They're non standard and therefore don't get relayed by old nodes. They won't make it into the longer chain because we're assuming the fork is activated. So what does an attack look like, exactly?
If someone blindly accepts non-standard zero confs they've got bigger problems.