How so? Seems like it's a pretty big step in the right direction, sure an attested phone is going to be much harder to compromise than one with custom os, custom kernel, and a user with root.
Attestation only detects user-initiated "compromises" like unlocking the bootloader and flashing a custom ROM. It does not detect exploitation.