Mind Your HEARTBEAT! Claw Background Execution Inherently Enables Silent Memory Pollution
Yechao Zhang, Shiqian Zhao, Jie Zhang, Gelei Deng, Jiawen Zhang, Xiaogeng Liu, Chaowei Xiao, Tianwei Zhang

TL;DR
This paper reveals a security flaw in Claw AI agents where background content can silently pollute memory and influence behavior without user awareness, highlighting risks of misinformation in shared session architectures.
Contribution
It formalizes the memory pollution pathway in Claw agents, demonstrates its impact with experiments, and emphasizes the threat of ordinary misinformation without prompt injection.
Findings
Misleading content can influence behavior with up to 61% credibility perception.
Memory pollution can reach 91% into long-term memory, affecting behavior across sessions.
Content dilution and pruning do not fully prevent pollution crossing session boundaries.
Abstract
We identify a critical security vulnerability in mainstream Claw personal AI agents: untrusted content encountered during heartbeat-driven background execution can silently pollute agent memory and subsequently influence user-facing behavior without the user's awareness. This vulnerability arises from an architectural design shared across the Claw ecosystem: heartbeat background execution runs in the same session as user-facing conversation, so content ingested from any external source monitored in the background (including email, message channels, news feeds, code repositories, and social platforms) can enter the same memory context used for foreground interaction, often with limited user visibility and without clear source provenance. We formalize this process as an Exposure (E) Memory (M) Behavior (B) pathway: misinformation encountered during heartbeat…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
