Short of a oscilloscope hiding in the computer you use (totally possible), no process can derive the private key from the Trezor in theory.
Even if you have processes that blatantly copy every USB's contents (or even log all interactions verbosely) and log all key presses/clipboard interactions on the machine, you can still use a Trezor without compromising anything.
You can also verify that your clipboard is not being manipulated as the Trezor can verify the address it will be signing a transaction with on the display.
ADC's may be expensive in low volume discrete form, but integrated in (standardized!) peripheral bus (USB) controllers, this could be very cheap.
As always, it depends on the threat model: do you wish to protect against manufacturers/nation states or not?
Esentially adding a micro controller with an Analog to Digital converter that can watch the power pin inside the USB controller/port itself would be relatively simple and cheap.
If you stick a USB drive into a compromised computer to make a transaction, a virus can steal the private key.
If you stick a Trezor or Ledger into a compromised computer to make a transaction, your private key is still safe.
While this attack shows the trezor is probably a bit amateur-hour, it does provide some amount of value.
Specifically, I was answering the question "Why not just use a USB drive"