There are probably going to be some big entities in the Lightning Network ("lightning service providers") that average users use to open channels in exchange for a fee. These LSPs need to closely monitor for malicious transactions, but the average user doesn't have to. The average user would only get ripped off if their LSP broadcast an invalid transaction. In that case, they could prove it to the network and everyone would leave the LSP. Eventually there will be long-standing LSPs with good reputation. People can open long-running payment channels with them. If on-chain transaction fees get really high, they could be set to timeout after a year. That gives both parties plenty of time to notice an invalid transaction. If they're paranoid about DoS or timing attack, they can close the channel a few days before it times out.
That's my understanding only from reading a few articles about how Lightning Network works, so what I'm saying might be ridiculous and I could be completely wrong.