CoolFace
Datasetpublic

lifelonglab/CAD-CICUNSW

CAD-CICUNSW Dataset Summary CAD-CICUNSW is a single-source continual anomaly detection benchmark scenario for network intrusion detection. It is derived from CIC-UNSW-NB15 / UNSW-NB15 and converts the original tabular network-intrusion data into a sequence of concept-grouped tasks. The dataset contains 1,084,928 samples, 5 tasks, and has a reported 12.76% anomaly ratio in the test set. Intended Use This dataset is intended for research on:… See the full description on the dataset page: https://huggingface.co/datasets/lifelonglab/CAD-CICUNSW.

sourceHugging Facecc-by-4.0updated 1mo agoView on Hugging Face
0likes24downloads
Dataset Card

CAD-CICUNSW

Dataset Summary

CAD-CICUNSW is a single-source continual anomaly detection benchmark scenario for network intrusion detection. It is derived from CIC-UNSW-NB15 / UNSW-NB15 and converts the original tabular network-intrusion data into a sequence of concept-grouped tasks.

The dataset contains 1,084,928 samples, 5 tasks, and has a reported 12.76% anomaly ratio in the test set.

Intended Use

This dataset is intended for research on:

  • continual anomaly detection;
  • continual learning for tabular data;
  • network intrusion detection;
  • robustness under distribution shift;
  • task ordering in continual-learning benchmarks;
  • forgetting and knowledge transfer across related network-traffic concepts;
  • benchmarking anomaly detectors under sequential task exposure.

The intended use is defensive machine learning research. The dataset should not be used to support offensive cybersecurity activity.

Dataset Source

  • CIC-UNSW-NB15: https://www.unb.ca/cic/datasets/cic-unsw-nb15.html
  • UNSW-NB15: https://research.unsw.edu.au/projects/unsw-nb15-dataset

Dataset Files

The repository contains the following files:

FileDescription
data.csvMain tabular dataset file.
orderings.jsonPredefined task orderings for continual-learning evaluation.
croissant.jsonCroissant metadata describing the dataset.

Dataset Structure

The main file is:

text
data.csv

The dataset contains task metadata, binary labels, and numerical flow-level features.

Core Columns

ColumnTypeDescription
task_idintegerNumeric identifier of the continual-learning task.
task_namestringName of the task, e.g. cicunsw_0.
task_splitstringSplit assignment for the row.
labelintegerBinary anomaly label. Conventionally, 0 denotes benign/normal traffic and 1 denotes anomalous/attack traffic.

Task Identifiers

The dataset contains the following task identifiers:

cicunsw_0, cicunsw_1, cicunsw_2, cicunsw_3, cicunsw_4

Feature Columns

The remaining columns are numerical network-flow features, including packet-count, byte-count, flag-count, duration, inter-arrival-time, and aggregate flow-statistics features. Representative examples include:

  • Src Port
  • Dst Port
  • Protocol
  • Flow Duration
  • Tot Fwd Pkts
  • Tot Bwd Pkts
  • TotLen Fwd Pkts
  • TotLen Bwd Pkts
  • Fwd Pkt Len Mean
  • Bwd Pkt Len Mean
  • Flow Byts/s
  • Flow Pkts/s
  • Flow IAT Mean
  • Fwd IAT Mean
  • Bwd IAT Mean

For the complete schema, see croissant.json.

Task Orderings

The dataset provides six predefined orderings in orderings.json. These orderings define different continual-learning evaluation regimes over the same task set.

OrderingTask sequence
curriculum_asccicunsw_4cicunsw_1cicunsw_3cicunsw_2cicunsw_0
curriculum_desccicunsw_0cicunsw_2cicunsw_3cicunsw_1cicunsw_4
generalization_desccicunsw_4cicunsw_1cicunsw_2cicunsw_3cicunsw_0
generalization_asccicunsw_0cicunsw_3cicunsw_2cicunsw_1cicunsw_4
smooth_driftcicunsw_4cicunsw_2cicunsw_1cicunsw_3cicunsw_0
abrupt_driftcicunsw_1cicunsw_2cicunsw_3cicunsw_0cicunsw_4

These orderings are intended to expose complementary continual-learning dynamics, including curriculum-like adaptation, generalization-oriented ordering, smooth drift, and abrupt drift.

Dataset Creation

The details of dataset creation can be found in our paper: link

Citation

When using the dataset, please cite:

@article{faber2026towards,
  title={Towards Principled Continual Anomaly Detection: A Systematic Framework and Benchmark Scenarios},
  author={Faber, Kamil and Smendowski, Mateusz and Corizzo, Roberto},
  journal={arXiv preprint arXiv:2607.18289},
  year={2026}
}