Search papers, labs, and topics across Lattice.
This paper analyzes the inherent vulnerabilities of optical-scan voting systems, highlighting non-adversarial failure modes that can undermine election integrity. By categorizing these failures into intuitive groups, such as vote recording and verification processes, the authors illustrate how stakeholders often overlook these issues in favor of hypothetical adversarial threats. The study reveals critical gaps in existing verification mechanisms that could lead to significant trust deficits in the electoral process, emphasizing the need for heightened awareness and improved safeguards.
Non-adversarial failures in optical-scan voting systems could undermine election integrity just as much as direct attacks, yet they remain largely unaddressed.
Optical-scan voting systems and their supporting ecosystem of people, processes, and technology are fallible. While a substantial body of work examines adversarial threats to such systems, we have encountered jurisdictions where the possibility of tabulator error is not fully internalized. Stakeholders there often find hypothetical attacks unconvincing, but some are persuaded by real-world accounts of equipment and procedural failures. This paper introduces a taxonomy of non-adversarial failure modes organized into intuitive categories: recording votes on paper, reading votes from the paper, combining votes as read into a reported outcome, and testing and verifying, all illustrated with documented incidents. We map common verification mechanisms against this taxonomy, identifying gaps that no paper-based audit can detect or correct, most notably failures that compromise the trustworthiness of the paper trail, such as giving voters the wrong ballot style (omitting contests they are eligible for, or including ones they are not), using ballot-marking devices to record votes, or failing to keep voted ballots secure and organized.