How to protect Plasma against DoS attacks?

Yes, I agree. But it is specific for your application/implementation. Plasma in the general sense is a pattern, not a specification. That’s why there are several Plasma styles already .
Also, I believe that in the original plasma paper, the solution for this case has already been discussed. It was mass-exit with bitmap of UTXOs which requires a bond to be placed. Any fraud proof can cancel the whole withdrawal.