Alec, I'd be interested in how Facebook has handled attacks like this against its one-hop onion service (RSOS), which has public IP addresses.
We’ve had no IP-level attacks that I am aware of.
We are already generally geared up to deal such attacks on our infrastructure, and because our Onions live in enclaves / are unreachable from “the internet”, living within the infrastructure, such attacks don’t impact the Onion site.
Our onions connect out to the internet / to the Tor network through (a cloud of) proxies. This is why RSOS is currently such a good fit for us, because (non-R) Single Onions would require inbound connectivity and thus presumably some mitigation would need to be applied.
-a