In what way is this not strictly better for the defender than if that same process was running as SYSTEM?
I don't think limiting the capabilities of a child process (even by running it as "SYSTEM_LITE") impacts its scheduling priority, security settings, etc. It would depend on the policy around the process.
You need to make sure there are no holes in the IPC. Like I said, it's presumably not infeasible, but it would have to be done right.
Why are those holes more dangerous than having the entire thing happen in SYSTEM land?
Naturally, there's a danger that it's not bullet-proof and will lead to escalations/escapes. However, how is the risk of that not a strict improvement over the situation where it's running as SYSTEM and doesn't even need to bother with that?
It sounds like it's strictly harder to weaponize faults in the component if they need to find a secondary problem in IPC encapsulation over just running code as SYSTEM as soon as they compromise the component.