User Inference Attacks on Large Language Models