Game of Trojans: Adaptive Adversaries Against Output-based Trojaned-Model Detectors