By definition if anyone can correlate who didn't sign an output to the one who provided an input, then the anonymity is broken.
So the only way the penalty fee payment could be uncorrelated from the inputs to the transaction, is to create the penalty payment after providing the inputs. Thus one could DOS at that point and refuse to provide the penalty payment.
Indeed they can prevent DOS if they break the anonymity by correlating your penalty payment to both your input and output.
Doesn't the refusal to sign only have to be correlated with the 0.1 DRK collateral for this to work?