I think the point is that with TPM, you would need a software vulnerability + physical access to compromise the system, rather than just physical access. The software vulnerability issue is why they want to combine TPM with SELinux, since TPM doesn't do anything to plug software security holes.