Sublinear Risk-Limiting Audits from Direct Ballot Selection and Statistical Ballot Manifests
Benjamin Fuller, Abigail Harrison, Alexander Russell
Abstract
Risk-limiting audits (RLAs) rigorously guarantee a specified maximum probability that an incorrect electoral outcome will not be detected. Efficient RLA methods require a software-independent count of the ballots in each batch, called a ballot manifest. While electoral procedures can efficiently provide rough estimates for batch sizes, even slight inaccuracies can invalidate conventional RLAs (Lindeman et al., EVT 2012). Thus, establishing a sufficiently accurate manifest often requires handling every ballot in the election and can dominate the cost of conducting an RLA. We propose two new risk-limiting techniques. The first is a statistical test that checks a trusted, coarse manifest against an untrusted, tabulator-supplied manifest to certify that the aggregate error is small; this bounds both the error in the reported ballot total and the distortion of the ballot-sampling distribution. The second is a new approach for election architectures that do not efficiently index ballots by identifier, as is typical of voter-facing tabulators. We call this approach direct ballot selection: it reverses the traditional comparison procedure by selecting physical ballots uniformly and comparing them to their corresponding cast vote records. This method also incorporates a new statistical test to check for identifier duplication. These techniques reduce the effort required to conduct RLAs. Our two main findings are: 1) Manifest creation time can be reduced, for California at a 3% margin, our model indicates that the overall audit time for comparison, polling, and direct selection audits is reduced by factors of approximately 438, 27, and 10, respectively and 2) Direct ballot selection improves over state-of-the-art polling for small margins. For Connecticut at a 1% margin, it requires 55% fewer ballots than the Minerva (Security 2021) and Providence (Security 2023) ballot polling methods.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7b1ff93e-3240-49d5-b53e-2d7ef11e2f15Builds on5
- Minerva- An Efficient Risk-Limiting Ballot Polling AuditFilip Zagórski, Grant McClearn, Sarah Morin, Neal McBurnett et al.USENIX Security 2021 · 9 citations
- DVSorder: Ballot Randomization Flaws Threaten Voter PrivacyBraden L. Crimmins, Dhanya Narayanan, Drew Springall, J. Alex HaldermanUSENIX Security 2024 · 2 citations
- The Decisive Power of Indecision: Low-Variance Risk-Limiting Audits and Election Contestation via Marginal Mark RecordingBenjamin Fuller, Rashmi Pai, Alexander RussellUSENIX Security 2024 · 1 citation
- PROVIDENCE: a Flexible Round-by-Round Risk-Limiting AuditOliver Broadrick, Poorvi L. Vora, Filip ZagórskiUSENIX Security 2023
- Adaptive Risk-Limiting Comparison AuditsBenjamin Fuller, Abigail Harrison, Alexander RussellS&P 2023
Related papers
- Can Voters Detect Malicious Manipulation of Ballot Marking Devices?Matthew Bernhard, Allison McDonald, Henry Meng, Jensen Hwa et al.S&P 2020 · 44 citations
- Busting the Paper Ballot: Voting Meets Adversarial Machine LearningKaleel Mahmood, Caleb Manicke, Ethan Rathbun, Aayushi Verma et al.CCS 2025
- Security Analysis of the Democracy Live Online Voting SystemMichael A. Specter, J. Alex HaldermanUSENIX Security 2021 · 24 citations
- ElectionGuard: a Cryptographic Toolkit to Enable Verifiable ElectionsJosh Benaloh, Michael Naehrig, Olivier Pereira, Dan S. WallachUSENIX Security 2024 · 12 citations
- Why Johnny Checks but Doesn't Alert: Reporting as the Missing Step in Verifiable Internet VotingTobias Hilt, Christian Mack, Benjamin Maximilian Berens, Melanie VolkamerCHI 2026
