It should be possible for the DHCP client to run as a normal user by giving it capabilities. Barring that, one could employ privilege separation to isolate the sensitive part.
Secondly, the ARP cache poising thing is a straw man. Two wrongs don't make a right and besides, you can use /etc/ethers to mitigate such attacks.