Binary signing is a complicated area ...
That "smart screen" warning is caused by the Dwarf Fortress.exe, not from DFHack, because Dwarf Fortress itself isn't signed. When running Dwarf Fortress.exe the first time it's triggering the warning:
"Windows Protected your PC
Microsoft Defender SmartScreen prevented an unrecognized app from starting. Running this app might put your PC at risk.
..."
Installing and running DFHack (by starting Dwarf Fortress) isn't causing any warning. And the first cloud scan is only starting after about 6 hours.
I can imagine that DFHack is suspicious for the scanner because it is hooking in another app, just like malware would do it.
And I imagine that most of your user base is now on the Steam version of DF, while I am using the free version. I'm curious if you could replicate it with the free version. You need to have set "cloud protection" and "automatic sample submission" both on ON. (I did set "automatic sample submission" OFF some time ago when I was developing some program, but some upgrade installation of Windows must have turned it back to ON...)
I checked my event log again and the cloud protection is only triggered by DFHack regulary. Other cloud scans I can find are rare and only every few months one entry. (It's under Applications and Services/Microsoft/Windows/Windows Defender/Operational in the event viewer, search there for "cloud").
My main intention to post this behaviour was that your are aware of this when others report that DF isn't starting anymore with DFHack (such a long starting time is looking at first like it isn't starting at all). And there isn't much you can do, expect telling affected users to wait it out or to disable the "automatic sample submission" or to set an exception for the DF folder in the Defender.