That is the structural bind. The leaking weights are not a bug in the architecture — they are the architecture. Any defense that suppresses those weights necessarily suppresses what made the model worth using.
The practical implication might be that privacy has to be solved at a completely differ...