Well, it is certainly complicated (I had another reply written but in fleshing out the different scenarios it got very complex and I gave up).
And I'm not sure that an attacker electing a 'smaller' number of witnesses is good either (can cause significant damage even with a minority, in fact according to BFT the threshold of malicious witnesses that can destroy the system is 33%).
The ideal number you want a minority stakeholder to be able to unilaterally elect is certainly zero, which is what approval voting strives for (assuring that all elected witnesses are 'acceptable' to the largest portion of the stake).
Of course that is an ideal and all real systems are likely to fail to live up to that ideal at some thresholds and under real conditions, but I think the one we have is pretty good. I would still like to see the vote limit increased or removed, which would further increase the vote weight totals (even a modest increase would keep steemit out more definitively; right now it is very close) and give us stronger protection on the backup list which is another vulnerability in a sense (even a relatively small stakeholder can promote witnesses from the backup list, which can be a type of long-term attack)
BTW, I'm not sure why you disagreed with my earlier reply which said this:
then becomes easier all else being equal for one large stakeholder to elect some witnesses even if not all of them
That's the same thing you are saying, as far as I can tell.
RE: Our Plan for Onboarding the Masses