Rethinking Membership Inference Attacks Against Transfer Learning