Security goal: unforgeability [GMR,BKR]
Prevent forgery (not just key-recovery)
Even if adversary is allowed a chosen-message attack
More formally: Adversary gets to query g(k,·) on q messages of its choice and obtain their tags (MACs).
Adversary wins if it then outputs a valid pair (m,tag) such that m is new.