When genuine AP receives the update list from ZD, it will know who is maliciousAP, then it will send deauth to those Mal APs on the channel it detected themal APs.
Please be careful as MAC and BSSID spoofed AP's may also deauthenticate actual approved client devices on Ruckus AP's and not just the "Malicious rogue" devices
Ruckus Rogue Detection type classification
rogue client detection
Details on Rogue APs and Rogue DHCP