It Doesn't Take a Thief: Optical-Scan Voting Systems Fail Even Without Adversaries
arXiv:2607.27101
The paper surveys how optical-scan voting systems can fail due to non‑adversarial errors, presenting a taxonomy of such failures and showing that many verification methods cannot detect them.
Abstract
Optical-scan voting systems and their supporting ecosystem of people, processes, and technology are fallible. While a substantial body of work examines adversarial threats to such systems, we have encountered jurisdictions where the possibility of tabulator error is not fully internalized. Stakeholders there often find hypothetical attacks unconvincing, but some are persuaded by real-world accounts of equipment and procedural failures. This paper introduces a taxonomy of non-adversarial failure modes organized into intuitive categories: recording votes on paper, reading votes from the paper, combining votes as read into a reported outcome, and testing and verifying, all illustrated with documented incidents. We map common verification mechanisms against this taxonomy, identifying gaps that no paper-based audit can detect or correct, most notably failures that compromise the trustworthiness of the paper trail, such as giving voters the wrong ballot style (omitting contests they are eligible for, or including ones they are not), using ballot-marking devices to record votes, or failing to keep voted ballots secure and organized.
to appear in Proceedings of E-Vote-ID 2026, LNCS, Springer, Cham