Gradient Inversion Attack: Leaking Private Labels in Two-Party Split Learning