DNSSEC has support for denial of existence (NSEC/NSEC3) proofs, which means resolvers may require the resolver to provide them. This means you can't just MITM a DS record away. However practically most people dont use locally DNSSEC verifying resolvers, instead relying on upstream resolvers to do the job for them, which can be easily manipulated by your ISP.
Aside from that they bloat the size of responses a lot. However if you can sign DNSSEC on the go, you can use Cloudflare's black lies approach and have small enough DNS responses. [1]