Take a two-wise independent hash function $h$ e.g. $h(x)=(a x+b) \bmod p$. Let $p>2^{n+1}$ be a prime number.

We define $G e n_p \sim U\left(F_p\right), U\left(F_p\right), E n c_{a, b}(x, r)=h(x+r) \| r$ (where $x \| r$ is the concatenation of $x(|x|=n)$ and randomness $r \sim U_n$ ) and $\operatorname{Dec}_{a, b}(y \| r)=\left((y-b) \cdot a^{-1}-r\right) \bmod p$. (Here $a=0$ with only $1 / p$ probability which is negligible)

For $x_1, x_2 \in F_p$, by 2 -wise indepdence for fixed $r_1 \neq r_2$

$$
\left\{h\left(x+r_1\right), r_1, h\left(x+r_2\right), r_2\right\}=\left\{U\left(F_p\right), r_1, U\left(F_p\right), r_2\right\}
$$


Since $r_1=r_2$ with only negligible probablility, when $r_1, r_2 \sim U_n$

$$
\begin{gathered}
\left\{h\left(x+r_1\right), r_1, h\left(x+r_2\right), r_2\right\} \approx_s\left\{U\left(F_p\right), U_n, U\left(F_p\right), U_n\right\} \\
\left\{E n c_{a, b}\left(x_1, r_1\right), E n c_{a, b}\left(x_2, r_2\right)\right\} \approx_s\left\{U\left(F_p\right), U_n, U\left(F_p\right), U_n\right\}
\end{gathered}
$$


Thus for $x_1, x_2, x_1^{\prime}, x_2^{\prime} \in F_p$,

$$
\left\{\operatorname{Enc}_{a, b}\left(x_1, r_1\right), \operatorname{Enc}_{a, b}\left(x_2, r_2\right)\right\} \approx_s\left\{U\left(F_p\right), U_n, U\left(F_p\right), U_n\right\} \approx_s\left\{\operatorname{Enc}_{a, b}\left(x_1^{\prime}, r_1^{\prime}\right), \operatorname{Enc}_{a, b}\left(x_2^{\prime}, r_2^{\prime}\right)\right\}
$$


Thus this is a 2 -secure private-key encryption.
For $x_1, x_2, x_3, x_1^{\prime}, x_2^{\prime}, x_3^{\prime} \in F_p$, since $r$ is included in the ciphertext, we also know $r_1, r_2, r_3, r_1^{\prime}, r_2^{\prime}, r_3^{\prime}$. Suppose the ciphertext $c t_i=y_i \| r_i$. We know that $a=\left(y_2-y_1\right) \cdot\left(x_2+r_2-x_1-r_1\right)^{-1}$ and $b=y_1-a\left(x_1+r_1\right)$. Then we are able to test whether $y_i=a\left(x_i+r_i\right)+b$ for all $i$. If yes, then this is the encryption of $x_1, x_2$ and $x_3$. Otherwise, this is the encryption of $x_1^{\prime}, x_2^{\prime}, x_3^{\prime}$.

We select $x_1=x_1^{\prime}, x_2=x_2^{\prime}$ and $x_3 \neq x_3^{\prime}$. When the ciphertext is encrypted $x_1, x_2, x_3$, this always outputs yes. When the ciphertext is encrypted $x_1^{\prime}, x_2^{\prime}, x_3^{\prime}$, we can recover $a$ and $b$ correctly, and with high probability we have $y_3^{\prime} \neq a\left(x_3+r_3^{\prime}\right)+b$ since $x_3^{\prime} \neq x_3$. Thus the distinguisher described above distinguishes $\left\{\operatorname{Enc}_{a, b}\left(x_1\right), \operatorname{Enc}_{a, b}\left(x_2\right), \operatorname{Enc}_{a, b}\left(x_3\right)\right\}$ and $\left\{\operatorname{Enc}_{a, b}\left(x_1^{\prime}\right), \operatorname{Enc}_{a, b}\left(x_2^{\prime}\right), \operatorname{Enc}_{a, b}\left(x_3^{\prime}\right)\right\}$.

Thus this is not a 3 -secure private-key encryption.