Could one defense be to design the chip to not have any empty space? In other words, fill in any empty area with test circuitry such that you couldn't tell which areas were actually used and which weren't.
Even worse, in many commercial chips, there are spare cells to allow for cheap low-level patching. The attacker can just swap out one of these cells with their own and have an attack that only modifies a single cell.