Measure and Countermeasure of the Capsulation Attack Against Backdoor-Based Deep Neural Network Watermarks | IEEE Conference Publication | IEEE Xplore