6TiSCHSet-2026: A Multi-Layer Attack Dataset and Leakage-Aware Intrusion-Detection Benchmark for IETF 6TiSCH Networks
IEEE ACCESS, cilt.14, ss.147867-147900, 2026 (SCI-Expanded, Scopus)
- Yayın Türü: Makale / Tam Makale
- Cilt numarası: 14
- Basım Tarihi: 2026
- Doi Numarası: 10.1109/access.2026.3736663
- Dergi Adı: IEEE ACCESS
- Derginin Tarandığı İndeksler: Scopus, Science Citation Index Expanded (SCI-EXPANDED), Compendex, INSPEC, Directory of Open Access Journals
- Sayfa Sayıları: ss.147867-147900
- Karadeniz Teknik Üniversitesi Adresli: Evet
Özet
The IETF 6TiSCH stack provides deterministic, low-power connectivity for the Industrial Internet of Things (IIoT), yet a single compromised node can disrupt its routing or link scheduling. Machine-learning intrusion detection needs labelled data, but no public dataset captures the TSCH and 6P link-scheduling layer, and per-node identity leakage inflates the scores reported on existing higher-layer datasets. We release 6TiSCHSet-2026, an open 6TiSCH attack dataset of 206 Contiki-NG runs and 2.08 million labelled records: seven attack families spanning the data plane, the RPL routing and control planes, the application layer and the MAC layer, at 21 and 31 motes under a placement-stratified design, 36 concurrent two-attacker runs, and an 84-run replication of the placement design over three radio seeds. A group-aware per-(run, node) evaluation protocol is part of the specification. Across seventeen classifiers, deep time-windowed models give the best trade-off, with a 1D-CNN reaching a mean per-attack F1 of 0.77, although a Nemenyi test does not separate the leading models from the tree ensembles. Naive row-level cross-validation inflates per-attack F1 by up to 0.79, and auditing the grouping key shows it removes all of that leakage on the overt families and leaves 0.08 to 0.26 on the stealth ones. Replication over three seeds shows that placement and scale effects lie within radio-seed variability. Ablating the protocol layers shows that the TSCH and 6P telemetry is what makes the MAC-layer attacks detectable, lifting 6P Cell Exhaustion from 0.82 to 1.00. Concurrent attacks are markedly harder, at binary F1 0.45. Every run uses the customised 4emac MAC, so the release is a 4emac/6TiSCH dataset.