REVIEW 2 major objections 1 minor 1 cited by
Voting by mail: a Markov chain model for managing the security risks of election systems
T0 review · 2 major / 1 minor · reviewed 2026-05-23 · grok-4.3
Pith's one-line read A discrete-time Markov chain model of vote-by-mail processes identifies ballot drop boxes and automatic notifications as key to shrinking the attack surface.
desk verdict New DTMC framework for VBM risk modeling, but the ranking of mitigations rests on chosen hypothetical probabilities rather than fitted data. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
discrete-time Markov chain with layered network approach that captures the interplay of VBM processes, threats, and mitigations over time
What would settle it
Compare the model's predicted risk reductions from installing drop boxes and notifications against observed rates of ballot loss, tampering, or delivery failures in jurisdictions that have and have not adopted those measures.
Extended reading notes
Core claim
The authors construct a DTMC that tracks ballot movement through successive states while incorporating a spectrum of failure modes and countermeasures; analysis of the resulting state probabilities under stress scenarios shows that adding ballot drop boxes and automatic ballot notification systems produces the largest reductions in the modeled attack surface.
Load-bearing premise
The discrete-time Markov chain and layered network structure can faithfully represent the dynamic interactions among voting processes, threats, and security measures.
Editorial extensions
If this is right
- The model quantifies how attack timing affects the effectiveness of different security controls.
- Hypothetical worst-case scenarios can be used to stress-test the resilience of an entire VBM workflow.
- Performance metrics derived from the chain allow direct comparison of mitigation packages on the same data set.
- The framework treats both accidental voter errors and sophisticated attacks within a single probabilistic structure.
Reading between the lines
- The same state-transition approach could be reused to compare VBM risk profiles across different counties or states that collect comparable process data.
- Embedding real-time incident logs into the chain would let operators update risk estimates during an active election cycle.
- Resource allocation decisions could be informed by ranking mitigations according to the size of the attack-surface reduction each produces in the model.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper introduces a discrete-time Markov chain (DTMC) framework with a layered network to model vote-by-mail (VBM) processes, incorporating states for process steps, malicious/non-malicious threats, and mitigations. It uses time-inhomogeneous transitions to evaluate dynamic risks and performance, applies the model to Milwaukee County data, and runs hypothetical worst-case attack scenarios to assess mitigations. The central claim is that ballot drop boxes and automatic notification systems are crucial for reducing attack surface.
Significance. A validated quantitative DTMC model for VBM risk assessment would be a useful addition to election security literature, moving beyond qualitative checklists by enabling scenario-based evaluation of mitigations. The Milwaukee County case study and stress-testing approach provide a concrete starting point, but the framework's impact is currently limited by the lack of data-driven parameter estimation.
major comments (2)
- [Case study section] Case study (Milwaukee County application): transition probabilities governing malicious attacks, error rates, and mitigation efficacy are chosen to illustrate worst-case timings rather than estimated or fitted from the supplied aggregate counts/rates. This choice directly supports the ranking of drop boxes and notifications as most effective, so the headline claim is conditional on those unvalidated numerical selections remaining representative.
- [Model definition section] Model construction: the DTMC state space and layered network are defined, but the paper does not show how the time-inhomogeneous transition matrix entries are constructed from the Milwaukee data versus assigned for hypothetical scenarios, nor does it include sensitivity analysis or validation against observed election outcomes.
minor comments (1)
- [Abstract] Clarify in the abstract and introduction whether any transition probabilities are derived from external data sources beyond the Milwaukee aggregates.
Simulated Author's Rebuttal
We thank the referee for the constructive feedback on our DTMC framework for vote-by-mail risk assessment. The comments correctly identify areas where the manuscript could better distinguish between data-derived elements and illustrative parameters. We address each point below and will make revisions to improve clarity and transparency.
read point-by-point responses
-
Referee: [Case study section] Case study (Milwaukee County application): transition probabilities governing malicious attacks, error rates, and mitigation efficacy are chosen to illustrate worst-case timings rather than estimated or fitted from the supplied aggregate counts/rates. This choice directly supports the ranking of drop boxes and notifications as most effective, so the headline claim is conditional on those unvalidated numerical selections remaining representative.
Authors: We agree that the transition probabilities for malicious attacks, errors, and mitigations are assigned to represent worst-case scenarios rather than fitted from the Milwaukee County aggregate counts. The supplied data informs process volumes, timings, and overall scale but lacks the granular per-step rates needed for statistical estimation of threat or mitigation parameters. The analysis is framed as a stress-test of the framework under extreme conditions, not as a calibrated prediction. We will revise the case study section to explicitly document the parameter selection rationale, state that results are conditional on the chosen values, and qualify the conclusions about drop boxes and notifications accordingly. revision: yes
-
Referee: [Model definition section] Model construction: the DTMC state space and layered network are defined, but the paper does not show how the time-inhomogeneous transition matrix entries are constructed from the Milwaukee data versus assigned for hypothetical scenarios, nor does it include sensitivity analysis or validation against observed election outcomes.
Authors: The manuscript uses Milwaukee County data for aggregate quantities such as ballot volumes and process durations, while threat and mitigation probabilities are assigned for the hypothetical scenarios. We acknowledge that the distinction and the explicit construction of the time-inhomogeneous matrices are not sufficiently detailed. We will add a dedicated subsection (or appendix) describing the sources and assignment rules for each class of parameters. We will also include a sensitivity analysis on the key threat and mitigation probabilities to demonstrate robustness. Direct validation against observed attack outcomes is limited by the low base rate of such events; we will discuss this constraint in the revised text. revision: yes
Circularity Check
No circularity: DTMC is a simulation framework with externally supplied parameters and data
full rationale
The paper introduces a new DTMC layered-network model for VBM risk assessment and evaluates it on Milwaukee County aggregate counts plus chosen hypothetical transition probabilities for worst-case scenarios. No equations or sections show a result that reduces by construction to its own fitted inputs, self-citations, or renamed known patterns. The central claims are conditional on the chosen parameters, which is standard modeling practice and does not constitute circularity. The derivation chain remains self-contained against external benchmarks.
Assumptions & free parameters
Cite this review
Pith. "Pith review of Voting by mail: a Markov chain model for managing the security risks of election systems." pith.science (2026). https://pith.science/paper/2410.13900
@misc{pith2026241013900,
author = {Pith},
title = {Pith review of: Voting by mail: a Markov chain model for managing the security risks of election systems},
year = {2026},
howpublished = {\url{https://pith.science/paper/2410.13900}},
note = {Machine review of arXiv:2410.13900}
}
read the original abstract
The scrutiny surrounding vote-by-mail (VBM) in the United States has increased in recent years, highlighting the need for a rigorous quantitative framework to evaluate the resilience of the absentee voting infrastructure. This paper addresses these issues by introducing a dynamic mathematical modeling framework for performing a risk assessment of VBM processes. We introduce a discrete-time Markov chain (DTMC) to model the VBM process and assess election performance and risk with a novel layered network approach that considers the interplay between VBM processes, malicious and non-malicious threats, and security mitigations. The time-inhomogeneous DTMC framework captures dynamic risks and evaluates performance over time. The DTMC model accounts for a spectrum of outcomes, from unintended voter errors to sophisticated, targeted attacks, representing a significant advancement in the risk assessment of VBM planning and protection. A case study based on real-world data from Milwaukee County, Wisconsin, is used to evaluate the DTMC model. The analysis includes hypothetical worst-case attack scenarios to stress-test VBM processes and to assess the efficacy of security measures and the impact of different attack timings. The analysis suggests that ballot drop boxes and automatic ballot notification systems are crucial for reducing the attack surface to ensure secure and reliable operations.
Figures
Figures from the paper (3 more)
Forward citations
Cited by 1 Pith paper
-
Ballot Design and Electoral Outcomes: The Role of Candidate Order and Party Affiliation
Using a natural experiment in North Carolina judicial races, the paper estimates that candidate-order flips relative to the presidential race cause 11.8% of Democratic and 15.4% of Republican partisan voters to cast v...
Reference graph
Works this paper leans on
-
[1]
Barry C. Burden. The experiences of municipal clerks and the electorate in the November 2020 General Election in Wisconsin, Sept 2021. URL https://thompsoncenter.wisc.edu/wp-content/uploads/sites/509/2021/09/ Burden-2020-Wisconsin-Election-Report-PUBLIC.pdf
work page 2020
-
[2]
The 2020 voting experience: Lessons learned and recommendations for reform, 2021
Bipartisan Policy Center. The 2020 voting experience: Lessons learned and recommendations for reform, 2021. URL https://bipartisanpolicy.org/download/?file=/wp-content/ uploads/2021/04/EPP-Voting-Experience_RV1.pdf. Accessed: 2024-09-02
work page 2020
-
[3]
J. Blessing, J. Gomez, P. McCoy, and T. Ngyuen. Security survey and analysis of vote-by-mail systems. Computers and Society, Cryptography and Security MIT , Sept. 2020
work page 2020
-
[4]
Final voting ward demographics
City of Milwaukee Common Council. Final voting ward demographics. Accessed on: Aug. 4, 2020. [Online]. Available: https://city.milwaukee.gov/ImageLibrary/Groups/ ccCouncil/2012PDF/FinalVotingWardDemographics-Ju.xls, 2012
work page 2020
-
[5]
Mail-in voting in 2020 infrastruc- ture risk assessment and infographic, July 2020
Cybersecurity and Infrastructure Security Agency(CISA). Mail-in voting in 2020 infrastruc- ture risk assessment and infographic, July 2020. URL https://www.cisa.gov/publication/ election-mail-risk
work page 2020
- [6]
-
[7]
Democracy Works. Ballotscout. https://www.democracy.works/ballotscout, 2021. Ac- cessed: 2024-05-21
work page 2021
- [8]
Show all 43 references
-
[9]
Accessed: 2025-04-27
2025
-
[10]
Haseltine, S
C. Haseltine, S. Wang, and L. Albert. Dynamic cyber-physical system security planning using attack graphs. In Proceedings of the IISE Annual Meeting , Seattle, WA, May 2022. Institute of Industrial and Systems Engineers
2022
-
[11]
Ballottrax
i3logix. Ballottrax. https://www.ballottrax.com/, 2024. Accessed: 2024-05-21
2024
-
[12]
J. Li, T. T. Allen, and K. Akah. Could simulation optimization have prevented 2012 central Florida election lines? In 2013 Winter Simulations Conference (WSC) , pages 2088–2096, Washington, DC, USA, 2013. IEEE
2012
-
[13]
What queueing means; polling places Covid-19?
C. McIntyre. “What queueing means; polling places Covid-19?” - MIT Election Lab, Aug. 2020. URL https://electionlab.mit.edu/sites/default/files/2020-08/ WhatQueueingMeansPollingPlacesCOVID19.pdf
2020
-
[14]
Municipalities, June 2023
Milwaukee County. Municipalities, June 2023. URL https://county.milwaukee.gov/EN/ Municipalities. 30
2023
-
[15]
November 3, 2020 - general election
Milwaukee Elections Commission. November 3, 2020 - general election. Nov. 6, 2020, Accessed on: June 5, 2021 [Online]. Available: https://city.milwaukee.gov/election/ ElectionInformation/ElectionResults/2020/November, 2020
2020
-
[16]
Voting wards 2020
Milwaukee OpenData. Voting wards 2020. Accessed on: Aug. 6, 2020. [Online]. Available: https://data.milwaukee.gov/dataset/voting-wards/resource/ 01139d6b-b65a-4d63-89da-b87f3986ff0d?inner_span=True , April 6, 2020, 2020
2020
-
[17]
Voting by mail and absentee voting, Mar
MIT Election Data + Science Lab. Voting by mail and absentee voting, Mar. 2021. URL https://electionlab.mit.edu/research/voting-mail-and-absentee-voting
2021
-
[18]
Report voting outside the polling place: Absentee, all-mail and other voting at home options
National Conference of State Legislatures. Report voting outside the polling place: Absentee, all-mail and other voting at home options. Updated on: July 12, 2022. [Online]. Available: https://www.ncsl.org/elections-and-campaigns/ voting-outside-the-polling-place , 2022
2022
-
[19]
Voting outside the polling place: Absentee, all-mail and other voting at home options
National Conference of State Legislatures. Voting outside the polling place: Absentee, all-mail and other voting at home options. Accessed on: June 21, 2023. https://www. ncsl.org/research/elections-and-campaigns/voting-outside-the-polling-place. aspx, 2022. https://www.ncsl.o...
2023
-
[20]
United States Postal Service performance of election and political mail during the November 2020 general election
Office of Inspector General. United States Postal Service performance of election and political mail during the November 2020 general election. Audit report, United States Postal Service, Washington, D.C., Mar. 2021
2020
-
[21]
United States postal service performance of election and political mail during the November 2020 General Election
Office of Inspector General. United States postal service performance of election and political mail during the November 2020 General Election. Audit report, United States Postal Service, Mar. 2021
2020
-
[22]
Rinaldi, J
S. Rinaldi, J. Peerenboom, and T. Kelly. Identifying, understanding, and analyzing critical infrastructure interdependencies. IEEE Control Systems Magazine , 21(6):11–25, 2001. doi: 10.1109/37.969131
2001 doi
-
[23]
R. G. Saltman. Accuracy, integrity and security in computerized vote-tallying. Commun. ACM, 31(10):1184–1191, oct 1988. ISSN 0001-0782. doi: 10.1145/63039.63041. URL https: //doi.org/10.1145/63039.63041
1988 doi
-
[24]
Scala, I
N. Scala, I. Bloomquist, Y. Mezgebe, and B. Jilcha. A process map and risk assessment for mail-based voting. In A. Ghate, K. Krishnaiyer, K. Paynabar, eds., editor, Proceedings of the 2021 Institute of Industrial and System Engineers (IISE) Annual Conference , 2021
2021
-
[25]
N. M. Scala, P. L. Goethals, J. Dehlinger, Y. Mezgebe, B. Jilcha, and I. Bloomquist. Evaluating mail-based security for electoral processes using attack trees. Risk Analysis, 42(10):2327–2343, 2022
2022
-
[26]
Schmidt and L
A. Schmidt and L. A. Albert. Designing pandemic-resilient voting systems. Socio- Economic Planning Sciences , 80:101174, 2022. ISSN 0038-0121. doi: https://doi.org/10. 1016/j.seps.2021.101174. URL https://www.sciencedirect.com/science/article/pii/ S003801212100166X. 31
2022
-
[27]
Schmidt and L
A. Schmidt and L. A. Albert. The drop box location problem. IISE Transactions, 56(4):424– 436, 2023. doi: 10.1080/24725854.2023.2213754. URL https://doi.org/10.1080/24725854. 2023.2213754
2023 doi
-
[28]
Schneier
B. Schneier. Attack trees: Modeling security threats. Dr. Dobb’s Journal , December 1999
1999
-
[29]
J. Shen. Merge Times and Hitting Times of Time-inhomogeneous Markov Chains . Dissertation, Duke University, Durham, NC, 2013
2013
-
[30]
B. I. Simidchieva, S. J. Engle, M. Clifford, A. C. Jones, S. Peisert, and M. Bishop. Mod- eling and analyzing faults to improve election process robustness. In In Proceedings of the 2010 USENIX/ACCURATE Electronic Voting Technology Workshop , 2010. URL https: //escholarship.or...
2010
-
[31]
C. Stewart. 2016 Survey of the performance of American elections. In 2020 Survey of the Performance of American Elections . Harvard Dataverse, 2021. doi: 10.7910/DVN/Y38VIQ/ SXXGGV. URL https://doi.org/10.7910/DVN/FSGX7Z
2016 doi
-
[32]
Stewart III and S
C. Stewart III and S. Ansolabehere. Waiting to vote. Election Law Journal, 14(1):47–53, 2015
2015
-
[33]
Election fraud map, 2025
The Heritage Foundation. Election fraud map, 2025. URL https://electionfraud. heritage.org/. accessed: 3/12/2025
2025
-
[34]
QuickFacts Milwaukee city, Wisconsin
United States Census Bureau. QuickFacts Milwaukee city, Wisconsin. Accessed on: Aug. 5, 2020. [Online]. Available: https://www.census.gov/quickfacts/fact/table/ milwaukeecitywisconsin/PST045219, July 2019
2020
-
[35]
Election operations assessment; Threat trees and matrices and Threat Instance Risk Analyzer (TIRA)
University of South Alabama. “Election operations assessment; Threat trees and matrices and Threat Instance Risk Analyzer (TIRA)”. Technical report, U.S. Election Assistance Commission (EAC), Washington, D.C., 2009. URL PDF:https://www.eac.gov/sites/ default/files/document_lib...
2009
-
[36]
Absentee ballot report, Oct
Wisconsin Elections Commission. Absentee ballot report, Oct. 2020. URL https://elections.wi.gov/statistics-data/absentee-statistics?combine=field_ subject_target_id=Allpage=12
2020
-
[37]
Voting by mail: Note on absentee ballot return, Oct
Wisconsin Elections Commission. Voting by mail: Note on absentee ballot return, Oct. 2020. URL https://elections.wi.gov/voters/voting-mail#230548828-2254551794
2020
-
[38]
WEC releases analysis of November 2020 election data
Wisconsin Elections Commission. WEC releases analysis of November 2020 election data. https://elections.wi.gov/news/ wec-releases-analysis-november-2020-election-data , 2020. [Online; accessed 28- December-2023]
2020
-
[39]
2020 general election voting and registration statistics report, el-109f
Wisconsin Elections Commission. 2020 general election voting and registration statistics report, el-109f. Report, Nov 2020. URL https://elections.wi.gov/statistics-data/ voting-statistics?combine=2020&field_subject_target_id=All. Accessed: 1-18-2024
2020
-
[40]
Absentee ballot report - November 3, 2020 General Election
Wisconsin Elections Commission. Absentee ballot report - November 3, 2020 General Election. Accessed on: June 5, 2021 [Online]. Available: https://elections.wi.gov/node/6862, 2020. 32
2020
-
[41]
November 3, 2020 Election Data report
Wisconsin Elections Commission. November 3, 2020 Election Data report. White Paper, Feb 2021. URL https://elections.wi.gov/sites/default/files/legacy/2021-01/D. %2520November%25202020%2520Election%2520Data%2520Report.pdf. Accessed: 1-17-2024
2020
-
[42]
M. Yang, M. J. Fry, and W. D. Kelton. Are all voting queues created equal? In Proceedings of the 2009 Winter Simulation Conference (WSC) , pages 3140–3149. IEEE, 2009
2009
-
[43]
Yasinsac and H
A. Yasinsac and H. Pardue. A process for assessing voting system risk using threat trees. In Conference on Information Systems Applied Research . Citeseer, 2010. 33
2010
Reviewed May 23, 2026 · model on record in the stance chip above.
Discussion (0). Sign in to comment.