated publications and reproducibility software are provided under the Related links section.
Files
Steps to reproduce
For detailed information on dataset acquisition, structure, preprocessing, attack scenarios, and analysis, refer to the associated Data in Brief article and the related Scientific Reports study. To use this dataset: 1. Download the dataset files. 2. Use `Raw_RealTime_Data` for raw MQTT network traffic captured during real-time attack scenarios. 3. Use `Preprocessed_Data` for processed datasets suitable for machine-learning and deep-learning experiments. 4. Refer to the accompanying metadata files for feature and encoding information. 5. The dataset contains real-world MQTT traffic including normal operation and multiple cyberattack scenarios. 6. Python-based tools, including PyShark, pandas, scikit-learn, and Jupyter Notebook, can be used for processing and analysis. 7. For model retraining, testing, and experimental reproduction, use the software repositories provided under “Related links”. Associated publications: MQTTEEB-D dataset article: https://doi.org/10.1016/j.dib.2025.111897 ISAAF application and validation study: https://doi.org/10.1038/s41598-025-28516-2 Associated software: MQTTEEB-D model retraining/testing: https://github.com/Khaoula-Karam/MQTTEEB-D_Model_Retrain_Testing_Database_Creation MQTTSET ML/DL investigation: https://github.com/Khaoula-Karam/MQTTSET_Investigation_ML_DL_Models
Institutions
Categories
Funders
- MG-FARM Project, funded by MESRSI and the European Union under LEAP-REGrant ID: Grant Agreement No. 963530