Heinrihs Kristians Skrodelis, Andrejs Romanovs
Industrial Control Systems (ICS) and SCADA networks underpin operational technology, yet intrusion detection system (IDS) research keeps reporting strong laboratory numbers while sidestepping deployment blockers—strict false-alarm budgets, real-time latency, nonstationary plant behavior. We present an operational sensitivity audit of an explainable hybrid IDS pipeline, treating windowing/stride, thresholding, and SHAP-based explanation generation as coupled components. On two labeled ICS datasets (CIC Modbus and TU Wien), 10 s to 30 s stride changes rarely flip attack-window decisions (2.15% and 3.87%), but on a benign-only IEC-104 trace the false-alarm rate jumps from 1.50 to 3.55 per hour—FAR is not stride-invariant. Global SHAP explanations stay stable under stride perturbation, yet decision-critical flip-window explanations do not (median cosine distance 0.161 on TU Wien). A KS drift detector flags an injected mean shift with zero pre-drift false alarms. Inference and fusion run sub-millisecond; every claim maps to a regenerable artifact.