A preprint reports that COPA had lower prompt-injection attack success rates than comparison defenses while matching or exceeding an undefended model on two QA tests