A simulator is a forger who has never seen the messages. Give it a short list of facts and let it invent the ciphertexts. The leftmost setting where nobody can tell its output from the real thing is exactly what the encryption leaks — and everything to the right of that point is information the scheme never revealed.
| Message sent | Real · Enc(m) | Simulated · S(L) |
|---|
If such a simulator exists, then everything an observer could possibly extract from a real ciphertext, she could equally have extracted from a transcript produced without the message — from the list of facts alone. So no other information was ever there to extract.
The slider is that L. Finding where indistinguishability begins is not a proof technique — it is the definition of how much leaks.