Why Johnny Checks but Doesn’t Alert: Reporting as the Missing Step in Verifiable Internet Voting
Authors
Paper Title
Why Johnny Checks but Doesn’t Alert: Reporting as the Missing Step in Verifiable Internet Voting
Publication Info
- Topic area: Usability and security challenges in end-to-end verifiable internet voting systems.
- Keywords: Internet voting, end-to-end verifiability, cast-then-audit, manipulation detection, reporting, usability, voter confidence, security, step-by-step guide, human factors.
Background and Problem
- Problem / challenge: While end-to-end verifiable internet voting systems allow voters to verify their ballots, prior research has not adequately addressed the distinction between detecting and reporting manipulations. Reporting is critical for actionable responses but remains underexplored, particularly in the cast-then-audit approach.
- Significance: Ensuring that voters can reliably detect and report manipulations is essential for maintaining the integrity of democratic elections conducted via internet voting.
- Motivation and related work: Previous studies have focused on detection but often conflated it with reporting, lacked realistic baselines, and did not provide structured guidance for voters. This paper builds on prior work by addressing these gaps and examining how usability improvements and structured guidance affect voter behavior.
Solution
- Proposed approach: An improved cast-then-audit internet voting system with usability enhancements and a step-by-step guide to support voters in detecting and reporting manipulations.
- Novelty:
- Introduction of an independent, out-of-band reporting channel to separate detection from reporting.
- Assessment of how perceived trust and risks evolve during manipulations and after debriefing.
- Creation of a realistic baseline system modeled after a real-world election for comparison.
- Development and evaluation of a step-by-step guide to aid voters in navigating the voting and verification process.
- Procedure and key techniques:
- Conducted a large-scale online user study (N = 437) with six experimental groups combining three system versions (Baseline, Improved, Improved without Guide) and two manipulation types (Vote Tampering, Verification Prevention).
- Measured detection and reporting rates, usability (effectiveness, efficiency, satisfaction), and voter confidence (trustworthiness, perceived risks to vote integrity and secrecy).
- Analyzed qualitative and quantitative data to evaluate the impact of system improvements and the step-by-step guide.
Results
- Concrete findings:
- Detection rates for Verification Prevention manipulations increased from 26% (Baseline) to 70% (Improved) and 42% (Improved without Guide).
- Reporting rates for detected manipulations rose from 13% (Baseline) to 83% (Improved) for Vote Tampering and from 5% (Baseline) to 83% (Improved) for Verification Prevention.
- The step-by-step guide significantly improved detection and reporting for Verification Prevention manipulations but had little effect on Vote Tampering.
- Usability metrics showed higher effectiveness (84% verification completion in Improved systems vs. 66% in Baseline) with similar satisfaction scores across systems.
- Trustworthiness declined after manipulations but recovered in the Improved system after debriefing, while perceived risks to vote integrity and secrecy decreased only in the Improved system post-debriefing.
- Advantage over baselines:
- The Improved system outperformed the Baseline in both detection and reporting rates, particularly for subtle manipulations like Verification Prevention.
- The step-by-step guide addressed gaps in voter knowledge and reduced unawareness of reporting channels, a common issue in the Baseline system.
- Experiments / evaluation:
- Participants completed two voting tasks (referendum and party election) with optional verification and were exposed to one of two manipulation types.
- Detection and reporting were measured independently, and participants’ confidence was assessed at three time points (after the first election, after the manipulated election, and after debriefing).
- Statistical analyses included chi-square tests, Kruskal-Wallis tests, and qualitative coding of open-text responses.
- Limitations and future work:
- The study was conducted online, which may have inflated verification rates due to participant compensation.
- The step-by-step guide represents one specific design; alternative formats should be explored.
- Results may not generalize to other cultural or electoral contexts, such as Estonia or Switzerland, where internet voting is more established.
- Future work should examine the applicability of step-by-step guidance to other individual verifiability approaches (e.g., tracking codes, cast-or-audit).
Summary
This study highlights the critical distinction between detecting and reporting manipulations in verifiable internet voting systems. By introducing usability improvements and a step-by-step guide, the researchers significantly increased both detection and reporting rates, particularly for subtle Verification Prevention manipulations. The Improved system also supported voter confidence recovery after manipulations, demonstrating the value of clear, actionable guidance. These findings underscore the importance of independent reporting channels and structured voter support in strengthening the human layer of election security. Future research should explore the generalizability of these results and extend step-by-step guidance to other verifiability approaches.
Research Questions / Practical Problems
Question signals indexed for this paper.
- 83%
From Oversight to Insight: Transforming Cybersecurity Governance in Boardrooms
CHI '26· Privacy by Design & User Control +2
- 71%
Public Views on Digital COVID-19 Certificates: a Mixed Methods User Study
CHI '22· Privacy by Design & User Control +2
- 71%
A World Full of Privacy and Security (Mis)conceptions? Findings of a Representative Survey in 12 Countries
CHI '23· Privacy by Design & User Control +2
- 71%
"It's Confusing, Insecure, and Messy" – Mapping the Gaps Between Stakeholders' Cybersecurity Mental Models in the Danish Defence Sector
CHI '26· Privacy Perception & Decision-Making +2
- 67%
Toggles, Dollar Signs, and Triangles: How to (In)Effectively Convey Privacy Choices
CHI '21· Privacy by Design & User Control +1
- 67%
Covert Embodied Choice: Decision-Making and the Limits of Privacy Under Biometric Surveillance
CHI '21· Privacy by Design & User Control +1
- 67%
Field Evidence of the Effects of Privacy, Data Transparency, and Pro-social Appeals on COVID-19 App Attractiveness
CHI '22· Privacy by Design & User Control +1
- 67%
Tips, Tricks, and Training: Supporting Anti-Phishing Awareness among Mid-Career Office Workers Based on Employees' Current Practices
CHI '23· Privacy Perception & Decision-Making +1
- 67%
“Our Users' Privacy is Paramount to Us”: A Discourse Analysis of How Period and Fertility Tracking App Companies Address the Roe v Wade Overturn
CHI '24· Privacy by Design & User Control +1
- 67%
Out-of-Device Privacy Unveiled: Designing and Validating the Out-of-Device Privacy Scale (ODPS)
CHI '24· Privacy by Design & User Control +1
Based on Jaccard similarity of research subtopics & professions (≥60%)