\section{Discussion and Limitations}
Compared with RelaxLoss, CRL is more effective for the model to maintain better generalizability while pursuing membership privacy. 
However, there are still room for improvement. 
On the one hand, it is still difficult for CRL to make the distribution of prediction of the model on the testing and the training sets fully consistent without any loss of models' utilities - thus that is a tradeoff.
On the other hand, more hyper-parameters increase the complexity of the search space.
Besides, the performance gap between CRL and Relaxloss will gradually become narrower as the model accuracy decreases a lot. We hope this work is inspiring so that in the future more research efforts can be contributed to improve the solution.


\section{Conclusion}
In this paper, we present \texttt{CRL}, an easy-deployed yet effective training paradigm that is able to help classification models defend against privacy attacks with minimal or no loss, and even with the improvement of models' generalization abilities. It makes the model behave \emph{indistinguishably} on member and non-member data by encouraging the membership prediction distribution and the non-membership distribution as \emph{consistent} as possible. Our experiments show the outperforming results compared to the well-known defense approaches and the state-of-the-art approaches. 