Yeah, that's exactly the point! How do you think that a decentralized system is any different?!
If everything is "decentralized", you still must have a way to get rid of bad actors. Even nostr is set up in a way that you can not force your node into anyone else's relay.
Forgive my bluntness, but the more you try to argue you point the more it seems you have no clue what you are talking about. There are plenty of things to criticize about Lemmy and ActivityPub in general, but you are missing the mark on all of them.
Okay, let me create an account on mastodon.social and use it to scrape content from every other instance.
Better yet, let me create an account on "i-want-privacy-in-a-public-internet.example.com" and access the federated timeline directly, then I can go and push the content from everyone into this discovery service.
What are they going to do? Unless they go to the point of asking for physical evidence behind the person asking for accounts and/or only give invitations to people they already know, and *completely shut down their own servers to the outside world, they will never be able to avoid data leakage.
And if they do get to do any of this, then what is the point of using anything based on ActivityPub? They will be better off by just using any of the existing group chat servers like Discord (or Matrix/XMPP if they still care about FOSS.)