You've still got the spike in network activity, and if you're running a relay, you've still got the spike in outgoing activity minus incoming activity.
Yes, but the local and remote activity can't be connected. Were somebody to connect and disconnect from Tor in the time surrounding an attack, you could; but you couldn't say that a Tor user is a culprit of an attack that went over the Tor network because they were using the Internet at the time. Perhaps they're just using Facebook or HN as they do many times each day.
Um, yes it can be connected. You have a graph that looks like /\_/-\_ of bandwidth differential on one machine and you have the graph that looks like /\_/-\_ of bandwidth used on the targeted machine. Case closed. The occasional connection to Facebook isn't going to obfuscate that.