Hmmmm. I don't know if I buy that. If the pattern is not cryptographically secure, then you're still vulnerable to man in the middle, and if it is cryptographically secure, wouldn't you get roughly the same security by just doing standard SSH key based auth?
Isn't the point to have some defense in depth, so if there is a zero-day exploit found for your SSH authentication, you are not wide open? In a way like the grooves on a key for a pin-tumbler lock.
That would cover a replay attack, but not a man in the middle attack (as the mitm would just intercept the new port knock pattern.)