arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

并非只有“窃贼”才会造成问题:无对抗情况下光学扫描投票系统也会失效

It Doesn't Take a Thief: Optical-Scan Voting Systems Fail Even Without Adversaries

Aleksander Essex, Philip B. Stark

arXiv 2607.27101首次发表:更新:

AI 中文总结

本文提出非对抗性失效模式分类法,指出光学扫描投票系统存在纸质审计无法纠正的漏洞,即使无对抗性威胁也会失效,为完善投票系统提供了依据。

AI 中文摘要

光学扫描投票系统及其人员、流程、技术构成的支撑生态是易出错的。尽管已有大量研究探讨这类系统面临的对抗性威胁,但我们发现部分司法管辖区并未充分重视计票机出错的可能性。这些地区的利益相关方常认为假设性攻击缺乏说服力,却会被设备和流程故障的真实案例说服。本文提出非对抗性失效模式的分类法,按直观类别组织:纸质选票记录、纸质选票读取、将读取的选票合并为报告结果,以及测试与验证,所有类别均有已记录事件作为例证。我们将常见验证机制与该分类法对照,发现了纸质审计无法检测或纠正的漏洞,最显著的是损害纸质痕迹可信度的故障,如向选民提供错误的选票样式(遗漏其有资格参与的竞选或包含无资格参与的竞选)、使用选票标记设备记录选票,或无法保证已投选票的安全与有序存放。

英文摘要

Optical-scan voting systems and their supporting ecosystem of people, processes, and technology are fallible. While a substantial body of work examines adversarial threats to such systems, we have encountered jurisdictions where the possibility of tabulator error is not fully internalized. Stakeholders there often find hypothetical attacks unconvincing, but some are persuaded by real-world accounts of equipment and procedural failures. This paper introduces a taxonomy of non-adversarial failure modes organized into intuitive categories: recording votes on paper, reading votes from the paper, combining votes as read into a reported outcome, and testing and verifying, all illustrated with documented incidents. We map common verification mechanisms against this taxonomy, identifying gaps that no paper-based audit can detect or correct, most notably failures that compromise the trustworthiness of the paper trail, such as giving voters the wrong ballot style (omitting contests they are eligible for, or including ones they are not), using ballot-marking devices to record votes, or failing to keep voted ballots secure and organized.

Commentsto appear in Proceedings of E-Vote-ID 2026, LNCS, Springer, Cham

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑