Task-by-task benchmark catalog
What each of the 30 IDS benchmark tasks contains
This page expands the benchmark metadata into one user-facing row per task. Counts, availability status, source paths, split mode, and provenance wording are taken from metadata/datasets.csv, metadata/datasets.json, the mirrored benchmark definitions, and the source/task manifests listed in those metadata files.
Train and test counts are shown as majority/minority row counts. Across the release, label = 0 is the majority benign/normal class and label = 1 is the minority attack class.
Reading the table
- Direct downloadable CSV means the public release includes a CSV under
data/. - Must be recreated locally means no public CSV is redistributed here; use the omitted-task copy and verification workflow.
- The page keeps task wording close to manifest fields such as
provenance_note,source_manifest,task_manifest_files,downloadable,public_csv, andlocal_reproduction.
All 30 Tasks
| Publication year | Source corpus | Task title | Classes | Train maj./min. | Test maj./min. | CSV availability | How it was made |
|---|---|---|---|---|---|---|---|
| 2018 | CIC-IDS-2017 | CIC-IDS-2017 Friday Bot vs BENIGNfriday_bot | 0: BENIGN1: Bot | 48,000 / 500 | 48,000 / 500 | Direct downloadable CSV | Retained non-DoS task from the preserved-ratio single-label 25D benchmark surface. Source manifest: Friday-WorkingHours-Morning.pcap_ISCX.csv; split mode classwise_temporal. |
| 2018 | CIC-IDS-2017 | CIC-IDS-2017 Thursday Web Attack - Brute Force vs BENIGNthursday_web_attack_bruteforce | 0: BENIGN1: Web Attack - Brute Force | 55,500 / 500 | 55,500 / 500 | Direct downloadable CSV | Retained non-DoS task from the preserved-ratio single-label 25D benchmark surface. Source manifest: Thursday-WorkingHours-Morning-WebAttacks.pcap_ISCX.csv; split mode classwise_temporal. |
| 2018 | CIC-IDS-2017 | CIC-IDS-2017 Tuesday FTP-Patator vs BENIGNtuesday_ftp_patator | 0: BENIGN1: FTP-Patator | 27,000 / 500 | 27,000 / 500 | Direct downloadable CSV | Retained non-DoS task from the preserved-ratio single-label 25D benchmark surface. Source manifest: Tuesday-WorkingHours.pcap_ISCX.csv; split mode classwise_temporal. |
| 2018 | CIC-IDS-2017 | CIC-IDS-2017 Tuesday SSH-Patator vs BENIGNtuesday_ssh_patator | 0: BENIGN1: SSH-Patator | 36,500 / 500 | 36,500 / 500 | Direct downloadable CSV | Retained non-DoS task from the preserved-ratio single-label 25D benchmark surface. Source manifest: Tuesday-WorkingHours.pcap_ISCX.csv; split mode classwise_temporal. |
| 2018 | CSE-CIC-IDS2018 | CSE-CIC-IDS2018 Bot vs BENIGNcse_cic_ids2018_bot | 0: BENIGN1: Bot | 23,500 / 500 | 23,500 / 500 | Direct downloadable CSV | Retained non-DoS task from the preserved-ratio single-label 25D surface. Source manifest uses all day-organized processed-flow CSVs in file order and a positive definition of normalized label equals 'bot'. |
| 2018 | CSE-CIC-IDS2018 | CSE-CIC-IDS2018 FTP-BruteForce vs BENIGNcse_cic_ids2018_ftp_bruteforce | 0: BENIGN1: FTP-BruteForce | 34,500 / 500 | 34,500 / 500 | Direct downloadable CSV | Retained non-DoS task from the preserved-ratio single-label 25D surface. Source manifest uses all day-organized processed-flow CSVs in file order and a positive definition of normalized label equals 'ftp bruteforce'. |
| 2018 | CSE-CIC-IDS2018 | CSE-CIC-IDS2018 Infilteration vs BENIGNcse_cic_ids2018_infilteration | 0: BENIGN1: Infilteration | 41,500 / 500 | 41,500 / 500 | Direct downloadable CSV | Retained non-DoS task from the preserved-ratio single-label 25D surface. Source manifest uses all day-organized processed-flow CSVs in file order and a positive definition of normalized label equals 'infilteration'. |
| 2018 | CSE-CIC-IDS2018 | CSE-CIC-IDS2018 SSH-Bruteforce vs BENIGNcse_cic_ids2018_ssh_bruteforce | 0: BENIGN1: SSH-Bruteforce | 35,500 / 500 | 35,500 / 500 | Direct downloadable CSV | Retained non-DoS task from the preserved-ratio single-label 25D surface. Source manifest uses all day-organized processed-flow CSVs in file order and a positive definition of normalized label equals 'ssh bruteforce'. |
| 2015 | CIC-UNSW-NB15 | CIC-UNSW-NB15 Exploits vs BENIGNcic_unsw_nb15_exploits | 0: BENIGN1: Exploits | 5,500 / 500 | 5,500 / 500 | Must be recreated locally; public CSV omitted | Retained non-DoS task from the preserved-ratio single-label 25D surface. Source manifest describes Data.csv joined row-wise with Label.csv in original row order; omitted-task manifest gives the exact benchmark source CSV to copy locally. |
| 2015 | CIC-UNSW-NB15 | CIC-UNSW-NB15 Fuzzers vs BENIGNcic_unsw_nb15_fuzzers | 0: BENIGN1: Fuzzers | 6,000 / 500 | 6,000 / 500 | Must be recreated locally; public CSV omitted | Retained non-DoS task from the preserved-ratio single-label 25D surface. Source manifest describes Data.csv joined row-wise with Label.csv in original row order; omitted-task manifest gives the exact benchmark source CSV to copy locally. |
| 2015 | CIC-UNSW-NB15 | CIC-UNSW-NB15 Generic vs BENIGNcic_unsw_nb15_generic | 0: BENIGN1: Generic | 38,500 / 500 | 38,500 / 500 | Must be recreated locally; public CSV omitted | Retained non-DoS task from the preserved-ratio single-label 25D surface. Source manifest describes Data.csv joined row-wise with Label.csv in original row order; omitted-task manifest gives the exact benchmark source CSV to copy locally. |
| 2015 | CIC-UNSW-NB15 | CIC-UNSW-NB15 Reconnaissance vs BENIGNcic_unsw_nb15_reconnaissance | 0: BENIGN1: Reconnaissance | 10,500 / 500 | 10,500 / 500 | Must be recreated locally; public CSV omitted | Retained non-DoS task from the preserved-ratio single-label 25D surface. Source manifest describes Data.csv joined row-wise with Label.csv in original row order; omitted-task manifest gives the exact benchmark source CSV to copy locally. |
| 2015 | CIC-UNSW-NB15 | CIC-UNSW-NB15 Shellcode vs BENIGNcic_unsw_nb15_shellcode | 0: BENIGN1: Shellcode | 85,000 / 500 | 85,000 / 500 | Must be recreated locally; public CSV omitted | Retained non-DoS task from the preserved-ratio single-label 25D surface. Source manifest describes Data.csv joined row-wise with Label.csv in original row order; omitted-task manifest gives the exact benchmark source CSV to copy locally. |
| 2021 | HIKARI-2021 | HIKARI-2021 Bruteforce vs BENIGNhikari_bruteforce_vs_benign | 0: BENIGN1: Bruteforce | 43,500 / 500 | 43,500 / 500 | Direct downloadable CSV | Modern7 materialization manifest records this candidate as materialized from staged train/test CSVs into the benchmark definition, with no dropped columns and train_test_source_row_index_overlap recorded as 0. |
| 2021 | HIKARI-2021 | HIKARI-2021 Probing vs BENIGNhikari_probing_vs_benign | 0: BENIGN1: Probing | 11,000 / 500 | 11,000 / 500 | Direct downloadable CSV | Modern7 materialization manifest records this candidate as materialized from staged train/test CSVs into the benchmark definition, with no dropped columns and train_test_source_row_index_overlap recorded as 0. |
| 2024 | CICIoMT2024Small mirror | CICIoMT2024Small mirror ARP Spoofing vs BENIGNciciomt2024_arp_spoofing_vs_benign | 0: BENIGN1: ARP Spoofing | 12,500 / 500 | 12,500 / 500 | Must be recreated locally; public CSV omitted | Modern7 materialization records this candidate from the public Hugging Face CICIoMT2024Small mirror. Provenance notes state the official UNB endpoint remains registration-gated; omission notes state labels were assigned from filenames. |
| 2024 | CICIoMT2024Small mirror | CICIoMT2024Small mirror MQTT Malformed Data vs BENIGNciciomt2024_mqtt_malformed_data_vs_benign | 0: BENIGN1: MQTT Malformed Data | 8,500 / 500 | 8,500 / 500 | Must be recreated locally; public CSV omitted | Modern7 materialization records this candidate from the public Hugging Face CICIoMT2024Small mirror. Provenance notes state the official UNB endpoint remains registration-gated; omission notes state labels were assigned from filenames. |
| 2022 | Edge-IIoTset | Edge-IIoTset SQL injection vs NORMALedge_iiotset_sql_injection_vs_normal | 0: NORMAL1: SQL_injection_attack | 15,500 / 500 | 15,500 / 500 | Must be recreated locally; public CSV omitted | Modern7 materialization records this candidate from a public Kaggle mirror while the official IEEE DataPort route remains gated. Edge feature filtering dropped timestamp, IP, payload, text, checksum, sequence, and related high-cardinality columns. |
| 2022 | Edge-IIoTset | Edge-IIoTset Password vs NORMALedge_iiotset_password_vs_normal | 0: NORMAL1: Password_attack | 16,000 / 500 | 16,000 / 500 | Must be recreated locally; public CSV omitted | Modern7 materialization records this candidate from a public Kaggle mirror while the official IEEE DataPort route remains gated. Edge feature filtering dropped timestamp, IP, payload, text, checksum, sequence, and related high-cardinality columns. |
| 2022 | Edge-IIoTset | Edge-IIoTset Uploading vs NORMALedge_iiotset_uploading_vs_normal | 0: NORMAL1: Uploading_attack | 21,000 / 500 | 21,000 / 500 | Must be recreated locally; public CSV omitted | Modern7 materialization records this candidate from a public Kaggle mirror while the official IEEE DataPort route remains gated. Edge feature filtering dropped timestamp, IP, payload, text, checksum, sequence, and related high-cardinality columns. |
| 2022 | 5G-NIDD | 5G-NIDD TCPConnectScan vs BENIGN5g_nidd_tcp_connect_scan_vs_benign | 0: BENIGN1: TCPConnectScan | 11,500 / 500 | 11,500 / 500 | Direct downloadable CSV | Additional10 materialization records the open Fairdata route as the local artifact source while the official IEEE DataPort route remains gated. Materialization dropped Offset, SrcTCPBase, and DstTCPBase. |
| 2022 | 5G-NIDD | 5G-NIDD SYNScan vs BENIGN5g_nidd_syn_scan_vs_benign | 0: BENIGN1: SYNScan | 11,500 / 500 | 11,500 / 500 | Direct downloadable CSV | Additional10 materialization records the open Fairdata route as the local artifact source while the official IEEE DataPort route remains gated. Materialization dropped Offset, SrcTCPBase, and DstTCPBase. |
| 2022 | 5G-NIDD | 5G-NIDD UDPScan vs BENIGN5g_nidd_udp_scan_vs_benign | 0: BENIGN1: UDPScan | 15,000 / 500 | 15,000 / 500 | Direct downloadable CSV | Additional10 materialization records the open Fairdata route as the local artifact source while the official IEEE DataPort route remains gated. Materialization dropped Offset, SrcTCPBase, and DstTCPBase. |
| 2022 | Edge-IIoTset | Edge-IIoTset Vulnerability scanner vs NORMALedge_iiotset_vulnerability_scanner_vs_normal | 0: NORMAL1: Vulnerability_scanner_attack | 16,000 / 500 | 16,000 / 500 | Must be recreated locally; public CSV omitted | Additional10 materialization records this candidate from a public Kaggle mirror while the official IEEE DataPort route remains gated. Edge feature filtering dropped timestamp, IP, payload, text, checksum, sequence, and related high-cardinality columns. |
| 2022 | Edge-IIoTset | Edge-IIoTset Backdoor vs NORMALedge_iiotset_backdoor_vs_normal | 0: NORMAL1: Backdoor_attack | 32,000 / 500 | 32,000 / 500 | Must be recreated locally; public CSV omitted | Additional10 materialization records this candidate from a public Kaggle mirror while the official IEEE DataPort route remains gated. Edge feature filtering dropped timestamp, IP, payload, text, checksum, sequence, and related high-cardinality columns. |
| 2022 | Edge-IIoTset | Edge-IIoTset Port Scanning vs NORMALedge_iiotset_port_scanning_vs_normal | 0: NORMAL1: Port_Scanning_attack | 35,500 / 500 | 35,500 / 500 | Must be recreated locally; public CSV omitted | Additional10 materialization records this candidate from a public Kaggle mirror while the official IEEE DataPort route remains gated. Edge feature filtering dropped timestamp, IP, payload, text, checksum, sequence, and related high-cardinality columns. |
| 2023 | RT-IoT2022 | RT-IoT2022 NMAP UDP SCAN vs BENIGNrt_iot2022_nmap_udp_scan_vs_benign | 0: BENIGN1: NMAP_UDP_SCAN | 2,000 / 500 | 2,000 / 500 | Direct downloadable CSV | Additional10 materialization records this staged RT-IoT2022 candidate as materialized for the benchmark definition, with no extra materialization drops and train_test_source_row_index_overlap recorded as 0. |
| 2023 | RT-IoT2022 | RT-IoT2022 NMAP XMAS TREE SCAN vs BENIGNrt_iot2022_nmap_xmas_tree_scan_vs_benign | 0: BENIGN1: NMAP_XMAS_TREE_SCAN | 3,000 / 500 | 3,000 / 500 | Direct downloadable CSV | Additional10 materialization records this staged RT-IoT2022 candidate as materialized for the benchmark definition, with no extra materialization drops and train_test_source_row_index_overlap recorded as 0. |
| 2023 | RT-IoT2022 | RT-IoT2022 NMAP OS DETECTION vs BENIGNrt_iot2022_nmap_os_detection_vs_benign | 0: BENIGN1: NMAP_OS_DETECTION | 3,000 / 500 | 3,000 / 500 | Direct downloadable CSV | Additional10 materialization records this staged RT-IoT2022 candidate as materialized for the benchmark definition, with no extra materialization drops and train_test_source_row_index_overlap recorded as 0. |
| 2023 | RT-IoT2022 | RT-IoT2022 NMAP TCP scan vs BENIGNrt_iot2022_nmap_tcp_scan_vs_benign | 0: BENIGN1: NMAP_TCP_scan | 6,000 / 500 | 6,000 / 500 | Direct downloadable CSV | Additional10 materialization records this staged RT-IoT2022 candidate as materialized for the benchmark definition, with no extra materialization drops and train_test_source_row_index_overlap recorded as 0. |
Use the files programmatically
python3 scripts/list_tasks.py --status all
python3 scripts/export_benchmark_splits.py \
--task friday_bot \
--output-dir ml_exports/friday_bot
The split helper reconstructs benchmark-consistent train/test CSVs from the metadata and row order. It does not download or redistribute omitted datasets.