There's a lot of overlap between cgroups, gVisor-style sandboxes, and VM-style sandboxes like Kata. The tradeoffs between them are mostly with respect to compatibility, robustness of the security boundaries, and performance. So, you know, the usual suspects.
We've reached a stage where we probably need better vocabulary for describing these tradeoffs :)
(I work on "near" the gVisor folks at Google, and I'm involved in the Kata community)
Honestly I don't see an advantage to this over a stricter seccomp policy, and most definitely slower.
See https://twitter.com/rauchg/status/991850924057350144 for why.
Basically run `mount` in a gvisor container and run `mount` in a runc container and see the major differences there. Just one example, but as you can see, linux mount namespaces tend to leak lots of mount information. some of it could be cleaned up with additional unmounts after setting up the new root for the container, but knowing what to unmount is not so simple (plus it's just janky AF).
(The OP even have figures to explain the differences e.g. at "Existing VM-based container technology")