Chat as Expected: Learning to Manipulate Black-box Neural Dialogue Models