E-Vote Your Conscience: Perceptions of Coercion and Vote Buying, and the Usability of Fake Credentials in Online Voting
Louis-Henri Merino, Alaleh Azhir, Haoqian Zhang, Simone Colombo, Bernhard Tellenbach, Vero Estrada-Galiñanes
IEEE Symposium on Security and Privacy 2024 · Day 3 · Continental Ballroom 6
Overview
This talk, "E-Vote Your Conscience: Perceptions of Coercion and Vote Buying, and the Usability of Fake Credentials in Online Voting," delves into one of the most persistent and insidious threats to electoral integrity in the era of digital democracy: voter coercion. Presented by Louis-Henri Merino and co-authored with Alaleh Azhir, Haoqian Zhang, Simone Colombo, Bernhard Tellenbach, and Vero Estrada-Galiñanes, the research explores how the convenience promised by online voting systems simultaneously amplifies the risk of malicious actors compelling or intimidating voters. The core of their work focuses on the efficacy and usability of a novel defense mechanism: fake credentials.

Key moments
- 0:00 Introduction to online voting and coercion problem
- 2:00 Fake credentials: a strategy to resist coercion
- 2:40 Overview of the TRIP coercion resistance scheme
- 4:00 Step-by-step process for creating credentials in TRIP
- 6:00 Study design and participant grouping explained
- 8:00 Details on security priming in the instructional video
- 9:00 Participants' reported experiences with voter coercion
- 10:00 Perceived likelihood of different coercion scenarios
E-Vote Your Conscience: Perceptions of Coercion and Vote Buying, and the Usability of Fake Credentials in Online Voting
Speakers: Louis-Henri Merino, Alaleh Azhir, Haoqian Zhang, Simone Colombo, Bernhard Tellenbach, Vero Estrada-Galiñanes
Conference: IEEE S&P
YouTube: https://www.youtube.com/watch?v=vxKenJuGQR4
Overview
This talk, "E-Vote Your Conscience: Perceptions of Coercion and Vote Buying, and the Usability of Fake Credentials in Online Voting," delves into one of the most persistent and insidious threats to electoral integrity in the era of digital democracy: voter coercion. Presented by Louis-Henri Merino and co-authored with Alaleh Azhir, Haoqian Zhang, Simone Colombo, Bernhard Tellenbach, and Vero Estrada-Galiñanes, the research explores how the convenience promised by online voting systems simultaneously amplifies the risk of malicious actors compelling or intimidating voters. The core of their work focuses on the efficacy and usability of a novel defense mechanism: fake credentials.
The presentation meticulously details the TRIP (Trust-Limited Coercion Resistant In-Person Registration) scheme, a system designed to enable voters to create both legitimate, tally-counting credentials and indistinguishable, non-counting fake credentials. Through a comprehensive user study, the researchers investigate voters' perceptions of coercion in real-world scenarios, their ability to understand and utilize fake credentials, and their capacity to detect malicious attempts by compromised registration kiosks. This research is crucial because as societies increasingly consider remote and online voting options, addressing sophisticated coercion vectors becomes paramount to maintaining voter autonomy and trust in democratic processes.
Background
▶ Watch: Introduction to online voting and coercion problem (0:00)
The allure of online voting systems is undeniable: they offer unparalleled convenience, allowing citizens to cast ballots from virtually any location using their personal devices. This accessibility promises to boost voter participation and streamline electoral processes. However, this increased convenience comes with a significant security trade-off: an elevated and more scalable risk of voter coercion. In traditional voting, coercion might involve direct threats or vote buying, often requiring physical presence or verifiable evidence like a ballot selfie. In online environments, these tactics can be amplified; for instance, dark DAOs (Decentralized Autonomous Organizations) could leverage smart contracts to offer anonymous financial incentives in exchange for votes cast via compromised voting applications, making coercion a highly scalable threat.
Previous attempts to resist coercion in digital voting often centered on deniable re-voting, where a voter could use their legitimate credential to override a previously cast coerced vote. However, this strategy is critically vulnerable to last-minute coercion, where a malicious actor could force a voter to re-cast their vote just before the election closes, rendering the deniability ineffective. This limitation highlights the need for more robust, proactive defenses.
The concept of fake credentials emerges as a promising alternative. In this model, voters can generate multiple credentials that, when used, cast votes that do not count in the final tally. Crucially, these fake credentials are designed to be indistinguishable from a legitimate, tally-counting "real credential" to an external observer, while the voter retains their real credential to cast their true, intended vote at any time. This allows a coerced voter to appear to comply with a coercer's demands by using a fake credential, without actually compromising their genuine vote. However, the deployment of fake credentials introduces its own set of challenges, primarily concerning usability and verifiability. Key questions arise: Can voters truly grasp the concept and proper use of fake credentials? Can they be confident they are using their real credential when they intend to? And, critically, can voters detect if a compromised registration system attempts to steal their real credential or issue them only fake credentials? These questions form the bedrock of the research presented in this talk, which investigates these concerns through the lens of the TRIP (Trust-Limited Coercion Resistant In-Person Registration) scheme.
Key Findings
▶ Watch: Overview of the TRIP coercion resistance scheme (2:40)
The study yielded several significant findings regarding the prevalence of coercion, the usability of the TRIP system, and the efficacy of security priming in detecting malicious registration attempts.
Firstly, the research underscores that voter coercion is not merely a theoretical threat but a tangible problem affecting real individuals. A substantial 26% of the 150 participants reported either personally experiencing or knowing someone who had experienced at least one form of voter coercion. Reported incidents included spousal oversight, pressure from labor unions or political parties, and colleagues being pressured to attend undesirable political rallies. When asked to rate the likelihood of various coercion scenarios, ballot selfies were perceived as the most likely, with 24% of participants rating it as "extremely likely." However, among those who actually reported knowledge of coercion, forceful coercion was the most frequently cited scenario, despite being perceived as the least likely by the general participant pool. Family members were identified as both the most perceived and most reported source of coercion, with 21% rating it as extremely likely and 58% of those with coercion experience mentioning instances involving family members.
Secondly, the study demonstrated the practical usability of the TRIP system for creating and using both real and fake credentials. A high success rate was observed: 95% of participants successfully created their credentials using the kiosk, and 92% successfully activated them, leading to a combined registration success rate of 87%. When instructed to cast their real vote using their real credential, 90% of participants were able to do so, resulting in a final overall success rate of 83%. This performance represents a notable usability improvement over existing coercion-resistant systems like PRE-VOTE (an in-person system) and general online voting systems like Helios. While TRIP did not quite match the 93% success rate of StarVote (a state-of-the-art, non-coercion-resistant in-person ballot marking device system), it is significantly narrowing this gap for a coercion-resistant online voting system. Furthermore, the concept of fake credentials was well-understood: 96% of participants exposed to fake credentials comprehended their purpose. A substantial 76% chose to create at least one fake credential during the study, and 53% indicated they would create fake credentials if such a system were available in reality, demonstrating a clear willingness to adopt this security measure.
Finally, the research highlighted the critical role of security priming in enhancing voter vigilance against malicious registration kiosks. In scenarios without security priming, only 10% of participants exposed to a malicious kiosk detected it and reported it to the facilitator. However, with security priming—an instructional video designed to be unsettling and to warn about hacked kiosks—this detection rate significantly increased to 47%, while maintaining a 0% false positive rate. This result is particularly compelling when compared to prior work, such as Bural et al.'s study on detecting malicious ballot manipulation from ballot marking devices, where security priming only increased detection from 7% to 13%. The researchers hypothesize that TRIP's higher detection rates stem from its simpler verification task: voters only need to verify the "realness" of their single real credential, as opposed to verifying each race on an entire ballot.
Technical Deep Dive
▶ Watch: Study design and participant grouping explained (6:00)
The core innovation investigated in this study is the TRIP (Trust-Limited Coercion Resistant In-Person Registration) scheme, designed to enable voters to generate both a single real credential and multiple indistinguishable fake credentials. The scheme aims to provide a robust defense against coercion by allowing voters to "throw away" votes using fake credentials without revealing their true intent, while maintaining the integrity of their actual ballot.
The overall TRIP registration process is structured into four main phases:
- Check-in: The voter first interacts with a government official, typically at a secure polling location. During this interaction, the voter obtains a unique check-in ticket, which serves as their authorization to proceed to the next stage.
- Kiosk Interaction in a Private Booth: Crucially, the subsequent credential creation occurs within a private booth, physically isolating the voter from potential coercers. Inside this booth, the voter interacts with a specialized kiosk. This kiosk is the central point for creating both real and fake credentials.
- Checkout: After creating their desired credentials, the voter presents any one of their credentials (real or fake) to an official at a checkout station. This step is designed to appear normal to an external observer, preventing a coercer from distinguishing between a voter who created a real credential and one who created only fake ones.
- Activation and Voting: Finally, voters can activate their credentials on a device of their choice (personal or public) and use them to cast their votes. Each credential has an expiration, after which it can no longer be used.
The distinction between creating a real and a fake credential lies in a subtle yet critical interaction within the private booth:
Real Credential Creation (Four Steps):
- Authorization: The voter first presents and scans their check-in ticket at the kiosk. This authorizes the kiosk to proceed with credential issuance for that specific voter.
- Initial Print: The kiosk then prints a partial receipt containing a unique QR code and a distinct symbol. This symbol is crucial for the voter's verification.
- Voter-Kiosk Synchronization: The voter is presented with a stack of pre-prepared, sealed envelopes. The voter must **pick and scan an envelope that bears the same symbol as printed on their receipt**. This step is a critical security measure: it ensures the voter is actively participating in the credential generation and verifying the link between the kiosk's output and the physical envelope. If the kiosk were malicious, printing a symbol that doesn't match any available envelope, a vigilant voter might detect this anomaly.
- Completion and Marking: Upon successful symbol matching, the kiosk completes the receipt. The voter then takes this completed receipt and inserts it into the selected envelope. They are instructed to mark this envelope in any memorable way they like to distinguish it as their real credential (e.g., writing "REAL" in all caps, adding a unique doodle). This internal marking is vital for the voter to confidently identify their real credential later.
Fake Credential Creation (Two Steps):
- Direct Scan: For fake credentials, the process is streamlined. The voter **picks and scans *any unused envelope*** from the stack. There is no symbol matching requirement.
- Completion and Marking: The kiosk immediately completes the receipt for this envelope. The voter then inserts the receipt and marks the envelope in a memorable way to distinguish it from the real credential (e.g., writing "real" in lowercase, or "FAKE"). This process can be repeated as many times as the voter desires within reasonable limits.
The security of TRIP hinges on several design principles: the private booth prevents direct observation of credential creation; the voter-kiosk synchronization step for real credentials provides a physical verification point; and the internal marking allows the voter to distinguish their credentials without external indicators, thus preserving deniability. The study design itself involved exposing participants to honest and malicious kiosks, with and without security priming. Security priming involved a more unsettling instructional video explicitly warning voters about potentially hacked kiosks and emphasizing the critical step of picking and scanning an envelope only after the kiosk prints a symbol and QR code. This detailed technical process and the experimental setup allowed the researchers to thoroughly evaluate the scheme's usability and security against sophisticated coercion tactics.
Demo / Proof of Concept
▶ Watch: Details on security priming in the instructional video (8:00)
While the talk did not feature a live software demonstration in the traditional sense, the entire user study served as a comprehensive proof of concept for the TRIP system. The researchers meticulously simulated the full voter experience, from initial instruction to credential creation and mock voting, effectively demonstrating the system's operational flow and real-world applicability.
Participants in the study first watched an instructional video that introduced them to the concept of fake credentials and guided them through the TRIP registration process. They then physically interacted with a specially designed kiosk within a simulated private booth environment. This involved using a check-in ticket, scanning QR codes, selecting envelopes with matching symbols (for real credentials), and marking their envelopes. Following credential creation, participants engaged in a mock election, casting votes using their newly acquired credentials, which allowed the researchers to assess their ability to correctly identify and use their real credential.
The study's setup, conducted in a suburban park in Boston, Massachusetts, aimed to recruit a diverse demographic and observe their natural interactions with the system. The various experimental groups, including those exposed to honest and malicious kiosks, with and without security priming, effectively showcased different operational scenarios. The instructional videos used in the study, including the "unsettling" security priming version, are publicly available on GitHub along with other study materials, allowing interested parties to review the exact content presented to participants and further understand the experimental conditions. This hands-on, simulated environment provided robust evidence of TRIP's usability and the impact of design choices on voter behavior and security awareness.
Defensive Implications
▶ Watch: Perceived likelihood of different coercion scenarios (10:00)
The findings from this research offer several critical insights for cybersecurity professionals, election officials, and system designers involved in developing and deploying online voting systems. The pervasive nature of voter coercion, as evidenced by the 26% of participants with direct experience or knowledge, underscores that coercion resistance must be a foundational requirement, not an afterthought, for any remote voting solution.
First, fake credentials emerge as a highly promising and usable defense mechanism against coercion. The study's finding that 96% of participants understood their use and 53% expressed willingness to create them in reality indicates a strong potential for voter adoption. Defenders should advocate for and implement systems that provide voters with tools for plausible deniability, allowing them to appear compliant with coercers without compromising their true vote.
Second, the TRIP scheme provides a robust architectural blueprint for a coercion-resistant registration process. Its combination of an in-person check-in, a private booth for credential creation, and a voter-kiosk synchronization step for real credentials offers layers of security. Election systems designers should consider incorporating similar multi-stage, verifiable registration processes that minimize the risk of a single point of failure or compromise. The design element requiring voters to verify one specific thing (the symbol match for real credentials) significantly enhances security and voter detection capabilities.
Third, voter education and security priming are indispensable. The dramatic increase in detection rates for malicious kiosks—from 10% to 47% with security priming—highlights the power of targeted, clear, and even "unsettling" instructional content. Defenders must invest in educational campaigns that not only explain how to use secure voting systems but also explicitly warn voters about potential threats, such as compromised kiosks, and instruct them on how to identify and report suspicious activities. This proactive vigilance, cultivated through effective priming, can turn voters into an active line of defense.
Finally, the research suggests that system design should prioritize simplicity in verification tasks. The hypothesis that TRIP's higher detection rates compared to ballot marking devices are due to voters only needing to verify "one thing" (the realness of their credential) is a crucial design principle. Complex systems requiring voters to verify multiple elements (e.g., every race on a ballot) may overwhelm users and reduce their ability to detect manipulation. Therefore, designers should strive for user interfaces and verification processes that are intuitive, straightforward, and minimize cognitive load, allowing voters to confidently assert the integrity of their vote.
Key Takeaways
- Coercion is a Real and Prevalent Threat: A significant portion of the population (26% in the study) has experienced or knows someone who has experienced voter coercion, highlighting its tangible impact on electoral integrity.
- Fake Credentials Offer a Viable Defense: The concept of fake credentials for plausible deniability against coercion is well-understood (96% comprehension) and desired by voters (53% willing to create them in reality).
- TRIP System Demonstrates Strong Usability: The TRIP (Trust-Limited Coercion Resistant In-Person Registration) scheme achieved an 83% overall success rate for registration and voting, representing a usability improvement over existing coercion-resistant systems.
- Security Priming Significantly Boosts Detection: Targeted voter education and "security priming" dramatically increase voters' ability to detect malicious registration kiosks (from 10% to 47%), underscoring its importance in system deployment.
- Simplicity in Verification is Key: Designing systems where voters need to verify only one critical element (e.g., the realness of a credential) can lead to higher detection rates of malicious activity compared to more complex verification tasks.
- Online Voting Requires Robust Coercion Resistance: As online voting systems are considered, incorporating strong, user-friendly coercion resistance mechanisms like fake credentials and secure registration schemes is paramount to maintaining voter trust and autonomy.
About the Speaker(s)
The talk "E-Vote Your Conscience: Perceptions of Coercion and Vote Buying, and the Usability of Fake Credentials in Online Voting" was presented by Louis-Henri Merino. He is one of the co-authors of this research, alongside Alaleh Azhir, Haoqian Zhang, Simone Colombo, Bernhard Tellenbach, and Vero Estrada-Galiñanes. The detailed research and presentation highlight their collective expertise in cybersecurity, voting systems, and human-computer interaction, focusing on critical issues surrounding electoral security and voter behavior in the context of emerging online voting technologies.
Reviews
Dr. Zero (Offensive Security Researcher) — MUST SEE
This research directly confronts the pervasive threat of voter coercion in online voting, proposing and rigorously evaluating a novel fake credential scheme within the TRIP system. The empirical findings on usability and the dramatic impact of security priming offer a critical, actionable blueprint for building genuinely coercion-resistant electoral systems. This isn't just theory; it's a vital contribution to democratic integrity.
Heather Calloway (CISO) — MUST SEE
This research directly confronts the critical governance challenge of voter coercion in online systems. The TRIP scheme, with with its usable fake credentials and effective security priming, offers a robust, evidence-backed path to securing electoral integrity. It provides actionable insights for policymakers and system designers responsible for protecting democratic processes.
→ Top-rated talks at IEEE Symposium on Security and Privacy 2024