What about spoofing IP addresses (bittorrent DHT / IPFS / deliberately faked Tor IP leaks / etc.) or a combined technique, so that the police think illegal material was shared from that IP, and when they come to investigate they find large quantities of random data, which they think is encrypted?