Cybersecurity expert protects democracy through academic independence

Wed 8 July 2026


Research Impact

Electronic voting in Estonia
Electronic voting in Estonia

End-to-End Verifiable Electronic Voting End-to-end verifiable electronic voting: how an election can be trusted without trusting the machines that run it.

Dr Thomas Haines Dr Thomas Haines, Senior Lecturer at the ANU School of Computing.

When it comes to democratic elections, reconciling the privacy of the voter with the need for election integrity creates a unique challenge for officials and the cybersecurity experts tasked with securing the ballot. One of those experts is ANU School of Computing Senior Lecturer Dr Thomas Haines, whose work has been applied to voting systems in Switzerland, Estonia, New South Wales, Western Australia, and the Australian Capital Territory.

While cybersecurity solutions exist to verify key transactions like banking transfers, the voting system is designed with the additional constraint of privacy. Without a public list of how individuals vote, the techniques applied to online banking don’t work.

“The worst-case scenario, privacy-wise, is that you publish the voting history of everyone,” Haines said. “This scenario has come very close several times.”

However, the larger concern is with potential election fraud.

“What most academics are worried about is the possibility of setting up a system that could have large scale tampering without leaving evidence, complicated by moments when candidates cast doubt on election security when they lose,” Haines said.

“Universities play a crucial role. You need organizations which have the appetite to take a principled position even if it’s going to annoy certain governments or vendors in the space.”
— Dr. Thomas Haines

Anonymity and integrity

In the 1980s, cryptographers came up with ways to demonstrate the validity of a statement without revealing the information. Since the late 2000s, these techniques have seen increased deployment in elections, such as the Estonian and Swiss electoral systems, as well as some Australian systems.

The format of voting matters for both anonymity and integrity.

“We have good solutions for voting in a booth,” Haines said. “You can check and make sure your ballot was received and counted correctly.”

The shuffle that hides who voted for what To keep your vote secret, encrypted ballots are shuffled so they can’t be traced back — and a proof guarantees not one was changed.

In Haines’ view, digital voting is less secure than the use of paper ballots. In Switzerland, voters receive a mail that sends them to a website to cast a vote with a unique set of codes, while Estonia provides a desktop application connecting to their online voting server.

“Many of these systems trust the internal components of security,” Haines said. “If you compromise the internal components, you lose the election integrity. The high-level view of academia is that online voting is an unsolved problem.”

A new challenge from artificial intelligence

Artificial intelligence is turbocharging both the process of finding software bugs and the challenge of cyberthreats. Many voting systems are being combed by AI for legitimate bugs, but in other case they are hallucinating problems.

Haines anticipates a need for security analysis to change with new auditing processes as AI writes more code for the systems themselves.

“You can use AI to look for implementation vulnerabilities,” he said. “AI will also drive much more sophisticated waves of phishing attacks, like a bot pretending to be a human on the phone or sending emails that are close to what they should be.”

The rise of AI’s role in cybersecurity is not limited to elections. Haines notes an increase in “black hat” activity, with a larger impact footprint without a larger number of hackers as there is a proliferation of autogenerated code that is rapidly deployed. He gives the example of LLM software OpenClaw, which was vibe-coded with many vulnerabilities and then deployed on millions of computers around the world.

“With programming that comes from AI, is it actually secure or what I actually wanted?” Haines said.

Academic independence critical to cybersecurity

Haines’ interest in cybersecurity stems from being an avid reader of historical nonfiction from a young age, where he learned that signals intelligence and cryptography has played an oversized role in many historical events.

Haines’ recommendations have led to the revision and withdrawal of real-world voting systems by Switzerland and the ACT for security reasons, which he sees as impactful work.

Haines’ recommendations have led to the revision and withdrawal of real-world voting systems by Switzerland and the ACT for security reasons, which he sees as impactful work.

“Universities play a crucial role,” he said. “You need organizations which have the appetite to take a principled position even if it’s going to annoy certain governments or vendors in the space. No company will be happy with me being annoying about a problem. That’s why I work in academia.”

arrow-left bars magnifying-glass xmark