Estimating all four distributions from samples

Each trial draws x from the source and r uniformly, then forms c = x ⊕ r. The top row uses every trial. The bottom row keeps only the trials matching a chosen message or a chosen ciphertext, so those panels fill in far more slowly.

Condition on message x*
Condition on ciphertext c*
 
0trials

P(x)

The source, over all trials. Outline is the published table.

P(c)

Ciphertexts, over all trials. Flat however lumpy the source is.

P(c | x = x*)

Only trials that sent x*. Uniform, and the same uniform for every choice of x*.

P(x | c = c*)

Only trials that produced c*. Converges to the source, not to uniform.

What each slice is converging to

Total variation distance, trials on a log axis.

P(c | x*) against uniform P(x | c*) against the source P(x | c*) against uniform distance from source to uniform