We can think of the adversary as playing a game:
- Input: whatever adversary necessarily knows from the beginning, e.g. public key, distribution of plaintexts, etc
- Oracle: models information adversary can obtain during an attack. different kinds of information characterise different types of attacks
- Output: whatever the adversary wants to compute, e.g. secret key, partial information on plaintext, etc. They win if they succeed.