Abstract—Belief and vulnerability have been proposed recently to quantify information flow in security systems. Both concepts stand as alternatives to the traditional approaches founded on Shannon entropy and mutual information, which were shown to provide inadequate security guarantees. In this paper we unify the two concepts in one model so as to cope with (potentially inaccurate) attackers’ extra knowledge. To this end we propose a new metric based on vulnerability that takes into account the adversary’s beliefs. Keywords-Security; information hiding, information flow; quantitative and probabilistic models; uncertainty; accuracy; I. I Protecting sensitive and confidential data is becoming increasingly important in many fields of human activities, such as electronic communication, auction, payment and voting. Many protocols for protecting confidential information have been proposed in the literature. In recent years the frameworks for reaso...