Dual-Stage Safe Herding Framework for Adversarial Attacker in Dynamic Environment