By the security of public-key encryption, we know for fixed $k_0$ and $k_0^{\prime}$, we have

$$
\left\{p k, E n c_{p k}^a\left(k_0\right)\right\} \approx_c\left\{p k, E n c_{p k}^a\left(k_0^{\prime}\right)\right\}
$$


Therefore trivially for fixed $k_0$ and $k_0^{\prime}$

$$
\left\{p k, E n c_{p k}^a\left(k_0\right), k_0\right\} \approx_c\left\{p k, E n c_{p k}^a\left(k_0^{\prime}\right), k_0\right\}
$$


Then let $k$ and $k^{\prime}$ be sampled from Gen ${ }^s$. We have

$$
\left\{p k, \operatorname{Enc}_{p k}^a(k), k\right\} \approx_c\left\{p k, \operatorname{Enc}_{p k}^a\left(k^{\prime}\right), k\right\}
$$


Since $k$ is already public, here for any fixed $m$

$$
\left\{p k, E n c_{p k}^a(k), k, E n c_k^s(m)\right\} \approx_c\left\{p k, E n c_{p k}^a\left(k^{\prime}\right), k, E n c_k^s(m)\right\}
$$


Hence we also have a weaker conclusion

$$
\left\{p k, E n c_{p k}^a(k), E n c_k^s(m)\right\} \approx_c\left\{p k, E n c_{p k}^a\left(k^{\prime}\right), E n c_k^s(m)\right\}
$$


Note for all $m_1$ and $m_2$, by security of private-key encryption

$$
\operatorname{Enc}_k^s\left(m_1\right) \approx_c \operatorname{Enc}_k^s\left(m_2\right)
$$


Finally,

$$
\begin{aligned}
\left\{p k, \operatorname{Enc}_{p k}^a(k), \operatorname{Enc}_k^s\left(m_1\right)\right\} & \approx_c\left\{p k, \operatorname{Enc}_{p k}^a\left(k^{\prime}\right), \operatorname{Enc}_k^s\left(m_1\right)\right\} \\
& \approx_c\left\{p k, \operatorname{Enc}_{p k}^a\left(k^{\prime}\right), \operatorname{Enc}_k^s\left(m_2\right)\right\} \\
& \approx_c\left\{p k, \operatorname{Enc}_{p k}^a(k), \operatorname{Enc}_k^s\left(m_2\right)\right\}
\end{aligned}
$$