Passive Inference Attacks on Split Learning via Adversarial Regularization