Double-Dip: Thwarting Label-Only Membership Inference Attacks with Transfer Learning and Randomization