Yes they still will get the port through a port scan, but in changing the default port and "forcing" the attacker to use a scanner... you as an attacker just set off the IDS system and the attackers...