acceptodds
Under review as a conference paper at ICLR 2027

CodeRetrX: Efficient and Scalable Function Retrieval with Hierarchical Code Search

Abstract

Function-level code search, the task of locating the functions in a large codebase that implement a given behavior (e.g., password authentication), is fundamental to program comprehension and underpins vulnerability discovery, large-scale migration, and data compliance. Emerging LLM-based tools (e.g., AI coding assistants) explore repositories iteratively, spending tokens at every step to decide what to read next, yet still miss most of the relevant functions. We present CodeRetrX, a framework for near-exhaustive, low-cost function retrieval at scale. It is built on hierarchical code search: fragment-level embeddings first locate query-relevant fragments inside every function, an LLM-guided gate then retains only the functions that contain such fragments, and full LLM evaluation is applied to those candidates alone. This design bounds token usage while retaining fragment-level semantics, enabling precise retrieval across large codebases without exhaustive traversal. On CodeRetrBench, our new benchmark of 18 multi-language repositories, CodeRetrX attains 88.16% recall, the highest among the compared methods, using only 26.17% of the tokens of exhaustive LLM traversal. Against embedding-then-LLM baselines, it raises recall from 61.43% to 88.16% (1.44x) at 78.83% of their cost. Its recall is more than 25x that of industrial coding assistants (Cursor, Claude Code) and more than 6x that of LocAgent, a state-of-the-art localization agent. Deployed as the retrieval stage of our vulnerability-discovery agent, CodeRetrX has contributed to 23 security advisories (21 CVEs, 20 of High or Critical severity) and two paid bug bounties in Web3 infrastructure, one rated High.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.