Inference attacks: How much information can machine learning models leak?