I don't think there IS a receive side, WMM only affects transmit? Or at least not sure what you mean here.
Your point about rate limits and starvation are well taken. At least for the AP you can sanitize dscp at the border router, this is the intent of DSCP, that it's not really end to end but only local domain specific with reclassification at the border.
On the other hand, for something like a rogue client device it's impossible to prevent an Android phone from sending everything in the VO queue. But that's already true regardless of what you do in the AP.