TL;DR
after you have enough people to mix, start the signing protocol with one of them only:
- round started, send me a blinded secret
- client sends blinded secret
- here is your signed blinded secret
- please register your outputs now
as you are doing the process one client at a time you know which input is what output, and to any client it cannot at all be distinguished from normal operation
I didn’t check the protocol specs fully but this could be possible
