Can Voters Detect Malicious Manipulation of Ballot Marking Devices?
Matthew Bernhard, Allison McDonald, Henry Meng, Jensen Hwa, Nakul Bajaj, Kevin Chang, J. Alex Halderman
Abstract
Ballot marking devices (BMDs) allow voters to select candidates on a computer kiosk, which prints a paper ballot that the voter can review before inserting it into a scanner to be tabulated. Unlike paperless voting machines, BMDs provide voters an opportunity to verify an auditable physical record of their choices, and a growing number of U.S. jurisdictions are adopting them for all voters. However, the security of BMDs depends on how reliably voters notice and correct any adversarially induced errors on their printed ballots. In order to measure voters' error detection abilities, we conducted a large study (N = 241) in a realistic polling place setting using real voting machines that we modified to introduce an error into each printout. Without intervention, only 40% of participants reviewed their printed ballots at all, and only 6.6% told a poll worker something was wrong. We also find that carefully designed interventions can improve verification performance. Verbally instructing voters to review the printouts and providing a written slate of candidates for whom to vote both significantly increased review and reporting rates -although the improvements may not be large enough to provide strong security in close elections, especially when BMDs are used by all voters. Based on these findings, we make several evidence-based recommendations to help better defend BMD-based elections.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a4c87132-38cd-468d-a485-4bafbf0afc21Cited by top-tier papers7
- Security Analysis of the Democracy Live Online Voting SystemMichael A. Specter, J. Alex HaldermanUSENIX Security 2021 · 24 citations
- "Why wouldn't someone think of democracy as a target?": Security practices & challenges of people involved with U.S. political campaignsSunny Consolvo, Patrick Gage Kelley, Tara Matthews, Kurt Thomas et al.USENIX Security 2021 · 15 citations
- Minerva- An Efficient Risk-Limiting Ballot Polling AuditFilip Zagórski, Grant McClearn, Sarah Morin, Neal McBurnett et al.USENIX Security 2021 · 9 citations
- E-Vote Your Conscience: Perceptions of Coercion and Vote Buying, and the Usability of Fake Credentials in Online VotingLouis-Henri Merino, Alaleh Azhir, Haoqian Zhang, Simone Colombo et al.S&P 2024 · 5 citations
- Busting the Paper Ballot: Voting Meets Adversarial Machine LearningKaleel Mahmood, Caleb Manicke, Ethan Rathbun, Aayushi Verma et al.CCS 2025
Related papers
- Why Johnny Checks but Doesn't Alert: Reporting as the Missing Step in Verifiable Internet VotingTobias Hilt, Christian Mack, Benjamin Maximilian Berens, Melanie VolkamerCHI 2026
- I-VAMOS: Independent Voting with Accessible Multimodal Offline System for Visually Impaired UsersGyeongdeok Kim, Chungman Lim, Gyungmin Jin, Gunhyuk ParkCHI 2026 · 1 citation
- Investigating Voter Perceptions of Printed Physical Audit Trails for Online VotingKarola Marky, Nina Gerber, Henry John Krumb, Mohamed Khamis et al.S&P 2024 · 1 citation
- Sublinear Risk-Limiting Audits from Direct Ballot Selection and Statistical Ballot ManifestsBenjamin Fuller, Abigail Harrison, Alexander RussellCCS 2026
- Machine-Checked Proofs of Privacy for Electronic Voting ProtocolsVéronique Cortier, Constantin Catalin Dragan, François Dupressoir, Benedikt Schmidt et al.S&P 2017 · 50 citations
