On the Importance of Difficulty Calibration in Membership Inference Attacks