If Firefox is backdoored, as per GP's hypothetical situation, your data can be sent to a sync server other than the one you configured.
The only realistic way to stop it would be to only use a specific audited version of FF. If that's the case then there's no need to use your own sync server because you already know it's not backdoored.
There can be no guarantee you’d not notice, but more importantly if you go down that path you can’t trust anything and that is a silly reason to not build defense in depth and not entrust your secrets to the cloud.