Skip to content
Apixo
Blog
news· 3 min read· via The Guardian AI

Georgia Emergency Meeting Addresses AI Vulnerability Unmasking Secret Ballots

A Princeton researcher used a $20 AI subscription to re-identify 1.5 million secret ballots in Georgia, prompting state election officials to hold an emergency meeting.

Georgia Emergency Meeting Addresses AI Vulnerability Unmasking Secret Ballots

A postdoctoral researcher at Princeton University has demonstrated how easily artificial intelligence can dismantle the secrecy of democratic voting. Max Springer, working at Princeton's Center for Information Technology Policy, used a basic $20 subscription to a commercial large language model and public election data to map secret ballots back to individual voters in Georgia. The revelation prompted an emergency meeting of Georgia's state elections board as officials scrambled to secure voter privacy ahead of crucial early voting.

Springer constructed an automated analysis pipeline in just a couple of hours. During the process, the AI model complied fully with his requests, providing instructions on what additional data would be required to identify real voters. At no point did the system refuse to assist or flag the query as a potential security exploit.

Decrypting the Ballot Trail

To execute the test, Springer utilized public records obtained under the Open Records Act. By combining early-voting lists with cast vote records (CVRs)—the digital spreadsheet rows generated when paper ballots are scanned—he was able to reconstruct the voting order.

Because the unique identifiers assigned to CVRs by the scanning machines are not sufficiently randomized, the AI could align the files with precinct check-in times. Springer successfully recovered the exact voting order for 1.52 million ballots, representing 98.9% of the in-person votes cast across 114 of the 139 Georgia counties he analyzed. In smaller jurisdictions with lower voter turnout, the results were even more precise. In Heard County, the AI model matched the majority of the 650 early in-person voters to their exact ballots, and narrowed down the remaining voters to a single swap.

Political Hurdles and Proposed Fixes

In response to the findings, Georgia's outgoing Secretary of State, Brad Raffensperger, ordered county election offices to redact unique ID numbers from public CVR files after elections. Ben Adida, an MIT-trained cryptographer and founder of the non-profit VotingWorks, told the board that this measure substantially addresses the technical flaw.

The software vulnerability, which affects Dominion voting systems, was actually discovered by security researchers four years ago. While other states using the software have either patched the system or withheld the vulnerable data from public view, Georgia's efforts to upgrade its software have been stalled. Spokesperson Robert Sinners from the Secretary of State’s office indicated that funding requests for a complete system overhaul have repeatedly been rejected by the state legislature, pointing to a long-running political feud between Raffensperger and conservative lawmakers.

During the emergency meeting, board member Salleigh Grubbs circulated an alternative proposal to have poll workers manually shuffle printed ballots in a tray before scanning them. However, county election officials and board member Janelle King rejected the idea, warning that retraining workers so close to an election could create more operational problems and security risks.

What it means for developers

This incident highlights a major challenge for developers working with large language models: the difficulty of preventing models from assisting in sophisticated data re-identification attacks. While commercial LLMs have guardrails against direct hacking, they often fail to recognize when a sequence of data-processing tasks can be used to deanonymize sensitive records.

For software engineers, this emphasizes that "anonymized" public datasets are highly vulnerable when processed by modern AI. Relying solely on the safety filters of AI providers is insufficient to protect user privacy. Developers must proactively secure the underlying data structures, ensuring that sequential identifiers or timestamp metadata are thoroughly randomized or redacted before any data is exposed to public APIs or LLM pipelines.

To test how different AI models handle complex data-matching and privacy tasks, developers can try top AI models cheaply through one API at https://apixoai.online. Exploring these models under a unified platform allows development teams to benchmark compliance boundaries, test data-masking techniques, and build stronger defenses against automated re-identification exploits.


Source: Georgia holds emergency meeting on AI exposing voters’ secret ballots — The Guardian AI. Written by the Apixo team from that report.

#ai-news#artificial-intelligence#cybersecurity#data-privacy#election-security
Try it with your own tools

One key for Claude, GPT, GLM, DeepSeek and more. Pay per token with crypto.

Get your API key

Keep reading