Comparing privacy notions for protection against reconstruction attacks in machine learning