Can We Infer Confidential Properties of Training Data from LLMs?