Turkish Journal of Electrical Engineering and Computer Sciences
Abstract
The efficacy of artificial intelligence (AI) in intrusion detection systems (IDS) is critically dependent on high-fidelity training data. However, as detailed in the manuscript's literature review, existing benchmark datasets are predominantly synthetic, outdated, or imbalanced and fail to capture the complexity of the contemporary threat landscape. To bridge this gap, this study introduces CUIP-X25, a novel real-world cyber-attack dataset captured over a four-month period using a dionaea honeypot deployed on a public network. Unlike synthetic alternatives, this dataset provides an authentic representation of modern adversarial tactics, techniques, and procedures, encompassing 3.16 million real events across ten distinct attack categories, including IoT-targeted exploits, malware injections, and brute-force attacks. To address class imbalance in AI model training, SMOTE was applied to create a balanced training dataset, yielding 4.57 million records. This study comprehensively details the data collection methodology, rigorous preprocessing pipeline, and heuristic-based algorithm for attack categorization, resulting in a cleaned dataset of 65 fully populated features. The dataset's validity was demonstrated through extensive statistical profiling, visualization, and experimental evaluation. Training random forest and hybrid CNN-LSTM models on CUIP-X25 achieved detection accuracies of 98.14% and 98.57%, respectively which are comparable to benchmark datasets. CUIP-X25 corpus is published in multiple formats, including raw SQLite log file, malware binaries, raw CSV files, original unbalanced dataset, and SMOTE-balanced dataset to support diverse research needs. By offering a realistic, validated, and publicly available benchmark, CUIP-X25 serves as an essential resource for developing next-generation AI-driven cybersecurity defenses.
DOI
10.55730/1300-0632.4278
Keywords
Real-world dataset, intrusion detection system, honeypot, dionaea, CUIP-X25, IoT security
First Page
833
Last Page
854
Publisher
The Scientific and Technological Research Council of Türkiye (TÜBİTAK)
Creative Commons License

This work is licensed under a Creative Commons Attribution 4.0 International License.
Recommended Citation
IQBAL, A, & ASGHAR, S (2026). CUIP-X25: a real-world network intrusion dataset for next-generation AI-driven security. Turkish Journal of Electrical Engineering and Computer Sciences 34 (5): 833-854. https://doi.org/10.55730/1300-0632.4278
Included in
Computer Engineering Commons, Computer Sciences Commons, Electrical and Computer Engineering Commons