dataset · Mendeley Data
MQTTEEB-D is a publicly available cybersecurity dataset gathered from a physical Internet of Things setup rather than simulated network traffic. Collected at the International University of Rabat in Morocco, the deployment used MySignals health sensors, a Raspberry Pi 4, and an MQTT broker server to capture authentic operational network behaviour. The dataset includes real-time executions of common cyberattacks, such as Denial of Service, SlowITe, malformed data injection, brute force, and MQTT publish flooding. Recorded using a Python network capture tool, the traffic was structured into comma-separated value files and processed through outlier removal, normalisation, standardisation, and class balancing via SMOTE. This resource provides raw and cleaned data forms to train, retrain, and test artificial intelligence models designed for intrusion detection across connected device networks.
Many Internet of Things systems rely on the lightweight MQTT communication protocol, which can be vulnerable to cyber threats. Because synthetic datasets often fail to reflect authentic operational conditions, defensive machine learning models can struggle in practice. Providing high-quality data from real hardware enables researchers and engineers to build more reliable threat-detection systems for critical deployments such as connected healthcare devices.
This dataset supports cybersecurity developers, artificial intelligence researchers, and Internet of Things device manufacturers seeking to train and benchmark intrusion detection systems. It has already been applied and tested experimentally in the development of the ISAAF attack prevention framework. As an open-access training resource, it represents an applied research asset that developers can immediately use to evaluate threat detection algorithms before deploying them into commercial networks.
AI-generated from the published abstract. Always read the original work before citing.
This dataset accompanies the research article on MQTTEEB-D and is intended for public use in cybersecurity research. The MQTTEEB-D dataset is a practical real-world data set for intrusion detection improvement in Message Queuing Telemetry Transport (MQTT)-based Internet of Things (IoT) networks. In contrast to already existing datasets that are constructed on simulated network traffic, MQTTEEB-D is obtained from a real-time IoT deployment at the International University of Rabat (UIR), Morocco. Using MySignals IoT health sensors, Raspberry Pi 4, and an MQTT broker server, this dataset represents the actual complexity of the active IoT communication process, which synthetic data fails to offer. To narrow the gap between simulated and real-world attack scenarios, various cyberattacks including Denial of Service (DoS), Slow DoS against Internet of Things Environments (SlowITe), Malformed Data Injection, Brute Force, and MQTT publish flooding were carried out in real-time, permitting close monitoring of network traffic anomalies. The data was captured using Python wrapper for tshark (PyShark) and organized into multiple Comma-Separated Values (CSV) files. To ensure high data quality, we performed pre-processing steps, such as outlier removal, normalization, standardization, and class balance. Several processed forms (raw, cleaned, normalized, standardized, Synthetic Minority Over-sampling Technique (SMOTE)) applied for this dataset are provided, along with detailed metadata to facilitate ease of use in cybersecurity research. This dataset provides an opportunity for researchers to develop and validate intrusion detection models in a real-world MQTT environment - a critical ingredient in Artificial Intelligence (AI)-driven cybersecurity solutions for IoT networks. The dataset will support future research IoT security and anomaly detection domains. MQTTEEB-D was subsequently used for the development and experimental validation of ISAAF, an AI-driven IoT security and attack prevention framework published in Scientific Reports. The study demonstrates the use of MQTTEEB-D for training, retraining, and evaluating intrusion-detection models under real-world MQTT conditions. Associated publications and reproducibility software are provided under the Related links section.
This page summarises published work. The authoritative version sits with the publisher.
DOI: 10.17632/jfttfjn6tr.2
Is something wrong with this record? Report it or request removal.
Discussion
Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.
No discussion yet. Open the first thread.
New to MARATTO™? Create a free account.