Sublinear Risk-Limiting Audits from Direct Ballot Selection and Statistical Ballot Manifests
Benjamin Fuller, Abigail Harrison, Alexander Russell
摘要
Risk-limiting audits (RLAs) rigorously guarantee a specified maximum probability that an incorrect electoral outcome will not be detected. Efficient RLA methods require a software-independent count of the ballots in each batch, called a ballot manifest. While electoral procedures can efficiently provide rough estimates for batch sizes, even slight inaccuracies can invalidate conventional RLAs (Lindeman et al., EVT 2012). Thus, establishing a sufficiently accurate manifest often requires handling every ballot in the election and can dominate the cost of conducting an RLA. We propose two new risk-limiting techniques. The first is a statistical test that checks a trusted, coarse manifest against an untrusted, tabulator-supplied manifest to certify that the aggregate error is small; this bounds both the error in the reported ballot total and the distortion of the ballot-sampling distribution. The second is a new approach for election architectures that do not efficiently index ballots by identifier, as is typical of voter-facing tabulators. We call this approach direct ballot selection: it reverses the traditional comparison procedure by selecting physical ballots uniformly and comparing them to their corresponding cast vote records. This method also incorporates a new statistical test to check for identifier duplication. These techniques reduce the effort required to conduct RLAs. Our two main findings are: 1) Manifest creation time can be reduced, for California at a 3% margin, our model indicates that the overall audit time for comparison, polling, and direct selection audits is reduced by factors of approximately 438, 27, and 10, respectively and 2) Direct ballot selection improves over state-of-the-art polling for small margins. For Connecticut at a 1% margin, it requires 55% fewer ballots than the Minerva (Security 2021) and Providence (Security 2023) ballot polling methods.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper5
- Minerva- An Efficient Risk-Limiting Ballot Polling AuditFilip Zagórski, Grant McClearn, Sarah Morin, Neal McBurnett 等USENIX Security 2021 · 被引用 9 次
- DVSorder: Ballot Randomization Flaws Threaten Voter PrivacyBraden L. Crimmins, Dhanya Narayanan, Drew Springall, J. Alex HaldermanUSENIX Security 2024 · 被引用 2 次
- The Decisive Power of Indecision: Low-Variance Risk-Limiting Audits and Election Contestation via Marginal Mark RecordingBenjamin Fuller, Rashmi Pai, Alexander RussellUSENIX Security 2024 · 被引用 1 次
- PROVIDENCE: a Flexible Round-by-Round Risk-Limiting AuditOliver Broadrick, Poorvi L. Vora, Filip ZagórskiUSENIX Security 2023
- Adaptive Risk-Limiting Comparison AuditsBenjamin Fuller, Abigail Harrison, Alexander RussellS&P 2023
相关 Paper
- Can Voters Detect Malicious Manipulation of Ballot Marking Devices?Matthew Bernhard, Allison McDonald, Henry Meng, Jensen Hwa 等S&P 2020 · 被引用 44 次
- Busting the Paper Ballot: Voting Meets Adversarial Machine LearningKaleel Mahmood, Caleb Manicke, Ethan Rathbun, Aayushi Verma 等CCS 2025
- Security Analysis of the Democracy Live Online Voting SystemMichael A. Specter, J. Alex HaldermanUSENIX Security 2021 · 被引用 24 次
- ElectionGuard: a Cryptographic Toolkit to Enable Verifiable ElectionsJosh Benaloh, Michael Naehrig, Olivier Pereira, Dan S. WallachUSENIX Security 2024 · 被引用 12 次
- Why Johnny Checks but Doesn't Alert: Reporting as the Missing Step in Verifiable Internet VotingTobias Hilt, Christian Mack, Benjamin Maximilian Berens, Melanie VolkamerCHI 2026
