Attack-to-Defense IoT: A Physical IoT Security Testbed for Labeled Dataset Generation and Machine Learning-Based Attack Detection
Resumo
The increasing adoption of Internet of Things (IoT) technologies has significantly expanded the attack surface of Cyber-Physical Systems (CPS), making realistic experimental environments essential for cybersecurity research. This work presents a low-cost and reproducible IoT cybersecurity testbed designed for realistic attack execution, multimodal labeled dataset generation, and Machine Learning (ML)-based intrusion detection. The proposed environment integrates ESP32-based embedded devices, MQTT/TLS communication, AWS cloud services, automated telemetry extraction pipelines, and supervised ML models. The infrastructure supports realistic attack scenarios including MQTT flooding, Sliver Command and Control (C2) beaconing, Denial-of-Service attacks, network scanning, and brute-force attacks against embedded services. The generated datasets combine PCAP-derived network traffic, MQTT telemetry, and sensor-generated events into a unified multimodal representation for intrusion detection experiments. Experimental results indicate that supervised ML algorithms, particularly Random Forest, are effective for detecting volumetric attacks and heterogeneous malicious traffic patterns in constrained IoT environments. The proposed platform contributes a reproducible physical infrastructure for IoT cybersecurity experimentation and establishes a foundation for future research involving Federated Learning (FL), TinyML, and distributed intrusion detection for CPS.
Referências
Alshamrani, A. and Anwar, A. (2022). Federated learning-based intrusion detection for mqtt-based iot networks. Sensors, 22(18):6854.
Aqachtoul, A., Karam, K., Elamrani, A., Najib, M., Rafalia, N., and Bakhouya, M. (2025). Mqtteeb-d: A real-world iot cybersecurity dataset for ai-powered threat detection in mqtt networks. Data in Brief, 62:111897.
Aveleira-Mata, J., Alaiz-Moretón, H., Bayón-Guitérrez, M., García-Ordás, M. T., Prieto-Fernandez, N., and García-Rodríguez, I. (2025). Mqtt uad: Mqtt under attack dataset. a public dataset for the detection of attacks in iot networks using mqtt protocol. Data in Brief, 63:112167.
Bishop Fox (2024). Sliver c2 framework. Available at: [link]. Accessed: 2026-05-10.
Fagan, M., Megas, K. N., Scarfone, K., and Smith, M. (2020). Foundational cybersecurity activities for iot device manufacturers. Technical Report NISTIR 8259, National Institute of Standards and Technology.
Farag, W., Wu, X.-W., Ezekiel, S., Rado, D., and Lassinger, J. (2025). Development and evaluation of a novel iot testbed for enhancing security with machine learning-based threat detection. Sensors, 25(18):5870.
Ferrag, M. A. et al. (2020). Deep learning for cyber security intrusion detection: Approaches, datasets, and comparative study. Journal of Information Security and Applications, 50:102419.
Freitas, A. et al. (2024). Mqtt-vet: Exploring mqtt protocol vulnerabilities. In Anais Estendidos do XIII Latin-American Symposium on Dependable Computing, page 111–113, Porto Alegre, RS, Brasil. SBC.
HiveMQ (2023). Mqtt security fundamentals. Available at: [link]. Accessed: 2026-05-10.
International Electrotechnical Commission (2021). Iec 62443: Security for industrial automation and control systems.
Lazzarini, R. et al. (2023). Federated learning for iot intrusion detection. Internet of Things, 22:100775.
Lyon, G. F. (2009). Nmap Network Scanning: The Official Nmap Project Guide to Network Discovery and Security Scanning. Insecure.
Meidan, Y. et al. (2018). N-baiot: Network-based detection of iot botnet attacks using deep autoencoders. IEEE Pervasive Computing, 17(3):12–22.
Nguyen, D. et al. (2021). Fediot: Federated learning for internet of things security. IEEE Internet of Things Journal, 8(16):12786–12795.
OASIS (2019). Mqtt version 5.0. Available at: [link]. Accessed: 2026-05-10.
Omotosho, A. et al. (2023). Ids-ma: Intrusion detection system for iot mqtt attacks using centralized and federated learning. Array, 18:100305.
OWASP Foundation (2024). Authentication cheat sheet. Available at: [link]. Accessed: 2026-05-10.
Rezaei, S. and Liu, X. (2019). Deep learning for encrypted traffic classification: An overview. IEEE Communications Magazine, 57(5):76–81.
Sanfilippo, S. (2005). hping3: Active network security tool. Available at: [link]. Accessed: 2026-05-10.
Silva, H. (2022). Csai-4-cps: A cyber security characterization model based on artificial intelligence for cyber physical systems. In 2022 IEEE/IFIP International Conference on Dependable Systems and Networks Workshops (DSN-W), pages 47–52. IEEE.
Silva, H. et al. (2021). Feature selection: Supporting the mining process on cyber-physical systems result datasets. In Workshop de Trabalhos de Iniciação Científica e Graduação (WTF).
Silva, H. and Moraes, R. (2024). Privacy-preserving iot intrusion detection: Challenges and solutions in implementing the csai-4-cps model. Computer Science & Information Technology (CS & IT), 14(7):95–108.
Verma, S. and Patel, A. (2024). Efficient network traffic feature sets for iot intrusion detection. arXiv preprint arXiv:2406.08042.
