My point is that if an attacker controls consensus (by having many IP addresses), he can double spend by signing transactions to send coins to an address, then by spaming the network to change the consensus and re-send the same coins to another address.
Not so for two reasons. First, the number of IP addresses you have is irrelevant. Trust is weighted by the number of signatures made with keys that a server has chosen to trust. Second, you can't "change the consensus". Once a consensus is reached on a given ledger, it's irrevocable. Every validator that witnesses the consensus signs the resulting ledger providing cryptographic proof that they agreed to that particular consensus. A transaction is not considered confirmed until the server possesses that cryptographic proof.