Researchers present Secure On-Policy Distillation (SecOPD), a defensive fine-tuning approach that provides token-level feedback to guide training rather than the sequence-level signals used in prior defenses. When a model processes injected prompts, individual tokens are scored against clean inputs by an initialization model. A defended Qwen 3.6-27B model achieved a 9.0% attack success rate against adaptive prompt injections, compared to 94.0% for the previous state-of-the-art defense, with results generalizing to unseen domains including agentic tool calling.