This data article presents a labelled flow-based network traffic dataset collected from a controlled Internet of Things (IoT) laboratory environment. The dataset captures network communication generated by Raspberry Pi-based IoT nodes configured to emulate service and client roles. Traffic was recorded during normal operations and during the execution of predefined cyberattack scenarios within an isolated experimental network. Network traffic was recorded at the packet level using passive network monitoring and stored in PCAPNG format. The packet captures were subsequently processed into bidirectional network flows, producing flow records with statistical and temporal attributes derived from the observed packet exchanges. Cyberattack-related flows were labelled using the experimental ground-truth markers recorded during each attack campaign, complemented by the fixed attacker node IP address. Flows outside the marked intervals were labelled as benign and corresponded to regular device communication. This combined labelling approach reduces the potential for overlap between benign and attack activities. The dataset covers nine attack scenarios grouped into six attack categories. It is released through a structured repository containing raw packet captures, labelled flow files, and supporting metadata for flow-based IoT traffic analysis, cyberattack detection research, and optional re-labelling.
Martínez et al. (Sun,) studied this question.