Industrial Control Systems (ICS) are increasingly exposed to cyber-physical attacks such as man-in-the-middle manipulation, sensor spoofing, and protocol-compliant command injection. Network-side defenses may lose process visibility under encrypted traffic or protocol-compliant spoofing, whereas host-side monitoring can disturb time-critical PLC execution if inference shares the scan-cycle scheduling path. This paper presents MGDefender, a scan-cycle-aware host-side protection framework that places PLC control and anomaly inference in separate real-time virtual machine (RTVM) and general-purpose virtual machine (GPVM) scheduling and memory domains. A restricted shared-memory ring buffer carries fixed-size I/O snapshots, and scan-boundary signals trigger only bounded acquisition in RTVM. Thus, protection of the PLC scheduling budget does not require suspending the detector as a low-criticality task. MGDefender further combines multivariate Gaussian denoising (MGD) with lightweight dynamic statistical process control (DSPC) to form the MGD-DSPC detector for identifying process-state deviations. An accompanying public artifact provides installation tests, explicit SWaT v0 input and preprocessing documentation, and an executable sample workflow with saved predictions and metrics. Author-archived Raspberry Pi 4B/OpenPLC measurements show microsecond-level cross-domain transfer and millisecond-level online inference with limited measured CPU and memory overhead. Complementary synthetic trace-driven comparisons expose the distinct trade-offs of shared-OS mixed-criticality degradation and statically provisioned dual-domain execution. These evidence classes support a fit-for-purpose architectural conclusion rather than universal performance superiority.
