The Hybrid Ladder MESSAGES 6 A (hired) δ = 0.36 A′ (you) δ/t = 0.060
CPA security implies CPA security for multiple encryptions

One challenge ciphertext. Six slots to fill. The ladder is how you get from one to the other.

There are two attackers on this page and everything depends on keeping them apart. A is the one you hired: it breaks the t-message game, and you never see inside it. A′ is the one you build: it plays the ordinary one-message CPA game, and it runs A once inside itself as a subroutine. The trouble is that A′'s challenger deals it exactly one ciphertext while A demands t — so whatever A′ builds, its two worlds differ in a single slot, and A's vectors differ in all of them. The ladder is the only thing that spans that gap, and it charges a toll of t for the crossing.

Who is who two attackers, two different games

the one you hired · never opened

A — the vector adversary

Already breaks multiple encryption. Its existence is the assumption you are trying to refute.
Plays
PrivKmult-cpa — the t-message game
Submits
two vectors M₀, M₁ of t messages
Receives
t ciphertexts, all under one key
Wins with
probability ½ + δ/2 — derived below, not assumed

A black box under contract. You never read its code, never rewind it, and run it exactly once. It will not tell you which slot it is reading.

the one you build · this is you

A′ — your machine

Assembled in the right-hand column. Everything you click on this page is a decision about A′.
Plays
PrivKcpa — the one-message game
Submits
a single pair m₀, m₁
Receives
one challenge ciphertext, plus an oracle
Wins with
probability ½ + δ/2t — the same average, over a shorter gap

Contains A. Its whole job is to dress one ciphertext up as a vector of t, hand that to A, and report A's verdict as its own.

A′’s own CPA challenger hands it one ciphertext c A′ — your machine · plays the ONE-message CPA game picks a rung i, buys slot i, fills the other t−1 from the oracle A — hired, black box plays the t-message game (c¹,…,cᵗ) b′ A′’s answer relayed, unchanged
A sits inside A′ and never learns it. Whenever the page says “A′ sends A”, that arrow is the one in the middle; whenever it says “deal a trial”, one whole box runs once.
The challenger · the vectors are on the table

Start at the top: look at what A actually submitted. Then assemble A′ in the right-hand column, walk every rung of the ladder, and deal enough trials to watch your advantage land where the algebra says it must.

What A submitted two vectors of t messages

drawn from M₀ drawn from M₁

The ladder rung 1 of 6 selected

visited 0/6

Each rung is a hybrid distribution Hi — a vector A could be handed: the first i slots carry messages from M₁, the rest from M₀. H₀ is exactly what A's own challenger deals when its bit is 0; Ht is exactly what it deals when the bit is 1. Each step between two rungs swaps a single slot — which is the only shape A′ can build, since it has one challenge ciphertext to place. The step bars are the increments pi − pi−1; they sum to δ no matter how they are distributed, which is the whole content of the telescoping.

Where ½ + δ/2 comes from the two-world average, written out

What A′ sends at this rung embedding the challenge at slot 1

the one ciphertext the CPA challenger deals you oracle call oracle call
A′'s own challenger flips 0
A′'s own challenger flips 1

Pr[A outputs 1] along the ladder

One point per rung. The shaded band is the increment your reduction is currently exploiting; the whole climb from p₀ to pt is δ.
Hover the plot to read a rung.
Trials dealt
0
one full run of A′
A′ guessed right
0
its own challenger's bit
Observed rate
deal to measure
Predicted
0.5300
½ + δ/2t