Dagstuhl Seminar 25411
Trustworthy Evidence-Based Elections
( Oct 05 – Oct 10, 2025 )
Permalink
Organizers
- Josh Benaloh (Microsoft Research - Redmond, US)
- Peter Rønne (University of Luxembourg, LU)
- Philip Stark (University of California - Berkeley, US)
- Melanie Volkamer (KIT - Karlsruher Institut für Technologie, DE)
Contact
- Michael Gerke (for scientific matters)
- Christina Schwarz (for administrative matters)
Shared Documents
- Dagstuhl Materials Page (Use personal credentials as created in DOOR to log in)
Schedule
This 5-day Dagstuhl Seminar 25411 was dedicated to “Trustworthy Evidence-Based Elections”, a topic whose relevance and importance is witnessed by a number of democracies being under threat and elections becoming political battlegrounds in themselves rather than free and fair elections of political candidates. In this earnest backdrop, the seminar reviewed the state of art of secure elections, explored paths towards trustworthy elections, and the open challenges, in particular by sharing and elaborating on novel ideas, approaches, and use cases. The full report gives a description of the program, collects the abstracts of the talks in Sec. 3, and a selection of the breakout groups in Sec. 4.
Day 1
The Dagstuhl Seminar was opened with a round of short individual presentations, followed by a discussion about the organization of the seminar and the planning of topics and talks. All participants were allowed and encouraged to contribute with talks on recent research, election experiences, open problems, and ideas. In addition, it was agreed to end each day with breakout sessions and a final joint synthesis session with reports from each of the breakout groups. Due to the large number of individual talks, the breakout groups had to be limited to one-two sessions per day. Each talk was followed by active discussions.
The first day also managed to feature two sessions of talks, first a short session on Evidence-Based Elections and a longer one on Usability in voting. The breakout groups included a group on Commitment-Based Elections, Coercion-Resistance & Usability, and Education & Outreach.
Day 2
The second day had two sessions of talks on Cryptographic Voting Protocols and Risk-Limiting Audits. Furthermore, in the afternoon a demo session was held which presented an explanatory video to enable informed decisions on whether or not to go for Internet voting, a demo of the Selene voting scheme, a demo on a protocol for voter enrollment in coercion-resistant elections, and a system to test paper ballots before elections in particular for logical errors. Finally, a demo on visualising the counting of individual ballots in STV was postponed until day 4.
The breakout groups included groups on Universally Verified elections and RLAs
Day 3
The morning of day three had two sessions of talks on respectively Trust and Security Definitions. Further, it included a talk on e-collection of signatures for referendums, a topic sharing many security problems with e-voting.
In the afternoon, the participants split into two groups, one group explored the hiking trails around Schloss Dagstuhl while another group visited the Celtic Hillfort of Otzenhausen.
Day 4
Day four had three sessions: Cryptographic Voting Protocols (the second session on this topic), Verified Implementations & Formal Verification, and Trust & Elections. From the talks in these sessions, several breakout groups emerged, especially groups looking at boardroom voting, trust in voting, a group initiating the work towards the creation of an open source software developer kit (SDK) for e-voting, and trustworthy randomness-generation for election audits.
Day 5
The final day started with discussions on creating a white-paper on trustworthy evidence-based elections, the structure of this and responsible editors. In addition, two rounds of breakout groups were organized: both dedicated to new topics, following up on earlier groups and preparing the whitepaper topics. In particular, there were groups on Usability, Post-Quantum E-Voting, Formal Verification and Security Definitions.
Josh Benaloh, Peter Rønne, and Melanie Volkamer
Recently, democracies have been challenged at their very core: election outcomes are regularly contested, election procedures questioned, and distrust sown, as exemplified by the aftermath of recent elections in the 2020 Presidential election in the US and the 2022 election in Brazil. Hence, one of the essential qualities of any election, poll, or referendum is that it should provide firm evidence that the announced result truly reflects the will of the electorate.
The last Dagstuhl Seminar on verifiable voting, which took place in 2011, more than a decade ago, addressed the visionary challenge of making elections more trusted by making elections trustworthy. Trustworthiness is important for in-person voting, but also postal and electronic voting. The latter has seen a marked increase in adoption in the last decade, including in legally binding national elections, despite the repeated discovery of serious security flaws of the systems in place.
Elections are complex cyber-physical processes coming in a plethora of very different shapes, from paper-based to electronic, from small student elections to large national elections, and with many context-specific differences. Elections involve multiple stakeholders, processes, and parts, and not least they are centered around voters with different abilities, who all should be able to use the system privately, independently, and accurately.
To improve on this situation and progress towards trustworthy, secure, usable, accessible, and evidence-based elections, we need to involve experts from a wide range of topics to cover the different aspects of electronic voting. In this Dagstuhl Seminar, we want to bring together experts in secure electronic voting, cryptography, verified software, statistics, and human-computer interfaces, coming from academia, industry, and government organizations, to evaluate the past successes and failures, to review the state of the art, to discuss emerging challenges, such as quantum-safe cryptography, and to point to future solutions for secure and privacy-preserving voting methods.
This seminar will include, but not be limited to the following topics:
- Risk-limiting audits for paper-ballot elections
- Evidence-based elections
- Cryptographic voting protocols; new cryptographic methods for verifiable voting
- Security definitions for voting
- Formal verification of protocols & machine-checked proofs
- Verified implementations
- Usability & User experience; Understanding the motivation and perception of voters
- Trust in electronic voting
The structure of the seminar will be a combination: overview of the state of the art, informal talks, and plenary sessions focused on these topics followed by breakout groups on selected topics in the afternoon.
The last day of the seminar will offer working groups dedicated to initiating an interdisciplinary white paper synthesizing the outcomes of the seminar and giving recommendations on the design and implementation of trustworthy evidence-based elections.
Josh Benaloh, Peter Rønne, Philip Stark, and Melanie Volkamer
Please log in to DOOR to see more details.
- Josh Benaloh (Microsoft Research - Redmond, US) [dblp]
- Michelle Blom (The University of Melbourne, AU) [dblp]
- Véronique Cortier (LORIA, CNRS - Nancy, FR) [dblp]
- Alexandre Debant (INRIA - Villers-lès-Nancy, FR) [dblp]
- Thi Van Thao Doan (University of Louvain, BE) [dblp]
- Constantin Catalin Dragan (University of Surrey - Guildford, GB) [dblp]
- David Dueñas-Cid (Kozminski University, PL) [dblp]
- Alexander Ek (KU Leuven, BE) [dblp]
- Bryan Ford (EPFL Lausanne, CH) [dblp]
- Pierrick Gaudry (CNRS - Nancy, FR) [dblp]
- Kristian Gjøsteen (NTNU - Trondheim, NO) [dblp]
- Thomas Haines (Australian National University - Acton, AU) [dblp]
- J. Alex Halderman (University of Michigan - Ann Arbor, US) [dblp]
- Lucca Hirschi (LORIA & INRIA - Villers-lès-Nancy, FR) [dblp]
- Audhild Høgåsen (Schweizerische Post - Bern, CH)
- Reto König (Bern University of Applied Sciences, CH) [dblp]
- Steve Kremer (INRIA - Villers-lès-Nancy, FR) [dblp]
- Oksana Kulyk (IT University of Copenhagen, DK) [dblp]
- Ralf Küsters (Universität Stuttgart, DE) [dblp]
- Vincent Laporte (LORIA & INRIA - Villers-lès-Nancy, FR) [dblp]
- Karola Marky (Ruhr-Universität Bochum, DE) [dblp]
- Jennifer Morrell (University of Minnesota - Minneapolis, US)
- Rafieh Mosaheb (University of Luxembourg, LU) [dblp]
- Florian Moser (famoser GmbH - Allschwil, CH)
- Michael Naehrig (Microsoft - Redmond, US) [dblp]
- Olivier Pereira (University of Louvain, BE) [dblp]
- Thomas Peters (University of Louvain, BE) [dblp]
- Bart Preneel (KU Leuven, BE) [dblp]
- Peter Rønne (University of Luxembourg, LU) [dblp]
- Sylvain Ruhault (ANSSI - Paris, FR)
- Mark D. Ryan (University of Birmingham, GB) [dblp]
- Peter Y. A. Ryan (University of Luxembourg - Esch-sur-Alzette, LU) [dblp]
- Kazue Sako (Waseda University - Tokyo, JP) [dblp]
- Roberto Samarone Araujo (Federal University of Pará - Belém, BR) [dblp]
- Steve Schneider (University of Surrey - Guildford, GB) [dblp]
- Carsten Schürmann (IT University of Copenhagen, DK) [dblp]
- Tjerand Silde (NTNU - Trondheim, NO) [dblp]
- Marcos Simplicio (University São Paulo, BR) [dblp]
- Vanessa Teague (Australian National University - Acton, AU) [dblp]
- Melanie Volkamer (KIT - Karlsruher Institut für Technologie, DE) [dblp]
- Poorvi Vora (George Washington University - Washington, DC, US) [dblp]
Related Seminars
Classification
- Computers and Society
- Cryptography and Security
- Human-Computer Interaction
Keywords
- Voting
- Elections
- Verifiable Voting
- Usable Security
- Risk-Limiting Audits

Creative Commons BY 4.0
