<SMALL SUBGROUP ATTACK> highlight the importance of proper parameter selection and validation in DH-based protocols. By ensuring received public keys belong to the intended subgroup and designing curves/protocols to minimize cofactors, these attacks can be neutralized. While the theoretical risk exists, practical impact is constrained by modern curve choices and mitigations like private key clamping.