Pith. sign in

REVIEW 2 major objections 1 minor 1 cited by

Voting by mail: a Markov chain model for managing the security risks of election systems

T0 review · 2 major / 1 minor · reviewed 2026-05-23 · grok-4.3

Pith's one-line read A discrete-time Markov chain model of vote-by-mail processes identifies ballot drop boxes and automatic notifications as key to shrinking the attack surface.

desk verdict New DTMC framework for VBM risk modeling, but the ranking of mitigations rests on chosen hypothetical probabilities rather than fitted data. read the letter →

arxiv 2410.13900 v3 submitted 2024-10-15 cs.CR math.PR

classification cs.CRmath.PR
keywords vote-by-mailMarkovchainriskassessmentelectionsecurityballotdropboxesmitigationsdiscrete-timemodelattacksurface
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

The paper develops a dynamic risk-assessment framework for absentee voting by modeling the entire vote-by-mail workflow as a time-inhomogeneous discrete-time Markov chain. A layered network structure represents the interactions among normal processes, malicious and non-malicious threats, and available security controls. Using Milwaukee County data, the model runs hypothetical worst-case attacks at different times to measure how specific mitigations change overall performance and risk.

What carries the argument

discrete-time Markov chain with layered network approach that captures the interplay of VBM processes, threats, and mitigations over time

What would settle it

Compare the model's predicted risk reductions from installing drop boxes and notifications against observed rates of ballot loss, tampering, or delivery failures in jurisdictions that have and have not adopted those measures.

Watch

Extended reading notes

Core claim

The authors construct a DTMC that tracks ballot movement through successive states while incorporating a spectrum of failure modes and countermeasures; analysis of the resulting state probabilities under stress scenarios shows that adding ballot drop boxes and automatic ballot notification systems produces the largest reductions in the modeled attack surface.

Load-bearing premise

The discrete-time Markov chain and layered network structure can faithfully represent the dynamic interactions among voting processes, threats, and security measures.

Editorial extensions

If this is right

  • The model quantifies how attack timing affects the effectiveness of different security controls.
  • Hypothetical worst-case scenarios can be used to stress-test the resilience of an entire VBM workflow.
  • Performance metrics derived from the chain allow direct comparison of mitigation packages on the same data set.
  • The framework treats both accidental voter errors and sophisticated attacks within a single probabilistic structure.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • The same state-transition approach could be reused to compare VBM risk profiles across different counties or states that collect comparable process data.
  • Embedding real-time incident logs into the chain would let operators update risk estimates during an active election cycle.
  • Resource allocation decisions could be informed by ranking mitigations according to the size of the attack-surface reduction each produces in the model.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, simulated authors' rebuttal, and a circularity audit.

Referee Report

2 major / 1 minor

Summary. The paper introduces a discrete-time Markov chain (DTMC) framework with a layered network to model vote-by-mail (VBM) processes, incorporating states for process steps, malicious/non-malicious threats, and mitigations. It uses time-inhomogeneous transitions to evaluate dynamic risks and performance, applies the model to Milwaukee County data, and runs hypothetical worst-case attack scenarios to assess mitigations. The central claim is that ballot drop boxes and automatic notification systems are crucial for reducing attack surface.

Significance. A validated quantitative DTMC model for VBM risk assessment would be a useful addition to election security literature, moving beyond qualitative checklists by enabling scenario-based evaluation of mitigations. The Milwaukee County case study and stress-testing approach provide a concrete starting point, but the framework's impact is currently limited by the lack of data-driven parameter estimation.

major comments (2)
  1. [Case study section] Case study (Milwaukee County application): transition probabilities governing malicious attacks, error rates, and mitigation efficacy are chosen to illustrate worst-case timings rather than estimated or fitted from the supplied aggregate counts/rates. This choice directly supports the ranking of drop boxes and notifications as most effective, so the headline claim is conditional on those unvalidated numerical selections remaining representative.
  2. [Model definition section] Model construction: the DTMC state space and layered network are defined, but the paper does not show how the time-inhomogeneous transition matrix entries are constructed from the Milwaukee data versus assigned for hypothetical scenarios, nor does it include sensitivity analysis or validation against observed election outcomes.
minor comments (1)
  1. [Abstract] Clarify in the abstract and introduction whether any transition probabilities are derived from external data sources beyond the Milwaukee aggregates.

Simulated Author's Rebuttal

2 responses · 0 unresolved

We thank the referee for the constructive feedback on our DTMC framework for vote-by-mail risk assessment. The comments correctly identify areas where the manuscript could better distinguish between data-derived elements and illustrative parameters. We address each point below and will make revisions to improve clarity and transparency.

read point-by-point responses
  1. Referee: [Case study section] Case study (Milwaukee County application): transition probabilities governing malicious attacks, error rates, and mitigation efficacy are chosen to illustrate worst-case timings rather than estimated or fitted from the supplied aggregate counts/rates. This choice directly supports the ranking of drop boxes and notifications as most effective, so the headline claim is conditional on those unvalidated numerical selections remaining representative.

    Authors: We agree that the transition probabilities for malicious attacks, errors, and mitigations are assigned to represent worst-case scenarios rather than fitted from the Milwaukee County aggregate counts. The supplied data informs process volumes, timings, and overall scale but lacks the granular per-step rates needed for statistical estimation of threat or mitigation parameters. The analysis is framed as a stress-test of the framework under extreme conditions, not as a calibrated prediction. We will revise the case study section to explicitly document the parameter selection rationale, state that results are conditional on the chosen values, and qualify the conclusions about drop boxes and notifications accordingly. revision: yes

  2. Referee: [Model definition section] Model construction: the DTMC state space and layered network are defined, but the paper does not show how the time-inhomogeneous transition matrix entries are constructed from the Milwaukee data versus assigned for hypothetical scenarios, nor does it include sensitivity analysis or validation against observed election outcomes.

    Authors: The manuscript uses Milwaukee County data for aggregate quantities such as ballot volumes and process durations, while threat and mitigation probabilities are assigned for the hypothetical scenarios. We acknowledge that the distinction and the explicit construction of the time-inhomogeneous matrices are not sufficiently detailed. We will add a dedicated subsection (or appendix) describing the sources and assignment rules for each class of parameters. We will also include a sensitivity analysis on the key threat and mitigation probabilities to demonstrate robustness. Direct validation against observed attack outcomes is limited by the low base rate of such events; we will discuss this constraint in the revised text. revision: yes

Circularity Check

0 steps flagged · score 0.0 of 10

No circularity: DTMC is a simulation framework with externally supplied parameters and data

full rationale

The paper introduces a new DTMC layered-network model for VBM risk assessment and evaluates it on Milwaukee County aggregate counts plus chosen hypothetical transition probabilities for worst-case scenarios. No equations or sections show a result that reduces by construction to its own fitted inputs, self-citations, or renamed known patterns. The central claims are conditional on the chosen parameters, which is standard modeling practice and does not constitute circularity. The derivation chain remains self-contained against external benchmarks.

Assumptions & free parameters 0 free parameters · 0 assumptions · 0 invented entities

Abstract-only review yields no explicit free parameters, axioms, or invented entities; full text required to audit these elements.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Voting by mail: a Markov chain model for managing the security risks of election systems." pith.science (2026). https://pith.science/paper/2410.13900

@misc{pith2026241013900,
  author       = {Pith},
  title        = {Pith review of: Voting by mail: a Markov chain model for managing the security risks of election systems},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/2410.13900}},
  note         = {Machine review of arXiv:2410.13900}
}
read the original abstract

The scrutiny surrounding vote-by-mail (VBM) in the United States has increased in recent years, highlighting the need for a rigorous quantitative framework to evaluate the resilience of the absentee voting infrastructure. This paper addresses these issues by introducing a dynamic mathematical modeling framework for performing a risk assessment of VBM processes. We introduce a discrete-time Markov chain (DTMC) to model the VBM process and assess election performance and risk with a novel layered network approach that considers the interplay between VBM processes, malicious and non-malicious threats, and security mitigations. The time-inhomogeneous DTMC framework captures dynamic risks and evaluates performance over time. The DTMC model accounts for a spectrum of outcomes, from unintended voter errors to sophisticated, targeted attacks, representing a significant advancement in the risk assessment of VBM planning and protection. A case study based on real-world data from Milwaukee County, Wisconsin, is used to evaluate the DTMC model. The analysis includes hypothetical worst-case attack scenarios to stress-test VBM processes and to assess the efficacy of security measures and the impact of different attack timings. The analysis suggests that ballot drop boxes and automatic ballot notification systems are crucial for reducing the attack surface to ensure secure and reliable operations.

Figures

Figures reproduced from arXiv: 2410.13900 by the authors.

Figure 1
Figure 1. Example of a portion of the VBM attack tree [PITH_FULL_IMAGE:figures/full_fig_p007_1.png] view at source ↗
Figure 2
Figure 2. Layered Network for time intervals 1 ≤ t < T − 1 recurrent in the DTMC, and all others are transient. If ballots are returned to the election office at t = T they are “not returned, late”(NC, L). Next, we summarize the transitions. Let Pt capture the transition probability matrix immedi￾ately after the time steps t = 1, 2, ..., T − 1. Voters can request ballots at different times. Let βt capture the number of ballot… view at source ↗
Figure 3
Figure 3. Layered Network for VBM on Election Day at time interval [PITH_FULL_IMAGE:figures/full_fig_p014_3.png] view at source ↗
Figures from the paper (3 more)
Figure 4
Figure 4. Figure 4: Comparison of recorded and modeled returned ballots for the state of Wisconsin for [PITH_FULL_IMAGE:figures/full_fig_p019_4.png]
Figure 5
Figure 5. Figure 5: Deviation in counted and unaltered (C, U) ballots from the baseline under three moderate [PITH_FULL_IMAGE:figures/full_fig_p025_5.png]
Figure 6
Figure 6. Figure 6: Results of a sensitivity analysis that evaluates the impact of mitigations M3, M4, M5, M6, [PITH_FULL_IMAGE:figures/full_fig_p028_6.png]

Discussion (0). Sign in to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Ballot Design and Electoral Outcomes: The Role of Candidate Order and Party Affiliation

    stat.AP 2025-07 conditional novelty 6.0 of 10

    Using a natural experiment in North Carolina judicial races, the paper estimates that candidate-order flips relative to the presidential race cause 11.8% of Democratic and 15.4% of Republican partisan voters to cast v...

Reference graph

Works this paper leans on

43 extracted references · 43 canonical work pages · cited by 1 Pith paper

  1. [1]

    Barry C. Burden. The experiences of municipal clerks and the electorate in the November 2020 General Election in Wisconsin, Sept 2021. URL https://thompsoncenter.wisc.edu/wp-content/uploads/sites/509/2021/09/ Burden-2020-Wisconsin-Election-Report-PUBLIC.pdf

  2. [2]

    The 2020 voting experience: Lessons learned and recommendations for reform, 2021

    Bipartisan Policy Center. The 2020 voting experience: Lessons learned and recommendations for reform, 2021. URL https://bipartisanpolicy.org/download/?file=/wp-content/ uploads/2021/04/EPP-Voting-Experience_RV1.pdf. Accessed: 2024-09-02

  3. [3]

    Blessing, J

    J. Blessing, J. Gomez, P. McCoy, and T. Ngyuen. Security survey and analysis of vote-by-mail systems. Computers and Society, Cryptography and Security MIT , Sept. 2020

  4. [4]

    Final voting ward demographics

    City of Milwaukee Common Council. Final voting ward demographics. Accessed on: Aug. 4, 2020. [Online]. Available: https://city.milwaukee.gov/ImageLibrary/Groups/ ccCouncil/2012PDF/FinalVotingWardDemographics-Ju.xls, 2012

  5. [5]

    Mail-in voting in 2020 infrastruc- ture risk assessment and infographic, July 2020

    Cybersecurity and Infrastructure Security Agency(CISA). Mail-in voting in 2020 infrastruc- ture risk assessment and infographic, July 2020. URL https://www.cisa.gov/publication/ election-mail-risk

  6. [6]

    De Witte

    M. De Witte. Examining effects, challenges of mail-in voting. Stanford News, Sept. 2020

  7. [7]

    Ballotscout

    Democracy Works. Ballotscout. https://www.democracy.works/ballotscout, 2021. Ac- cessed: 2024-05-21

  8. [8]

    Haseltine

    C. Haseltine. Vbm dtmc github repository. https://github.com/HaseltineC/VBM-DTMC,

Show all 43 references
  1. [9]

    Accessed: 2025-04-27

  2. [10]

    Haseltine, S

    C. Haseltine, S. Wang, and L. Albert. Dynamic cyber-physical system security planning using attack graphs. In Proceedings of the IISE Annual Meeting , Seattle, WA, May 2022. Institute of Industrial and Systems Engineers

  3. [11]

    Ballottrax

    i3logix. Ballottrax. https://www.ballottrax.com/, 2024. Accessed: 2024-05-21

  4. [12]

    J. Li, T. T. Allen, and K. Akah. Could simulation optimization have prevented 2012 central Florida election lines? In 2013 Winter Simulations Conference (WSC) , pages 2088–2096, Washington, DC, USA, 2013. IEEE

  5. [13]

    What queueing means; polling places Covid-19?

    C. McIntyre. “What queueing means; polling places Covid-19?” - MIT Election Lab, Aug. 2020. URL https://electionlab.mit.edu/sites/default/files/2020-08/ WhatQueueingMeansPollingPlacesCOVID19.pdf

  6. [14]

    Municipalities, June 2023

    Milwaukee County. Municipalities, June 2023. URL https://county.milwaukee.gov/EN/ Municipalities. 30

  7. [15]

    November 3, 2020 - general election

    Milwaukee Elections Commission. November 3, 2020 - general election. Nov. 6, 2020, Accessed on: June 5, 2021 [Online]. Available: https://city.milwaukee.gov/election/ ElectionInformation/ElectionResults/2020/November, 2020

  8. [16]

    Voting wards 2020

    Milwaukee OpenData. Voting wards 2020. Accessed on: Aug. 6, 2020. [Online]. Available: https://data.milwaukee.gov/dataset/voting-wards/resource/ 01139d6b-b65a-4d63-89da-b87f3986ff0d?inner_span=True , April 6, 2020, 2020

  9. [17]

    Voting by mail and absentee voting, Mar

    MIT Election Data + Science Lab. Voting by mail and absentee voting, Mar. 2021. URL https://electionlab.mit.edu/research/voting-mail-and-absentee-voting

  10. [18]

    Report voting outside the polling place: Absentee, all-mail and other voting at home options

    National Conference of State Legislatures. Report voting outside the polling place: Absentee, all-mail and other voting at home options. Updated on: July 12, 2022. [Online]. Available: https://www.ncsl.org/elections-and-campaigns/ voting-outside-the-polling-place , 2022

  11. [19]

    Voting outside the polling place: Absentee, all-mail and other voting at home options

    National Conference of State Legislatures. Voting outside the polling place: Absentee, all-mail and other voting at home options. Accessed on: June 21, 2023. https://www. ncsl.org/research/elections-and-campaigns/voting-outside-the-polling-place. aspx, 2022. https://www.ncsl.o...

  12. [20]

    United States Postal Service performance of election and political mail during the November 2020 general election

    Office of Inspector General. United States Postal Service performance of election and political mail during the November 2020 general election. Audit report, United States Postal Service, Washington, D.C., Mar. 2021

  13. [21]

    United States postal service performance of election and political mail during the November 2020 General Election

    Office of Inspector General. United States postal service performance of election and political mail during the November 2020 General Election. Audit report, United States Postal Service, Mar. 2021

  14. [22]

    Rinaldi, J

    S. Rinaldi, J. Peerenboom, and T. Kelly. Identifying, understanding, and analyzing critical infrastructure interdependencies. IEEE Control Systems Magazine , 21(6):11–25, 2001. doi: 10.1109/37.969131

  15. [23]

    R. G. Saltman. Accuracy, integrity and security in computerized vote-tallying. Commun. ACM, 31(10):1184–1191, oct 1988. ISSN 0001-0782. doi: 10.1145/63039.63041. URL https: //doi.org/10.1145/63039.63041

  16. [24]

    Scala, I

    N. Scala, I. Bloomquist, Y. Mezgebe, and B. Jilcha. A process map and risk assessment for mail-based voting. In A. Ghate, K. Krishnaiyer, K. Paynabar, eds., editor, Proceedings of the 2021 Institute of Industrial and System Engineers (IISE) Annual Conference , 2021

  17. [25]

    N. M. Scala, P. L. Goethals, J. Dehlinger, Y. Mezgebe, B. Jilcha, and I. Bloomquist. Evaluating mail-based security for electoral processes using attack trees. Risk Analysis, 42(10):2327–2343, 2022

  18. [26]

    Schmidt and L

    A. Schmidt and L. A. Albert. Designing pandemic-resilient voting systems. Socio- Economic Planning Sciences , 80:101174, 2022. ISSN 0038-0121. doi: https://doi.org/10. 1016/j.seps.2021.101174. URL https://www.sciencedirect.com/science/article/pii/ S003801212100166X. 31

  19. [27]

    Schmidt and L

    A. Schmidt and L. A. Albert. The drop box location problem. IISE Transactions, 56(4):424– 436, 2023. doi: 10.1080/24725854.2023.2213754. URL https://doi.org/10.1080/24725854. 2023.2213754

  20. [28]

    Schneier

    B. Schneier. Attack trees: Modeling security threats. Dr. Dobb’s Journal , December 1999

  21. [29]

    J. Shen. Merge Times and Hitting Times of Time-inhomogeneous Markov Chains . Dissertation, Duke University, Durham, NC, 2013

  22. [30]

    B. I. Simidchieva, S. J. Engle, M. Clifford, A. C. Jones, S. Peisert, and M. Bishop. Mod- eling and analyzing faults to improve election process robustness. In In Proceedings of the 2010 USENIX/ACCURATE Electronic Voting Technology Workshop , 2010. URL https: //escholarship.or...

  23. [31]

    C. Stewart. 2016 Survey of the performance of American elections. In 2020 Survey of the Performance of American Elections . Harvard Dataverse, 2021. doi: 10.7910/DVN/Y38VIQ/ SXXGGV. URL https://doi.org/10.7910/DVN/FSGX7Z

  24. [32]

    Stewart III and S

    C. Stewart III and S. Ansolabehere. Waiting to vote. Election Law Journal, 14(1):47–53, 2015

  25. [33]

    Election fraud map, 2025

    The Heritage Foundation. Election fraud map, 2025. URL https://electionfraud. heritage.org/. accessed: 3/12/2025

  26. [34]

    QuickFacts Milwaukee city, Wisconsin

    United States Census Bureau. QuickFacts Milwaukee city, Wisconsin. Accessed on: Aug. 5, 2020. [Online]. Available: https://www.census.gov/quickfacts/fact/table/ milwaukeecitywisconsin/PST045219, July 2019

  27. [35]

    Election operations assessment; Threat trees and matrices and Threat Instance Risk Analyzer (TIRA)

    University of South Alabama. “Election operations assessment; Threat trees and matrices and Threat Instance Risk Analyzer (TIRA)”. Technical report, U.S. Election Assistance Commission (EAC), Washington, D.C., 2009. URL PDF:https://www.eac.gov/sites/ default/files/document_lib...

  28. [36]

    Absentee ballot report, Oct

    Wisconsin Elections Commission. Absentee ballot report, Oct. 2020. URL https://elections.wi.gov/statistics-data/absentee-statistics?combine=field_ subject_target_id=Allpage=12

  29. [37]

    Voting by mail: Note on absentee ballot return, Oct

    Wisconsin Elections Commission. Voting by mail: Note on absentee ballot return, Oct. 2020. URL https://elections.wi.gov/voters/voting-mail#230548828-2254551794

  30. [38]

    WEC releases analysis of November 2020 election data

    Wisconsin Elections Commission. WEC releases analysis of November 2020 election data. https://elections.wi.gov/news/ wec-releases-analysis-november-2020-election-data , 2020. [Online; accessed 28- December-2023]

  31. [39]

    2020 general election voting and registration statistics report, el-109f

    Wisconsin Elections Commission. 2020 general election voting and registration statistics report, el-109f. Report, Nov 2020. URL https://elections.wi.gov/statistics-data/ voting-statistics?combine=2020&field_subject_target_id=All. Accessed: 1-18-2024

  32. [40]

    Absentee ballot report - November 3, 2020 General Election

    Wisconsin Elections Commission. Absentee ballot report - November 3, 2020 General Election. Accessed on: June 5, 2021 [Online]. Available: https://elections.wi.gov/node/6862, 2020. 32

  33. [41]

    November 3, 2020 Election Data report

    Wisconsin Elections Commission. November 3, 2020 Election Data report. White Paper, Feb 2021. URL https://elections.wi.gov/sites/default/files/legacy/2021-01/D. %2520November%25202020%2520Election%2520Data%2520Report.pdf. Accessed: 1-17-2024

  34. [42]

    M. Yang, M. J. Fry, and W. D. Kelton. Are all voting queues created equal? In Proceedings of the 2009 Winter Simulation Conference (WSC) , pages 3140–3149. IEEE, 2009

  35. [43]

    Yasinsac and H

    A. Yasinsac and H. Pardue. A process for assessing voting system risk using threat trees. In Conference on Information Systems Applied Research . Citeseer, 2010. 33

Pith tools

Reviewed May 23, 2026 · model on record in the stance chip above.